Privacy Policy
Effective Date: August 20261. Information We Collect
When you create a merchant account, generate API keys, or interact with our payment infrastructure, JamsrPay collects minimal operational information necessary to provide payment routing and webhook notifications:
- Account Credentials: Email address, merchant business name, and encrypted authentication tokens.
- Public Wallet Addresses: Public blockchain receiving addresses (e.g. TRON, Solana, Ethereum) designated by you for receiving automated settlement routing.
- Transaction Metadata: Public on-chain transaction hashes, invoice amounts, timestamp, and webhook delivery status.
2. How We Use Collected Information
We use the data collected strictly for the following operational purposes:
- Facilitating non-custodial cryptocurrency invoice creation and status monitoring.
- Dispatching cryptographically signed HMAC webhook notifications to merchant endpoints.
- Preventing denial-of-service (DoS) attacks, brute-force exploits, and unauthorized API usage.
- Delivering automated monthly billing summaries and merchant dashboard analytics.
3. Data Security & Encryption
We implement industry-standard cryptographic practices. API secrets, webhook signing keys, and account authentication records are encrypted at rest using AES-256 and transmitted exclusively over HTTPS (TLS 1.3).
JamsrPay never requests, stores, or accesses merchant private keys, seed phrases, or custody credentials under any circumstances.
4. Third-Party Sharing & Disclosures
We do not sell, rent, or monetize your personal information or merchant transaction telemetry. Information is only shared under the following limited conditions:
- Public blockchain broadcast: On-chain payments inherently broadcast transaction hashes to decentralized public ledgers.
- Infrastructure service providers: Strictly vetted cloud and database providers under confidentiality agreements.
- Legal compliance: Where required to comply with enforceable court orders or applicable regulations.
5. Cookies & Local Browser Storage
JamsrPay does not deploy third-party advertising cookies or cross-site tracking pixels. We only utilize strictly necessary session tokens and functional local storage:
- Strictly Necessary: Cryptographic CSRF tokens and secure session identifiers required for merchant dashboard authentication.
- Functional Storage: Local storage preferences that remember your interface theme (dark/light mode) and active currency filter selections.
6. Your Privacy Rights & Data Deletion
Depending on your jurisdiction (e.g. GDPR, CCPA), you have the right to request access to, export, or deletion of your merchant account data. To request complete account erasure, contact our security team at [email protected].