Data handling
Scopes, storage, retention and deletion.
NOT WRITTEN YET — not for production
This document has not been written yet, and it is the one the security section on the home page points at. It must state the exact read-only scopes requested on each platform, where tokens and pulled data are stored, the retention period, what happens to a paused account's history, and how a merchant gets everything deleted. The retention answer is still an open decision — it is the [VERIFY] placeholder in the security section.