Privacy Policy
Last updated: 14 July 2026
This Privacy Policy describes what data the web3e crypto payment gateway processes, for what purposes and on what legal grounds, as well as what rights data subjects have. web3e is a crypto payment gateway that lets merchants accept cryptocurrency payments from their buyers; it is not a bank, a money-transmitter, an e-money institution, a custodian bank or an exchange, and it provides no investment or financial advice. By using web3e, you agree to the terms of this Policy.
1. General Provisions and the Data Controller
This Policy applies to the processing of personal data when using the web3e crypto payment gateway (the "Service").
web3e acts as the data controller with respect to the data of merchant accounts and their users.
With respect to the minimal data of the Merchant's buyers (end customers) that reaches the Service in the course of a payment — primarily the on-chain sender address — the Merchant acts as the controller of its own commercial relationship, while web3e processes such data on its own account solely for settlement, security and mandatory anti-money-laundering (AML) and sanctions compliance.
2. What Data We Process
Merchant account data: name, email address, organization details, user accounts and their roles.
Wallet and settlement data: crypto wallet addresses, the extended public key (xpub) you provide for non-custodial settlement, per-invoice deposit addresses, and payout destination addresses. In non-custodial mode web3e never receives or stores your private key.
On-chain transaction data: transaction hashes, amounts, assets, networks, confirmations, senders and recipients associated with your invoices and payouts.
Integration data: API keys, webhook (IPN) endpoints and signing secrets, and related configuration.
Buyer data (minimal): the on-chain sender address of an incoming payment and the associated transaction, captured for reconciliation and AML screening. We do not collect buyers' names, cards or bank details — the Service is crypto-only and handles no full card data.
Technical data and logs: device and browser information, activity logs, and strictly functional cookies. The IP address is processed in the technical logs of our infrastructure and when the country is detected for the interface language; we do not store it in the application records of accounts, invoices or payouts.
3. Purposes and Legal Bases for Processing
Providing access to the Service and performing the agreement with the Merchant, including invoicing, hosted checkout and IPN webhooks.
Settling payments — crediting the Merchant's custodial balance or forwarding funds to the Merchant's own wallet in non-custodial mode — and processing crypto payouts.
Complying with legal obligations, including anti-money-laundering (AML), counter-terrorist-financing and sanctions requirements.
Ensuring security, preventing fraud, abuse and prohibited use of the Service.
Merchant support, and the improvement and development of the Service.
The legal bases for processing are performance of the agreement, compliance with legal obligations, the data subject's consent where required, and our legitimate interest in operating the Service securely.
4. The Blockchain Is Public and Immutable
Cryptocurrency transactions are recorded on public, decentralized blockchains that web3e does not own or control. Wallet addresses, amounts, assets and transaction hashes written to a blockchain are inherently public and permanent.
Because of the nature of a blockchain, such on-chain data cannot be altered, deleted or "erased" by web3e or by anyone else — a request to delete data does not extend to information already recorded on a public ledger.
Blockchain transactions are irreversible and final: there are no chargebacks, and any refund is a separate, merchant-initiated on-chain transaction. You should treat any address you publish or transact with as public information.
5. Cookies
We use strictly functional cookies and similar technologies for the operation of the Service and to save your settings (interface theme and language). We do not use analytics, advertising or tracking cookies.
To determine the interface language, country detection by IP address may be used; for this purpose the visitor's IP address is sent to an external geolocation provider (MaxMind, USA).
You can manage cookies in your browser settings; disabling some cookies may limit the functionality of the Service.
6. AML and Sanctions Screening
To comply with legal requirements and protect the Service, every incoming deposit sender and every payout destination address is screened against sanctions lists (including OFAC) and on-chain risk and scam lists before funds move.
Screening is performed on our own side: we download public sanctions and scam lists (including the OFAC SDN list) and match addresses against them locally. Wallet addresses and transaction data are not passed to third-party screening providers for this purpose.
Where a screening produces a hit, we may quarantine an incoming deposit, block a payout, and record the outcome. We may also suspend or terminate an account and are obliged to retain and, where required, report the relevant information to competent authorities.
7. Transfer to Third Parties and Processors
To operate the Service, we engage third-party service providers (processors), including:
blockchain infrastructure and node providers, used to create addresses, read transactions and broadcast payouts;
a geolocation provider (MaxMind, USA), which receives the visitor's IP address to determine the country for the interface language;
email and notification providers, for account and transaction messages;
hosting and infrastructure providers.
Data is transferred to such processors only to the extent necessary to provide the corresponding services. Note that broadcasting a transaction inherently publishes it to a public blockchain and to the wider network of node operators, which is not a transfer within our control.
8. Custodial vs Non-Custodial and Fund-Related Data
The Merchant chooses per account whether settlement is custodial or non-custodial. In custodial mode, incoming funds are held as a Merchant balance that the Merchant withdraws on request; such balances are held solely to enable payouts, are not bank deposits, and are not insured or guaranteed.
In non-custodial mode, funds settle directly to the Merchant's own wallet derived from the xpub the Merchant provides; web3e stores only that watch-only extended public key and never the private key.
In both modes we maintain internal accounting records (a double-entry ledger) of balances, credits, payouts and fees associated with the account.
9. International Data Transfers
Data may be processed and stored on servers located in various countries, including outside the country of the data subject's location.
For international data transfers, we take reasonable measures to ensure an adequate level of protection in accordance with applicable law. On-chain data, by its nature, is replicated globally across a public network and is not confined to any jurisdiction.
10. Retention Periods
We retain data for the period necessary for the purposes of its processing, performance of the agreement, and compliance with legal requirements — including AML and sanctions record-keeping obligations, which may require retaining account and transaction records for several years after the relationship ends.
After the applicable retention period expires, data under our control is deleted or anonymized, unless otherwise provided by law. Data recorded on a public blockchain cannot be deleted (see Section 4).
11. Security Measures
We apply organizational and technical data protection measures, including encryption of sensitive data, restricting access on a need-to-know basis, access control, and confirmation of payouts by a one-time code sent to e-mail where the merchant has enabled such confirmation.
Signing secrets and API keys are treated as confidential; IPN webhooks are HMAC-signed so callbacks cannot be forged or replayed.
Despite the measures taken, no method of transmitting and storing data provides absolute protection, and the use of cryptocurrency carries inherent risk borne by the user.
12. Rights of Data Subjects
With respect to their personal data, a data subject has the right to: access the data, request its correction, deletion, restriction of processing, object to processing, and exercise the right to data portability.
These rights are subject to legal limits — in particular, we cannot delete data we are required to retain for AML, sanctions or accounting purposes, and we cannot alter or remove information already recorded on a public blockchain.
To exercise these rights, please use the contacts indicated below. We handle requests within the periods established by applicable law.
13. Children's Data
The Service is not intended for persons under 18 years of age. We do not knowingly collect the personal data of such persons.
If you become aware that a minor's data has been provided to us without proper grounds, please let us know, and we will take measures to delete it.
14. Changes to the Policy
We may amend this Policy. A new version takes effect from the moment of its publication, unless another date is specified.
We recommend reviewing the current version of the Policy periodically.
15. Contacts
For matters related to the processing of personal data and the exercise of data subjects' rights, please use the contacts indicated below.