Payment Processing Addendum

Last Updated: July 26, 2026

This Payment Processing Addendum ("PPA") governs ArmoryFlow's storage, use, and handling of your payment-processing credentials and related checkout orchestration for Storefront and other transactions on your merchant account.

This addendum supplements the Terms of Service and Storefront Operator Agreement. SaaS subscription fees you pay ArmoryFlow remain governed by the Terms and Refund Policy, not by this addendum.

1. Purpose and Acceptance

This PPA governs ArmoryFlow's storage, use, and handling of your payment-processing credentials and related checkout orchestration for Storefront and other transactions on your merchant account.

By providing payment credentials, completing processor boarding through ArmoryFlow, enabling Storefront checkout, or otherwise authorizing ArmoryFlow to submit charges on your behalf, you agree to this PPA.

2. Definitions

  • Supported Processor means a payment processor or gateway ArmoryFlow supports from time to time, which may include Authorize.net, Payroc, EMG by Deluxe, and successors or alternates we enable.
  • Payment Credentials means API keys, login IDs, transaction keys, merchant IDs, boarding tokens, public keys, private keys, webhook secrets, and other authentication material you provide or authorize for a Supported Processor.
  • Merchant Account means your merchant or payment account with a Supported Processor, which you own and control.
  • Payment Token means a tokenized payment reference created by hosted fields, Accept.js, network tokenization, or similar methods so raw card data is not stored by ArmoryFlow.
  • Transaction means a payment authorization, capture, sale, or similar request submitted to your Merchant Account through ArmoryFlow.
  • Distributor Credentials means credentials you provide for firearms distributor systems such as API or FTP access.

3. Authorization

3.1 Payment processing authorization

You authorize Circle Square Inc. to:

  • Store Payment Credentials in encrypted form for processing Transactions on your Storefront and other enabled features that use the same Merchant Account.
  • Decrypt and use Payment Credentials at Transaction time to submit charges on your behalf.
  • Use processor-hosted fields or tokens so raw card data is handled per the processor's model.
  • Perform credential validation or test transactions when you configure payments.
  • Receive webhooks or status callbacks needed to record Transaction outcomes.

This authorization is limited to Transactions initiated through ArmoryFlow features you enable. We will not use Payment Credentials for unrelated purposes.

3.2 Distributor credentials authorization

You authorize storage and use of Distributor Credentials to sync catalog, inventory, and pricing data per your settings. Unless you separately enable and authorize order-submission or dropship features, this authorization is limited to reading inventory and product data.

If you enable order submission, you authorize ArmoryFlow to submit orders or purchase orders using your credentials as a technology convenience, and you remain solely responsible for those orders and distributor compliance.

3.3 Revocation

You may revoke by removing credentials or disabling the integration in settings. Upon revocation, we will delete stored credentials within a commercially reasonable period, target 24 hours, disable affected checkout or sync features, and cease new uses of those credentials. In-flight Transactions may still complete.

4. Your Merchant Account Responsibilities

You alone are responsible for:

  • Underwriting, approval, and ongoing good standing of your Merchant Account.
  • Your agreement with the Supported Processor and card-network rules.
  • PCI obligations applicable to you as merchant.
  • Descriptors, statements, refunds, voids, chargebacks, representments, and fees.
  • Prohibited-goods rules of your processor, including firearms policies.
  • Not using payment-request or similar links as a substitute for required firearm transfer workflows.
  • Configuring tax correctly as described in Section 6.

5. ArmoryFlow's Security Role

ArmoryFlow maintains security controls appropriate to its role as a technology platform, including encryption at rest for stored secrets and access controls. ArmoryFlow's PCI scope depends on the integration model, such as hosted fields, iframe-based capture, or Accept.js.

You must protect admin access to ArmoryFlow, rotate credentials if compromised, and notify us promptly of suspected credential compromise.

No security measure is perfect. Section 10 of the Terms and Section 8 of this addendum allocate liability.

6. Tax Configuration

You alone enable tax collection, if desired, and configure nexus jurisdictions, rates, and related settings.

Tax tools are conveniences only. ArmoryFlow does not:

  • Determine where you have nexus.
  • Validate that your settings are correct or complete.
  • Guarantee legal sufficiency of tax amounts charged.
  • File, remit, or report tax on your behalf.
  • Provide legal or tax advice.

Misconfiguration and resulting under-collection, over-collection, penalties, interest, or assessments are solely your responsibility. See also the Storefront Operator Agreement.

7. Transaction Processing; Failures; Refunds

Checkout validates cart and pricing server-side, uses Payment Tokens, submits the Transaction to your Supported Processor, and records outcomes.

Declined or failed Transactions create no completed paid order, subject to rare race conditions. Unknown or delayed processor outcomes may require reconciliation, and you agree to cooperate.

Refunds or voids may be available in-product for some processors or may require your processor dashboard. You remain responsible for your refund policy and consumer-law compliance.

Chargebacks are between you, the consumer, and your processor. ArmoryFlow may provide logs to assist but is not responsible for chargeback outcomes.

8. Limitation of Liability

IN ADDITION TO THE TERMS AND STOREFRONT OPERATOR AGREEMENT, ARMORYFLOW AND CIRCLE SQUARE INC. SHALL HAVE NO LIABILITY FOR DECLINED, FAILED, DELAYED, OR ERRONEOUS TRANSACTIONS ON YOUR MERCHANT ACCOUNT, CHARGEBACKS, FRAUD CLAIMS, OR PAYMENT DISPUTES, FEES, PENALTIES, OR CHARGES BY PROCESSORS OR CARD NETWORKS, TAX LIABILITY, PENALTY, INTEREST, ASSESSMENT, AUDIT, OR FINE FROM YOUR TAX CONFIGURATION OR NONCOMPLIANCE, CREDENTIAL COMPROMISE CAUSED BY YOUR ACTIONS OR THIRD-PARTY BREACHES OUTSIDE OUR REASONABLE CONTROL, DISTRIBUTOR ACCOUNT FEES, PENALTIES, OR ACTIONS, OR PROCESSOR OR NETWORK OUTAGES.

9. Indemnification

In addition to the Terms and SOA, you will indemnify Circle Square Inc. from claims arising from Transactions on your Merchant Account, chargebacks, fraud, disputes, your violation of processor terms, tax errors from your configuration, consumer payment claims, distributor-term violations, and unauthorized use of credentials you provided.

10. General

This PPA controls over the Terms and SOA on Payment Credential and Transaction-orchestration matters to the extent of conflict.

Modifications follow the Terms.

Governing law and dispute resolution follow the Terms.

Contact: legal@armoryflow.com, support@armoryflow.com, and security@armoryflow.com.

By providing processor or distributor credentials, completing processor boarding, enabling checkout, or otherwise using covered payment features, you acknowledge that you have read, understood, and agree to be bound by this Payment Processing Addendum.