Privacy Policy

1. Who we are

PayAgents ("PayAgents," "we," "us," or "our") provides developer infrastructure that enables software agents to send and receive payments across multiple payment rails through a single API and SDK (the "Service"), available at payagents.io and app.payagents.io.

This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the choices you have.

If you have questions, contact us at team@payagents.io.

2. Scope

This policy applies to information we process about:

  • Developers who create an account, use the dashboard, or integrate our SDK/API.
  • Visitors to our websites.

It does not govern how the developers who build on PayAgents handle the data of their own end users. Those developers are independent controllers responsible for their own privacy practices.

3. Information we collect

Information you provide:

  • Account information: email address and authentication credentials (passwords are stored only as salted hashes; we never store them in plaintext).
  • Communications you send to us: (for example, support requests).

Information generated by your use of the Service:

  • API keys and their metadata: name, creation date, last-used time, status.
  • Transaction records: amounts, timestamps, the payment rail used, the endpoint paid or the charge issued, payment proofs (such as on-chain transaction hashes or Lightning payment preimages), and balance changes.
  • Configuration you set: spending policies, approval thresholds, accepted rails, and webhook endpoints.

Information collected automatically:

  • Technical data: IP address, browser/device type, and timestamps, collected through server logs and, where applicable, cookies or similar technologies for authentication and security.

Information from third parties:

  • Data returned by our payment-rail and infrastructure providers: (for example, settlement confirmations and exchange-rate information) necessary to complete and record transactions.

Compliance information (where applicable):

Where required to meet legal or regulatory obligations, we may collect identity or verification information (for example, to satisfy know-your-customer ("KYC") or anti-money-laundering ("AML") requirements). We collect such information only where a legal obligation or risk assessment requires it.

We do not intentionally collect special categories of personal data, and we ask that you not submit them.

4. Blockchain and payment data

Because the Service settles payments over public blockchain networks and the Lightning Network:

  • On-chain transactions (including wallet addresses, amounts, and transaction hashes) are recorded on public ledgers that we do not control and cannot alter or delete.
  • We store references to these transactions (such as transaction hashes and preimages) as proof of payment and for reconciliation.
  • Information written to a public blockchain may be permanent and publicly visible. Please consider this before transacting.

5. How we use information

We use information to:

  • Provide, operate, and maintain the Service, including authenticating you, routing and settling payments, tracking balances, and enforcing the spending policies you configure.
  • Prevent, detect, and investigate fraud, abuse, security incidents, and violations of our Terms.
  • Comply with legal, regulatory, tax, accounting, and anti-money-laundering obligations.
  • Communicate with you about the Service, including transactional and security notices.
  • Improve and develop the Service, including debugging and analytics.

Legal bases (where required, e.g. under GDPR/DPDP): performance of our contract with you, our legitimate interests (such as security and service improvement), compliance with legal obligations, and, where applicable, your consent.

Regulations we work to comply with: Depending on where you and your users are located, applicable data-protection and financial regulations may include the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Brazilian General Data Protection Law (LGPD), India's Digital Personal Data Protection Act (DPDP), and other regional regulations.

6. How we share information

We share information only as described here:

  • Service providers / processors: who host our infrastructure, run our database, process payments, and provide analytics or communications, under agreements that limit their use of the data. This includes our cloud hosting, database, payment-rail, and blockchain-facilitator providers.
  • Payment networks and facilitators: as necessary to execute and settle transactions.
  • Legal and safety: when required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of PayAgents, our users, or others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not sell your personal information, and we do not serve third-party advertising in the Service.

7. International transfers

We and our providers may process information in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

8. Data retention

We retain information for as long as your account is active and as needed to provide the Service. We retain transaction and financial records for the period required by applicable tax, accounting, and anti-money-laundering laws, which may extend beyond account closure. Blockchain records, as noted, cannot be deleted by us.

9. Security

We use technical and organizational measures designed to protect information, including encryption in transit, hashed credentials, scoped API keys, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your API keys and account credentials confidential.

10. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact team@payagents.io. We will respond as required by applicable law. Note that some data (such as records we must keep for legal reasons, or immutable blockchain records) may be exempt from deletion.

If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority. If you are in India, you may have rights under the Digital Personal Data Protection Act.

11. Children

The Service is not directed to individuals under the age of 18, and we do not knowingly collect their personal data.

12. Changes

PayAgents reserves the right to make changes in this privacy policy as and when required. The update shall be notified to users on this page and on our web app and wallet. We encourage users to periodically review this privacy policy to remain informed. After any changes are made if the user continues to use our service then it shall be assumed that the user has agreed to the updated terms.

13. Contact

PayAgents
Email: team@payagents.io