This policy explains the limited information Nuemed Pay uses to connect your existing Stripe account, operate the app and support you. It is separate from Nuemed’s clinic-platform privacy policy.
1. Scope of this policy
This Privacy Policy applies to the Nuemed Pay applications for iOS and Android, the Nuemed Pay backend service and related Nuemed Pay support. It explains what information is processed when a merchant connects an existing Stripe account and uses Tap to Pay on a supported phone or a supported Stripe Terminal reader.
Nuemed Pay is a business service for merchants. It is separate from the Nuemed clinic-management platform. The clinic-platform privacy policy remains available at nuemed.io/privacy.
2. Who we are
Nuemed Pay is provided by Vantis Strategies LLC, a Wyoming limited liability company doing business as Nuemed. Our mailing address is 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA.
Privacy questions and rights requests may be sent to privacy@nuemed.io. Product support is available through Nuemed Pay Help.
3. Stripe and payment data
Nuemed Pay connects to the merchant’s existing Stripe account using Stripe Connect. Stripe provides the payment-processing account, Stripe Terminal services, Tap to Pay functionality, payment ledger, card-data handling, settlement and payout services under the merchant’s agreements with Stripe.
Stripe Terminal readers and Tap to Pay collect and encrypt card information. Nuemed Pay does not receive or store full card numbers, security codes, PINs or bank-account credentials.
Nuemed Pay’s PostgreSQL database does not copy or retain payment amounts, tips, refunds, customer details, receipt email addresses, card brands, card last-four digits, payment descriptions or payment history. The merchant’s payment record remains in Stripe.
Stripe processes information under its own terms and privacy policy.
4. Information Nuemed Pay keeps
While a Stripe account is connected and active, Nuemed Pay keeps only the operational information needed to authenticate the app and make authorised Stripe requests:
- The Stripe connected-account identifier, account country, default currency, test/live mode and operational capability flags such as whether charges and payouts are enabled.
- Random internal record identifiers.
- A SHA-256 hash of the random app-installation identifier and a hash of the session token. The original installation identifier and session token are stored using the device’s operating-system secure storage, such as iOS Keychain or Android Keystore.
- Session expiry, last-use time and basic record timestamps.
- The selected Stripe Terminal location identifier and preferences such as whether tips are enabled and the preferred payment method.
- Short-lived Stripe login-flow and handoff hashes.
- Stripe webhook event identifiers and event types used to prevent duplicate processing.
Nuemed Pay does not send the device’s user-assigned name to its backend. A merchant’s business name and business email may be read from Stripe when displaying connection status in the app, but they are not stored in the Nuemed Pay database.
5. Information processed temporarily
The Nuemed Pay backend temporarily receives and processes information needed to service a request in real time. This can include a payment amount, tip amount, Stripe location identifier, a refund amount or reason, limited payment-status information returned by Stripe, and a receipt email address supplied after a payment.
A receipt email address travels through the Nuemed Pay backend solely so it can be forwarded to Stripe. Nuemed Pay does not retain the email address in PostgreSQL or include it in application logs.
If the merchant creates a Stripe Terminal location, the business location details entered in the app pass through the Nuemed Pay backend to Stripe and are not copied into the Nuemed Pay database.
Please do not submit patient names, medical information, card information or unnecessary payment information through support or diagnostics. Nuemed Pay does not provide payment-reference or description fields for recording this information.
6. Device permissions
Bluetooth
Bluetooth access is requested when a merchant searches for and connects to a supported Bluetooth reader. The permission is used for reader discovery, connection and operation.
Location
Stripe Terminal may request device location when needed for Tap to Pay, reader compatibility, security or payment operation. Nuemed Pay’s backend never receives or stores the device’s GPS coordinates. Stripe may process location information as part of its Terminal service.
Nuemed Pay does not access the merchant’s contacts, photographs, microphone or advertising identifier.
7. Diagnostics, crash reports and support
Nuemed Pay does not include advertising SDKs, general-purpose product-analytics SDKs, session replay or a separate crash-reporting SDK. Stripe states that its mobile SDK collects analytics and fraud-prevention information when its components are used, including device model, operating-system version, device characteristics and interactions with the Stripe SDK. Stripe says this information is used to improve its products and prevent fraud, and is not used for advertising. More information is available in Stripe’s mobile SDK privacy details. Apple or Google may make standard crash reports available through their developer consoles where a user has chosen to share diagnostics with app developers.
