Privacy Policy
The account is deliberately thin: an email address or a 32-character token, plus a password hash. Nothing else is requested — no passport, no selfie, no phone number, no legal name, no street address. Crediting a payment adds four fields to that record: the invoice's USD amount, the coin, the deposit address, and the transaction hash that matched. That is the entire customer object.
Two explicit negatives. Coins and wallets are never fed to AML scoring or chain-analysis tooling — a public ledger is not our enforcement surface. And traffic content is not stored: no payload captures, no netflow mirrors. Connection metadata lives at most 24 hours, then it is dropped. Email exists to deliver credentials and invoices; a disposable inbox works as long as it receives. Nothing feeds a mailing-list economy, because nothing is for sale.
What we cannot protect you from is stated plainly. Your wallet's privacy is a property of the coin you pick, not of our rack: pay in Monero and the invoice trail ends at a one-time address, pay in transparent-chain assets and a public explorer does the work for anyone. Data retention follows the facility's law, and every jurisdiction page names the governing one. The full mechanics of what is and is not collected are documented in the warrant canary and the acceptable use policy.