Legal

Privacy Policy

We keep the smallest amount of data needed to route a transaction, prove it happened and support you when something breaks.

Last updated: 12 August 2026

Data we collect

Account and contact details, Agent ID and wallet channel metadata, transaction records (order id, amount, fee, status, timestamps), API logs, webhook delivery attempts and IP addresses used for whitelisting.

Data we never expose

Wallet credentials, PINs and full account numbers are never returned in API responses or webhooks. Sensitive identifiers are masked in dashboards, logs and support tickets.

How we use it

To route and settle transactions, enforce limits and cooldowns, detect abuse, produce reconciliation reports, and provide technical support.

Sharing

Data is shared only with the wallet provider needed to complete a transaction, with infrastructure vendors under contract, and with regulators where legally required. We do not sell data.

Retention and security

Transaction records are retained for statutory audit periods; API logs for a shorter operational window. Encryption in transit, encrypted secrets at rest, signed webhooks, IP whitelisting and role-based internal access are enforced.

Your rights

You may request access, correction or deletion of data that is not subject to legal retention by writing to support@pay2capital.com.