CryptumPay Privacy Policy

Last updated: May 31, 2026

This Privacy Policy explains how CryptumPay collects, uses, stores, shares and protects personal data when you visit our website, use the CryptumPay console, create an account, request a demo, use our payment pages, make or receive crypto payments, contact support, use our APIs or otherwise interact with CryptumPay.

This Privacy Policy applies to:

  • website visitors;
  • merchants;
  • merchant representatives;
  • payers;
  • users of CryptumPay payment pages;
  • users of the CryptumPay console;
  • users of the CryptumPay mobile application, where available;
  • other persons who interact with CryptumPay.

By using CryptumPay, you acknowledge that your personal data may be processed as described in this Privacy Policy.

If you do not agree with this Privacy Policy, you must not use CryptumPay.

1. Who We Are

“CryptumPay”, “we”, “us” or “our” means the CryptumPay service, website, console, payment pages, APIs, widgets, mobile application where available, and related services operated by the Administration of CryptumPay.

“Administration” means the administration and operating team of the CryptumPay service.

For the purposes of this Privacy Policy, CryptumPay generally acts as an independent data controller for the personal data processed in connection with accounts, merchant onboarding, KYC, KYB, AML, payments, withdrawals, refunds, security, support, analytics and compliance.

2. Contact

For privacy-related questions, requests or complaints, contact us at:

info@cryptumpay.com

You may also contact us through the official CryptumPay support channels listed on our website or in the CryptumPay console. However, legal and privacy-related requests should be sent to the email address above.

3. Relationship with the Terms of Use

This Privacy Policy forms part of the legal framework for using CryptumPay and should be read together with the CryptumPay Terms of Use.

If there is any inconsistency between this Privacy Policy and the Terms of Use regarding personal data processing, this Privacy Policy governs the relevant personal data processing matter.

The English version of this Privacy Policy is the controlling version. Any translation is provided for convenience only.

4. Personal Data We Collect

We may collect different categories of personal data depending on how you interact with CryptumPay.

4.1. Data collected from website visitors

When you visit our website, we may collect:

  • technical data, such as IP address, browser type, device type, operating system, user agent, pages visited, referrer URL, date and time of visit and server log data;
  • cookie and similar technology data;
  • analytics data;
  • information submitted through website forms, such as email address, Telegram username, company website or domain and any message or request you submit.

4.2. Data collected when you request a demo

When you request a demo or contact CryptumPay through the website, we may collect:

  • email address;
  • Telegram username or contact;
  • company website or domain;
  • company-related information you provide;
  • message content;
  • communication history.

4.3. Data collected during merchant registration and login

When a Merchant or merchant representative creates an account or logs in to the console, we may collect:

  • email address;
  • password or authentication credentials;
  • email verification status;
  • login method;
  • Google login data, where you choose to sign in with Google;
  • Telegram login data, where you choose to sign in with Telegram;
  • two-factor authentication data;
  • authentication logs;
  • login history;
  • IP addresses used for login;
  • device and browser data;
  • user agent data;
  • security notifications;
  • account settings;
  • API whitelist or IP whitelist settings, where available.

If you use Google or Telegram login, the relevant provider may share account information with us, such as account identifier, email address, username or other information made available through that login method.

4.4. Merchant KYC and KYB data

For merchant onboarding, verification, compliance, AML, sanctions and risk-management purposes, we may collect information and documents including:

  • company name;
  • registration number;
  • country of registration;
  • legal address;
  • directors;
  • beneficial owners;
  • authorised representatives;
  • company documents;
  • website or domain;
  • proof of domain ownership or authorised use;
  • business description;
  • expected transaction volume;
  • source of funds;
  • licences, permits or registrations, where applicable;
  • additional information reasonably required for KYC, KYB, AML, sanctions, compliance or risk review.

4.5. Individual KYC data

Where individual identity verification is required, we may collect or receive data including:

  • full name;
  • date of birth;
  • country;
  • identity document data;
  • identity document image or scan;
  • selfie or liveness verification data;
  • verification result;
  • verification status;
  • related compliance records.

KYC verification may be performed through third-party identity verification providers.

4.6. Merchant service data

When a Merchant uses CryptumPay, we may collect and store:

  • project names and settings;
  • domains and websites connected to projects;
  • API keys and related technical settings;
  • webhook URLs;
  • payment settings;
  • payment page settings;
  • payment widget settings;
  • transaction history;
  • withdrawal history;
  • withdrawal addresses, where applicable;
  • payment amounts;
  • assets;
  • networks;
  • payment statuses;
  • transaction hashes;
  • internal order identifiers;
  • order names or descriptions submitted by the Merchant;
  • API request and response data;
  • webhook delivery data;
  • support communications.

