Mainnet validation is in progress. Payments and new API keys are disabled.View readiness

Policy

Data minimization policy

Privacy claims are easy to make and hard to verify. These are the principal data categories our current schema and delivery paths use, plus categories we deliberately avoid. Implementation-specific security and operational records may also be retained when needed to protect or operate the service.

What we store

  • Merchant accountEmail, hashed password, approval status, billing plan.
  • API keysBcrypt hash of the key, display label, prefix, created/last-used time, and lifecycle timestamps. Fine-grained scopes are not currently available.
  • InvoicesInvoice ID, amount, currency, coin, status, expiry, on-chain txid, one-way IP security hash, and limited request metadata.
  • Optional customer referencesA merchant may provide its own external customer ID or receipt email. These are stored only for that merchant's checkout and subscription workflow.
  • Webhook deliveriesEndpoint URL, secret used for signing, signed payload, response code, bounded response body, retry count, and delivery timestamps.
  • Address allocationDeposit-address ownership and derivation allocation records retained for reconciliation. Automated rotation is not currently claimed.

What we don't store

  • Raw customer IP addresses in payment records.
  • Payer identity fields required by XMRGate as a condition of checkout.
  • Cross-site advertising identifiers or full browser fingerprints from the checkout page.
  • Geolocation data of any kind.
  • Payment-card or bank-account credentials.
  • Cross-merchant customer profiles or advertising audiences.

Retention

Invoices and on-chain references are retained for merchant accounting and payment reconciliation. Webhook delivery records are retained while needed for retry and audit history. Application logs omit raw client addresses and authentication secrets; retention periods will be published before production payments are enabled.

Subpoenas & data requests

We comply with valid legal requests from our jurisdiction. Because of the policy above, the data available to disclose is structurally limited by the implementation and retention policy. Records may identify a merchant's customer when the merchant supplies a customer reference or email; XMRGate does not independently require payer identity for every payment.