Data handling

Scopes, storage, retention and deletion.

NOT WRITTEN YET — not for production

This document has not been written yet, and it is the one the security section on the home page points at. It must state the exact read-only scopes requested on each platform, where tokens and pulled data are stored, the retention period, what happens to a paused account's history, and how a merchant gets everything deleted. The retention answer is still an open decision — it is the [VERIFY] placeholder in the security section.