SETSimple. Easy. Transactions.SET Consults · a member of SET Enterprises

PUBLIC LEGAL / PRIVACY POLICY

Minimized records.
Bounded retention.

This Policy explains how SET Enterprises, LLC handles information through the public Set-Ledger dashboard and its protected server operations. It covers website access, paid review and maintenance engagement records, client workspaces, hook receipt, command audit, and archive retention.

Last updated: September 10, 2026 · Console operator: SET Enterprises, LLC

Do not submit regulated data: the Console is designed for minimized operational records, not full payment credentials, identity documents, banking credentials, biometric, or SAR information.

1. Scope and roles

This Policy applies to information SET Enterprises, LLC receives through Set-Ledger. It does not govern Stripe, OpenAI, Cloudflare, a financial institution, a webhook sender, or another third party acting under its own authority. Those parties may have separate controller, processor, service-provider, or contractual roles.

2. Information Set-Ledger handles

Set-Ledger may process:

  • public website request, device, cookie, network, diagnostic, and access-log information handled by the hosting platform;
  • webhook source, event name, status, timestamp, bounded payload as received, and payload hash;
  • command target, command name, status, timestamp, bounded submitted payload without field-level substitution, and payload hash;
  • archive metadata, including object key, size, source timestamp, archive timestamp, and expiry; and
  • customer email, provider customer and transaction identifiers, service selection, paid amount and currency, subscription state, approval history, and client workspace membership;
  • technical security information needed to protect the service.

Set-Ledger is not intended to collect full payment credentials, bank details, customer files, government identifiers, identity images, biometrics, raw transaction data, or SAR information. Set-Ledger does not automatically remove sensitive fields from accepted payloads. Oversized payloads are rejected, and senders must minimize content before transmission.

3. How information is used

Information is used to deliver the public website, verify signed machine requests, record operational events, keep webhook history separate from command history, create retrievable .log records, enforce retention, diagnose incidents, protect Set-Ledger, and comply with legal preservation duties. Public visitors cannot view stored webhook payloads, protected delivery history, command records, or archives. Command records are not used to execute commands or make financial or regulated decisions.

4. Service providers and disclosure

The Console uses ChatGPT Sites and its underlying hosting, database, and object-storage infrastructure. Those providers process information necessary to host, secure, store, and deliver the Console under their applicable agreements and notices. Information may also be disclosed when required by law, to protect rights and security, or in a business reorganization subject to appropriate safeguards.

The Console does not intentionally sell personal information, use it for cross-context behavioral advertising, or install application-controlled advertising trackers.

5. Stripe boundary

SET sends the customer email and selected service to its checkout backend and Stripe to prepare an explicitly requested checkout. Stripe processes payment details and recurring billing. Signed Stripe events provide the payment and subscription records used for engagement approval. Privy handles customer authentication for the separate wallet service. A reference to a provider alone does not establish an integration or authorize an unrelated activity.

If an authorized person separately uses Stripe or a Stripe Connect Platform, Stripe and the platform may collect and share account, representative, customer, activity, and transaction data under their own agreements and roles. Review the current Stripe Connected Account Agreement and Stripe Privacy Policy. Requests about Stripe-controlled information should be directed to Stripe or the relevant platform as those documents provide.

6. Retention and deletion

Webhook and command records remain in separate hot-history stores for up to 30 days. When a retention sweep runs, eligible records are written to .log objects and then removed from hot storage. Archive metadata and .log objects remain available for up to 180 days after archival, then are purged during a retention sweep.

Retention is triggered separately from webhook acceptance through authorized command activity and the maintenance hook; it is not a promise of deletion at an exact second. Records may be kept longer when reasonably necessary for a documented legal hold, security incident, dispute, or backup lifecycle, and access remains restricted during that period.

7. Security controls and limitations

The informational site is public, while server-side authentication and an operator allowlist protect the Delivery Center, history, and archive reads. Machine writes require a valid Stripe, GitHub, or Set-Ledger HMAC signature; timestamped signatures have a five-minute window. Other controls include duplicate detection, payload-size limits, payload hashes, separate history stores, and fail-closed behavior when storage or authorization is unavailable. Accepted payload content remains unredacted in protected storage and archived logs.

No safeguard guarantees absolute security. Authorized operators must minimize payloads, protect credentials and hook secrets, and report suspected misuse promptly through an authorized SET Enterprises channel.

8. Privacy requests and choices

Depending on applicable law and context, a person may have rights to request access, correction, deletion, restriction, objection, portability, or an appeal. Requests must be submitted to the project owner through an authorized internal SET Enterprises channel. Identity and authority will be verified before a request is fulfilled. Some records may be unavailable because they have expired, contain only hashes, or must be preserved by law.

The Console is for authorized business users and is not directed to children.

9. Changes and contact

This Policy may change if the Console’s data flow, retention model, providers, access policy, or law changes. The effective date will be updated, and material changes will receive appropriate internal notice. Privacy questions and incident reports must be sent through an authorized internal SET Enterprises channel; webhook and command payloads are not contact channels.