Privacy policy
Version of 24 September 2026
This policy covers the profitpay.store site and the ProfitPay API. It lists what data ProfitPay keeps and who else receives it.
What we keep
- Merchant account
- Your email address, a hash of your password, the business name, the website address if you gave one, and the interface language you chose. We do not keep the password itself.
- Products and invoices
- Product names, descriptions and prices, invoice amounts and descriptions, transaction hashes and confirmation counts. The payment page does not ask the payer for a name or an email address.
- Addresses
- Deposit addresses with your labels and the addresses funds are withdrawn to. ProfitPay keeps the private keys of the deposit addresses it creates in encrypted form.
- API keys
- The API keeps only a hash of each key. The dashboard keeps an encrypted copy of the keys issued in it so that it can call the API on your behalf.
- Webhooks
- The delivery URL, the signing secret in encrypted form, and a delivery log: each event with its data, the response code of your server and the first 4 KB of its response or the error text.
- Server logs
- Requests to pages and to the API are logged with the address, the response code and the processing time. Passwords, API keys and webhook secrets are not written to the logs. Your IP address is used to limit how often requests can be made.
Cookies
We set only the cookies the site needs: your sign-in, protection of forms against forged requests, the language you chose, and one-time notices after actions in the dashboard. A sign-in lasts 12 hours and is extended while you use the dashboard; with “Remember me” it also survives closing the browser.
There are no analytics, advertising or third-party scripts: pages, fonts and scripts load only from profitpay.store.
Who else receives data
- Transfers and addresses are public on the blockchains themselves. To see incoming transfers, ProfitPay asks blockchain access providers about the addresses of your invoices.
- Invoice and payment events are sent to the webhook URLs you set.
- The data is stored on a server that ProfitPay rents from a hosting provider.
Protection
The site opens over HTTPS, and the browser sends the sign-in cookie only over a secure connection. Passwords are stored as hashes; webhook secrets and the dashboard’s copies of API keys are encrypted. Database backups are encrypted too. After several failed sign-in attempts in a row, signing in to the account is blocked for a few minutes.
How long data is kept
Account, invoice and payment data is kept while the account exists. A deleted webhook stays in the database together with its delivery log. Deleted data remains in the encrypted backups until newer backups replace them.
Requests about your data
To get a copy of your data, correct it or delete your account, write to us at privacy@profitpay.store.
We may ask you to confirm that the account is yours, for example by writing from the email address it is registered to.
Changes
When this policy changes, the new version appears on this page with a new date.