Privacy Policy
This is a privacy-first payment platform, and this policy is written to prove it. Where other gateways collect as much as they can get away with, we built the opposite: a system that is architecturally incapable of profiling you. Below is exactly what we hold, why, and what we never touch.
01The short version
We collect the minimum needed to run a payment service: an email address to sign in, invoices you create, and the public blockchain data required to confirm payments. We cannot collect what we never receive — your wallet keys are generated in your browser and never transmitted to us.
We do not run advertising trackers, we do not sell data — there is no data worth selling — and we do not ask for your phone number, your ID or your business registration. Ever.
02What we collect and why
Account: your email address and an internal user identifier. Your email is used solely for sign-in links and essential service notifications. There is no newsletter and no marketing list.
Merchant data you enter: store name, brand color, wallet public keys (xpub/zpub or payment codes), webhook endpoint URLs, optional Lightning node connection (password encrypted with AES-256-GCM) and your dashboard preferences such as interface language.
Invoices: amount, optional order reference, the derived one-time stealth address, its payment status and confirmations. This is what allows us to watch the chain for your payments and notify your systems.
Technical logs: minimal request records used for abuse prevention (rate limiting) and error monitoring. Error reports are scrubbed before storage — email addresses, wallet addresses, invoice identifiers, IPs and tokens are replaced with placeholders like [email] or [btc-address].
03What we never collect
No identity documents, no phone numbers, no home or business addresses, no bank accounts, no date of birth, no photos. No third-party analytics beacons, no advertising pixels, no session recorders. We have no way to associate your invoices with anything beyond the public keys you gave us — by design, there is no rich profile of you to seize, subpoena or steal.
04Your wallet keys
Seed phrases and private keys are generated locally in your browser, encrypted with AES-256-GCM under a password only you know (PBKDF2-SHA256, 600,000 iterations), and stored in your browser's storage. They never leave your device in unencrypted form — we literally have no field in which to store them. If you lose your password, nobody — including us — can recover the wallet.
05Buyers who pay your invoices
The payment page requires no account, no cookies beyond an interface-language preference, and collects nothing about the buyer. We see what the blockchain sees: a transaction to a one-time address. We cannot know who paid — and neither can anyone watching the chain.
06Where the data lives and how long
Data is stored in an encrypted production database (Neon/PostgreSQL) and encrypted off-site backups (AES-256-GCM envelopes whose key derives from the platform secret). Accounts and invoices live as long as your account does; you can request deletion at any time and encrypted backups roll off automatically on a retention schedule. Technical security logs are short-lived.
07Who can see your data
Inside the platform: only the founding team, for operating the service and answering support requests. Outside: your webhook receivers (they receive exactly the events you subscribe to, signed) and the public blockchain (public data by definition). We do not share, sell, or monetize data. We would comply with a binding legal order where legally required — but what we hold is deliberately so minimal that such an order yields almost nothing.
08Your choices
You can export your data (earnings CSV, per-invoice spending keys, wallet backups) at any time from the dashboard. You can request full account deletion through the support channel — we remove the account and invoice records; the blockchain itself is public and outside anyone's control. And you can leave at any time: your seed phrase works in any compatible wallet, with or without us.
Questions about privacy reach the founding team directly through the contact page — no email address needed.