Privacy Policy
Effective date: July 26, 2026
1. Information We Collect
We collect information needed to operate PayLayer as a commerce and identity platform, including creator email addresses, workspace names, merchant USDT wallet addresses, product records, store configuration, webhook configuration, and account setup information.
2. User Authentication and Identity
When applications use PayLayer authentication, we process user email addresses, OTP login events, session state, subscription status, entitlement status, and access-check activity. PayLayer uses this information to authenticate users and tell creator applications whether access should be granted.
3. Sessions, Devices, and Security Logs
We may process session tokens, token hashes, device/browser information, IP-derived request metadata, login attempts, failed verification attempts, active sessions, revoked sessions, API usage logs, and security events. These records help protect users, creators, and the PayLayer platform.
4. Payment and Blockchain Data
PayLayer facilitates USDT TRC-20 payments. Blockchain transactions, wallet addresses, and transaction hashes are public by design. We store payment records needed to verify payments, track subscription and entitlement status, calculate fees, send webhooks, and produce Proof Receipts.
5. Store Checkout Data
For store checkout, we process order references, payment amounts, buyer email addresses when provided, redacted order snapshots, webhook delivery records, payment status, refund markers, and Proof Receipt metadata. Merchants remain responsible for their own product catalog, fulfillment, and customer support records.
6. How We Use Information
- Provide payments, authentication, sessions, subscriptions, entitlements, store checkout, APIs, webhooks, and Proof Receipts.
- Validate sessions and access rights for creator applications.
- Detect fraud, abuse, invalid payment attempts, and security risks.
- Operate dashboards, monitoring, support, and account recovery.
- Comply with applicable legal, financial, and security obligations.
7. Data Sharing
We do not sell personal data. We share only the minimum data needed with creator applications using PayLayer, such as authenticated user identity, subscription status, entitlement status, access result, expiry time, payment status, and webhook payloads relevant to that creator's product or store.
8. Data Retention
We retain identity, session, payment, entitlement, webhook, security, and proof records for as long as needed to provide the Service, maintain financial integrity, resolve disputes, comply with law, and protect the platform. You may request deletion where legally and operationally permitted.
9. Security
PayLayer uses security controls including encrypted transport, OTP authentication, hashed tokens, API authentication, authorization checks, rate limiting, session revocation, monitoring, audit logs, and direct-to-wallet payment design. No system can be guaranteed completely secure.
10. Contact
For privacy questions: privacy@pay-layer.com