Merchants must not submit unnecessary personal data through API fields, metadata, order descriptions, webhook URLs, support requests or other technical fields.

4.7. Payer data

When a Payer uses a CryptumPay payment page, widget, API-based checkout or other payment interface, we may collect and store:

  • email address, if the Payer chooses to provide it for payment status notifications or support purposes;
  • selected asset;
  • selected blockchain network;
  • payment amount;
  • payment status;
  • transaction hash;
  • user agent data;
  • payment page interaction data;
  • refund address, where the Payer provides one;
  • refund status;
  • support communications.

We do not intentionally store the Payer’s source wallet address as a separate profile field. However, blockchain transactions are public, and transaction hashes may be linked to wallet addresses and other on-chain information available on public blockchains.

4.8. Mobile application data

Where the CryptumPay mobile application is available, we may collect and process:

  • email address;
  • wallet connection data;
  • WalletConnect or similar wallet connection data;
  • saved payment method data;
  • selected wallet, asset and network combinations;
  • list of Merchants for which the user has authorised saved payment method use;
  • payment confirmation history;
  • push notification tokens;
  • device data;
  • application logs;
  • support communications.

CryptumPay does not store Face ID, Touch ID or similar biometric data. Biometric confirmation is handled by the user’s device or operating system, where available.

4.9. Support and communication data

When you contact us, we may collect:

  • email address;
  • Telegram username;
  • message content;
  • attachments you provide;
  • support request history;
  • payment or account identifiers related to the request;
  • technical information needed to resolve the request.

5. Data We Receive from Third Parties

We may receive personal data or related information from third parties, including:

  • identity verification providers;
  • KYC and KYB providers;
  • AML and blockchain analytics providers;
  • email service providers;
  • authentication providers, such as Google or Telegram, where you use them to log in;
  • hosting, cloud, database, logging and monitoring providers;
  • content delivery, DNS and security providers;
  • support providers;
  • analytics providers;
  • security and fraud-prevention providers;
  • blockchain networks and public blockchain data sources.

The data received depends on the service used and the purpose of processing.

6. Public Blockchain Data

Crypto transactions are recorded on public blockchains.

Public blockchain data may include:

  • wallet addresses;
  • transaction hashes;
  • asset type;
  • network;
  • transaction amount;
  • timestamp;
  • transaction status;
  • other on-chain data.

CryptumPay does not control public blockchains and cannot delete, modify or hide data recorded on public blockchains.

Even if CryptumPay does not store a Payer’s source wallet address as a separate profile field, a transaction hash may allow on-chain data to be viewed through public blockchain explorers or other blockchain analytics tools.

7. How We Use Personal Data

We may use personal data for the following purposes:

  • providing the website;
  • providing the CryptumPay console;
  • creating and managing accounts;
  • verifying email addresses;
  • enabling login and authentication;
  • enabling two-factor authentication;
  • sending login and security notifications;
  • processing demo requests;
  • onboarding Merchants;
  • verifying Merchants;
  • performing KYC and KYB checks;
  • performing AML, sanctions and risk checks;
  • generating payment invoices;
  • processing crypto payments;
  • displaying payment statuses;
  • sending payment status notifications;
  • processing refunds;
  • processing withdrawals;
  • maintaining Merchant Balances;
  • providing APIs, widgets and webhooks;
  • maintaining transaction history;
  • providing support;
  • troubleshooting technical issues;
  • preventing fraud, abuse, money laundering, sanctions evasion and prohibited activity;
  • protecting accounts, systems and funds;
  • monitoring service performance;
  • analysing website and product usage;
  • improving the Service;
  • complying with legal, regulatory, compliance, AML, sanctions, accounting, audit and recordkeeping obligations;
  • enforcing the Terms of Use;
  • resolving disputes;
  • protecting the rights, safety and legitimate interests of CryptumPay, Users, Merchants, Payers and third parties.

8. Legal Bases for Processing

Where applicable data protection law requires a legal basis for processing, we rely on one or more of the following legal bases.

8.1. Performance of a contract

We process personal data where necessary to provide the Service, manage accounts, process payments, process withdrawals, provide support and perform our obligations under the Terms of Use.

8.2. Legal and compliance obligations

We process personal data where necessary to comply with legal, regulatory, AML, sanctions, accounting, audit, reporting, recordkeeping or other compliance obligations.

8.3. Legitimate interests

We process personal data where necessary for our legitimate interests, including:

  • operating and improving the Service;
  • preventing fraud and abuse;
  • protecting the security of accounts, systems and funds;
  • performing risk management;
  • conducting analytics;
  • communicating with Users;
  • handling support requests;
  • enforcing the Terms of Use;
  • defending legal claims;
  • maintaining business records.

