Privacy Policy
NicoSoft Payment is business-to-business payment infrastructure. This Policy explains what data the Gateway and its console process. It is not a consumer product, and we do not knowingly collect data directly from End Users beyond what an Integrator passes to us.
01Data we process
- Account data — Project name and description, and credentials. Secrets are stored encrypted at rest, and console passwords are stored only as one-way hashes — never in plaintext.
- Integration data — orders, your client_order_id, and any client_metadata you attach. You control the contents of client_metadata and must keep personal data out of it.
- On-chain data — receive addresses, transaction hashes, block numbers, and amounts. This data is inherently public on the blockchain.
- Technical and security data — IP address, user agent, and request identifiers, used for rate-limiting, the IP blocklist, and abuse prevention.
- Console operator data — username, email, last-login metadata, and an audit log of administrative actions.
02How we use data
- Operate the Gateway and settle payments.
- Secure the Service and prevent fraud and abuse.
- Maintain audit trails and meet compliance obligations.
- Diagnose issues and improve reliability.
03Legal bases
We process data to perform our contract with Integrators, and for the legitimate interests of operating secure payment infrastructure.
04Sharing
We share data only as needed to run the Service: blockchain RPC and node providers (to read chain state and broadcast sweeps), hosting and infrastructure providers, and where required by law. We do not sell personal data or use it for advertising.
05Retention
We retain order, transaction, and audit records for as long as needed to operate the Service and to meet legal and compliance obligations. Older records may be moved to archived form, and some records may be kept where deletion would conflict with those obligations.
06Security
- Credentials and secrets encrypted at rest; passwords stored only as one-way hashes.
- Two-factor authentication and a single active session per console account.
- Rate limiting and IP blocklisting on administrative and API access.
- Browser-side protections on the administrative console.
- Least-privilege access to internal systems.
07International transfers
The Service may process data in jurisdictions other than yours. Where required, we rely on appropriate safeguards for such transfers.
08Your choices
Integrators control the personal data they send in client_metadata, and can request access to or deletion of their Project data, subject to legal retention. Direct requests to the contact below.
10Changes and contact
We may update this Policy; material changes will be announced through the console or documentation. Privacy questions: privacy@nicosoft.dev.