Privacy Policy
Last updated 17 September 2026
This describes what Vorixpay does with personal data. There is less of it than you might expect: we run no analytics, no advertising and no third-party trackers, and we never see a card number or a bank account. What we do hold is an account, the payments made through it, and whatever customer details a merchant chooses to store.
1.Who is responsible for your data
Vorixpay is the data controller for merchant account data. The service is non-custodial and runs no analytics, advertising or third-party trackers. For any question about your data, or to exercise a right over it, contact us at [email protected].
Where a merchant stores their own customers’ details with us, that merchant decides what is collected and why. They are the controller for it; we process it on their behalf to run the service.
2.What we collect
When you open a merchant account
- Your email address and business name.
- A hash of your password — never the password itself.
- If you switch it on, two-factor settings: an authenticator secret and recovery codes.
- Your notification preferences.
As you use the service
- Invoices you create: title, description, amount, token, network, expiry, any metadata and redirect URL you set.
- Payments seen on-chain: amounts, token, transaction hashes, block numbers, the paying address and the deposit address.
- The payout wallet addresses you register, and the deposit addresses we issue for you.
- API keys, stored as hashes, with the time each was last used.
- Webhook endpoints you register and the delivery attempts made to them.
- A log of emails we send you, so the same notification is not sent twice.
- Ordinary server logs, including IP addresses, kept for security and debugging.
Customer records, if a merchant creates them
- A name, email address, phone number or wallet address, where the merchant supplies one — for example to label a permanent payment address or to email an invoice.
3.What we do not collect
- No card numbers, bank accounts or payment credentials — there are none in this product.
- No analytics, advertising or third-party tracking scripts. The site sets no tracking cookie.
- No identity documents. We do not currently run identity verification on merchants; if that changes because a regulator requires it, this policy will change first.
- No private keys. We never see the key to your payout wallet, and we could not use one if we did.
4.Cookies
The dashboard sets three cookies, all strictly necessary: your session token, the token that renews it, and which of Test or Live mode you are looking at. The admin panel sets its own session cookie for our staff. There are no analytics or advertising cookies, so there is no consent banner to click.
5.Why we use it, and on what basis
Under applicable data protection law, we rely on:
- Performance of a contract — running your account, issuing addresses, collecting your money, sending you notifications about it.
- Legitimate interest — keeping the service secure, investigating abuse, preventing fraud, and debugging failures.
- Legal obligation — anti-money-laundering record keeping and any reporting we are required to make.
We do not sell personal data, and we do not use it to profile or advertise to anyone.
6.The blockchain part, which we cannot undo
Payments happen on public blockchains. The addresses involved, the amounts, the times and the transaction hashes are public, permanent and outside our control. Anyone can read them, and nobody — including us — can edit or delete them.
A wallet address is not a name, but it can sometimes be linked to a person by combining public records. If that matters to you or your customers, take it into account when choosing which addresses to use. Deleting your account with us removes our records; it does not and cannot remove anything already written on a blockchain.
7.Who else sees it
- Our hosting provider, where the servers and database run.
- Our email provider, which delivers the messages we send you.
- Cloudflare, which sits in front of the site and sees request metadata.
- Our error-monitoring provider, which receives a report when something breaks: what failed, on which page, and an account identifier — not your name, your email, your IP address or anything you typed.
- Blockchain node providers, which see the queries we make about addresses and transactions.
- Professional advisers, and regulators or law enforcement where we are legally required to disclose.
Some of these operate in other countries, so your data may be transferred across borders. We use providers that offer an adequate level of protection and rely on the transfer conditions in applicable data protection law. We do not otherwise share personal data with third parties.
8.How long we keep it
- Account data: while your account is open, and for [five] years after it closes, to meet anti-money-laundering record-keeping duties.
- Invoice and payment records: for the same period, because they are financial records.
- Server logs: [90] days.
- Email logs: [12] months.
9.How it is protected
- Traffic is encrypted in transit. Passwords are hashed with bcrypt and never stored in readable form.
- API keys are stored as hashes; the key itself is shown to you once and cannot be recovered from us.
- Two-factor authentication is available on merchant accounts and used on ours.
- Webhook deliveries are signed so you can verify they came from us.
- The key that can change where your money goes is not held on any server we run.
10.Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct it if it is wrong;
- delete it, where we are not required to keep it for a legal or accounting reason;
- restrict or object to a particular use;
- provide it in a portable form.
Write to [email protected] and we will respond within 30 days. If you are a customer of a merchant using Vorixpay, ask that merchant first — the data is theirs to correct or delete, and we will help them do it.
If you are not satisfied, you can complain to the data protection authority that applies to you.
11.If something goes wrong
If a breach of personal data occurs and it is likely to harm anyone, we will report it to the relevant data protection authority within 72 hours of becoming aware of it, and tell affected people where we are required to.
12.Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children.
13.Changes
We will update this page when what we do changes, and change the date at the top. If a change materially affects how we use your data, we will email the address on your account before it takes effect.
See also our terms of service and the security page, which explains what we can and cannot do with your money.