Privacy Policy

Effective date: July 26, 2026

1. Information We Collect

We collect information needed to operate PayLayer as a commerce and identity platform, including creator email addresses, workspace names, merchant USDT wallet addresses, product records, store configuration, webhook configuration, and account setup information.

2. User Authentication and Identity

When applications use PayLayer authentication, we process user email addresses, OTP login events, session state, subscription status, entitlement status, and access-check activity. PayLayer uses this information to authenticate users and tell creator applications whether access should be granted.

3. Sessions, Devices, and Security Logs

We may process session tokens, token hashes, device/browser information, IP-derived request metadata, login attempts, failed verification attempts, active sessions, revoked sessions, API usage logs, and security events. These records help protect users, creators, and the PayLayer platform.

4. Payment and Blockchain Data

PayLayer facilitates USDT TRC-20 payments. Blockchain transactions, wallet addresses, and transaction hashes are public by design. We store payment records needed to verify payments, track subscription and entitlement status, calculate fees, send webhooks, and produce Proof Receipts.

5. Store Checkout Data

For store checkout, we process order references, payment amounts, buyer email addresses when provided, redacted order snapshots, webhook delivery records, payment status, refund markers, and Proof Receipt metadata. Merchants remain responsible for their own product catalog, fulfillment, and customer support records.

6. How We Use Information

7. Data Sharing

We do not sell personal data. We share only the minimum data needed with creator applications using PayLayer, such as authenticated user identity, subscription status, entitlement status, access result, expiry time, payment status, and webhook payloads relevant to that creator's product or store.

8. Data Retention

We retain identity, session, payment, entitlement, webhook, security, and proof records for as long as needed to provide the Service, maintain financial integrity, resolve disputes, comply with law, and protect the platform. You may request deletion where legally and operationally permitted.

9. Security

PayLayer uses security controls including encrypted transport, OTP authentication, hashed tokens, API authentication, authorization checks, rate limiting, session revocation, monitoring, audit logs, and direct-to-wallet payment design. No system can be guaranteed completely secure.

10. Contact

For privacy questions: privacy@pay-layer.com