IP Library Granted Patent US 12,518,332
Granted Patent B1
US 12,518,332 · App. 18/315,387 · Granted Jan 6, 2026

Storage service for sensitive customer data

Inventor: Jonathan Andrew Wolter (San Francisco, CA)
Assignee: Block, Inc.
G06Q50/265G06F16/951G06F40/174H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,332
App. No.
18/315,387
Granted
Jan 6, 2026
Kind
B1
Abstract

A first inline frame is provided from one or more servers of a service provider for display on a browser executing on a computing device of a first user within a website of a second user. A data retention policy is received from a computing component associated with the second user. Sensitive user data is received via the first inline frame from the computing device of the first user. A token is associated with the sensitive user data. The token is returned to the second user via the computing component. A request is received from the computing component that specifies the token. An electronic payment is initiated responsive to receiving the request, based at least in part on the sensitive user data.

Claims (63)

1 . One or more computing devices, comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed, cause the one or more processors to perform actions comprising:

providing, from one or more servers of a service provider, a first inline frame for display on a browser executing on a computing device of a first user within a website of a second user;

receiving, via the first inline frame and from the computing device of the first user, first user data obtained by the first inline frame, wherein the first user data comprises sensitive data associated with the first user and wherein the first inline frame provides access to the first user data by the service provider and prevents access to the first user data by the website of the second user;

receiving, from a computing component associated with the second user, a data retention policy for the first user data from, wherein the data retention policy is specified by the second user;

in response to receiving the first user data via the first inline frame, associating a token with the first user data, wherein the token is a reference to the first user data;

returning the token to the second user via the computing component such that the token can be used as a future reference to the first user data;

receiving a request from the computing component, wherein the request specifies the token; and

responsive at least in part to receiving the request, initiating an electronic payment by the first user that is based at least in part on the first user data.

2 . The one or more computing devices of claim 1 , wherein the request further specifies virtual cart information, and wherein the electronic payment is further based at least in part on the virtual cart information.

3 . The one or more computing devices of claim 1 , wherein the first user data comprises payment information associated with the first user, wherein the payment information comprises one or more of a payment instrument identifier, a name of the first user, an address of the first user, or an account identifier of a financial account of the first user.

4 . The one or more computing devices of claim 3 , wherein the request comprises a first request, and wherein initiating the electronic payment comprises:

sending, by a payment processing component of the service provider to a data storage component of the service provider, the token and a second request for the payment information;

receiving, by the payment processing component and from the data storage component, the payment information; and

processing, by the payment processing component, the electronic payment based at least in part on the payment information and transaction data received from the second user.

5 . The one or more computing devices of claim 1 , wherein initiating the electronic payment comprises processing a credit card payment or a debit card payment to the second user.

6 . The one or more computing devices of claim 1 , the actions further comprising:

causing presentation of at least a portion of the first user data via a display associated with the computing component.

7 . The one or more computing devices of claim 1 , the actions further comprising one or more of:

storing the first user data in a database associated with the service provider in accordance with the data retention policy; or

deleting the first user data from the database in accordance with the data retention policy.

8 . The one or more computing devices of claim 1 , wherein the request comprises a first request, and the actions further comprising:

returning the token to the first user via the computing device of the first user as a reference to the first user data;

receiving a second request from the computing device of the first user, wherein the second request specifies the token;

causing presentation of at least a portion of the first user data via a display associated with the computing device of the first user via a second inline frame; and

receiving, via the second inline frame and from the computing device of the first user, an indication of an update to the first user data.

9 . The one or more computing devices of claim 1 , wherein the service provider provides data storage services and payment processing services to a plurality of merchants, wherein the second user is one of the plurality of merchants.

10 . A method comprising:

providing, from one or more servers of a service provider, a first inline frame for display on a browser executing on a computing device of a first user within a website of a second user;

receiving, via the first inline frame and from the computing device of the first user, first user data obtained by the first inline frame, wherein the first user data comprises sensitive data associated with the first user and wherein access to the first user data by the website of the second user is prevented by the first inline frame;

receiving, from a computing component associated with the second user, a data retention policy for the first user data, wherein the data retention policy is specified by the second user;

in response to receiving the first user data via the first inline frame, associating a token with the first user data, wherein the token is a reference to the first user data;

returning the token to the second user via the computing component such that the token can be used as a future refence to the first user data;

receiving a request from the computing component, wherein the request specifies the token; and

responsive at least in part to receiving the request, initiating an electronic payment by the first user that is based at least in part on the first user data.

11 . The method of claim 10 , wherein the request further specifies virtual cart information, and wherein the electronic payment is further based at least in part on the virtual cart information.

