Privacy Notice

This Privacy Notice describes how 402pay.co (“402pay”, “we” or “us”) collects, uses, discloses and protects personal data in connection with its website and the Services, and the rights available to individuals in respect of that personal data. “Personal data” means any information relating to an identified or identifiable individual. Capitalized terms not defined in this notice have the meanings given in our Terms of Service.

Scope

This notice applies to personal data for which 402pay determines the purposes and means of processing and therefore acts as controller, including personal data relating to:

  • visitors to our website and readers of our Documentation;
  • businesses that use the Services, and the individuals who act on their behalf;
  • payers, being individuals who make a Payment to a business through the Services, to the extent that 402pay processes their personal data for its own purposes, such as the prevention of fraud; and
  • any individual who contacts us.

Where 402pay processes personal data on behalf of a business in providing the Services, it acts as a processor or service provider to that business, which determines how that personal data is used. Requests concerning such personal data should be directed to the business, and any such request received by 402pay will be referred to the business.

This notice does not apply to Third-Party Services, including the providers that process Card Payments and the wallets and exchanges from which payers send Payments, each of which is governed by its own privacy notice.

Personal data we collect

Information you provide

  • Account information, such as your name, email address and sign-in credentials. Passwords are stored only in a form that cannot be reversed.
  • Business information, such as the name, website and contact details of your business, information about its ownership and activities, and its settings.
  • Information that you create or submit through the Services, such as payment requests and related records.
  • Wallet information, such as public keys, addresses, balances and transaction history. Any recovery phrase stored with us is encrypted on your device with a password that we do not receive.
  • Information provided by payers, such as an email address, a country and the details of a Payment, including its amount, currency and payment method.
  • The content of any communication you send to us, including through our contact form.

Information collected automatically

  • Technical and log information, such as IP address, browser and device type, and the pages and interfaces accessed, with the date and time of access.
  • Session and security information, such as the devices, browsers and approximate locations from which an account is accessed, and activity recorded in the account's audit log.
  • The results of automated security checks used to distinguish individuals from automated traffic, which rely on technical information about your browser and connection.

Information from other sources

  • Public blockchain data relating to Payments, such as addresses, transaction identifiers and confirmations.
  • Information from the providers that process Card Payments, such as the status of a payment.
  • Information from providers that assist us in verifying businesses.

Information we do not collect

402pay does not receive or store, in readable form, any recovery phrase, private key or wallet password capable of controlling Digital Assets, or any biometric or other factor used to unlock a passkey on your device. Full card numbers, expiry dates and security codes are provided directly to the relevant card payment provider and are not received by 402pay. 402pay does not intentionally collect special categories of personal data and does not purchase personal data from data brokers.

How we use personal data

402pay uses personal data only for the purposes set out below. For individuals in the European Economic Area, Switzerland and the United Kingdom, the table also identifies the legal basis for each purpose.

PurposeCategories of dataLegal basisRetention
Providing, operating and supporting the Services.Account, business, wallet and Payment information; communications.Performance of our contract with the business.For the duration of the account.
Securing accounts and the Services, including authentication, verification and the detection of automated traffic.Account, session, security and log information.Our legitimate interest in maintaining the security of the Services.For the duration of the account.
Preventing, detecting and investigating fraud and abuse.Payment, log and blockchain information; information from card payment providers.Our legitimate interest in protecting businesses, payers and the Services.Up to five years after the relevant Payment.
Complying with legal and regulatory obligations, including record keeping.Business and Payment information.Compliance with a legal obligation.For the period required by law, typically five years.
Responding to enquiries submitted through our website.Contact details and the content of the enquiry.Our legitimate interest in responding to prospective customers.For as long as necessary to respond to the enquiry.
Analyzing and improving the Services.Log and usage information, aggregated where possible.Our legitimate interest in improving the Services.Up to 12 months, unless aggregated.

402pay does not sell personal data and does not share it for cross-context behavioral advertising. Automated fraud and abuse controls may result in a Payment being declined; any individual affected may request human review by writing to privacy@402pay.co.

402pay may aggregate or de-identify personal data so that it can no longer reasonably be used to identify any individual, and may use and disclose such data for any lawful purpose, including to analyze, improve and promote the Services. 402pay maintains such data in that form and does not attempt to re-identify any individual from it.

402pay sends businesses the communications necessary to provide the Services, including verification codes, password reset links, notices concerning their accounts and Payments, notices concerning the security of their accounts, and notices of changes to our terms. Communications concerning account security and communications that 402pay is required to send to operate the Services or by law cannot be disabled while an account remains open. Any promotional communication will contain a means of opting out.

Disclosure of personal data

402pay discloses personal data only to the following categories of recipients:

  • the business to which a payer makes a Payment, to enable the business to fulfill the order and respond to the payer;
  • the providers that process Card Payments, in accordance with their own terms and privacy notices;
  • service providers that host and operate the Services, deliver communications, provide security and anti-abuse services, or assist in verifying businesses, each of which is contractually required to use personal data only to provide services to 402pay (a list of current service providers is available on request);
  • professional advisers, such as legal advisers, auditors and insurers, who are bound by duties of confidentiality;
  • competent authorities and other parties where required by law or legal process, or where necessary to enforce our agreements or to protect the rights, property or safety of our users, the public or 402pay; and
  • a purchaser or successor in connection with any merger, acquisition or sale of assets, in which case businesses will be notified before their personal data becomes subject to a different privacy notice.