8.4. Consent

We may rely on consent where required, including for certain cookies, analytics, marketing communications or optional features.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal of consent does not affect processing that occurred before withdrawal.

9. KYC, KYB, AML and Compliance Processing

CryptumPay may process personal data for KYC, KYB, AML, sanctions, fraud-prevention, compliance and risk-management purposes.

This may include:

  • collecting identity and company information;
  • verifying documents;
  • checking beneficial ownership;
  • checking domain ownership;
  • analysing business models;
  • screening transactions;
  • reviewing blockchain activity;
  • assessing source of funds;
  • detecting suspicious activity;
  • applying restrictions or holds;
  • keeping compliance records;
  • reporting activity where required or appropriate.

KYC, KYB and AML processing may involve third-party verification and compliance providers.

We may refuse to provide or continue providing the Service if required verification or compliance information is not provided or cannot be verified.

10. Cookies and Similar Technologies

CryptumPay uses cookies and similar technologies.

We may use:

  • essential cookies required for website, console and payment page operation;
  • authentication cookies required for login and account sessions;
  • security cookies used to protect accounts and prevent abuse;
  • preference cookies, where available;
  • analytics cookies and similar technologies used to understand website and product usage.

We use analytics tools, including Google Analytics and Yandex Metrica, to understand how visitors use our website and improve the Service.

Google Analytics and Yandex Metrica may set or access cookies, device identifiers or similar technologies. These tools may collect information such as pages visited, session duration, approximate location, device type, browser type, referrer and interaction data.

We do not use advertising pixels or advertising cookies unless this Privacy Policy is updated or additional notice is provided.

You can control cookies through your browser settings. If you disable certain cookies, some parts of the website, console or payment pages may not work properly.

Where required by applicable law, non-essential analytics cookies and similar technologies will be used only with consent or another valid legal basis.

Where consent is required by applicable law for certain cookies or similar technologies, we will seek consent or provide relevant choices as required by law.

11. Analytics

We may use analytics tools to:

  • measure website traffic;
  • understand page performance;
  • understand user flows;
  • detect technical problems;
  • improve the website and Service;
  • evaluate marketing and product effectiveness.

Analytics data is generally used in aggregated or statistical form, but it may include online identifiers or technical data that can be considered personal data under applicable law.

12. How We Share Personal Data

We may share personal data with the following categories of recipients:

  • hosting and cloud infrastructure providers;
  • database providers;
  • content delivery, DNS and security providers;
  • email service providers;
  • identity verification providers;
  • KYC and KYB providers;
  • AML and blockchain analytics providers;
  • exchange and liquidity infrastructure providers;
  • support service providers;
  • analytics providers;
  • error tracking, logging and monitoring providers;
  • security and fraud-prevention providers;
  • professional advisers;
  • authorities, regulators, law enforcement or courts where required or appropriate;
  • business successors, where rights or obligations are assigned or transferred in accordance with the Terms of Use.

We do not sell personal data.

For routine conversion, we do not intentionally share personal identity data with exchanges or liquidity providers. Conversion-related information is generally limited to technical transaction information such as amount, asset and network.

In exceptional cases, additional information may be processed or disclosed where required by law, compliance obligations, sanctions checks, investigations, risk controls or protection of CryptumPay, Users, Merchants, Payers or third parties.

13. Third-Party Providers

We use third-party providers to operate CryptumPay.

These providers may process personal data on our behalf or independently, depending on the service and context.

We may change providers from time to time. For that reason, this Privacy Policy generally describes providers by category rather than by name.

Third-party providers may have their own privacy policies and processing practices.

14. International Data Transfers

CryptumPay is operated by a distributed team and may use service providers located in different countries.

Your personal data may be processed, stored or accessed in countries other than your country of residence.

Where required by applicable law, we will use appropriate safeguards for international transfers, which may include contractual safeguards, technical measures, organisational measures or other lawful transfer mechanisms.

15. Data Retention

We retain personal data for as long as necessary for the purposes described in this Privacy Policy, including legal, compliance, AML, sanctions, security, accounting, audit, dispute-resolution, fraud-prevention and operational purposes.

We do not keep all categories of data for the same period. Retention periods may vary depending on the type of data, the reason for processing, legal requirements, risk level and operational needs.

In particular:

  • account data may be retained while the account is active and for a period after closure where necessary;
  • KYC, KYB and AML records may be retained for as long as necessary for legal, compliance, AML, sanctions, audit, dispute and security purposes;
  • transaction history may be retained for legal, compliance, AML, accounting, audit, dispute and security purposes;
  • payment and withdrawal records may be retained for legal, compliance, AML, accounting, audit, dispute and security purposes;
  • support communications may be retained for legal, compliance, dispute-resolution, security and service-quality purposes;
  • server logs may be retained for as long as necessary for security, troubleshooting, audit, fraud-prevention and operational purposes, unless a longer period is required for legal, compliance or dispute-resolution reasons.

