Legal

Privacy Policy

Last Updated: July 30, 2026 · Effective: August 1, 2026

This Privacy Policy describes how ZPAY Protocol (“ZPAY”, “we”, “our”) collects, uses, and protects information in connection with the ZPAY payment routing protocol, developer API, and web dashboard. By using ZPAY services, you agree to the practices described herein.

1. Information We Collect

ZPAY operates on a privacy-first, non-custodial architecture. We do not collect, store, or have access to your private cryptographic keys, seed phrases, or wallet master passwords — ever. When you use the ZPAY web dashboard or developer API, we may process minimal operational data necessary for service delivery, including: • Public wallet addresses and transaction hashes (inherently public on Stellar) • API request metadata (timestamps, endpoint paths, response codes) • Basic telemetry for routing performance optimization • Email address if provided during account creation We do not collect payment card numbers, bank account details, or sensitive government-issued identity documents. KYC/AML identity exchange, where legally required, is handled directly by licensed Stellar anchor partners under their own privacy regimes.

2. How We Use Your Information

We use the minimal data we collect exclusively for the following purposes: • Operating, maintaining, and improving the ZPAY payment routing protocol • Sending transactional notifications and critical security alerts • Debugging and resolving API errors on behalf of developer accounts • Fulfilling legal obligations under applicable financial regulations • Fraud prevention and anomaly detection on transaction flows We do not sell, rent, or share your personal data with third-party advertisers or data brokers under any circumstances.

3. Blockchain Transparency

Please be aware that transactions executed on the Stellar blockchain are inherently public. Your public wallet address and all associated transaction ledger entries are permanently, immutably recorded on-chain and accessible to anyone operating a Stellar node. ZPAY has no ability to modify, delete, or obscure on-chain transaction records. This is a property of the underlying Stellar Consensus Protocol, not a ZPAY policy choice. Users should treat their public wallet addresses as pseudonymous, not anonymous.

4. Data Security & Encryption

All off-chain communication between your client application and ZPAY API endpoints is encrypted using TLS 1.3 standards with forward secrecy enabled. Our API infrastructure rejects connections on older, insecure TLS versions. We employ zero-knowledge principles wherever architecturally feasible — meaning our systems are designed to process the minimum data needed without retaining it. API keys are one-way hashed in storage and are never logged in plaintext. Multi-Party Computation (MPC) distributes cryptographic responsibilities across geographically separated infrastructure nodes, eliminating single points of compromise.

5. Data Retention

We retain operational metadata (API request logs, error traces) for a maximum of 90 days for debugging purposes, after which it is automatically purged. Account information, if provided, is retained for the duration of your account's active status. Upon account deletion request, we purge all off-chain personal data within 30 days, subject to any retention obligations imposed by applicable financial regulations. On-chain transaction data recorded to the Stellar ledger cannot be deleted — this is an immutable property of the blockchain.

6. GDPR Rights for EU Residents

If you are resident in the European Union, you have the following rights under GDPR: • Right of Access: Request a copy of the data we hold about you • Right to Rectification: Request correction of inaccurate data • Right to Erasure: Request deletion of off-chain personal data ("right to be forgotten") • Right to Portability: Receive your data in a structured, machine-readable format • Right to Object: Object to processing of your data for specific purposes To exercise any of these rights, contact privacy@zpay.route. We will respond within 30 days.

7. Cookies & Tracking

The ZPAY web dashboard uses strictly necessary session cookies for authentication. We do not deploy tracking cookies, advertising pixels, or third-party analytics scripts that profile user behavior. No personal data is transmitted to advertising networks as a result of your use of the ZPAY platform.

8. Contact & Complaints

If you have questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please contact our privacy compliance team at privacy@zpay.route. If you are an EU resident and believe we have not adequately addressed a GDPR complaint, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

GetStarted.

Fast, secure, and borderless payments powered by ZPAY on Stellar.

ZPAY Logo
ZPAY

The agentic payment router built on Stellar. Instant, borderless, and programmable by AI.

© 2026 ZPAY Technologies. All rights reserved.

All systems operational · Built on Stellar