This Privacy Policy explains how CryptoPAYR Limited collects, uses, shares and protects personal data, and the rights you have over it. We are the data controller for personal data processed in connection with the Services. It applies alongside our Cookie Policy and Sub-processors page. Where this policy refers to the GDPR, it means the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR as applicable to you.
Data we collect
- Account data — name, email, password hash, and merchant/business details;
- Verification data — identity and compliance information where required by law (KYC/AML), including beneficial-ownership and source-of-funds information;
- Transaction data — payment amounts, currencies, wallet addresses, and metadata;
- Technical & analytics data — IP address, device/browser/OS information, pages viewed, referrer, approximate location, and first-party cookies set by our own self-hosted analytics (see our Cookie Policy). We do not use third-party advertising or cross-site tracking;
- Support data — the contents of support tickets and any attachments you send us;
- Optional buyer data — an email address provided to receive a receipt.
How we use it
To provide and secure the Services, process payments, meet legal and regulatory obligations (including AML/CTF and the Travel Rule), prevent fraud, understand and improve how our sites are used, and communicate with you.
Legal bases
Under the GDPR we rely on the following legal bases:
- Performance of a contract — to create and operate your account, process payments and provide support;
- Legal obligation — to meet AML/CTF, Travel Rule, tax and other regulatory requirements;
- Legitimate interests — to secure the Services, prevent fraud and abuse, and measure and improve our sites using privacy-preserving first-party analytics (balanced against your rights and interests);
- Consent — where required, for example for any non-essential cookies; you may withdraw consent at any time without affecting prior processing.
Sharing
We share data with the service providers that help us operate, listed in our Sub-processors page (for example identity-verification, email and infrastructure providers), and with regulators or law enforcement where legally required. We do not sell personal data, and we do not share it with advertisers.
International transfers
Some of our sub-processors are located outside the European Economic Area / United Kingdom (for example in the United States). Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) or an adequacy decision, so that your data continues to receive an equivalent level of protection.
Retention
We retain personal data for as long as needed to provide the Services and to meet legal and record-keeping obligations (compliance and transaction records are typically kept for at least five years after the relationship ends, as required by AML law). Raw analytics logs are kept only for a limited period and then deleted or anonymised; aggregated, non-identifying statistics may be kept longer.
Your rights
Subject to applicable law, you have the right to: access a copy of your data; have inaccurate data corrected; have data erased; restrict or object to certain processing (including profiling and direct marketing); receive your data in a portable format; and, where we rely on consent, withdraw it. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. To exercise any of these rights, contact [email protected]; we will respond within the time required by law and may need to verify your identity first. Some rights are limited where we must retain data to meet legal or regulatory obligations.
Complaints
If you have concerns about how we handle your data, please contact us first at [email protected] so we can try to resolve them. You also have the right to lodge a complaint with your local data-protection supervisory authority (in the EU, your national authority; in the UK, the Information Commissioner's Office, ico.org.uk).
Security
We use technical and organisational measures including encryption in transit, hashed credentials and access controls. No system is perfectly secure; please protect your own credentials.
Contact
Questions about this policy? Contact us at [email protected] or by post at CryptoPAYR Limited, Cayman Corporate Centre, Office 2852, George Town, Grand Cayman, Cayman Islands.