Privacy Policy

Pacha Exchange is a business platform. This policy explains what we collect about you and the people at your organization, why we hold it, who we share it with, how long we keep it, and how you get it back or have it erased.

Last updated: August 28, 2026

1. Who controls your data

Pacha Exchange, Inc. is a company incorporated in Delaware, United States, with its place of business at 3114 Leland Street, Chevy Chase, Maryland 20815, United States. It is the controller of the personal data described here. Write to administration@pachaexchange.com, or to that address, for anything in this policy — including requests to see, correct, export or delete your data.

We are established in the United States and serve users in Peru, the European Union and elsewhere, so we comply with United States federal and state privacy law, with Peru's data protection law, and, where it applies, with the GDPR. Our operations in Peru are run by our Peruvian subsidiary, part of the same group and our establishment there. Users in Peru may send any request in this policy to that company or to us; either route reaches the same team.

Where your organization uploads data about its own staff, customers or suppliers into the platform, your organization is the controller of that data and we act as its processor, under the terms of your service agreement with us.

2. What we collect

CategoryExamples
Account and identityName, work email, phone, job role, password hash, language, profile photo, login history and the devices or IP addresses you sign in from
Organization and legalCompany name, tax identifier, registered and operating addresses, legal documents you upload, team membership and permissions
CommercialListings, orders, negotiations, shipments, inventory, agronomy records, connections and contacts, and the messages and notes attached to them
FinancialPrices, payment terms, invoices, settlements, payment evidence, and bank account details you add for payouts (stored encrypted)
Files you uploadInvoices, packing lists, liquidations, receipts, photos and any other document or spreadsheet you or your counterparties submit
Technical and usagePages visited, features used, timestamps, browser and device data, error logs, and AI token usage counted for billing

We do not ask for special-category data (health, biometrics, political or religious views) and you should not upload it. We do not knowingly collect data from anyone under 18; the platform is for business use only.

3. Where it comes from

  • From you directly, when you register, fill in a form or upload a file.
  • From your organization, when an administrator invites you or edits your permissions.
  • From your counterparties, when another company on the platform records an order, a document or a contact that names you.
  • From service providers, such as carriers and tracking services that return shipment status, and payment providers that confirm a transaction.

4. Why we use it, and on what legal basis

PurposeLegal basis
Running your account and delivering the features of your planPerformance of our contract with you or your organization
Processing your documents with AI agents so the platform can extract, reconcile and route the data they containPerformance of contract; legitimate interest in automating manual data entry
Billing, invoicing, collections and usage meteringPerformance of contract; legal obligation under tax law
Security, fraud prevention, abuse detection and audit loggingLegitimate interest in keeping the platform and its users safe
Service emails: verification codes, invitations, payment reminders, incident noticesPerformance of contract
Product analytics and improvementConsent, given through our cookie banner
Responding to lawful requests and defending legal claimsLegal obligation; legitimate interest

Where we rely on consent, you may withdraw it at any time without affecting anything we did before you withdrew it.

5. How we use artificial intelligence

Parts of the platform are built on large language models. When you upload a document, ask an agent a question, or use extraction, reconciliation, ERP export, the settlement reader or the company analyst, the content you submit is sent to our AI provider, Anthropic, and processed on servers in the United States.

  • That content can include personal data and commercial data contained in your files, and the prompts you type.
  • Anthropic processes it on our instructions as a subprocessor and does not use content submitted through its commercial API to train its models.
  • AI output is a suggestion, not a decision. Extractions, reconciliation matches and settlement readings are surfaced for a person at your organization to review, edit or reject.
  • We do not make decisions about you that produce legal or similarly significant effects using automated processing alone.
  • AI is imperfect. Check its output before you rely on it for a payment, a contract or a filing.

Where the platform tells you that you are talking to an agent, you are interacting with an AI system rather than a person.

6. Who we share it with

The platform is a marketplace, so some sharing is the point of the product: counterparties you trade with see the listings, orders, documents and contact details you send them, and members of your own organization see data according to the permissions your administrator sets.

Beyond that, we share data with the service providers below. Each one processes it only on our instructions and for the purpose named.

