Privacy Policy

Last updated: March 31, 2026

1. Overview

MutoPay ("we", "us", "our") is a self-custody crypto payment gateway. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

We are committed to collecting only the data necessary to operate the Service and to being transparent about how it is used.

2. Data We Collect

Merchant Account Data

When you sign in with Google, we receive and store:

  • Email address
  • Name (from your Google profile)
  • Google account identifier

We also store your configured wallet address, API keys (hashed), and webhook configuration.

Payment Data

For each payment processed through MutoPay, we store:

  • Payment amount, currency, and status
  • Source and destination token information
  • Blockchain transaction hashes
  • Wallet addresses (sender and recipient)
  • Payment metadata provided by the merchant
  • Timestamps (creation, expiry, completion)

We do not collect or store customer personal information. Customers interact directly with MutoPay's payment page using their own wallet — no account creation, email, or personal details are required from customers.

Usage Data

We collect anonymized usage data via Google Analytics to understand how the Service is used. This includes page views, session duration, and referral sources. No personally identifiable information is linked to this data.

Error Tracking

We use Sentry for error monitoring. When errors occur, technical context (stack traces, request metadata) may be captured. This data is used solely for debugging and improving service reliability.

3. How We Use Your Data

We use collected data to:

  • Authenticate your merchant account
  • Process and monitor payments
  • Deliver webhook notifications
  • Detect and prevent fraud or abuse
  • Improve the Service's reliability and performance
  • Communicate important updates about the Service

We do not sell, rent, or share your data with third parties for marketing purposes.

4. Third-Party Services

MutoPay uses the following third-party services that may process data as part of normal operation:

  • Cloudflare — hosting, CDN, and DDoS protection. May process IP addresses and request metadata.
  • Google Sign-In — authentication. Subject to Google's Privacy Policy.
  • Li.Fi / ParaSwap — token swap and bridge routing. Wallet addresses and transaction data are shared to execute swaps.
  • WalletConnect (Reown) — wallet connectivity. Subject to Reown's Privacy Policy.
  • Google Analytics — anonymized usage analytics.
  • Sentry — error tracking and monitoring.

5. Data Storage and Security

Data is stored on Cloudflare's global network using Cloudflare D1 (SQLite). API keys are stored as salted hashes — we cannot recover your original API key after generation.

Webhook secrets are stored encrypted. All communication with the Service is over HTTPS. We use industry-standard security practices to protect your data, but no system is 100% secure.

6. Data Retention

Merchant account data is retained for as long as your account is active. Payment records are retained indefinitely for audit and compliance purposes.

Webhook delivery logs are retained for 90 days. Error tracking data in Sentry is retained for 30 days.

7. Your Rights

You have the right to:

  • Access the data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your payment data

To exercise these rights, contact us at privacy@mutopay.com.

8. Cookies

MutoPay uses minimal cookies:

  • Authentication tokens — stored in browser localStorage, not cookies. Used to maintain your login session.
  • Google Analytics — uses cookies for anonymized usage tracking. You can opt out via your browser settings or the Google Analytics opt-out extension.

9. Children

MutoPay is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the merchant dashboard. The "Last updated" date at the top indicates the most recent revision.

11. Contact

For privacy-related questions, contact us at privacy@mutopay.com.