This Law Enforcement Policy explains how Digital Workers, LLC d/b/a 402pay.co ("402pay", "we" or "us") handles requests from law enforcement, regulators, courts and others for information about the businesses that use 402pay and the people who pay them ("payers"). It sets out what 402pay is, which records we hold and for how long, what we can and can't do about a payment, and how to send us a request.
This policy describes our practice. It isn't legal advice, it doesn't create rights for anyone, and it doesn't change our Terms of Service, Acceptable Use Policy, Privacy Notice or Data Processing Agreement, which govern the Services and how we treat the data of businesses and payers. Where the law requires something different from what is written here, we follow the law.
1Who this policy is for
This policy is for:
- law enforcement agencies, regulators and other government authorities looking into a matter that involves 402pay;
- courts, and parties to civil or criminal cases, seeking records through legal process;
- the partners we work with, and other providers in payments and crypto, looking into fraud or abuse; and
- anyone reporting a checkout page that infringes their rights or breaks the law.
Businesses can see and export their own records in the Dashboard, and payers can open their receipt. If you want the personal data we hold about you, our Privacy Notice explains how to ask for it.
2What 402pay is and isn't
402pay is software and a hosted service. Businesses use our Dashboard, hosted checkout pages and API to accept payments in crypto and by card, and to run the self-custody wallet that receives them. We are a technology provider, not a party to the sales businesses make: the business is the seller, and it decides what it sells, to whom, at what price and whether to refund.
We don't take custody of businesses' or payers' crypto, hold deposits or customer funds for anyone, or exchange one asset for another, and we don't process card transactions ourselves: independent partners do, as Section 5 describes.
Crypto payments are non-custodial. Each checkout normally pays to a fresh address derived from the business's own wallet, so payments reach the business directly, apart from payments we direct to our own addresses to collect the fees the business owes. A wallet connected with a single address reuses that address for every checkout. Only whoever controls a wallet's keys can move what it holds.
When a business creates or imports a wallet with us, its browser encrypts the recovery phrase with a password we never receive, and we store only that encrypted copy and the wallet's public keys. A business can instead connect a wallet it runs in another app and share only its public keys or addresses.
3What we can and can't do
3.1We can't move, freeze or reverse crypto
Because we never hold the keys that can move the crypto in a business's wallet, we cannot freeze, seize, move, redirect, reverse or recover it, or any transfer on a blockchain. Once a network confirms a transfer, it is final, and no one, including us, can undo it. We don't run or control any blockchain, and we can't stop anyone from sending crypto straight to an address on its network, even after we have closed the account it belongs to.
Requests to freeze, seize or return crypto need to go to whoever controls it: the business that holds the wallet, or an exchange or other custodian the crypto has moved to. A business that connected a wallet it runs elsewhere may have given us an address that an exchange or other custodian controls, and then that custodian controls the funds. Some stablecoin issuers can freeze their tokens at an address, and those requests go to the issuer.
With valid legal process, or in an emergency as Section 7 describes, we can confirm the address, network and token a payment went to, and whether the business connected that address from a wallet it runs elsewhere, so you can ask the issuer or custodian to freeze it quickly. The fees we receive from payments are our own funds, and we respond to an order to seize them like any other legal process.
3.2What we can do
Within the Services, we can:
- suspend or close a business's account, and with it the business's access to the Dashboard and API;
- disable its payment links and API keys, so its checkout pages stop taking payments;
- stop generating new checkout addresses in its wallet;
- decline or block checkouts and payments, including those our fraud and abuse checks flag;
- preserve the records we hold, as Section 8 describes; and
- disclose the records we hold, as Section 6 describes.
These steps work within the Services only. They don't touch a business's wallet, whose crypto stays under the control of whoever holds its keys, and they can't stop or undo a transfer someone sends on a network.
We decide whether to take them under our Terms of Service and Acceptable Use Policy, or because the law, a court order or a regulator requires it. If you ask us to restrict an account, tell us why, and whether restricting it could alert its owner to an investigation. A request to keep an account open doesn't bind us, and we decide it under our Terms of Service.
We don't monitor a business, wallet or address for authorities, or report its future activity, without a court order that specifically authorizes disclosure of future activity.
3.3Refunds, disputes and chargebacks
Refunds are the business's decision, and it sends them from its own wallet; we can't send one for it. Card payers dispute a card payment with their card issuer, and the partner that processed the payment handles the chargeback, so requests about disputes and chargebacks go to them. If you paid a business that turned out to be a fraud, report it to your local police, and in the United States to the FBI's Internet Crime Complaint Center at ic3.gov. Report it to us too, at legal@402pay.co with your receipt, so we can review the business under our Acceptable Use Policy.
4What we hold
4.1Records we keep
We keep the records the Services need, for the periods our Privacy Notice and Data Processing Agreement set out. The main ones are:
| Records | What they include | How long we keep them |
|---|---|---|
| Business accounts | The business's name, website, support email and settings, the information it gave us to verify it, and what it creates in the Services, such as payment links, API keys and webhooks. | While the account is open. After it closes, only what we must keep by law, to resolve disputes or to prevent fraud. |
| Customer records | The customers a business adds, and those created automatically from its checkouts: each one's name, email address, notes, whether the business blocked them, and the payments tied to them. A payment without an email address is tied to an existing customer when it comes from an address that customer paid from before. | While the account is open. We delete them within 90 days after it closes, as our Data Processing Agreement provides, unless the law requires us to keep them. |
| Wallets | Public keys, or the addresses a connected wallet shared; every address derived from them and the business it belongs to; and the payments received at each address, the sends made or recorded through the Services, and the balances those add up to. A wallet may hold more than came through us, and the blockchain is the full record. For a wallet created or imported with us, also its recovery phrase, encrypted with a password we never receive. | While the account is open. An address that received a payment stays in that payment's record. |
| Checkouts and payments | The amount and currency, the coin and network, the address paid to and the address paid from, transaction hashes, timestamps and status, and any reference or metadata the business attached. Also the payer's email address, which card checkouts always ask for and crypto checkouts ask for when the business chooses to or supplies it through the API, and a country taken from the payer's browser settings. For a card payment, whether it was approved or why it failed, including a failed identity check, each partner we tried, and which partner processed it. | While the account is open. After it closes, what we keep to prevent fraud (up to five years after the payment) or to meet legal obligations (as long as the law requires, typically five years). We delete the references, metadata and notes the business attached within 90 days after it closes, unless the law requires us to keep them. |
| Referrals | Which business referred which, and the code it used, the fees each referral earned, and the monthly payouts we sent the referrer, with the address and transaction hash of each. | While the account is open. After it closes, records of the payouts we made, for as long as the law requires, typically five years. |
| User accounts | For each person who signs in: the email address they sign in with and when it was confirmed, the address it replaced and when, any name they give, whether two-step verification is on, and for each passkey they add, its credential ID, public key, signature counter and name, which password manager or device made it when their browser said, and when it was added and last used, but never biometrics, which stay on their device. | While the account is open, and a replaced email address only for a year after the change. |
| Sessions and logs | For each signed-in session, the device and browser, IP address, approximate location and when it was last used. The security emails we sent each person, such as notices of a new sign-in or a changed password, and when. Request logs with the IP address, browser, the pages or API endpoints requested, and when. | Session data and security logs while the account is open. Other logs up to 12 months unless aggregated, or up to five years after a payment where we keep them to prevent fraud. |
| Activity | The audit log of what people using a business's account did in the Dashboard, when each API key was last used, the events we recorded for the business, and the webhooks we sent it, with the signed body and the status each endpoint returned. | While the account is open. |
| Compliance records | The records we keep to meet our legal obligations. | As long as the law requires, typically five years. |
We can only produce what we still hold when a request reaches us, so if you need records kept while you obtain legal process, send a preservation request as Section 8 describes.
4.2What we don't hold
We don't have, and can't produce:
- private keys, recovery phrases or wallet passwords in readable form: the encrypted copy of a recovery phrase opens only with a password the business alone knows, which we can't reset or recover, and we can't decrypt that copy and don't try to;
- the crypto in a business's wallet, or deposits or customer funds held for anyone, because payments go to the business's own wallet;
- card numbers, expiry dates or security codes, or the documents and details a card partner uses to verify a payer's identity, which stay with that partner;
- who controls a blockchain address, beyond what a business or payer has told us, such as a payer's email address, or payments we have grouped by the address they came from;
- a user's password in readable form: we keep only a hash we can't reverse;
- a passkey's private key, or the fingerprint, face or PIN that unlocks it, which never leave the user's device or password manager; and
- what a business sold, where it delivered it, or other records it keeps in its own systems, beyond what it sends us.
5Card payments
Card payments are processed by independent partners, not by us. The partner takes the card details, verifies the payer's identity where it needs to, charges the card and delivers the payment to the business's wallet as crypto. The card details, the payer's identity documents and the details behind the partner's checks stay with the partner, under its own terms and privacy notice, and we don't receive them. We do receive the outcome, such as whether a payment was approved or why it failed, including a failed identity check.
Send requests for those records, and about card disputes and chargebacks, to the partner. If you give us the receipt or payment ID of a card payment, we can tell you which partner processed it once we have confirmed who is asking, as Section 6.1 allows. For our own records of a card payment, listed in Section 4, send us a request as Section 6 describes.
6Making a request
6.1The legal process we need
We disclose records about a business or a payer only in response to legal process that is valid and binding on us, such as a subpoena, court order or search warrant. There are three exceptions: in an emergency, as Section 7 describes; where the law requires us to report something on our own; and to tell an authority whose identity we have confirmed which partner processed a card payment it identifies by its receipt or payment ID, since that reveals nothing about the payer beyond what the receipt shows. The process must come from an authority with jurisdiction over us and the records.
Any disclosure we make voluntarily covers only data we hold for our own purposes, as our Privacy Notice describes. Personal data we process for a business, such as its customers' details, we disclose only where the law requires it, or where the business asks us to, as our Data Processing Agreement provides.
The process we generally need depends on the records:
| Records | What we generally need |
|---|---|
| Business and user account details, customer records, and payment, referral and compliance records | A subpoena, or its equivalent where you are. |
| Session data, logs and activity | A court order, or its equivalent where you are. |
| Wallet public keys and encrypted recovery phrases | A search warrant, or its equivalent where you are, that names them specifically. |
Where the law that applies requires more, we ask for it.
6.2What to include
Send every request in writing, in English or with an English translation, on official letterhead or from an official email address, with:
- the name of the agency or court, and the name, title, badge or ID number and contact details of the officer or other person responsible, including an email address on an official domain;
- the legal authority for the request, and a copy of the legal process itself, signed where it must be;
- identifiers for what you are asking about, such as a business's name or ID, a payment link or its code, a payment or receipt ID, a wallet address or a transaction hash, since a name or email address alone may not be enough to find records;
- the date range the request covers, as narrow as the investigation allows;
- the specific records you seek; and
- the date you need a response by, and whether the law or a court order bars us from telling the business about the request, with a copy of that order.
6.3Serving a request
Address legal process to Digital Workers, LLC d/b/a 402pay.co. Government authorities can send it to legal@402pay.co, and we accept their legal process by email as a courtesy, without waiving any objection, including to jurisdiction or to how it was served. Where the law requires formal service, serve it as that law requires; email legal@402pay.co first and we will tell you where. We don't take requests by phone or through our support channels, and a request sent anywhere else may not reach the right people.
6.4Civil and private requests
Parties to civil cases, such as disputes between a business and its customers, should first ask the business involved, which holds its own records of the sale and can export its payment records from the Dashboard. A subpoena or other process from a private party must be served as the rules of civil procedure require, and we don't accept it by email. Before we produce records, we tell the business involved and give it time to object, as Section 9 describes, and the party asking pays our reasonable costs of responding. A private party outside the United States needs process from a U.S. court, such as under the Hague Evidence Convention or by letters rogatory.
6.5Requests from outside the United States
If you are an authority outside the United States, send your request through a mutual legal assistance treaty, letters rogatory, an agreement between your country and the United States under the CLOUD Act, or another channel the law recognizes. We may respond to a request you send us directly where the laws that apply to the records and to us allow it.
Where a request from outside the European Economic Area or the United Kingdom seeks personal data that the GDPR or the UK GDPR protects, we assess it under those laws, including Article 48 of the GDPR, and may ask you to use a mutual legal assistance treaty instead. If you send a European Production or Preservation Order, we assess whether Regulation (EU) 2023/1543 applies to the Services and, where it does, respond as it requires.
6.6How we review requests
We review every request for validity, jurisdiction and scope. We don't process a request that is incomplete, isn't properly served or that we can't verify came from the authority named in it, and we will tell you what is missing where we can. We push back on requests that are overbroad or vague, challenge them where we have reasonable grounds, and disclose only the minimum the request lawfully requires.
Where a request seeks personal data we process for a business, such as its customers' details, we first try to redirect it to that business, as our Data Processing Agreement commits us to. Allow at least 15 business days for a standard request; we handle emergency requests ahead of all others.
On request, we certify records under Federal Rule of Evidence 902(11) or 902(13), or the state equivalent, so a custodian shouldn't need to testify, and we don't provide expert testimony. We deliver records electronically. Where the law allows, we may ask a government authority to reimburse the reasonable cost of responding, and private parties pay it, as Section 6.4 describes.
7Emergency requests
If you are a law enforcement or other government official and believe someone faces an imminent risk of death or serious physical injury that records we hold could help prevent, email legal@402pay.co with "Emergency disclosure request" in the subject. Include a signed statement that describes the emergency, who is at risk, why the records are needed without delay and exactly which records you need, with your name, agency and contact details. If you aren't an official and someone is in danger, contact your local emergency services.
We review emergency requests ahead of all others, and we verify every one by calling the agency on a number we find independently. Where the law allows, we may disclose records voluntarily, in good faith and limited to what the emergency needs, which is usually only basic account information, and we may ask for legal process afterward. We decide each request on its facts, and handle one that doesn't describe a genuine emergency like any other.
A voluntary disclosure covers only data we hold for our own purposes, as our Privacy Notice describes. Personal data we process for a business under our Data Processing Agreement, we disclose only where the law requires it or the business asks us to.
8Preservation requests
While you obtain legal process, you can ask us to preserve the records we hold about a specific business, payment or address. Send the request to legal@402pay.co from the officer or other person responsible, with the identifiers and date range described in Section 6.2. We preserve a copy of the records we hold at that time for 90 days, and extend it once for another 90 days if you renew the request before the first period ends. We disclose preserved records only once we receive valid legal process for them, and if none arrives in that time, they return to our normal retention periods. We can't preserve records a card partner holds, and transfers on a blockchain are already public and permanent.
9Notice to businesses
We tell the business whose records are requested about the request, including a preservation request, as our Data Processing Agreement and Terms of Service commit us to. Before we disclose its records, we give it at least 7 days' notice, so it can seek to challenge the request. We don't notify it when the law or a court order forbids it, and in an emergency we may notify it only once the risk has passed. When a nondisclosure order ends, we notify the business then.
We don't contact payers about requests. The business controls its customers' data and decides whether to tell them.
If notice would harm an investigation, include the order or other legal authority that bars it, and how long it lasts.
10Businesses' own responsibilities
Each business that uses 402pay is responsible for complying with the laws that apply to it, including consumer protection, anti-money laundering, sanctions, tax and data protection laws, and for holding every license its business needs, as our Terms of Service and Acceptable Use Policy require. The business is the seller in every sale made through 402pay: it knows what it sold and to whom, keeps its own records of its sales and customers, controls its wallet and decides whether to refund.
That makes the business the right first contact for most questions about a sale, a customer or the funds it received, and for requests to hold or return funds. The law may require a business to respond to requests sent to it, and it can export its payment records from the Dashboard to do so. Using 402pay doesn't make us responsible for a business's compliance, and we don't answer requests sent to a business on its behalf unless it asks us to.
11Content on checkout pages
11.1Reporting a checkout page
Checkout pages show content that businesses give us, such as their name and a description of what they sell. If you believe a checkout page is being used for fraud, sells something our Acceptable Use Policy prohibits, or infringes your copyright, trademark or other rights, email legal@402pay.co with the link to the page and what you saw. We review every report under our Acceptable Use Policy, and we can remove content, disable a payment link, or suspend or close the business's account. We host checkout pages, not a business's own website, so for content there, also contact the business or its hosting provider.
11.2Copyright claims
To report content on a checkout page that you believe infringes your copyright, including under the U.S. Digital Millennium Copyright Act, send a notice to legal@402pay.co with:
- your name, address, phone number and email address;
- the copyrighted work you believe is infringed;
- the checkout page, and the content on it you believe infringes, in enough detail for us to find it;
- a statement that you believe in good faith that the use isn't authorized by the copyright owner, its agent or the law;
- a statement that the information in your notice is accurate and, under penalty of perjury, that you own the copyright or are authorized to act for its owner; and
- your physical or electronic signature.
When we remove content or disable a payment link because of a notice, we tell the business and may send it a copy of the notice, including your contact details. We may close the accounts of businesses that repeatedly infringe the rights of others. Knowingly misrepresenting that content infringes can make you liable for damages.
11.3Counter-notices
A business that believes content was removed by mistake or misidentification can send a counter-notice to legal@402pay.co with:
- its name, address, phone number and email address;
- the content that was removed or disabled, and where it appeared before;
- a statement, under penalty of perjury, that it believes in good faith the content was removed or disabled as a result of a mistake or misidentification;
- a statement that it consents to the jurisdiction of the U.S. federal district court for its address, or, if its address is outside the United States, of any judicial district in which we may be found, and that it will accept service of process from the person who sent the notice or their agent; and
- its physical or electronic signature.
We send a complete counter-notice to the person who sent the notice, and restore the content 10 to 14 business days after we receive it, unless they tell us first that they have filed a court action to stop the infringement. Knowingly misrepresenting that content was removed by mistake can make the business liable for damages.
12Requests from partners and other providers
The partners that process card payments for businesses on 402pay, and other providers, such as exchanges, wallet providers and other payment companies, can reach us at legal@402pay.co about fraud, abuse or a legal matter involving a business on 402pay. Include your company's name, your role and the identifiers described in Section 6.2. We review what you report and cooperate as our agreements and the law allow, and we share personal data only as our Privacy Notice and Data Processing Agreement allow, which for data we process for a business means only where the law requires it.
13Changes to this policy
We may update this policy as the law and the Services change, by publishing a new version here.
14Contact us
Send legal process from government authorities, emergency and preservation requests, and reports under this policy, to legal@402pay.co. For questions about personal data, email privacy@402pay.co, and for anything about an account, email support@402pay.co.