12 . The method of claim 10 , wherein the first user data comprises payment information associated with the first user, wherein the payment information comprises one or more of a payment instrument identifier, a name of the first user, an address of the first user, or an account identifier of a financial account of the first user.

13 . The method of claim 12 , wherein the request comprises a first request, and wherein initiating the electronic payment comprises:

sending, by a payment processing component of the service provider to a data storage component of the service provider, the token, and a second request for the payment information;

receiving, by the payment processing component and from the data storage component, the payment information; and

processing, by the payment processing component, the electronic payment based at least in part on the payment information and transaction data received from the second user.

14 . The method of claim 10 , further comprising:

storing the first user data in a database associated with the service provider in accordance with the data retention policy; or

deleting the first user data from the database in accordance with the data retention policy.

15 . The method of claim 10 , wherein initiating the electronic payment comprises processing a credit card payment or a debit card payment to the second user.

16 . The method of claim 10 , wherein the service provider provides data storage services and payment processing services to a plurality of merchants, wherein the second user is one of the plurality of merchants.

17 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions executable by the one or more processors, wherein the instructions cause the one or more processors to perform acts comprising:

providing, from one or more servers of a service provider, a first inline frame for display on a browser executing on a computing device of a first user within a website of a second user;

receiving, via the first inline frame and from the computing device of the first user, first user data obtained by the first inline frame, wherein the first user data comprises sensitive data associated with the first user and wherein the first inline frame prevents access to the first user data by the website of the second user;

receiving, from a computing component associated with the second user, a data retention policy for the first user data, wherein the data retention policy is specified by the second user;

in response to receiving the first user data via the first inline frame, associating a token with the first user data, wherein the token is a reference to the first user data;

returning the token to the second user via the computing component such that the token can be used as a future reference to the first user data;

receiving a request from the computing component, wherein the request specifies the token; and

responsive at least in part to receiving the request, initiating an electronic payment by the first user that is based at least in part on the first user data.

18 . The system of claim 17 , wherein the request further specifies virtual cart information, and wherein the electronic payment is further based at least in part on the virtual cart information.

19 . The system of claim 17 , wherein the first user data comprises payment information associated with the first user, wherein the payment information comprises one or more of a payment instrument identifier, a name of the first user, an address of the first user, or an account identifier of a financial account of the first user.

20 . The system of claim 19 , wherein the request comprises a first request, and wherein initiating the electronic payment comprises:

sending, by a payment processing component of the service provider to a data storage component of the service provider, the token, and a second request for the payment information;

receiving, by the payment processing component and from the data storage component, the payment information; and

processing by the payment processing component, the electronic payment based at least in part on the payment information and transaction data received from the second user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: WOLTER, JONATHAN ANDREW
To: SQUARE, INC.
Reel/Frame 063606/0374 →
CHANGE OF NAME Recorded May 10, 2023
From: SQUARE, INC.
To: BLOCK, INC.
Reel/Frame 063621/0557 →
Continuity (1)
Continuation 15923804 · Mar 16, 2018
References Cited (22)
US 9251372B1 · Lahoz · 2016 [cited by examiner]
US 10366429B2 · Isaacson et al. · 2019 [cited by applicant]
US 10417706B1 · Simon · 2019 [cited by applicant]
US 10482284B1 · Tang · 2019 [cited by examiner]
US 10546292B1 · Karaivanov · 2020 [cited by examiner]
US 10565596B2 · DeTella · 2020 [cited by examiner]
US 10853350B1 · Sharifi Mehr · 2020 [cited by examiner]
US 11790470B1 · Wolter · 2023 [cited by examiner]
US 20040054918A1 · Duri · 2004 [cited by examiner]
US 20070299735A1 · Mangalick · 2007 [cited by examiner]
US 20100094755A1 · Kloster · 2010 [cited by examiner]
US 20130117185A1 · Collison · 2013 [cited by examiner]
US 20130198080A1 · Anderson · 2013 [cited by examiner]
US 20140032418A1 · Weber · 2014 [cited by examiner]
US 20140108172A1 · Weber · 2014 [cited by examiner]
US 20150073989A1 · Green · 2015 [cited by examiner]
US 20150341322A1 · Levi · 2015 [cited by examiner]
US 20180007059A1 · Innes · 2018 [cited by examiner]
US 20180191735A1 · Lahoz · 2018 [cited by examiner]
US 20190147515A1 · Hurley · 2019 [cited by examiner]
US 20190197217A1 · Donovan · 2019 [cited by examiner]
US 20190230080A1 · Boothby · 2019 [cited by examiner]