We may be unable to delete certain data if retention is necessary for legal, compliance, AML, sanctions, accounting, audit, security, fraud-prevention or dispute-resolution purposes.

16. Account Deletion

You may request account deletion by contacting CryptumPay support.

Before deleting or closing an account, we may need to verify your identity, authority or account ownership.

Account deletion may be refused, delayed or limited if:

  • the account has a non-zero Merchant Balance;
  • transactions are pending;
  • refunds are pending;
  • withdrawals are pending;
  • AML or sanctions checks are pending;
  • there are unresolved disputes;
  • the account is under investigation;
  • retention is required for legal, compliance, AML, sanctions, accounting, audit, security or dispute-resolution purposes.

Even after account deletion, certain records may be retained where required or necessary.

17. Data Security

We use technical and organisational measures designed to protect personal data.

These measures may include:

  • two-factor authentication;
  • encryption;
  • IP allowlists or whitelists where available;
  • access controls;
  • security logs;
  • monitoring;
  • security notifications;
  • internal access restrictions;
  • technical safeguards for accounts and systems.

No method of transmission or storage is completely secure. We cannot guarantee absolute security of personal data.

Users are responsible for maintaining the security of their accounts, devices, email, passwords, two-factor authentication methods, API keys and connected systems.

18. Personal Data Breaches

We maintain procedures intended to help identify, assess and respond to personal data breaches.

If a personal data breach occurs, we may investigate the incident, take steps to mitigate potential harm and notify affected users, authorities or other parties where required by applicable law.

We may also document personal data breaches where required or appropriate.

19. User Rights

Depending on applicable law and your location, you may have rights regarding your personal data, including the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • request data portability;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a data protection authority.

To exercise your rights, contact us at:

info@cryptumpay.com

We may need to verify your identity, authority or account ownership before responding to your request.

We may refuse to act on a request if we cannot verify the identity, authority or account ownership of the requester.

We will respond within a reasonable period. Where GDPR or another applicable law applies, we will respond within the period required by applicable law.

Some requests may be refused, delayed or limited where necessary for legal, compliance, AML, sanctions, accounting, audit, security, fraud-prevention or dispute-resolution purposes.

20. Children

CryptumPay is not intended for persons under 18 years old.

Persons under 18 must not use CryptumPay.

If we learn that a person under 18 has provided personal data or created an account, we may restrict, suspend or delete the account and related data, subject to legal, compliance, AML, security and dispute-resolution requirements.

21. Merchant Customer Data

CryptumPay is not intended to be used as a general customer data storage tool.

Merchants must not submit unnecessary personal data about their customers through API fields, metadata, order descriptions, support requests, webhook URLs or other technical fields.

If a Merchant provides a payer email or other customer-related data for payment notifications, support, fraud prevention, payment processing or other Service-related purposes, the Merchant is responsible for ensuring that it has a lawful basis and has provided all required notices to the relevant customer.

Where a Merchant provides customer-related data to CryptumPay, the Merchant is responsible for ensuring that it has all required rights, permissions and legal grounds to provide that data.

CryptumPay may process such data where necessary to provide the Service, process payments, provide support, maintain security, perform compliance checks, prevent fraud, resolve disputes and enforce the Terms of Use.

22. Emails and Notifications

We may send emails and notifications related to:

  • account registration;
  • email verification;
  • login activity;
  • security alerts;
  • two-factor authentication;
  • payment status;
  • refund status;
  • withdrawals;
  • support requests;
  • service updates;
  • legal or policy updates;
  • compliance requests.

We may also send product or informational communications where permitted by law.

You may opt out of non-essential marketing communications where applicable. You cannot opt out of essential service, security, compliance or transactional communications.

23. Telegram and External Communication Channels

If you contact CryptumPay through Telegram or another external communication channel, that platform may process your data according to its own privacy policy.

CryptumPay does not control the privacy practices of Telegram, Google or other third-party platforms.

You should not send sensitive information through external communication channels unless necessary.

24. Google and Telegram Login

If you choose to log in using Google or Telegram, we may receive information from the relevant provider, such as your account identifier, email address, username or other information made available through that login method.

Your use of Google or Telegram login is also subject to the privacy practices of the relevant provider.

You may be able to manage connected applications and permissions through your Google or Telegram account settings.

25. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes may be posted on the website, in the console or otherwise communicated by reasonable means.

The updated Privacy Policy becomes effective when posted or on the date stated in the updated Privacy Policy.

Continued use of CryptumPay after the updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy.

26. Contact

For questions, requests or complaints regarding this Privacy Policy or personal data processing, contact:

info@cryptumpay.com