The purpose of this policy is to ensure that all employees are aware of the PCI compliance aspects of handling credit card information and of the necessary steps if card data is accidentally exposed. This policy applies to all Ripple Treasury employees that may encounter third-party card information. It does not apply to the handling of Ripple Treasury credit cards. Ripple Treasury’s Credit Card Data Handling Policy is broken down into two core sections, card handling and steps to manage exposure.
Card Handling
Some areas of the Ripple Treasury application (and supporting hardware) are responsible for the processing, storage or transmission of cardholder data (specifically card numbers). Card information (whether encrypted or not) must never be removed (via file transfer or other methods) from the servers designated for this purpose.
Card information may also be presented to employees via email, paper documents, or electronic file outside of mechanisms formally agreed to handle card information in a PCI-compliant manner.
Steps to Manage Exposure
If card information is received or exposed outside of the designated card handling mechanisms, the following steps should be taken:
Delete the offending data (files, paper copies, emails).
Notify the Security & Compliance team (compliance@greasury.com) that card information has been exposed, noting the source of the data.
Notify IT to remove potential exposure from archived server copies of electronic information.
Copyright 2025 Ripple Labs Inc.
