Privacy Policy

Effective Date: August 2026
Privacy-First & Non-Custodial ArchitectureJamsrPay does not custody merchant funds or store private cryptographic keys. All transaction settlements route directly on-chain between customer and merchant wallets.

1. Information We Collect

When you create a merchant account, generate API keys, or interact with our payment infrastructure, JamsrPay collects minimal operational information necessary to provide payment routing and webhook notifications:

  • Account Credentials: Email address, merchant business name, and encrypted authentication tokens.
  • Public Wallet Addresses: Public blockchain receiving addresses (e.g. TRON, Solana, Ethereum) designated by you for receiving automated settlement routing.
  • Transaction Metadata: Public on-chain transaction hashes, invoice amounts, timestamp, and webhook delivery status.

2. How We Use Collected Information

We use the data collected strictly for the following operational purposes:

  • Facilitating non-custodial cryptocurrency invoice creation and status monitoring.
  • Dispatching cryptographically signed HMAC webhook notifications to merchant endpoints.
  • Preventing denial-of-service (DoS) attacks, brute-force exploits, and unauthorized API usage.
  • Delivering automated monthly billing summaries and merchant dashboard analytics.

3. Data Security & Encryption

We implement industry-standard cryptographic practices. API secrets, webhook signing keys, and account authentication records are encrypted at rest using AES-256 and transmitted exclusively over HTTPS (TLS 1.3).

JamsrPay never requests, stores, or accesses merchant private keys, seed phrases, or custody credentials under any circumstances.

4. Third-Party Sharing & Disclosures

We do not sell, rent, or monetize your personal information or merchant transaction telemetry. Information is only shared under the following limited conditions:

  • Public blockchain broadcast: On-chain payments inherently broadcast transaction hashes to decentralized public ledgers.
  • Infrastructure service providers: Strictly vetted cloud and database providers under confidentiality agreements.
  • Legal compliance: Where required to comply with enforceable court orders or applicable regulations.

5. Cookies & Local Browser Storage

JamsrPay does not deploy third-party advertising cookies or cross-site tracking pixels. We only utilize strictly necessary session tokens and functional local storage:

  • Strictly Necessary: Cryptographic CSRF tokens and secure session identifiers required for merchant dashboard authentication.
  • Functional Storage: Local storage preferences that remember your interface theme (dark/light mode) and active currency filter selections.

6. Your Privacy Rights & Data Deletion

Depending on your jurisdiction (e.g. GDPR, CCPA), you have the right to request access to, export, or deletion of your merchant account data. To request complete account erasure, contact our security team at [email protected].