Privacy Policy
Privacy terms for ATM accounts, checkout, app integrations, payment records, and AT Protocol data.
1. Overview
This Privacy Policy explains how Atmosphere Money Inc. collects, uses, shares, and protects information when people use ATM websites, dashboards, checkout, app integrations, APIs, webhooks, and related services.
ATM is built on AT Protocol. Some records and profile data are public by design. Other information, especially payment processor data, buyer contact details, fulfillment details, OAuth tokens, and compliance data, is kept private where ATM controls the system.
2. Information we collect
We collect AT Protocol identity information such as DID, handle, profile display name, avatar, description, OAuth grants, service endpoints, public records, and records you create or authorize ATM to create.
When you first sign in, ATM may create your ATM payment profile using available public Atmosphere profile data, which today usually means your existing Bluesky profile record (app.bsky.actor.profile), to seed your display name, avatar, and description. After creation, your ATM profile record is the payment-facing source of truth, and you can edit it in settings.
We collect payment and commerce information such as payment amount, currency, payment type, payer or guest status, recipient, originating app, product or ticket references, discounts, subscription status, invoices, receipts, refund status, dispute status, and app webhook events.
If you create a pledge before a recipient can accept payments, we collect the pledge amount and cadence, automatic-conversion choice, consent version and time, payer email, status and attempt history, and Stripe references for the saved card. Stripe collects the card details. ATM does not store the raw card number or security code, and no payment or public payment record exists merely because a card was saved.
We may collect customer and fulfillment information such as name, email, billing address, shipping address, messages, order details, attendee names and registration answers for tickets, ticket status, tax information, and support communications when needed for checkout, fulfillment, compliance, support, or fraud/risk handling.
If your AT Protocol account shares an account email with ATM during sign-in, ATM stores it privately and uses it only as a convenience hint, such as prefilling processor onboarding or checkout contact fields. ATM never writes email addresses into public AT Protocol records and does not forward this account email hint to apps on its own; the only buyer contact details an originating app receives are those collected or confirmed during that app's checkout, delivered through private app-scoped channels such as signed webhooks and scoped endpoints.
We collect technical information such as IP address, device/browser data, logs, request metadata, rate-limit data (including IP-based rate-limit counters), and diagnostic events.
ATM uses first-party cookies and browser storage to keep you signed in, remember theme and account-switcher choices, protect checkout and return flows, and operate guest subscription or scanner sessions. Dashboard and scanner sessions are separate; scanner sign-in proves control of an AT Protocol account without creating payment roles. Guest subscription management links use single-use tokens stored as hashes and expiring within 24 hours. ATM does not use third-party advertising or analytics cookies.
When ATM records acceptance of recipient or app terms, it stores the DID, agreement, version, source, server time, and keyed hashes of observed IP and browser user-agent signals. The acceptance record does not store the raw IP address or raw user-agent in those audit fields.
3. Sources of information
We receive information directly from you when you sign in, configure an account or app, complete checkout, save a pledge card, manage a subscription, claim or scan a ticket, contact support, or exercise a privacy right.
We also receive information from the originating app, a recipient or organizer, Stripe and other payment or financial partners, your AT Protocol account host, public AT Protocol repositories and indexers, identity and DID directories, service providers, and other people involved in a payment, order, ticket, refund, dispute, or support request.
ATM creates information from service activity, including ledger and proof status, fraud or security signals, account and app configuration, fee distributions, delivery logs, consent evidence, ticket audit events, and aggregated reliability or payment statistics.
4. Payment processor information
ATM uses payment processors such as Stripe. Payment details, onboarding data, identity verification, bank account details, payment method details, disputes, payouts, tax settings, and similar processor information may be collected directly by the processor or displayed through embedded processor components. Where Stripe collects or processes information, Stripe's Privacy Policy and applicable Stripe terms also apply.
ATM stores only the processor information it needs to operate the service, reconcile payments, support dashboards, route app fees, handle refunds or disputes, and meet legal or compliance obligations. ATM does not store raw card numbers or full payment credentials.
Processor information may be shared between ATM, the processor, connected accounts, originating apps, financial partners, card networks, banks, and service providers as needed to process payments, manage risk, comply with law, support disputes, provide receipts, and operate connected-account services.
5. Public protocol data
Public AT Protocol data can be read, copied, indexed, cached, displayed, or stored by anyone. This may include ATM profile fields, catalog records, and, when a live checkout identifies public attestation as enabled, an ATM broker-anchored payment record and proof. A payment record may include the recipient DID, final amount and currency, payment type or cadence, transaction identifier, timestamps, public product or entitlement references, and proof references or status.
