Privacy Policy
Last updated 15 September 2026
This policy explains what NoCenterPay does with personal data, and applies alongside our Terms of Service. The controller is [LEGAL ENTITY NAME], [ADDRESS], Estonia. Contact: [EMAIL].
1. What we collect
From you, when you create an account:
- Username and a hashed password. We never store the password itself.
- Your plan, subscription status, and monthly volume.
- Merchant names you choose, and hashed API keys.
When you use the API:
- Blockchain addresses, coins, amounts, invoice IDs and statuses.
- Callback URLs and delivery attempts.
- Any metadata you attach to an invoice. You choose what goes in it — do not put personal data there unless you need to.
- Transaction hashes and block heights read from public ledgers.
Automatically:
- IP address, timestamps and user agent for security, rate limiting and abuse prevention.
- Server logs of requests and errors.
2. What we do not collect
We do not collect identity documents, proof of address, or any other KYC material, because we never handle funds. We do not have your private keys or seed phrases and cannot ask for them. We do not run advertising trackers or sell data to anyone.
3. Why we process it
- To provide the Service — performance of our contract with you.
- To bill you and enforce plan limits — performance of our contract.
- To keep the Service secure and prevent abuse — our legitimate interest.
- To comply with legal obligations, including accounting and lawful requests from authorities.
4. A note on blockchain data
Addresses and transactions you register are already public and permanent on their networks. We cannot delete, alter, or restrict anything recorded on a blockchain — that is outside anyone's control, including ours. What we can delete is our own copy.
5. Who else sees it
We use third parties only where necessary to run the Service: hosting and database providers, blockchain node providers (to read public chain data), and exchange-rate sources. We send your callback URL nothing but the invoice data you created.
We do not sell personal data. We disclose it to authorities only where legally required, and only what is required.
6. How long we keep it
- Account data: while your account exists, then up to 30 days.
- Payment records: 7 years, as required for accounting.
- Security logs: 90 days.
- Webhook delivery logs: 30 days.
7. Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interest. Write to [EMAIL] and we will respond within one month.
You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.
8. Security
Passwords are hashed, API keys are stored only as hashes, and webhook secrets are encrypted at rest. Access to production systems is limited. No system is perfectly secure, but note what a breach of ours would not expose: no private keys, no funds, and no identity documents, because we never hold any.
9. Transfers outside the EEA
Where a provider processes data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses.
10. Changes
We will announce material changes by email or in the dashboard at least 14 days before they take effect.