Privacy Policy
Last updated: 8 October 2026
This Privacy Policy explains what personal data Flexrix Pay (“we”, “us”) processes when you use our websites, the merchant dashboard, the API and the hosted payment page (together, the “Service”), why we process it, and the rights you have.
Flexrix Pay is privacy-first. We do not ask for identity documents, selfies or proof of address, we do not use analytics or advertising trackers, and we do not sell personal data.
1. Who is responsible
Flexrix Pay is the controller of the personal data described in this Policy. For any privacy question or request, write to [email protected] with the subject “Privacy”.
2. Whom this Policy covers
- merchants and the team members they invite to the dashboard;
- customers of merchants who pay through the hosted payment page or to an address we provide (“payers”); and
- visitors to our websites.
3. What we collect
Account data (merchants and team members): email address; password, stored only as a salted scrypt hash; account type; country of residence; company name and referral code if you give them; your acceptance of our terms and your declarations, with the time and IP address of sign-up; and your language.
Security data: your authenticator secret, stored encrypted; session records (IP address, browser user agent, times); a count of failed sign-in attempts, used to lock the account temporarily against password guessing; and an audit log of actions taken in the dashboard, with the IP address they came from.
API and integration data: API key identifiers (secrets are stored encrypted); webhook endpoint addresses and delivery records; and a log of API requests made with your keys (method, path, status, duration, IP address and signature diagnostics — never request bodies or secrets).
Transaction data: invoices and payment links (amounts, currency, order reference and any metadata you send), deposit addresses, blockchain transaction identifiers, sending and receiving addresses, amounts, times, payouts and their destination addresses, screening results and ledger entries. Blockchain transactions are public by nature.
Payer data: when someone pays a merchant through the Service, we process their wallet address and transaction on the blockchain, technical data such as IP address and browser in our server logs, and whatever the merchant includes in the invoice. Payers do not create an account with us.
Communications: the emails you send us and our replies.
Website visitors: technical data in our server and network logs (IP address, browser user agent, requested page and time).
4. Why we use it and our legal bases
- To provide the Service — create and run your account, process payments and payouts, send webhooks and service emails: performance of our contract with you.
- To keep the Service and your account secure — authentication, two-factor codes, session management, rate limiting, abuse and fraud prevention, audit logs: our legitimate interest in a secure Service, and yours.
- To screen payments and payouts against sanctions lists and issuer blacklists, block Restricted Jurisdictions and keep the records described in our AML Policy: compliance with legal obligations where they apply to us, and otherwise our legitimate interest in preventing financial crime and complying with sanctions.
- To help you integrate — the API request log and webhook testing tools: performance of our contract.
- To answer your messages and handle complaints: performance of our contract and our legitimate interest in responding.
- To establish, exercise or defend legal claims: our legitimate interest.
We do not send marketing emails. If we ever want to, we will ask for your consent first.
5. What you must provide
Your email address, password, country, account type and declarations are needed to open an account; without them we cannot provide the Service. Everything else we collect arises from your use of the Service.
6. Automated decisions
Two of our controls take effect automatically: sign-up is refused from a Restricted Jurisdiction, and a payment or payout that matches a sanctions list or an issuer blacklist is held or blocked. A held payment is always reviewed by a person before a final decision, and you can ask us to review any of these outcomes by writing to [email protected].
7. Who receives it
We share personal data only with:
- our hosting provider, Tube-Hosting, which operates our dedicated servers in Germany;
- Cloudflare, which provides our network, DNS, TLS and protection against attacks, and through which all traffic to the Service passes;
- Zoho, which delivers our emails from its European Union data centre;
- WalletConnect (Reown), only when a payer chooses to pay with WalletConnect on the hosted payment page, to relay the connection between the payment page and the payer’s wallet;
- blockchain infrastructure providers (such as node and indexing services), which receive public addresses and transaction queries from our servers — not your account data;
- the merchant, for payer data relating to that merchant’s invoices and deposit addresses;
- authorities, courts and law enforcement, where the law requires it; our professional advisers, under a duty of confidentiality; and a successor to our business, if it is transferred, under this Policy.
8. International transfers
Our servers and databases are located in Germany, in the European Union. Cloudflare processes traffic in many countries, including the United States, and relies on the EU–US Data Privacy Framework and standard contractual clauses. Where any other provider processes personal data outside the European Economic Area, we rely on an adequacy decision or on standard contractual clauses.
9. How long we keep it
- Account, transaction, ledger and screening records, and the dashboard audit log: for as long as your account is open and for five years after it is closed, or longer if the law requires it or a claim is pending.
- API request log: 7 days.
- Dashboard sessions: deleted 7 days after they expire or you sign out. A session lasts at most 12 hours and ends after 30 minutes of inactivity.
- Sign-ups that are never completed: deleted after 24 hours.
- Server access logs: 14 days.
- Emails with us: up to five years after our last exchange.
Data written to a public blockchain is permanent and cannot be deleted by us or anyone else.
10. Your rights
Depending on where you live, you have the right to access your personal data, to correct it, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw any consent you have given. We will respond within one month; if a request is complex, we may extend this by up to two further months and will tell you why. Requests are free of charge unless they are manifestly unfounded or excessive.
We may need to keep some data despite an erasure request, for example records we must keep under our AML Policy or the law, or data needed for a legal claim. We will tell you if this applies.
You also have the right to lodge a complaint with the data protection authority where you live or work, or where you think an infringement took place. We would appreciate the chance to resolve your concern first.
11. How we protect it
All connections are encrypted with TLS, and our servers accept connections only from Cloudflare using mutual certificate authentication. Passwords are stored as salted scrypt hashes, and authenticator secrets and API secrets are encrypted at rest. Two-factor authentication is mandatory. Keys that control funds are held in an isolated signing service. Database access follows least privilege, and dashboard actions are written to an audit log that cannot be altered.
If a personal data breach occurs that is likely to put your rights at risk, we will notify the competent authority within 72 hours where required and inform you without undue delay if the risk to you is high.
12. Cookies and local storage
- Dashboard: one strictly necessary session cookie, __Host-fp_session (HttpOnly, Secure, SameSite=Strict), which keeps you signed in. It expires after 12 hours at most.
- Websites: we do not set cookies. On the price and converter pages, your chosen currency is saved in your browser’s local storage so the page remembers it.
- Hosted payment page: no cookies. If a payer connects a wallet with WalletConnect, the WalletConnect library stores connection data in the browser’s local storage to keep the connection open.
- Cloudflare may set strictly necessary security cookies to protect the Service from automated attacks.
We use no analytics, advertising or tracking cookies. Because we only use what is strictly necessary, we do not show a cookie banner.
13. Children
The Service is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
14. Merchants and their customers
Each merchant decides why it accepts payments and what it does with its customers’ data, and is an independent controller for that. Merchants must tell their customers that payments are processed by Flexrix Pay and may link to this Policy.
15. Changes to this Policy
We will tell merchants about material changes by email and in the dashboard before they take effect. The date at the top of this page shows when this Policy was last updated.
16. Contact
Flexrix Pay — [email protected] (subject “Privacy”)