The ATM broker record does not by itself name a signed-in payer. ATM requires authority tied to the payment before writing a payer-owned public record, and a recipient-owned proof is published only through manual sync or a separate auto-sync choice backed by a valid grant. A guest payment record has no payer DID. The owner of any payer- or recipient-owned repository is nevertheless identifiable from that repository.
Completed payment records are durable receipts. A refund, dispute, or transfer may update or invalidate a proof without deleting the historical payment record. Deleting data from ATM may not delete records or copies stored by an account host, appview, search index, cache, archive, or third-party app. Do not publish sensitive personal information in public protocol records.
6. How we use information
We use information to provide ATM, authenticate users, create and manage checkout sessions, process payments, save and convert authorized pledges, route app fees, manage subscriptions, send recurring-payment notices, issue and verify tickets, write or verify payment proofs, deliver webhooks, display dashboards, provide support, prevent fraud and abuse, improve performance, and comply with law.
We may use aggregated or de-identified information to understand usage, reliability, checkout performance, app activity, and payment trends.
Where data-protection law requires a legal basis, ATM processes information as needed to perform its agreements and provide requested services; comply with legal, accounting, tax, payment, fraud-prevention, and security obligations; pursue legitimate interests in operating, securing, supporting, and improving ATM; and, where required, based on consent. You may withdraw consent for future processing where consent is the basis, without affecting earlier processing.
7. How information is shared
We share information with service providers that help us operate ATM. Current providers include Stripe (payment processing, Connect onboarding and identity verification, Link, and fraud/risk tooling), Neon (database hosting), Vercel (web hosting and deployment), Railway (hosting for ATM's AppView indexing service), Upstash (Redis infrastructure used for rate limiting), Cloudflare R2 (a delivery cache for avatars and media, not canonical storage), Resend (transactional email such as ticket delivery and guest subscription links), and Inngest (background job processing). ATM also interacts with the AT Protocol network, including the PLC directory for DID resolution and your PDS host for OAuth sign-in and record reads/writes. We may update this provider list as ATM's infrastructure changes.
We share app-scoped payment and order information with the app that originated a payment so the app can provide checkout, fulfillment, customer support, fraud/risk handling, refunds, reporting, webhooks, and proof status. Apps do not receive unrestricted creator payment-account data through ATM.
We share information with creators, organizers, or sellers when they need it to fulfill a purchase, support a payer, manage a subscription, verify a ticket, handle a refund, or respond to a dispute. We may share information when required by law, legal process, security needs, or to protect rights and safety.
Depending on the activity and applicable law, ATM may act as an independent controller for account, ledger, security, processor, compliance, and platform operations, while an originating app or recipient may separately control information it receives for fulfillment, customer support, event operations, or its own legal duties. Apps and recipients are responsible for their own notices and lawful processing. If a separate data-processing agreement is legally required for a particular relationship, the parties must put one in place before relying on ATM for that processing.
We do not sell private payment, checkout, fulfillment, or connected-account personal information, and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics or for purposes outside providing, securing, supporting, and complying with the service. Public AT Protocol records are different: they are public by design and may be viewed, copied, indexed, or reused by third parties outside ATM.
8. Additional U.S. state disclosures
During the preceding 12 months, ATM has collected the categories described above: identifiers and public profile information; customer, payment, transaction, subscription, pledge, commercial, ticket, and support records; internet or device activity; professional or business information supplied for recipient or app onboarding; sensitive information such as account credentials, financial details handled by Stripe, government or tax information used for onboarding, and private communications; and inferences used for fraud, security, or account support.
ATM uses and discloses these categories for the service, business, security, legal, and compliance purposes described in this Policy. Recipients and originating apps receive only transaction-scoped customer or fulfillment information they need for their separate responsibilities. Service providers and payment partners receive information for contracted services, processing, risk, security, support, or legal compliance.
ATM has not sold private personal information or shared it for cross-context behavioral advertising during the preceding 12 months. ATM does not knowingly sell or share the personal information of people under 16. ATM uses sensitive personal information only for providing, securing, supporting, and complying with the service, not to infer characteristics for advertising. Public AT Protocol records are publicly available by design and are distinct from a sale of ATM's private customer data.
