GhostPay

GhostPay Privacy Policy

Effective date: September 3, 2026. This policy explains what personal data [LEGAL ENTITY NAME] ("GhostPay", "we", "us") collects when you use the GhostPay website, dashboard, checkout pages, embed script and API (the "Service"), why we collect it, who we share it with and what rights you have. It applies to merchants (account holders) and to buyers who pay through a GhostPay checkout.

1. Who is responsible

The data controller for the Service is [LEGAL ENTITY NAME]. You can reach us at support@ghostpay.cloud. For data a merchant collects about its own customers (for example through delivery emails or their own website), the merchant is the controller and GhostPay acts as a processor on the merchant's behalf.

2. What we collect

Merchants

  • Name, email address and a hashed password.
  • Payout wallet addresses per token and network, payment links, subscription plans, invoices and delivery templates you configure.
  • Merchant API key, session tokens (stored hashed) and security events such as login times and the IP address of requests.
  • Notification preferences and support correspondence.

Buyers

  • Email address and, optionally, a name entered at checkout or when subscribing — used to deliver the purchase and payment reminders.
  • Order data: amount, token, network, order id, status, timestamps, and the invoice or subscription the order belongs to.
  • Language preference (stored locally in your browser) and the IP address / user-agent of requests for security and rate limiting.

On-chain data

When a payment is made we record the public blockchain transaction data needed to match it to an order: transaction hash, sending wallet address, receiving contract address, token, amount and block time. This data is public on the blockchain by nature and cannot be deleted from it.

We do not collect card numbers, bank details, private keys or seed phrases. We do not use advertising trackers.

3. Why we use it (purposes and legal bases)

  • Providing the Service — creating orders, detecting payments on-chain, settling to merchant wallets, sending receipts, delivery emails and payment reminders (performance of a contract).
  • Security and abuse prevention — authentication, session expiry, rate limiting, fraud and orphan-deposit investigation (legitimate interest).
  • Legal obligations — keeping transaction records, responding to lawful requests.
  • Communication — transactional emails (verification codes, password resets, payment notifications). We do not send marketing emails without consent.

4. Who we share it with (processors)

We use a small number of service providers that process data on our behalf:

  • Supabase — database hosting for accounts, orders, invoices and subscriptions.
  • Brevo — transactional email delivery (verification codes, receipts, delivery and reminder emails).
  • Vercel — hosting of the website and dashboard.
  • Railway — hosting of the API and the blockchain listener.
  • Public blockchain networks (BSC, Ethereum, Tron) and their RPC providers — for detecting and settling payments.

Merchants see the email, name and order data of their own buyers in the dashboard so they can deliver the product and provide support. We may disclose data when required by law or to protect the rights, safety and security of GhostPay, merchants or buyers. We do not sell personal data.

5. International transfers

Our providers may store data in the United States or the European Union. Where required, transfers are protected by standard contractual clauses or equivalent safeguards offered by the provider.

6. Retention

  • Merchant account data: for as long as the account exists, then deleted or anonymised within 90 days of closure, except records we must keep for legal or accounting reasons.
  • Orders, invoices, receipts and on-chain matching records: kept while the merchant account exists and for up to 5 years afterwards for accounting, dispute and compliance purposes.
  • Buyer email addresses on expired, unpaid orders: deleted or anonymised after 90 days.
  • Session tokens: expire automatically and are removed after expiry or logout. Verification and reset codes expire within minutes.
  • Server logs containing IP addresses: up to 30 days.

7. Your rights

Depending on where you live (for example under the GDPR or similar laws) you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to lodge a complaint with a supervisory authority. To exercise these rights, email support@ghostpay.cloud from the address linked to your account or order. Buyers can also contact the merchant directly. Note that data recorded on public blockchains cannot be altered or erased by GhostPay.

8. Cookies and local storage

GhostPay does not use advertising or analytics cookies. The dashboard stores your session in your browser's local storage; buyer pages store only your language preference. Clearing your browser storage logs you out and resets the language.

9. Security

Passwords are hashed, session tokens expire and are stored hashed, payout-wallet changes require your password, and all traffic uses TLS. No system is perfectly secure: keep your credentials and API key confidential and rotate the key if you suspect a leak.

10. Children

The Service is not directed to children under 18 and we do not knowingly collect their data. Contact us if you believe a minor has provided personal data.

11. Changes

We may update this policy. Material changes will be announced in the dashboard or by email at least 14 days before they take effect. The effective date at the top always reflects the current version.

12. Contact and governing law

[LEGAL ENTITY NAME] — support@ghostpay.cloud. This policy is governed by the laws of [JURISDICTION]. See also our Terms of Use.