Your grant data is sensitive. We treat it that way.
Cardholder data, transaction records, and grant information are held to strict data handling practices. Here is what we do, in plain language.
How we handle cardholder and transaction data
We collect only what is required to operate the card program and provide grant compliance reporting. We do not sell data or use it for advertising.
Encryption in transit and at rest
All data in transit uses TLS 1.3. Transaction records and cardholder data stored on our platform are encrypted at rest using AES-256.
Card data handled by our banking partner
Primary card account numbers (PANs) and full magnetic stripe data are handled by our banking partner's PCI-compliant infrastructure. KleerCard systems store only truncated card numbers.
Access controls
Platform access is separated by organization. Internal KleerCard staff access to customer data is role-based and logged. Finance directors control which staff can view card and transaction data within their account.
Infrastructure
KleerCard runs on AWS in the US region. We do not transfer customer data outside the United States for processing or storage during normal operations.
Retention and deletion
Transaction data is retained for seven years to support grant audit requirements. After account cancellation, data enters a 30-day export window before deletion per our data retention policy.
No data selling
We do not sell, license, or share your transaction or organizational data with third parties for marketing or advertising purposes. Data is shared only with service providers necessary to operate the platform.
Card security is handled at the network level
Controls built into the card, not the review process
Merchant category restrictions
Define which merchant category codes are allowed on each card. A grant restricted to program expenses can block entertainment, travel, and office supply categories from the card level.
Spending limits per card
Set per-transaction and monthly spending limits. If a single purchase exceeds the configured limit, it is declined or flagged for approval before processing.
Grant period enforcement
Set grant period end dates. Cards assigned to a grant with an expired period are automatically restricted from new charges, preventing post-period overspending. Available on Organization tier.
Where we are heading on certifications
We are an early-stage company. Here is an honest picture of our compliance posture today and what we are working toward.
Have a specific security question before you commit?
We are happy to answer detailed questions about our data practices, infrastructure, or card program before you sign up. Email us directly.