Privacy Policy
A plain-language account of the limited data needed to operate the service. Last updated July 20, 2026.
1. The principle
CryptoPayIn does not require merchant identity, KYC documents, an email address or a phone number to create an account. A checkout likewise requires no CryptoPayIn customer account. A merchant can, however, ask a buyer for information needed to fulfil an order — such as an email address, custom checkout answers or a shipping name and address. We treat that as operational order data, not identity-verification data.
2. What we store
- Account: a keyed hash of your account key (the key itself is never stored), creation timestamp, a non-reversible network fingerprint for signup-abuse prevention, and optional encrypted TOTP material plus hashed recovery codes if you enable 2FA.
- Operations: payments, balances, ledger entries, payout addresses you configure, hashed API keys and webhook endpoints — the data required to run your account.
- Checkout and fulfilment: buyer details that the merchant's checkout requests, which may include email, custom fields and shipping details. Checkout IP addresses are stored only as purpose-separated, non-reversible abuse-prevention fingerprints.
- Technical: transient IP-based rate-limit counters, bounded rolling web-server logs and security audit records used to prevent and investigate abuse.
- Support: the content of tickets you write to us.
3. What we do not do
- No merchant identity verification, no KYC files and no identity-document storage.
- No advertising trackers, no analytics beacons, no third-party scripts on this site other than the anti-bot challenge on account creation.
- No sale or sharing of data with data brokers — there is nothing sellable to share.
- No chain-surveillance profiling of your customers.
4. Cookies
Strictly necessary Secure, HttpOnly and SameSite cookies protect authenticated dashboard and administrator sessions and their login flows. Account creation uses Cloudflare Turnstile as an anti-bot control; its challenge may use browser storage or cookies under Cloudflare's policy. Public payment and shop pages do not use advertising or analytics cookies.
5. On-chain data
Blockchain transactions are public by nature on transparent networks (except privacy assets such as Monero). Nothing we can do alters what a public chain records; choose assets accordingly.
6. Retention & deletion
Funded payments and ledger records are retained for account integrity; the ledger is append-only by design. Unfunded abandoned public invoices are removed seven days after expiry, unfunded API invoices after 30 days, and completed webhook-delivery logs after 90 days. Orphan checkout sessions expire automatically. Closing an account (zero balance required) removes its operational configuration; rate-limit counters and web logs expire on bounded rolling windows.
7. Disclosure
We hold no merchant KYC dossier. If legally compelled within our operating jurisdiction, we can only produce the limited records in Section 2, including any fulfilment details a buyer supplied to a merchant checkout. We do not publish user data voluntarily.
8. Contact
Privacy questions: open a ticket from your dashboard. Changes to this policy are indicated by the date above.