Privacy Policy
The shortest privacy policy you'll read this year — because we collect almost nothing. Last updated July 19, 2026.
1. The principle
CryptoPayIn is built so that we do not know who you are. There is no name, email, phone, address or identity document anywhere in the product — for merchants or for their customers. What we cannot collect, we cannot leak, sell or be compelled to disclose.
2. What we store
- Account: a salted, peppered hash of your account key (the key itself is never stored), creation timestamp, optional TOTP secret and hashed recovery codes if you enable 2FA.
- Operations: payments, balances, ledger entries, payout addresses you configure, API keys (hashed) and webhook endpoints — the data required to run your account.
- Technical: transient IP-based rate-limiting counters and security logs for abuse prevention (signup/login throttles), and standard web-server logs with short retention.
- Support: the content of tickets you write to us.
3. What we do not do
- No identity collection, no KYC files, no document storage.
- No advertising trackers, no analytics beacons, no third-party scripts on this site other than the anti-bot challenge on account creation.
- No sale or sharing of data with data brokers — there is nothing sellable to share.
- No chain-surveillance profiling of your customers.
4. Cookies
One session cookie, set only when you log in to the dashboard, strictly necessary for authentication (Secure, HttpOnly, SameSite). The public website sets no cookies at all.
5. On-chain data
Blockchain transactions are public by nature on transparent networks (except privacy assets such as Monero). Nothing we can do alters what a public chain records; choose assets accordingly.
6. Retention & deletion
Operational records (ledger, payments) are retained while your account exists and as required for platform integrity — the ledger is append-only by design. Closing your account (zero balance required) removes its operational configuration; rate-limit and web logs expire on short rolling windows.
7. Disclosure
We hold no identity data to disclose. If legally compelled within our operating jurisdiction, we can only produce what Section 2 lists — which contains no names. We publish no user data voluntarily.
8. Contact
Privacy questions: open a ticket from your dashboard. Changes to this policy are indicated by the date above.