Privacy Policy
This document is provided for information and is not legal advice.
Last updated: · Questions about this document:
1. Summary
ZeroKYC means what it says: we do not run identity verification and we do not ask for identity documents. We collect the minimum needed to run a merchant account, process payments and provide support. The data controller is ZEROKYC Payments LTD, a company registered in the British Virgin Islands (company No. 2194836), registered office: Suite 404, Oceanic Business Centre, 12 Coral Bay Road, Road Town, Tortola, VG1110, British Virgin Islands. Contact for all privacy matters: [email protected].
This policy explains what we collect, why, for how long, and who can see it.
2. What we collect
Account data: email address, display name, password hash (we never store the password itself), two-factor secret (encrypted), interface language, notification settings.
Operational data: invoices and their public blockchain metadata (amounts, addresses, transaction hashes, statuses), API keys (stored as hashes), webhook endpoints, subscription billing records, records of actions in the admin console (audit log).
Support data: messages and attachments you send in the support widget or the support Telegram bot, stored in our self-hosted Chatwoot instance.
Technical data: IP addresses and user agent for security and rate limiting (via our CDN), aggregated and anonymised usage analytics.
3. What we never collect
No identity documents, no selfies, no proof of address, no bank statements. There is no KYC questionnaire to fill.
We never ask for and never accept: seed phrases, private keys, wallet passwords, API secret keys, webhook signing secrets. Our support staff is contractually forbidden from requesting them — anything sent to support is treated as compromised.
4. Payments on public blockchains
Blockchain transactions are public by design. When a buyer pays an invoice, the amount, addresses and transaction hash are permanently visible to anyone on the network. We cannot make a blockchain payment private, and we do not remove blockchain data.
5. Third parties
Cloudflare (CDN, DDoS protection) — sees connection metadata for every visitor.
Blockchain RPC providers and indexers (TronGrid, toncenter, mempool.space, public EVM nodes) — see public-chain queries needed to detect payments.
Yandex.Metrika — anonymised visit analytics on the marketing site (with IP masking features of the counter).
Our self-hosted Chatwoot instance — support conversations; hosted on the same infrastructure as the Service.
We do not sell data and do not run advertising trackers on the merchant console.
6. Retention and your rights
Account and billing records are kept while the account exists and as long as accounting rules require. Support conversations are kept for 24 months. Audit records are append-only and kept for the life of the platform.
You can export or delete your account data from the merchant console (Settings), except records we must keep by law or for fraud prevention. For any privacy request, use the contact page of this website.