PII data
Reveal helps you understand payment performance and settlements using data from the Gateway Accounts you connect. Some of that data can identify a person. Reveal separates non-payment personal data (such as name or email) from payment-related attributes (such as card brand or last four digits) so you can decide how much customer-level detail Reveal may use.
You control whether Reveal may access non-payment personal data. That choice is part of onboarding and is reflected in Reveal’s customer-data permission settings. For broader ingestion and deletion rules, see Data control.
Non-payment personal data
Non-payment personal data includes customer details such as name, email address, phone number, and address.
You can choose not to provide this information to Reveal. During onboarding, Reveal asks for permission to access customer data:
- Yes (allow): Reveal may use non-payment personal data associated with your connected sources for analytics that need a customer-level identifier.
- No (deny): Reveal does not rely on that non-payment personal data for your workspace.
If personal details appear only because your payment processor returns them to Reveal under the credentials you granted, Reveal’s handling still follows the permission you set for PII access. Non-payment personal data is used for your Reveal workspace only. It is not shared with other Reveal customers.
Payment-related data
Even when you deny non-payment PII, Reveal still needs payment attributes to deliver value. Reveal may receive information such as:
- The Gateway Account used for a transaction
- The payment method type
- Card brand, expiry date, and last four digits of the card number (when the processor provides them)
These attributes support anonymous or aggregate analysis of authorization rates, declines, settlements, and fees. They are essential for Transactions and Settlements insights. On their own, truncated card identifiers are not a substitute for the non-payment personal data described earlier, but they are still sensitive and are protected under Reveal’s security practices. See Card vaulting and Data policies, processes, and methods.
Why teams allow PII access
Allowing non-payment personal data can help when your team needs per-customer analysis, for example:
- Understanding behavior or drop-offs with the same identifiers your operations team already uses
- Linking subscription or refund patterns to a known customer key
- Supporting a customer-level deletion request with a unique identifier that exists in Reveal
If you deny PII access, you can still use Reveal for processor-level and segment-level analytics. You may have fewer options for customer-keyed workflows and for pinpointing a single customer’s records for deletion. See Data control.
Take the next step
- Data control: What Reveal can ingest and how deletion works.
- Card vaulting: Cardholder data and PCI context for Reveal.
- Data policies, processes, and methods: Encryption, access, and hosting practices.
- Reveal overview: How Reveal uses connected payment data.
Was this article helpful?