Payments in Digital Assets are recorded on public blockchains, on which the addresses, amounts and identifiers of transactions are publicly visible and cannot be altered or deleted by any person, including 402pay. 402pay does not publish the identity associated with any address, but third parties may be able to associate an address with an individual by other means.

International transfers

402pay uses cloud infrastructure located in multiple countries, and personal data may therefore be processed outside the country in which you reside, including in the United States. Where personal data is transferred from the European Economic Area, Switzerland or the United Kingdom, 402pay relies on transfer mechanisms recognized by applicable law, such as the standard contractual clauses approved by the European Commission and the United Kingdom addendum to them.

Your rights

Rights available to you

Depending on your place of residence, you may have the right to:

  • be informed of and access the personal data that we hold about you, including the purposes of processing and the recipients to whom it is disclosed;
  • request the correction of inaccurate or incomplete personal data;
  • request the deletion of your personal data, subject to any obligation to retain it;
  • object to or request the restriction of processing, and withdraw any consent on which processing is based;
  • receive your personal data in a portable, machine-readable format or request its transmission to another person;
  • opt out of the sale or sharing of personal data and of profiling that produces legal or similarly significant effects; and
  • appeal any decision that we make in respect of a request.

These rights are subject to conditions and exceptions under applicable law, and 402pay may retain personal data where necessary to comply with legal obligations, resolve disputes or prevent fraud. 402pay will not discriminate against any individual for exercising these rights.

Making a request

Businesses may access and update much of their personal data through the Dashboard. Other requests may be submitted to privacy@402pay.co and should include sufficient information to allow us to locate the relevant personal data. 402pay will verify the identity of the requester before acting on a request, using information that it already holds.

Where permitted by law, a request may be made by an authorized agent with your written permission, which 402pay may verify with you. 402pay does not charge a fee for requests unless they are manifestly unfounded or excessive and will respond within the period required by applicable law, generally 30 days, or 45 days under applicable U.S. state laws, subject to any permitted extension. Requests concerning personal data that 402pay processes on behalf of a business will be referred to that business.

Residents of U.S. states

Certain U.S. states, including California, Colorado, Connecticut and Virginia, grant their residents rights in respect of personal data. During the preceding 12 months, 402pay collected the categories of personal data described in “Personal data we collect”, from the sources described there, for the purposes described in “How we use personal data”, and disclosed them for business purposes to the recipients described in “Disclosure of personal data”. 402pay has not sold personal data or shared it for cross-context behavioral advertising and does not use sensitive personal data to infer characteristics about any individual.

402pay treats a Global Privacy Control signal as a request to opt out of sale and sharing. If 402pay declines a request, you may appeal by replying to its decision and, if the appeal is denied, may contact the attorney general of your state.

The European Economic Area, Switzerland and the United Kingdom

402pay is the controller of the personal data to which this notice applies, and the table in “How we use personal data” identifies the legal basis for each purpose. Where processing is based on our legitimate interests, you may object to it, and where it is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing. You may also lodge a complaint with the supervisory authority of the place where you reside or work or where an alleged infringement occurred, although we ask that you contact us first so that we may seek to resolve your concern.

Security and retention

402pay applies technical and organizational measures designed to protect personal data, including encryption in transit and at rest, the encryption of recovery phrases on the user's device before transmission, the storage of passwords and other secrets only in irreversible form, and the restriction of access to personnel who require it. No system is completely secure, and 402pay will notify affected individuals and the competent authorities of any personal data breach as required by applicable law.

402pay retains personal data for the periods described in “How we use personal data”. When a business closes its account, 402pay deletes or anonymizes the related personal data, except to the extent that it is required to retain it for legal, tax, dispute resolution or fraud prevention purposes, and securely deletes personal data when it is no longer required.

Cookies and similar technologies

402pay does not use advertising cookies or third-party tracking technologies. Our website and the Services use cookies and similar technologies, such as browser local and session storage, only where they are strictly necessary, namely to:

  • keep you signed in and maintain the security of your account, including by recognizing devices from which you have signed in;
  • remember settings and choices that you make, such as your display preferences and your cookie choices; and
  • distinguish individuals from automated traffic on pages where security checks are performed.

Any other cookies, such as those used to measure how the website is used, are set only with your consent, which you may withdraw at any time. You may also clear cookies and browser storage through your browser settings, although doing so may sign you out of the Services.

Children

The Services are not directed to individuals under 18 years of age, and 402pay does not knowingly collect personal data from them. If 402pay becomes aware that it has collected such personal data, it will delete it promptly. Any concern in this regard may be raised with privacy@402pay.co.

Changes to this notice

402pay may amend this notice by publishing an updated version and will notify businesses of any material change before it takes effect, by email or through the Dashboard. Each version applies to personal data collected while it is in effect. This notice forms part of our Terms of Service.

Contact us

402pay is responsible for the personal data to which this notice applies. Questions about this notice, our processing of personal data or your rights may be sent to privacy@402pay.co. Questions about an account may be sent to support@402pay.co, and security vulnerabilities may be reported to security@402pay.co.