GhostPayEffective date: September 3, 2026. This policy explains what personal data [LEGAL ENTITY NAME] ("GhostPay", "we", "us") collects when you use the GhostPay website, dashboard, checkout pages, embed script and API (the "Service"), why we collect it, who we share it with and what rights you have. It applies to merchants (account holders) and to buyers who pay through a GhostPay checkout.
The data controller for the Service is [LEGAL ENTITY NAME]. You can reach us at support@ghostpay.cloud. For data a merchant collects about its own customers (for example through delivery emails or their own website), the merchant is the controller and GhostPay acts as a processor on the merchant's behalf.
When a payment is made we record the public blockchain transaction data needed to match it to an order: transaction hash, sending wallet address, receiving contract address, token, amount and block time. This data is public on the blockchain by nature and cannot be deleted from it.
We do not collect card numbers, bank details, private keys or seed phrases. We do not use advertising trackers.
We use a small number of service providers that process data on our behalf:
Merchants see the email, name and order data of their own buyers in the dashboard so they can deliver the product and provide support. We may disclose data when required by law or to protect the rights, safety and security of GhostPay, merchants or buyers. We do not sell personal data.
Our providers may store data in the United States or the European Union. Where required, transfers are protected by standard contractual clauses or equivalent safeguards offered by the provider.
Depending on where you live (for example under the GDPR or similar laws) you may have the right to access, correct, delete or export your personal data, to restrict or object to certain processing, and to lodge a complaint with a supervisory authority. To exercise these rights, email support@ghostpay.cloud from the address linked to your account or order. Buyers can also contact the merchant directly. Note that data recorded on public blockchains cannot be altered or erased by GhostPay.
GhostPay does not use advertising or analytics cookies. The dashboard stores your session in your browser's local storage; buyer pages store only your language preference. Clearing your browser storage logs you out and resets the language.
Passwords are hashed, session tokens expire and are stored hashed, payout-wallet changes require your password, and all traffic uses TLS. No system is perfectly secure: keep your credentials and API key confidential and rotate the key if you suspect a leak.
The Service is not directed to children under 18 and we do not knowingly collect their data. Contact us if you believe a minor has provided personal data.
We may update this policy. Material changes will be announced in the dashboard or by email at least 14 days before they take effect. The effective date at the top always reflects the current version.
[LEGAL ENTITY NAME] — support@ghostpay.cloud. This policy is governed by the laws of [JURISDICTION]. See also our Terms of Use.