Skip to content

Penumbra Platform Privacy Policy

Last updated: May 30, 2026 · Effective: May 30, 2026 · v1.0

This policy describes how Penumbra (a payment orchestration platform operated by Arrowhead Advisory Group LLC) collects, uses, retains, and shares information when merchants operate their payment processing through the Penumbra platform. It is distinct from the privacy disclosures on our public marketing surfaces (penumbrahq.com, arrowheadadvisorygroup.com), which cover prospective-customer browsing only.

1. Who we are

Penumbra is a brand operated by Arrowhead Advisory Group LLC, a Florida limited liability company. We provide a payment orchestration platform that routes card-present and card-not-present transactions across multiple payment service providers, performs chargeback defense, and offers operational analytics to merchants.

For privacy questions, data-subject access requests, or any legal notice under this policy, contact us at privacy@penumbrahq.com.

2. Information we collect from merchants

When you onboard your business onto the Penumbra platform we collect the following categories of information:

  • Business identification: legal business name, DBA, EIN/TIN, business type, formation jurisdiction, MCC code, business address, and website.
  • Principal/owner identification: name, date of birth, last-four of Social Security Number (or equivalent national identifier), ownership percentage, residential address, and contact information for each owner with twenty-five percent or greater ownership. This data is collected to satisfy our Bank Secrecy Act and Know-Your-Customer obligations.
  • Banking information: ABA routing number, deposit account number, and account type used for settlement.
  • Processing history: monthly volume estimate, average ticket size, current processor (if any), and chargeback history disclosed during onboarding.
  • Contract acceptance: electronic signature, signature date, and IP address at the time you accept the Merchant Service Agreement.

3. Information we collect during ongoing use of the platform

  • Transaction data: transaction amount, currency, timestamp, merchant identifier, processor identifier, authorization code, settlement status, refund status, and routing decision metadata. We do not store raw cardholder primary account numbers (PANs) on Penumbra infrastructure; card data is tokenized client-side by the integrated processor's JavaScript libraries (Stripe.js, Worldpay Collect.js, Square Web Payments) and only the resulting processor token is transmitted to Penumbra.
  • Dispute and chargeback data: reason codes, dispute amounts, evidence packages assembled by the platform, rebuttal text generated by our AI services, and any image evidence (receipts, signatures, shipping proofs) uploaded by merchants or end-customers to support the defense.
  • Operational telemetry: API request logs, authentication events, error logs, and performance metrics necessary to operate the platform and meet our service level commitments.
  • Account user data: name, email, role, last-sign-in timestamp, and authentication factors for each merchant team member with platform access.

4. Information we collect about end-customers (your customers) when processing payments on your behalf

When you process a transaction through Penumbra we receive limited information about your end-customer from your point-of-sale or checkout integration. This information may include the cardholder name, billing address, email address (if provided by your checkout), Address Verification Service result, Card Verification Value match result, and the processor token representing the cardholder payment instrument. We process this data as your service provider (a "processor" under the California Consumer Privacy Act and a "processor" under the General Data Protection Regulation) solely to execute the transaction, route the payment, defend against chargebacks, and maintain audit trails required by applicable law.

We do not use end-customer data for our own marketing, do not sell it to third parties, and do not enrich it with information from other sources. Our obligations to end-customers flow through the Data Processing Addendum between Penumbra and the merchant.

5. How we use the information

  • To deliver the platform: routing transactions to the optimal payment service provider, assembling chargeback evidence, generating rebuttal letters, providing analytics and operational dashboards.
  • To satisfy legal and regulatory obligations: Know-Your-Customer screening, anti-money-laundering monitoring, Office of Foreign Assets Control sanctions screening, suspicious activity reporting, tax reporting (including IRS Form 1099-K where applicable), and any other obligation imposed by applicable law.
  • To prevent fraud and abuse: identifying patterns consistent with merchant fraud, end-customer fraud, account takeover, or platform abuse.
  • To improve the platform: aggregate anonymized analysis of platform performance, routing decisions, and chargeback outcomes. This use never identifies any individual merchant or end-customer.
  • To communicate with you: service announcements, security notifications, billing communications, and responses to your inquiries.

6. Subprocessors

Penumbra relies on the following categories of third-party subprocessors to deliver the platform. Each subprocessor receives only the categories of data necessary for its function and is contractually obligated to protect that data consistent with this policy and any applicable Data Processing Addendum.

  • Payment service providers: Worldpay, Adyen, NMI, Stripe, Square, Circle, Dwolla, PayPal. Each processes transactions that the routing engine assigns to it. Each maintains its own privacy policy applicable to the transactions it processes for you.
  • Infrastructure: Railway (application hosting), Netlify (dashboard delivery), Cloudflare (where applicable, edge security and DNS), and the underlying public cloud providers Railway and Netlify rely on.
  • AI services: Anthropic (primary, Claude models), Google (Gemini, failover), OpenAI (GPT models, failover, activated at launch). These services generate chargeback rebuttal text and perform image evidence forensics. Transaction-identifying inputs are tokenized before transmission where feasible; raw cardholder identifiers are never sent to these services.
  • Email delivery: Resend, for transactional notifications. Bounce and complaint events are processed via signed webhooks and trigger automatic suppression-list updates.
  • Observability and security: Sentry (error tracking), Prometheus and Alertmanager (operational metrics), Microsoft Clarity and RB2B on the public marketing surfaces only (not on the authenticated dashboard).
  • Sanctions screening and identity verification: integrated payment service provider screening as the initial layer; future independent OFAC and identity-verification subprocessors will be disclosed here when activated.

