Privacy Policy
Draft template — not legal advice. Must be reviewed by a lawyer and completed with the operator's legal details before production use.
What we store
- Merchant account data: business name, email, password hash, two-factor settings, team members.
- Security data: sign-in IP addresses, session records and security events.
- Payment data: invoices, deposit addresses, transaction hashes, payout destinations, and the customer identifiers merchants send (e.g. their own user IDs).
- Emails we send (in the outbox) for delivery and troubleshooting.
Why
To provide the service, secure accounts, prevent fraud, keep accounting records and meet legal obligations.
Sharing
With infrastructure and email providers acting on our behalf, blockchain networks (transactions are public by nature), and authorities where legally required. We do not sell personal data.
Retention
Accounting and transaction records are kept as long as required by law; security logs for a limited period; backups rotate automatically.
Your rights
Depending on your jurisdiction you may request access, correction or deletion of personal data, subject to legal retention duties. Contact the operator.
Cookies
Only a strictly necessary, HttpOnly session cookie is used for signing in. No advertising or tracking cookies.
Last updated: draft.