Privacy policy

Last updated: July 2026

This policy explains what personal data Payhusk ("we") processes when you use payhusk.com, why, and the choices you have. Payhusk is a payment gateway that lets merchants accept USDT and USDC; the merchant you buy from is responsible for their own shop and its data practices.

What we collect

Merchant accounts: your email address, a salted hash of your password (we never store the password itself), API keys and webhook secrets, and your invoice and withdrawal records — amounts, tokens, networks, order references, callback URLs and destination addresses.

Payers: we do not ask payers to create accounts and do not collect names, emails or card details from them. We process the blockchain data needed to detect a payment: the deposit address we issued, the transaction ID and the amount.

Technical data: standard server logs (IP address, user agent, timestamps) kept for security and abuse prevention, and a single session cookie for logged-in merchants. We use no advertising or cross-site trackers.

Why we process it

To operate the service (creating invoices, matching payments, paying out balances), to secure it (authentication, fraud and abuse detection), to meet legal obligations that apply to payment services, and to communicate service messages such as email verification. We do not sell personal data and we do not use it for third-party advertising.

Web archiving disabled

We block web-archiving services (such as the Internet Archive's crawlers) and instruct search engines not to cache our pages. This protects payers: payment pages carry time-limited deposit addresses, and a cached or archived snapshot could induce someone to send funds to an address that is no longer reserved for them. Always act only on the live page.

Blockchains are public

Payments happen on public ledgers (Ethereum, Tron, BNB Smart Chain). Transactions there are visible to anyone and cannot be edited or deleted by us or by you. Wallet addresses and transaction IDs are pseudonymous but may become linkable to you through information outside our control.

Sharing

We share data only with infrastructure providers acting on our instructions (hosting, email delivery), with authorities where the law requires it, and — for a given invoice — with the merchant who issued it (payment status, transaction ID). Webhook payloads are sent to the callback URL the merchant configured.

Retention

Account data is kept while your account is active. Transaction records are kept for as long as bookkeeping and anti-money-laundering rules require. Server logs are kept briefly and then deleted or anonymized.

Security

Passwords are hashed with Argon2, webhook payloads are signed so receivers can authenticate them, and deposit addresses are derived from watch-only keys — the keys able to move funds are not stored on this system.

Your rights

Subject to applicable law, you can request access to, correction of, or deletion of your personal data, object to certain processing, and lodge a complaint with your supervisory authority. Note that we cannot alter data recorded on public blockchains, and legal retention duties may delay deletion of transaction records. Contact privacy@payhusk.com to exercise these rights.

Changes

We will post any changes to this policy on this page and update the date above. Material changes will be announced to account holders by email.

This document ships as a template with the Payhusk scaffold — have it reviewed by legal counsel and adapted to your jurisdiction before going to production.