Privacy policy
Last updated 1 September 2026. This date changes only when the words change.
This is a template, not legal advice. It describes how Payaider actually works, but no lawyer has reviewed it and it does not know which country you operate in. Have it reviewed, and fill in the parts marked as unset, before this service takes a real payment.
This policy covers the personal data we hold about merchants and the people who run them: what we collect, why, who else sees it, how long we keep it, and what you can ask us to do about it. It also says plainly which parts we cannot undo, because a payment on a public blockchain is permanent and no policy can change that.
What we collect
We collect what we need to run your account, to verify your business because the law requires it, and to keep the service from being used against you.
Account details. Your business name, the name and email address of the person who signed up, your password stored only as a hash we cannot reverse, any second factors you enrol (an authenticator secret, or a passkey’s public key), and the record of sign-ins and security changes.
Verification documents, and the identity data inside them. Registered company name, number and address; and for directors and beneficial owners, names, dates of birth, nationalities, addresses and the identity documents you upload. These are the most sensitive records we hold. Where this deployment keeps the files themselves they are encrypted at rest and readable only by the reviewers deciding your case; where it does not, the bytes are dropped on upload and we keep only a hash that shows which file you sent.
Payout wallet addresses. Each address you register, its network, the label you gave it, and the proof of ownership you provided — a signed message, or the small transfer we asked you to make.
Payment metadata. The amount, asset and network of each payment, the transaction hash, the addresses involved, timestamps, your invoice reference, and whatever you put in the metadata field yourself. We do not ask for your customer’s name or details; if you send them in metadata that is your decision, and you need your own basis for it.
Technical logs. IP addresses, user-agent strings, the paths and times of requests, which API key was used, and the outcome of each webhook delivery attempt. There are no advertising or analytics trackers here, and these pages load nothing from anyone else.
Why we use it, and our lawful basis
To perform our contract with you. Running your account, watching the networks for your payments, matching them, sending webhooks, calculating and billing fees, and answering support requests.
To meet a legal obligation. Anti-money-laundering rules require us to identify the businesses we serve, screen them and their addresses against sanctions lists, keep a record of what we checked and when, and in some cases report a suspicion. Verification data is used for this and kept for this.
For our legitimate interests. Preventing fraud, detecting compromised accounts, securing and debugging the service, and stopping abuse. We use the least data that does the job and keep technical logs briefly, weighing these uses against your rights rather than assuming they win.
We do not sell personal data, do not share it for anyone else’s advertising, and do not use your verification documents for anything but deciding your case and keeping the record the law requires. That decision is made by a person: provider reports are evidence put in front of them, never an approval or refusal on their own.
Who we share it with
- Our verification provider, who receives your business and officer details to check them against company registries, sanctions lists and identity data, and returns evidence for our reviewer to weigh.
- Our email provider, who receives the address we are writing to and what the message says — verification mail, password resets, notices about your account.
- Blockchain data providers and node operators, who receive the addresses and transaction hashes we ask about. That data is already public; the query still tells them which addresses interest us.
- The infrastructure providers hosting the service and storing its data, under contracts binding them to use it only as we instruct.
- Our professional advisers, and law enforcement, regulators or courts where we are legally required to respond — sometimes without being permitted to tell you.
That is the whole list. If we add a category we will update this page and, where the change is material, tell you.
On-chain data is public and permanent
A payment made to you is a public record forever. The amount, the sending address, your receiving address and the time are written to a public blockchain by the person who paid you. We do not put them there and cannot take them away. No right in this policy and no request to us can delete, redact or obscure them: they are not ours to change, and they exist on thousands of machines we do not control.
Addresses are also linkable. Once anyone connects one of yours to your business — from your checkout page, an invoice, or a customer who mentions it — every payment ever made to that address can be read together as a history. If that matters, use separate addresses for separate parts of the business, and decide before you publish one rather than after.
How long we keep it
- Account details: while your account is open, and for a limited period after it closes so we can deal with questions, disputes and billing.
- Verification documents and the identity data in them: for the statutory record-keeping period applying to anti-money-laundering records after our relationship ends — commonly five years where the usual international standards are followed, and longer where a regulator or court requires it.
- Payment metadata and fee records: kept as accounting and anti-money-laundering records for the same statutory period.
- Technical logs: a short rolling window measured in months, after which they are deleted or reduced to aggregates that identify nobody.
Closing your account does not erase the anti-money-laundering records. We must keep them for the full statutory period and we will, even if you ask us to delete everything. What we can do is stop using them for anything except that obligation. Better to say so now than to discover it together when you make a request.
Not set. The exact retention periods depend on the law of the jurisdiction the operator names in the terms of service, which has not been set. Replace the periods above with the ones that apply there.
Your rights, and how to use them
Depending on where you live, you may have the right to:
- ask what we hold about you, and get a copy of it
- have inaccurate data corrected
- have data erased, where we have no obligation or overriding reason to keep it
- ask us to restrict how we use it while a question about it is resolved
- object to a use resting on our legitimate interests
- receive the data you gave us in a portable form
- withdraw a consent, where consent was the basis we relied on
- complain to your data protection authority, which you can do without asking us first
To use any of them, write to the address below, ideally from the email address on the account. From any other address we will ask for something showing the request is really yours, because handing an account’s data to a stranger who asked politely is itself a breach. We answer within one month, tell you before the month is out if a complex request needs longer, and charge nothing unless a request is manifestly unfounded or repetitive and the law allows a fee.
Two limits, stated up front. We cannot erase anti-money-laundering records inside the statutory period, and we cannot erase anything from a blockchain. Where we refuse part of a request for one of those reasons we will say which, and point you at the rule.
How we protect it
In general terms, because the detail of a control is more useful to an attacker:
- traffic is encrypted in transit, and the console sets a strict content policy — it loads no third-party script, font or image at all
- verification documents are encrypted at rest, and access is limited to the reviewers who need it and recorded when it happens
- passwords are stored as slow one-way hashes, never in a form we could read
- second factors are available and encouraged on every account that reaches the console: an authenticator app, or a passkey
- API keys and webhook secrets are shown once and stored only as hashes, so a copy of our store hands nobody a working key
There is no wallet key here to steal. We hold no private key for any merchant wallet, so the worst outcome of a breach of our systems does not include somebody moving your money. It could still include your business and identity data, which is why the controls above exist. No system is perfectly secure; if a breach affects your personal data we will tell you and the relevant authority within the time the law sets, saying what we know rather than waiting until we know everything.
International transfers
Some providers listed above operate outside the country where you are based, so your data may be processed elsewhere. Where it leaves a jurisdiction that restricts transfers we rely on the safeguards that jurisdiction provides — an adequacy decision, or standard contractual clauses with the provider — together with the technical measures described above.
Not set. Which safeguards apply depends on where the operator is established and where its providers are. The operator must confirm the mechanism for each provider once the governing jurisdiction in the terms of service is set, and name it here.
Contacting us about privacy
Write to wecare@softbnb.com about privacy, or to make any of the requests above. Mail we send you comes from a different address, so write to this one rather than replying to a notification.
Not set. The identity of the data controller has not been set. The operator must publish here the legal name and registered address of the company that decides how this data is used, and the name of a data protection officer or representative if the law where they operate requires one.
If we change this policy we will update the date at the top, and for a material change tell you by email before it takes effect.