A complete subprocessor list with current versions is available upon request and is referenced in the Data Processing Addendum between Penumbra and the merchant.

7. Data retention

We retain information for the periods required by applicable law and our payment-card-industry obligations. Specifically:

  • Transaction records: seven years from the date of the transaction, consistent with Payment Card Industry Data Security Standard guidance and Internal Revenue Service recordkeeping requirements.
  • Know-Your-Customer documentation: five years from the closure of the merchant account, consistent with Bank Secrecy Act recordkeeping requirements.
  • Dispute and chargeback records: the longer of seven years or the duration of any active legal proceeding involving the dispute.
  • API request logs: ninety days for operational logs and twelve months for security-relevant authentication logs.
  • Marketing and prospect communications: the period necessary to manage the prospective business relationship, generally not exceeding three years from last contact.

Where applicable law requires longer or shorter retention than the above, applicable law controls. Merchants may request earlier deletion of records not subject to legal retention requirements through the contact email above.

8. Security

We implement reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction. These include:

  • Encryption of all sensitive fields at rest using the Advanced Encryption Standard at 256-bit key length (AES-256).
  • Encryption of all data in transit using Transport Layer Security version 1.3 or later (TLS 1.3+).
  • Tokenization of cardholder primary account numbers on the merchant's checkout surface, before the data reaches Penumbra infrastructure, consistent with Payment Card Industry Data Security Standard Self-Assessment Questionnaire A posture.
  • Role-based access controls and least-privilege provisioning for Penumbra personnel.
  • Continuous monitoring, alerting on anomalous access patterns, and incident response procedures consistent with our published Incident Response Plan.
  • Annual independent security review (initial review pending; details will be added when completed).
  • Annual SOC 2 Type II audit (target: Phase 4 / 2027 of the platform roadmap).

No security program is perfect. In the event of a security incident affecting your data, we will notify you consistent with our contractual obligations, applicable law, and our Incident Response Plan. Notification timing is the lesser of seventy-two hours from confirmation of the incident or any shorter period required by applicable law.

9. Your rights and choices

Merchants and merchant principals may exercise the following rights with respect to their information, subject to verification of identity and to any exceptions provided by applicable law:

  • Right to know: request disclosure of the categories and specific pieces of personal information we have collected about you in the prior twelve months.
  • Right to access: request a copy of your personal information in a portable format.
  • Right to correct: request correction of inaccurate personal information.
  • Right to delete: request deletion of personal information not subject to legal retention requirements.
  • Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising. The right is described here for completeness.
  • Right to non-discrimination: we will not deny goods or services, charge different prices, or provide a different level of service in retaliation for exercising any of the above rights.

To exercise any of the above rights, email privacy@penumbrahq.com with the subject line "Privacy Request." We will respond within forty-five days, with a single forty-five-day extension permitted under California law if circumstances warrant.

End-customers whose information we process on behalf of a merchant should direct their requests to the merchant whose payment they made. We support merchants in fulfilling end-customer requests as their service provider.

10. International data transfers

Penumbra operates from the United States. Our infrastructure is currently hosted in the United States. We do not knowingly process personal information from the European Economic Area, the United Kingdom, or Switzerland through our public marketing surfaces. For merchants whose end-customers include residents of those regions, the Data Processing Addendum between Penumbra and the merchant addresses cross-border transfer mechanisms (including, where applicable, Standard Contractual Clauses).

11. California residents

If you are a California resident, you have the rights described in Section 9 above under the California Consumer Privacy Act and the California Privacy Rights Act, including the right to opt out of the sale or sharing of personal information. Penumbra does not sell personal information collected through the platform or share it for cross-context behavioral advertising. The "Do Not Sell or Share My Personal Information" link on our public marketing surfaces addresses prospect-tier reverse-IP enrichment by RB2B, which is not operative on the authenticated dashboard surface this policy governs.

12. Children

The Penumbra platform is a business-to-business platform not directed to children under thirteen years of age. We do not knowingly collect personal information from children under thirteen. If we learn that we have collected personal information from a child under thirteen, we will delete it promptly.

13. Changes to this policy

We may update this policy from time to time. We will post the updated policy at this URL and update the "Last updated" date at the top. For material changes affecting how we use or share information, we will provide additional notice to active merchants by email at least thirty days before the change takes effect, except where a shorter period is required by law or warranted by a security or compliance imperative.

14. Governing law and jurisdiction

This policy is governed by the laws of the State of Florida, without regard to its conflict-of-laws principles. Disputes arising under or related to this policy are subject to the exclusive jurisdiction of the state and federal courts located in Escambia County, Florida, except where applicable law provides otherwise.

Contact

Arrowhead Advisory Group LLC, operating the Penumbra brand.
Email: privacy@penumbrahq.com

This document is version v1.0. The Merchant Service Agreement and the Data Processing Addendum are the controlling documents for any commercial relationship.