Legal

Privacy Policy

Last updated: June 1, 2025 · Applies to all users of CryptoGateway

1. Information We Collect

Account Information

When you register, we collect your name, email address, business name, and contact details.

Payment Data

We collect blockchain wallet addresses, transaction IDs, and payment amounts required to process crypto payments. We do not store private keys.

API Usage

We log API calls, IP addresses, request timestamps, and response codes for security and debugging purposes.

Device & Browser

We collect browser type, operating system, and IP address for security monitoring and fraud prevention.

Communications

We retain contact form submissions and support emails to resolve queries and improve our service.

2. How We Use Your Information

Service Delivery

To process cryptocurrency payments, generate wallet addresses, send webhooks, and settle funds to your wallet.

Security

To detect fraud, prevent abuse, monitor for suspicious activity, and protect your account.

Communication

To send transaction confirmations, payment alerts, service updates, and respond to your queries.

Compliance

To comply with applicable anti-money laundering (AML) laws and regulatory requirements.

Analytics

To understand how merchants use our platform and improve our services.

3. Data Sharing

No Sale of Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

Service Providers

We may share data with trusted providers who help operate our platform (e.g., email delivery, server hosting) under strict confidentiality agreements.

Legal Requirements

We may disclose information when required by law, court order, or to protect our legal rights.

Blockchain Data

Blockchain transactions are publicly visible by nature. Wallet addresses and transaction IDs on public blockchains cannot be made private.

4. Data Retention

Account Data

Retained while your account is active and for 7 years after closure for legal and tax compliance.

Transaction Records

Payment records retained for 7 years per financial regulations.

API Logs

API access logs retained for 90 days then purged.

Support Emails

Retained for 2 years after last contact.

5. Cookies

Session Cookies

Essential cookies keep you logged into the merchant dashboard. These are deleted when you close your browser.

Preference Cookies

Store your dashboard display preferences (optional, consent-based).

Analytics Cookies

Help us understand how visitors use the site. You can decline these via the cookie banner.

6. Security

Encryption

All data is transmitted over TLS/SSL. Passwords are hashed with bcrypt. JWT tokens use HS256 signing.

Access Controls

Role-based access (Admin/Sub-admin/Merchant) ensures each user sees only their own data.

No Key Storage

We never store private keys on our servers. All wallet keys are derived client-side from your MASTER_MNEMONIC.

7. Your Rights

Access

You may request a copy of the personal data we hold about you.

Correction

You may update your account information at any time via the dashboard settings.

Deletion

You may request deletion of your account and personal data subject to our legal retention obligations.

Portability

You may export your payment history in CSV format from the dashboard.

8. Contact

Data Enquiries

For privacy questions, data requests, or to report a privacy concern, email us at: support@srglobalmarkets.com