ProviderPurposeProcessing location
Amazon Web ServicesHosting, file storage, databases, transactional emailUnited States
AnthropicAI processing of documents and text you submit to platform agentsUnited States
MongoDB AtlasPrimary application databaseUnited States
StripeSubscription billing and payment card processingUnited States
CulqiPayment processing for transactions settled in PeruPeru
PrometeoBank connectivity used to issue payouts you instructUruguay / Peru
Google AnalyticsProduct usage analytics (loaded only with your consent)United States
MapboxMaps and geocoding shown in the appUnited States
ShipsGo, VizionContainer and vessel tracking for your shipmentsEuropean Union / United States
Open-MeteoWeather data for field and agronomy featuresEuropean Union

We also disclose data to professional advisers, to authorities where the law requires it, and to an acquirer if the business is sold — in which case this policy continues to apply until you are told otherwise.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law. We have not done so in the past twelve months.

7. International transfers

The platform runs on infrastructure in the United States, so data you enter in Peru or Europe is transferred there and processed by us and by the providers listed above. When personal data leaves the European Economic Area, the United Kingdom or Peru, we rely on Standard Contractual Clauses or an equivalent transfer mechanism, together with encryption in transit and at rest. Ask us and we will describe the safeguards that apply to a specific transfer.

8. How long we keep it

DataRetention
Account and profile dataFor as long as the account is active, then up to 24 months
Commercial and financial records, invoices and settlementsFor the period required by applicable tax and commercial law — generally seven years in the United States, and five years after the relevant tax period for records tied to Peru
Documents you uploadUntil you delete them or the parent record is deleted; a background sweep removes orphaned and abandoned uploads
Security and audit logsUp to 12 months
Analytics dataUp to 14 months, or until you withdraw consent
BackupsRolling, overwritten within 90 days

When a retention period ends we delete the data or irreversibly anonymize it. Records we must keep for tax or legal reasons are retained even after an account closes, and are not used for anything else.

9. Your rights

Depending on where you live, you have some or all of the following rights. We honour all of them for every user, wherever you are.

  • Access — get a copy of the personal data we hold about you and know who we shared it with.
  • Rectification — correct anything inaccurate or incomplete.
  • Erasure — have your data deleted, except records we must keep by law.
  • Portability — receive your data in a structured, machine-readable format, or have it sent to another provider.
  • Objection and restriction — object to processing based on legitimate interest, or ask us to pause it while a dispute is resolved.
  • Opt out — of any sale of personal data, targeted advertising, or profiling with a legal or similarly significant effect. We do none of these, so there is nothing to opt out of, but the right stands if that ever changes.
  • Withdraw consent — turn off analytics cookies at any time from our Cookie Policy.
  • Non-discrimination — we will not degrade your service because you exercised a right.

To exercise any of these, write to administration@pachaexchange.com from the address on your account, or ask us to verify you another way. We answer within 45 calendar days and will tell you if we need one extension. An authorized agent may act for you if you confirm the authorization. Using these rights is free.

If we refuse a request, we will tell you why and how to appeal. To appeal, reply to our decision at administration@pachaexchange.com with the word "appeal". We will decide within 60 days, explain our reasoning in writing, and give you a way to complain to your state attorney general if you are still unsatisfied.

If data was uploaded about you by an organization that uses Pacha, we will forward your request to that organization, since it decides what happens to its records.

10. Security

  • Traffic is encrypted with TLS and stored data is encrypted at rest.
  • Bank account details are encrypted with AES-256-GCM under a key held in a managed secret store, separate from the database.
  • Documents you upload live in a private bucket and are reachable only through short-lived signed links issued to authorized users.
  • Access is role- and permission-based, sessions can be revoked, and logins from unrecognized sources are challenged with a one-time code.
  • Photos published on public listing pages are served from a public content network. Do not put confidential material in a listing image.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority within the deadlines the law sets — 72 hours under the GDPR, 60 days under Delaware law, and the period required by Peruvian law.

11. Cookies

We set only strictly necessary cookies until you agree to more. Read the Cookie Policy for the full list and to change your choice.

12. Changes and complaints

We update this policy when our practices change. Material changes are announced in the app or by email before they take effect, and the date at the top always shows the current version.

Talk to us first at administration@pachaexchange.com. You can also complain to the Delaware Department of Justice, to your own state attorney general in the United States, to the Autoridad Nacional de Protección de Datos Personales in Peru, or to your national data protection authority in the European Union or the United Kingdom.