Bank data is sensitive. Here is exactly what we collect, where it goes, and how it's protected. We've tried to write this so it's actually useful — not a marketing page dressed up as a policy.
When your end user connects their bank through Plaid Link, Delegate reads the minimum set of signals needed to score whether the account represents a real banking relationship. Specifically:
crypto module before storage. rolling outThe application servers and database run on Railway. We do not operate our own physical infrastructure. Database backups are encrypted and retained per Railway's managed-Postgres policy.
organization_id. Customers can only read and write their own end users' data. Isolation is enforced at the application query layer and verified by tests.Plaid is our open-banking provider. They are how Delegate reaches more than 12,000 US financial institutions without negotiating each one individually.
Every verification, every data access, every configuration change, every case resolution is written to an append-only audit log.
We have tried to be precise about what is in place versus what is in progress. This section will change as our compliance posture matures.
Every third-party service Delegate uses that touches customer or end-user data is listed below. We will update this list and notify customers at least 30 days before adding a new subprocessor that processes user data.
security@deliverfaster.services. We will acknowledge within one business day and keep you updated until resolution.