LEGAL & COMPLIANCE

Privacy Policy & Data Protection.

At Pair2FA, we treat security and privacy as inseparable. This policy details how we collect, process, encrypt, and safeguard your team’s sensitive information in full compliance with global standards.

Effective & Last Updated: September 2026 · Version 2.4

AES-256-GCM Vault

2FA secrets are encrypted at rest with authenticated AES-256-GCM keys.

ENCRYPTED AT REST

Zero Data Monetization

We never sell user data, profile behavior, or share records with advertisers.

100% PRIVATE

1-Click Right to Erasure

Delete your workspace or export seed keys anytime without vendor lock-in.

COMPLETE CONTROL

GDPR & CCPA Ready

Full compliance with EU GDPR, UK DPA, and California CCPA/CPRA regulations.

GLOBAL COMPLIANCE
01

Information We Collect & Process

Pair2FA collects only the minimal set of data necessary to authenticate users, manage workspace memberships, and securely generate 30-second TOTP verification codes for your team. We divide collected data into four distinct categories:

Account & Identity Data

Full name, email address, password hash (Bcrypt), and OAuth profile tokens provided during registration or Google sign-in.

Vault Metadata & Secrets

Account titles, service labels (AWS, GitHub, Supabase), and encrypted 2FA secret keys. Raw secret keys are encrypted before storage.

Audit & Access Logs

Timestamps, IP addresses, user agent details, and user IDs recording code copy actions for workspace security auditing.

Billing Metadata

Stripe customer and subscription IDs, subscription status, seat counts, and invoice history. Payment card numbers are processed directly by Stripe and never reach our servers.

02

Zero-Knowledge Vault Encryption Architecture

We implement defense-in-depth cryptographic security to ensure your 2FA secret keys are protected even in the unlikely event of physical infrastructure compromise:

  • Authenticated AES-256-GCM: All seed keys are encrypted using Galois/Counter Mode (GCM), ensuring both confidentiality and cryptographic data integrity.
  • In-Memory TOTP Processing: Generated 30-second verification passcodes are computed ephemerally in RAM and are never written to server logs or disk storage.
  • TLS 1.3 In-Transit Security: All client-to-server traffic is enforced using HTTPS with HSTS and TLS 1.3 encryption.
03

Third-Party Subprocessors & Infrastructure

Pair2FA partners strictly with enterprise cloud subprocessors meeting SOC 2 Type II and ISO 27001 compliance standards. Data is shared only to maintain service operations:

SubprocessorPurposeLocationCompliance
Vercel Inc.Edge Hosting & Serverless ExecutionUnited States / Global CDNSOC 2 Type II, ISO 27001
Amazon Web Services (AWS)Encrypted Database Vault StorageUS-East (N. Virginia)SOC 1/2/3, ISO 27001, HIPAA
Stripe, Inc.Payment Processing & Subscription BillingUnited States / GlobalPCI-DSS Level 1
Resend / SendGridTransactional Member Invite NotificationsUnited StatesSOC 2 Type II, GDPR Compliant
04

Data Retention & Immediate Erasure Rights

We retain workspace data only as long as your workspace remains active. When an owner initiates workspace deletion:

  • All encrypted TOTP keys, shared accounts, and access roles are permanently purged from primary production databases within 24 hours.
  • Backup snapshots rotate and hard-expire completely within 14 business days.
  • You may request a raw JSON/CSV export of all stored secrets prior to workspace closure to prevent lock-in.
05

Global Privacy Rights (GDPR & CCPA/CPRA)

Depending on your location, you hold explicit statutory privacy rights under EU GDPR, UK DPA, or California CCPA/CPRA:

Right to Access & PortabilityRequest copies of all stored personal metadata and vault items.
Right to RectificationUpdate incorrect profile information directly from account settings.
Right to Erasure (Forgotten)Request immediate hard deletion of all account records and logs.
Non-DiscriminationWe never deny service or alter pricing based on exercising privacy rights.

Data Protection Officer (DPO)

Questions about our privacy compliance or exercising legal rights?

Email Privacy Team
PAIR2FA

Stronger teams
start here.

Share 2FA access. Save time. Stay secure.

2 min setup

Be up and running

Built for teams

Simple permissions

No long-term contracts

Cancel anytime

TRUSTED BY MODERN TEAMS