The app can prepare an optional manual diagnostics report containing only the app version, broad device type, operating-system version and a generic error code. The merchant sees the report before choosing where to share it. Nothing is transmitted automatically.
If a merchant contacts support, Nuemed receives the information the merchant chooses to include. Support messages should not contain patient, medical, card or payment information.
8. Why we use information and our legal bases
We use the limited information described above to:
- Connect and authenticate the merchant’s Stripe account and device session.
- Provide payments, refunds, receipts, locations, preferences and transaction views requested by the merchant.
- Protect the OAuth handoff, prevent duplicate webhook processing, maintain security and investigate operational faults.
- Provide support, comply with law and enforce the Nuemed Pay Merchant Terms.
Where data-protection law applies, our legal bases may include performing our contract with the merchant, our legitimate interests in operating and securing the service, and compliance with legal obligations. We do not use Nuemed Pay information for targeted advertising or sell it to data brokers.
9. Sharing and service providers
Information is disclosed only as needed to operate Nuemed Pay, comply with law or protect the service:
- Stripe: payment processing, Stripe Connect, Terminal, Tap to Pay, receipts, refunds, disputes, payment-account services, and the SDK analytics and fraud-prevention processing described above.
- Hetzner and Coolify: EU-region infrastructure used to host the backend, PostgreSQL database, operational logs and encrypted backups.
- Apple and Google: app distribution and any platform-provided crash reports or services governed by the user’s device settings and the applicable platform policies.
- Authorities or professional advisers: where disclosure is required by law or reasonably necessary to establish, exercise or defend legal rights.
Production access is restricted to named personnel, protected with multifactor authentication and recorded through the relevant platform controls. There is no routine employee or contractor access to merchant payment information.
10. Retention, disconnection and deletion
- Connection, session and preference records are kept while the merchant remains connected and active.
- Each authenticated app request extends the session for 90 days. An inactive connection with no valid session is automatically revoked and deleted after 90 days.
- Processed Stripe webhook identifiers are deleted after 30 days.
- Expired Stripe login-flow records are cleared by the scheduled lifecycle process and retained for no more than 30 days after expiry.
- Application and hosting logs are retained for no more than 30 days.
- Deleted data may remain in encrypted rotating backups for up to 30 days before automatic expiry.
A merchant can choose Disconnect and delete Nuemed data under Settings → Help & legal. Nuemed Pay then revokes its Stripe access and permanently deletes the connection, device session, preferences, login flows and related webhook records. The merchant’s Stripe account and Stripe payment history are not deleted.
If Stripe is temporarily unavailable when access is revoked, Nuemed Pay deletes the main records and retains only the Stripe account identifier in a retry job. That identifier is deleted immediately after Stripe confirms revocation.
Instructions are available at Nuemed Pay Help. A merchant may also contact privacy@nuemed.io.
11. Security
Nuemed Pay uses HTTPS, hashed tokens and identifiers, operating-system secure storage, separate production and staging services, Stripe webhook-signature verification, rate limiting, restricted operational logs, encrypted backups and role-based production access.
Stripe secret keys are held on the backend and are never embedded in the mobile applications. No service can guarantee absolute security, and merchants remain responsible for protecting their devices, Stripe credentials and authorised access.
12. Hosting and international processing
The Nuemed Pay backend, PostgreSQL database, operational logs and encrypted backups are hosted on Hetzner infrastructure in Frankfurt, Germany through Coolify. Stripe, Apple and Google may process information in other locations under their own contractual and legal arrangements.
Where applicable law requires an international-transfer safeguard, we use appropriate contractual or legal mechanisms for providers acting on our behalf.
13. Your privacy rights
Depending on where the merchant or an individual is located, rights may include access, correction, deletion, restriction, objection and data portability, as well as the right to complain to a data-protection authority.
Requests may be sent to privacy@nuemed.io. We may need to verify the requester’s identity and authority. These rights are not absolute and may be limited where law permits or requires.
Nuemed Pay is intended for business users and is not directed to children.
14. Nuemed website privacy
This policy describes the Nuemed Pay app and backend. Visits to the public Nuemed website—including this policy page—are governed by the general Nuemed Privacy Policy and Cookie Policy. Website analytics are separate from the Nuemed Pay app; the app itself does not contain analytics or tracking SDKs.
15. Changes and contact
We may update this policy when Nuemed Pay, our providers or applicable requirements change. We will update the date above and provide additional notice where a material change requires it.
Privacy enquiries: privacy@nuemed.io
Support: info@nuemed.io
Mail: Vantis Strategies LLC, 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA.