Paysell
SolutionsPricingDocsBlog
Logg innOpprett konto
Policies

Privacy Policy

What personal data Paysell collects from merchants and cabinet users, why, how long it is kept and what rights data subjects have.

Updated
6. sep. 2026
On this page
  • 1. Who we are
  • 2. Scope
  • 3. Personal data we process
  • 4. Why we process data and on what legal basis
  • 5. Blockchain data — important limitations
  • 6. Cookies
  • 7. How long we keep data
  • 8. Who we share data with
  • 9. International transfers
  • 10. How we protect data
  • 11. Your rights
  • 12. Automated decision-making
  • 13. Children
  • 14. Changes to this policy
  • Contact
On this page
  • 1. Who we are
  • 2. Scope
  • 3. Personal data we process
  • 4. Why we process data and on what legal basis
  • 5. Blockchain data — important limitations
  • 6. Cookies
  • 7. How long we keep data
  • 8. Who we share data with
  • 9. International transfers
  • 10. How we protect data
  • 11. Your rights
  • 12. Automated decision-making
  • 13. Children
  • 14. Changes to this policy
  • Contact

Version 1.0 · Effective [[Effective date]] · Last updated [[Effective date]]

In short: Paysell processes a limited set of data about merchants and their payments: account credentials, session metadata, shop details, wallet addresses, and transaction records. We use this data to operate the payment service, to meet accounting and legal obligations, and to protect the platform against fraud and abuse. We do not sell personal data, and we do not run advertising or analytics tracking on our website today.

1. Who we are#

This Privacy Policy explains how [[Company legal name]], registration number [[Registration number]], registered at [[Registered address]] ("Paysell", "we", "us"), processes personal data in connection with the Paysell website at https://paysell.me, the merchant cabinet, and the merchant API at https://paysell.me/api/merchant/v1 (together, the "Service").

Paysell is the controller of the personal data described in this policy. For questions about this policy or about how your data is handled, contact [[DPO email]] or [[Legal email]].

2. Scope#

This policy applies to:

  • Merchants — persons who register an account, operate a shop, and receive payments through Paysell;
  • Buyers — persons who pay a merchant's invoice through Paysell (we process their blockchain address and payment data, but we do not collect their identity);
  • Visitors to https://paysell.me.

This policy does not cover the practices of merchants themselves. When you buy goods or services from a merchant that uses Paysell, that merchant is the controller of your customer data and its own privacy policy applies. Where Paysell processes personal data on a merchant's behalf, the Data Processing Agreement applies.

3. Personal data we process#

We only process the data listed below. We do not collect government identity documents, payment card data, or fiat bank details, and we do not operate an automated identity-verification (KYC) system today. We may, however, ask you for verification documents in the circumstances described in section 4.5, in the Merchant Verification (KYC/KYB) Policy and in the Terms of Service. Any document you send us in that context is processed for verification and record-keeping only.

CategoryWhat it includesSource
Account dataEmail address (stored encrypted at rest), password hash (Argon2), account status, notification preferences and recordsYou
Authentication dataTwo-factor authentication (TOTP) secret (stored encrypted), recovery codes, active session records including IP address, user agent and timestampsYou and your device
Shop dataShop name, website URL, description, expected monthly turnover, fee rate assigned at registrationYou
Integration dataAPI keys (stored hashed; the plaintext key is shown to you once), webhook endpoint URLs, webhook delivery attempts and responsesYou
Wallet dataMerchant payout addresses you submit, and the TON addresses from which buyers send payments to invoice addressesYou and the TON blockchain
Transaction dataInvoices, payment records, amounts, assets (TON / USDT on TON), on-chain transaction hashes, fees charged, balance movements, withdrawal requests and their approval statusThe Service and the TON blockchain
Support dataSupport ticket text and any attachments or information you include in it, plus our repliesYou
Administrative recordsStaff audit log entries recording actions taken by Paysell operators on accounts, shops, payments and withdrawalsThe Service
Technical logsWeb server and application logs (nginx, uvicorn) containing IP address, request path, timestamp, status code and user agentYour device
CookiesStrictly necessary cookies only — see the Cookie PolicyYour browser

Providing account, shop and wallet data is necessary to use the Service. If you do not provide it, we cannot open an account, accept payments on your behalf, or pay out your balance.

4. Why we process data and on what legal basis#

Where data protection law of the [[Jurisdiction]] requires a legal basis, we rely on the following.

PurposeLegal basis
4.1 Creating and operating your account, authenticating you, and providing the merchant cabinet and APIPerformance of a contract with you
4.2 Generating invoices, detecting incoming payments on the TON blockchain, crediting your balance, charging our fee, and executing withdrawals to your addressPerformance of a contract
4.3 Sending service communications — webhook deliveries, notifications, security alerts, and replies to support ticketsPerformance of a contract
4.4 Keeping accounting and transaction records, and responding to lawful requests from courts, regulators and law-enforcement authoritiesCompliance with a legal obligation
4.5 Preventing, detecting and investigating fraud, abuse, money laundering and unauthorized access; requesting verification information under the AML/CTF and Sanctions Policy; reviewing withdrawals and large incoming payments manually; holding or freezing balances where we have a reasonable concernLegitimate interests in protecting the platform, our merchants and third parties, and legal obligation where applicable
4.6 Maintaining security, availability and capacity of our infrastructure, including server logs and backupsLegitimate interests in operating a secure service
4.7 Establishing, exercising or defending legal claimsLegitimate interests / legal obligation
4.8 Any future analytics or marketing communicationsConsent, which you may withdraw at any time

Where we rely on legitimate interests, we have considered the impact on you and process no more data than is necessary for that purpose.

5. Blockchain data — important limitations#

Paysell operates on the TON public blockchain. Please understand the following before you use the Service:

  • Blockchain records are public and permanent. Invoice addresses, payment amounts, transaction hashes and the addresses of senders and recipients are recorded on a public ledger that anyone can read. Paysell does not control that ledger.
  • We cannot delete or alter on-chain data. A request to erase your personal data cannot extend to the blockchain. If a wallet address is linked to you, that link may persist publicly for as long as the network exists.
  • Analysis by third parties. Blockchain analytics firms, exchanges and authorities may be able to associate addresses with individuals using information we do not hold and do not control.
  • Stablecoin issuer. USDT on TON is issued by Tether, which has the technical ability to freeze balances at specific addresses. See the Crypto-Asset Risk Disclosure.

Consider carefully which wallet address you submit for payouts, and do not include information in an invoice description that you do not want to be visible to third parties.

6. Cookies#

The Paysell cabinet and website set only strictly necessary cookies: access_token and refresh_token (session authentication) and NEXT_LOCALE (your language preference). We do not use advertising or analytics cookies today. Full details, including lifetimes and how to control cookies, are in the Cookie Policy.

7. How long we keep data#

We do not yet operate a formally certified retention schedule. The following periods are the schedule we apply and intend to formalize; specific figures marked as placeholders will be confirmed once our jurisdiction and accounting obligations are fixed.

DataRetention period
Account and shop dataLife of the account plus [[N]] years after closure
Transaction records (invoices, payments, withdrawals, ledger entries)[[5]] years from the transaction, for accounting, tax and anti-money-laundering purposes
Support tickets[[3]] years from closure of the ticket
Session records, API keys, webhook configurationDeleted or revoked with the account; session records retained [[12]] months
Web server and application logs[[90]] days
Staff audit log[[5]] years
BackupsRotated; deleted data disappears from backups within [[35]] days

After these periods, data is deleted or irreversibly anonymized, except where a longer period is required by law or is necessary to defend a legal claim.

8. Who we share data with#

We do not sell personal data and we do not share it for advertising purposes. We disclose data only to:

  • Our hosting provider, [[Hosting provider, country]], which operates the virtual server on which the Service runs and therefore stores our data on our instructions;
  • Public blockchain networks — when we broadcast a withdrawal, the destination address and amount become public on the TON blockchain, and when we read the chain we query public TON data providers using invoice and wallet addresses;
  • Authorities — courts, regulators, tax authorities and law-enforcement agencies, where we receive a lawful request, or where we consider disclosure necessary to prevent or report a crime;
  • Professional advisers — lawyers, auditors and accountants bound by confidentiality;
  • A successor entity, in the event of a merger, acquisition or transfer of the business, subject to this policy.

We may also disclose information to a merchant about payments made to that merchant's own shop, and to a buyer's payment service provider where necessary to investigate a specific transaction.

9. International transfers#

Our infrastructure is located in [[Hosting provider, country]]. Where personal data is transferred outside [[Jurisdiction]], we rely on the transfer mechanisms available under applicable law, such as an adequacy decision or standard contractual clauses. You may request information about the safeguards in place by writing to [[DPO email]]. Note that blockchain data is by its nature distributed globally and cannot be confined to a single territory.

10. How we protect data#

Our technical and organizational measures include: encryption in transit (HTTPS); encryption at rest for email addresses and two-factor secrets; Argon2 password hashing; hashed storage of API keys; optional two-factor authentication with recovery codes; a session list that lets you review and revoke active logins; HMAC-SHA256 signing of outbound webhooks; rate limiting; manual operator review of every withdrawal; separation of hot and cold wallet funds; a staff audit log; and regular backups. Further detail, and how to report a vulnerability, is in the Security and Responsible Disclosure policy.

No system is perfectly secure. You are responsible for protecting your password, your two-factor device and your API keys.

11. Your rights#

Subject to the law of [[Jurisdiction]], you may:

  • Access the personal data we hold about you and receive a copy;
  • Rectify inaccurate or incomplete data — most account and shop data can be corrected directly in the cabinet;
  • Erase your data, subject to important limits: we must retain transaction and accounting records for the periods in section 7, and we cannot erase blockchain records;
  • Restrict or object to processing based on legitimate interests, including on grounds relating to your particular situation;
  • Port the data you provided to us, in a structured, commonly used, machine-readable format;
  • Withdraw consent where processing is based on consent, without affecting prior processing;
  • Complain to the supervisory authority in [[Jurisdiction]] — [[Supervisory authority]] — or to the authority where you live or work.

To exercise a right, write to [[DPO email]] from the email address registered to your account, or open a support ticket in the cabinet. We will respond within one month and may ask for information to verify your identity. We do not charge for this unless a request is manifestly unfounded or excessive.

12. Automated decision-making#

We do not make decisions producing legal or similarly significant effects about you by automated means alone. Withdrawal approvals, shop approvals and holds are decided by a human operator, and you may ask for an explanation and contest a decision through the Complaints Handling Procedure.

13. Children#

The Service is available only to persons aged 18 or over acting in a business capacity. We do not knowingly process the data of children. If we learn that an account belongs to a minor, we will close it and delete the associated data, subject to our retention obligations.

14. Changes to this policy#

We may update this policy as the Service and our legal obligations develop. The version number and effective date at the top of this page always identify the current text. If a change materially affects your rights, we will notify registered merchants by email or through the cabinet before it takes effect.

Contact#

PurposeContact
Data protection and privacy requests[[DPO email]]
Legal correspondence[[Legal email]]
Security reports[[Security email]]
General support[[Support email]] or a support ticket in the merchant cabinet
Postal address[[Company legal name]], [[Registered address]]
← All legal documents
On this page
  • 1. Who we are
  • 2. Scope
  • 3. Personal data we process
  • 4. Why we process data and on what legal basis
  • 5. Blockchain data — important limitations
  • 6. Cookies
  • 7. How long we keep data
  • 8. Who we share data with
  • 9. International transfers
  • 10. How we protect data
  • 11. Your rights
  • 12. Automated decision-making
  • 13. Children
  • 14. Changes to this policy
  • Contact
On this page
  • 1. Who we are
  • 2. Scope
  • 3. Personal data we process
  • 4. Why we process data and on what legal basis
  • 5. Blockchain data — important limitations
  • 6. Cookies
  • 7. How long we keep data
  • 8. Who we share data with
  • 9. International transfers
  • 10. How we protect data
  • 11. Your rights
  • 12. Automated decision-making
  • 13. Children
  • 14. Changes to this policy
  • Contact

Questions?

If anything here is unclear, or you need this document signed, write to us.

Contact support

Related documents

Cookie PolicyRefunds, Disputes and ChargebacksCrypto-Asset Risk DisclosureComplaints Handling Procedure
Paysell

Crypto payments for online business — fast, chargeback-free, no red tape.

Product

  • How it works
  • Pricing
  • Payment methods
  • Security
  • FAQ
  • Blog

Solutions

  • E-commerce
  • Digital goods
  • SaaS & subscriptions
  • Online education
  • Freelance & services
  • Games
  • iGaming
  • Trading platforms
  • All solutions

Developers

  • Documentation
  • Quick start
  • Webhooks
  • API reference (OpenAPI)
  • llms.txt for AI agents
  • Logg inn
  • Opprett konto

Legal

  • Terms of Service
  • Privacy Policy
  • Fee Schedule and Limits
  • Acceptable Use Policy and Prohibited Businesses
  • AML/CTF and Sanctions Policy
  • Merchant Verification (KYC/KYB) Policy
  • Refunds, Disputes and Chargebacks
  • Crypto-Asset Risk Disclosure
  • All legal documents

© 2026 Paysell

Paysell is a crypto-asset payment service. Balances are not bank deposits, and the value of crypto-assets depends on the market.