9. Your choices and rights
You may update your ATM profile from settings. You may revoke AT Protocol OAuth grants through supported account or provider tools. You may manage payment methods, subscriptions, and guest subscription links through ATM or processor-provided flows where available.
Depending on where you live, you may have rights to know or access the information ATM holds about you; correct inaccurate information; delete information; receive a portable copy; restrict or object to processing; withdraw consent; opt out of qualifying sale, sharing, or targeted advertising; and appeal a denied request. ATM does not discriminate against you for exercising an applicable privacy right.
Contact ATM to make a privacy request. You may use an authorized agent where applicable law permits. ATM may verify your identity, account control, or the agent's authority before responding and will respond within the period required by applicable law. If ATM denies a request, the response will explain the applicable reason and any available appeal path. Some information may need to be retained for payments, consent evidence, fraud prevention, legal, tax, accounting, security, dispute, or protocol-integrity reasons. Public records controlled by your account host or copied by third parties may need to be addressed with those services as well.
10. Data retention
We keep information as long as needed to provide ATM, maintain payment records, operate proof and ledger systems, comply with law, resolve disputes, prevent fraud, enforce agreements, and support accounting or tax obligations.
Short-lived operational data is trimmed on default schedules: completed checkout-session state after about 30 days; delivered webhook delivery logs after about 30 days and failed deliveries after about 90 days; processor webhook event logs after about 30 days; short-lived tokens after about 7 days; expired OAuth sessions after about 30 days; released or expired ticket holds after about 30 days; and ticket audit and ticket delivery logs after about 365 days. Guest subscription management links are single-use and expire within 24 hours. These windows are operational defaults that ATM may tune over time.
Canonical payment, receipt, ledger, attestation, dispute, refund, subscription, issued-ticket, legal-acceptance, recurring-notice evidence, pledge, and public protocol records are not trimmed by those operational schedules and may be retained for longer periods because they are part of financial, consent, legal, audit, and protocol-integrity systems. When a pledge is cancelled, expires, fails terminally, or is superseded, ATM detaches the saved platform card but may retain the pledge and consent history as authorization and audit evidence.
11. Security
We use technical and organizational safeguards designed to protect private data, including access controls, private no-store responses for sensitive dashboard APIs, rate limits, scoped service-auth, and separation between public protocol records and private payment data. Sensitive operational secrets are stored in reduced forms where possible: guest subscription management tokens and ticket scan tokens are stored as hashes, and payer-assertion tokens are never stored in full; ATM keeps only verification metadata such as issuer, expiry, and a token hash.
No system is perfectly secure. You are responsible for keeping your AT Protocol account, devices, email, payment processor account, and credentials safe.
If a security incident affects personal information, ATM will investigate and provide notices to affected people, regulators, processors, apps, or recipients when applicable law or contractual duties require it.
App developers that receive ATM data must follow the App Developer Terms, keep webhook and service-auth secrets secure, and use payer, buyer, attendee, customer, and recipient information only for the app-scoped purposes ATM permits.
12. Children
ATM is not directed to children under 13, children under 13 may not create an ATM account or use ATM checkout, and ATM does not knowingly collect personal information from a child under 13. If you are under the age of majority where you live, you may use ATM only with the permission and supervision of a parent or legal guardian who agrees to the applicable terms and is responsible for payment activity. Payment recipients must satisfy the processor's age and contracting requirements, which may require being at least 18.
If you believe a child under 13 provided personal information to ATM, contact ATM so it can investigate and delete the information where appropriate.
13. International use
ATM, apps, processors, and service providers may process information in multiple countries, including the United States. Where applicable law requires safeguards for an international transfer, ATM relies on lawful mechanisms made available for the relevant transfer, such as contractual protections, adequacy decisions, or certified transfer frameworks. Contact ATM for information about safeguards that apply to a particular transfer.
14. Changes and contact
We may update this Privacy Policy as ATM changes. ATM will ordinarily provide at least 30 days' advance notice of a material change through the site, dashboard, email, app communications, or another appropriate channel, unless an earlier change is reasonably necessary for law, security, fraud prevention, or processor requirements.
Privacy questions or requests can be sent through ATM's contact page, to contact@atmosphere.money, or by mail to Atmosphere Money Inc., 150 Jefferson St, Unit 3, Brooklyn, NY 11206.
Questions?
Contact Atmosphere Money through the contact page or by email at contact@atmosphere.money. Legal notices may also be mailed to Atmosphere Money Inc., 150 Jefferson St, Unit 3, Brooklyn, NY 11206.