When you share your merchant processing statements with weAudit, you are placing significant trust in our hands. That trust is something we take seriously — not just as a contractual obligation, but as a reflection of who we are and how we operate.
Data Handling
weAudit collects and retains only the information necessary to perform the audit engagement — including merchant processing statements, fee schedules, and audit findings. weAudit does not store, transmit, or retain any cardholder data, payment card numbers, or sensitive authentication data belonging to Client or Client’s customers.
Access Controls
Access to Client audit data is strictly limited to weAudit’s Chief Executive Officer, Vice President of Operations, and the auditor assigned to Client’s account. No other weAudit personnel, contractors, or third parties are granted access to Client-specific data without Client’s prior written consent.
Infrastructure Security
All Client data is hosted on DigitalOcean’s enterprise cloud infrastructure. Under the industry-standard Shared Responsibility Model, weAudit clients benefit from DigitalOcean’s certified security foundation. All data is transmitted exclusively over HTTPS-encrypted connections, and role-based authentication is required for all internal system access.
MADR Technology & Proprietary Systems
weAudit utilizes MADR (Mass Analysis Data Reporting), its proprietary, in-house developed auditing technology, to perform analysis and generate findings. MADR operates exclusively on weAudit’s secured infrastructure, does not transmit Client data to external platforms or third-party services, and is subject to the same access controls and confidentiality obligations described throughout this policy.
No Third-Party Disclosure
weAudit will not sell, license, share, or disclose Client data to any third party for any purpose — including marketing, benchmarking, or research — without the express written consent of Client. This obligation survives the termination of the engagement agreement.
Data Retention
weAudit retains Client audit data for a period of three (3) years following the conclusion of the engagement, after which data is securely archived or deleted. Clients may request deletion of their data at any time by submitting a written request to weAudit’s principal office. weAudit will confirm completion of any deletion request within thirty (30) business days.
Security Incidents
In the unlikely event of an unauthorized access or data breach affecting Client data, weAudit will notify Client in writing within seventy-two (72) hours of discovery and will cooperate fully in any remediation efforts.
Limitation
The security commitments on this page apply solely to data in weAudit’s custody and control. weAudit is not responsible for the security of data transmitted by Client through unsecured channels or stored on Client’s own systems.