Legal

Privacy Policy

Effective 2026-09-04 · What we collect, who else sees it, and what we cannot delete.

Version 2026-09-04.1

1. Who we are

This website and the paygate service are operated under the name paygate, which is a product name rather than a registered company — see §1 of our terms of service, which govern everything this policy does not. This policy explains what we do with personal data.

Two different relationships are covered here and they are not the same. If you are a merchant, we are the controller of your account data. If you are a merchant’s customer, the merchant is the controller and we process on their behalf — see §6.

2. If you only visit this website

Reading this site does not require an account and we do not ask you for anything. Our hosting provider records ordinary server logs — IP address, browser, the page requested and the time — which exist to keep the site up and to spot abuse.

If you arrive from an advert, the click identifier in the link (for example gclid or fbclid) and any campaign parameters are kept in your browser for the duration of that visit and added to the link if you go on to open an account. That is how we know which advert brought a merchant to us. It is stored in your browser’s session storage, not on our servers, and it is discarded when you close the tab.

3. Cookies and advertising

We use Google Analytics, Google Ads and the Meta pixel to understand which adverts and which pages actually bring merchants to us. None of them stores anything on your device until you accept.

Google’s tag loads for everyone, but with every storage and advertising signal set to denied before it does — in that state it reports an anonymous, cookieless page view and nothing that identifies you. If you accept, that restriction is lifted and Google may set cookies to measure conversions and build advertising audiences. The Meta pixel loads only if you accept, because it cannot be run in a restricted state.

If you decline, we still count the visit; we simply cannot connect it to you or to a later signup. You can change your mind at any time by clearing this site’s data in your browser, which removes the stored choice and shows the banner again.

We also store two things that are not tracking and have no consent banner because they never leave your browser: whether you chose the light or dark theme, and the fact that you answered this banner.

4. If you open a merchant account

If you open a merchant account we hold:

  • Account details — your name, email address and a password stored as an irreversible hash. We cannot read your password.
  • Business profile — your shop name, logo, website and support address, which appear on the checkout pages your customers see.
  • Sessions — a browser description and an IP address per signed-in session, so you can see and revoke them. Deliberately coarse: it is a session list, not a device fingerprint.
  • Payment records — the payments, refunds, invoices and ledger entries generated by your use of the service, including blockchain addresses and transaction identifiers, which are public information on the chain itself.

We use this to provide the service, to keep your account secure, to bill you, and to meet legal obligations. We do not sell it, and we do not share it with advertisers.

5. Identity verification

Where identity verification is required, you are asked for your legal name, your country, and — for a business — its registered name and number. Verification itself runs in a flow that goes from your browser directly to our verification provider. Your identity documents are never received or stored by us.

Of what the provider returns, your verified name, document number, date of birth and address are stored under encryption and can only be read through a single audited path that records who read them and when. Only the document’s type, country, expiry date and last four characters are held in readable form. A completed verification lasts two years.

Verification may involve biometric processing of your face in order to match you to your document. Where you are verifying as a business, you are responsible for obtaining that consent from the individual concerned before submitting them — this is set out in §20 of the terms.

We also screen merchants against sanctions and adverse-media lists, because we are required to. A match is never actioned automatically; a person reviews it.

6. Your customers’ data

When a merchant sends us information about their own customer — a reference, an email address, a name, or arbitrary metadata — the merchant is the controller of that data and we are their processor. We process it only to operate the payment they asked us to operate.

If you are a customer of a business that uses paygate and you want your data corrected or removed, contact that business. They decide; we act on their instruction.

We also record the blockchain address a payment arrived from, so that an unmatched or mistaken transfer can be investigated rather than silently lost.

7. Who else processes data

We share personal data with the following categories of processor, and no others:

  • Our hosting and database providers, which store the service’s data.
  • Our identity verification provider, which receives identity documents directly from your browser and returns a verdict.
  • Google (Analytics and Ads) and Meta, for website measurement and advertising — and only after you accept, as described in §3.
  • Blockchain networks. A payment is a public transaction on a public ledger. Addresses and amounts are visible to anyone, permanently, and that is a property of the technology rather than a choice we make. Nothing we could do would make a confirmed transfer private.

8. How long we keep things, and what cannot be deleted

Operational records expire on their own: exchange-rate quotes and network cost observations after seven days, sessions and tokens seven days after they expire, along with stored request keys and rate-limit counters.

Ledger entries and administrative audit records cannot be edited or deleted at all. This is enforced by the database itself, and it applies to us as much as to anyone. The ledger is the only record of who is owed what, and an audit log that can be rewritten is not an audit log. We would rather tell you this than accept an erasure request covering those records and quietly fail to carry it out.

Verification records are kept for as long as anti-money-laundering rules require and are then removed. Everything else is kept while your account is open, and for a reasonable period afterwards for tax, accounting and dispute purposes.

9. Your rights

Depending on where you live you may have the right to access the personal data we hold about you, to correct it, to have it erased, to restrict or object to how we use it, to receive a copy in a portable form, and to withdraw consent for anything based on consent — advertising cookies above all.

Ask us at support@paygatehq.com and we will act within the time the law allows. Two honest limits: we cannot erase the records described in §8, and we cannot alter or remove anything already written to a public blockchain, because neither is within anybody’s power. Where we cannot do something, we will say so and explain why rather than leaving the request open.

If you are unhappy with our answer you may complain to your local data protection authority.

10. International transfers

Our providers may process data outside your country, including in the United States. Where that happens we rely on the transfer mechanisms those providers make available, such as standard contractual clauses.

11. Security

Passwords are stored using a modern password-hashing algorithm and are not recoverable. API keys are stored only as irreversible hashes — a key is shown to you once at creation and never again, because a key we cannot read is a key we cannot leak. Sensitive verification fields are encrypted, and reading one writes an audit record.

No system is perfectly secure, and we make no claim that ours is. Keeping your own API keys and password safe is your responsibility, and anything done with your keys is treated as done by you.

12. Children

paygate is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18.

13. Changes

We may update this policy. If a change is material we will tell account holders before it takes effect, and the date at the top of this page will change.

14. Contact

Questions about this policy, or a request about your data, go to support@paygatehq.com. There is no postal address to give — see §1.