This Privacy Notice explains how Digital Workers, LLC d/b/a 402pay.co ("402pay", "we" or "us") collects, uses, shares and protects personal data, and the choices you have. Personal data means any information about a person who can be identified, such as a name, an email address or an IP address.
1Who this notice covers
This notice applies when we decide how and why personal data is used, which makes us its controller. That covers:
- people who visit our website or read our developer documentation;
- merchants, meaning the businesses that use 402pay and the people who act for them;
- payers, meaning people who pay a merchant through 402pay, for the data we use for our own purposes, such as preventing fraud; and
- anyone who contacts us.
When we run a merchant's checkout, we process payers' data for that merchant, as their processor, under our Data Processing Agreement. The merchant decides how that data is used, so questions about it should go to them first. If you send us a request about data we process for a merchant, we will pass it on to them.
This notice doesn't cover services we don't run, such as the providers that carry out card payments or the wallets and exchanges payers send from. They have their own privacy notices, which we encourage you to read.
2What we collect
2.1What merchants give us
- Account details: the email address you sign in with, and your password, which we keep only as a one-way hash we can't reverse.
- Passkeys, if you sign in with them: for each one, a credential ID, its public key, a signature counter, the name you give it and, when your browser tells us, which password manager or device made it, and when it was added and last used.
- Business details, such as your business's name, website and support email, and the settings you choose.
- What you create in the Services, such as payment links, customers, notes, API keys and webhooks.
- Wallet data: public keys, addresses, balances and transactions. If you create or import a wallet with us, we also store its recovery phrase, but only after your browser has encrypted it with a password we never receive.
- Messages you send us, and information you give us to verify your business.
2.2What payers give us
- Your email address, which checkout asks for on every card payment, and on crypto payments when the merchant chooses to. A merchant can also give it to us itself.
- A country, taken from your browser's language settings.
- The amount, currency, coin and network you pay with.
2.3What we collect automatically
- Log data: your IP address, browser, the pages or API endpoints you request, and when.
- Session data for merchants: the device and browser of each signed-in session, its IP address and approximate location, and when it was last used, and the devices and countries you have recently signed in from, so we can tell you about a new one.
- Activity in the Dashboard, which we record in your business's audit log.
- On the sign-up, sign-in and password reset pages, the result of a security check by Cloudflare Turnstile, which reads technical details of your browser and connection, such as your IP address, to tell people from bots.
2.4What we get from others
- From public blockchains: the address a crypto payment came from, its transaction hash and its confirmations.
- From the independent providers that process card payments: whether a card payment was approved and why a payment failed.
- From the providers that help us verify businesses.
2.5What we don't collect
We never store your password itself, only a hash of it, and we never see your wallet's encryption password. We never receive a recovery phrase or a private key that can spend funds in readable form. A passkey's private key never leaves your device or password manager, and the fingerprint, face or PIN you unlock it with stays on your device, so we never receive either. Full card numbers, expiry dates and security codes go to the provider that processes the card payment, never to us. We don't collect sensitive data, such as health or biometric data, and we don't buy data from data brokers.
3How we use personal data
We use personal data only for the purposes below. For people in the European Economic Area, Switzerland and the United Kingdom, the table also gives the legal basis we rely on.
| Purpose | Data | Legal basis | How long we keep it |
|---|---|---|---|
| Providing the Services to merchants, including checkout, receipts, webhooks and support. | Account details, business details, what you create, wallet data, messages. | Performing our contract with the merchant. | While the account is open. |
| Keeping accounts secure, including sign-in with a password or passkey, confirming email addresses, password resets, two-step verification, sessions, security emails and the check that keeps bots out of sign-up, sign-in and password resets. | Account details, passkeys, session data, security check results, log data, activity. | Our legitimate interest in keeping accounts safe. | While the account is open. |
| Preventing fraud and abuse. | Payment data, log data, data from blockchains and card payment providers. | Our legitimate interest in protecting merchants, payers and the Services. | Up to five years after the payment. |
| Meeting legal obligations, such as record keeping. | Business details, payment data. | Legal obligation. | As long as the law requires, typically five years. |
| Understanding how the Services are used, so we can fix and improve them. | Log data and activity, aggregated wherever we can. | Our legitimate interest in improving the Services. | Up to 12 months, unless aggregated. |
We don't sell personal data or share it for cross-context behavioral advertising. Our fraud and abuse checks can block a payment automatically; if that happens to you, you can ask us at privacy@402pay.co to have a person review it.
4Who we share it with
We share personal data only with:
- the merchant a payer paid, so they can fulfill the order, answer questions and handle refunds;
- the independent provider that processes a card payment, under its own terms and privacy notice;
- Cloudflare, which runs the security check on our sign-up, sign-in and password reset pages. It processes the check for us, and uses what it learns to improve the check, under its own privacy policy;
- service providers that host and run the Services for us, providers that deliver our emails, and providers that help us verify businesses, each bound by contract to use it only for the work they do for us (we share the current list on request);
- professional advisers, such as lawyers, auditors and insurers, who are bound to keep it confidential;
- authorities and other parties, when the law or legal process requires it, as our Law Enforcement Policy describes, or when we need to enforce our agreements or protect the rights, property or safety of our users, the public or 402pay; and
- a buyer or successor, if 402pay is part of a merger, acquisition or sale of assets. We will tell merchants before their data falls under a different privacy notice.
5Aggregated and de-identified data
We may turn personal data into aggregated or de-identified data that can no longer reasonably identify anyone, such as the number of payments made on each network, and use or share it for lawful purposes, including to understand, improve and promote the Services. We keep such data in that form and don't try to identify anyone from it.
6Public blockchains
Crypto payments are recorded on public blockchains. Anyone can see a transaction's addresses, amount and hash, and no one, including us, can change or delete them. We don't publish who is behind an address, but others may be able to connect an address to a person using other information.
7International transfers
We run on cloud infrastructure with servers in many countries, so your data may be processed outside the country where you live, including in the United States. When we transfer personal data out of the European Economic Area, Switzerland or the United Kingdom, we rely on safeguards the law recognizes, such as the European Commission's standard contractual clauses and the UK addendum to them.
8Communications from us
We send merchants the messages the Services need, such as codes that confirm an email address, password reset links, notices about their account and payments, and changes to our terms. We email you about your account's security, such as sign-ins from a new device and changes to your email, password, passkeys, two-step verification or wallet, and you can't turn these off while you have an account. We don't email payers: their receipt is a page they can open, print or save. If we send merchants product news, every such email has a link to stop it. You can't opt out of messages we must send to run the Services or that the law requires.
9Your rights
9.1What you can ask for
Depending on where you live, you may have the right to:
- find out what personal data we hold about you, how we use it and who we share it with, and get a copy of it;
- correct it if it is wrong or incomplete;
- have it deleted, unless we must keep it by law;
- object to or restrict how we use it, and withdraw consent where we rely on it;
- receive it in a portable, machine-readable format, or have us send it to someone else;
- opt out of the sale or sharing of personal data, and of profiling that has legal or similarly significant effects; and
- appeal a decision we make about your request.
These rights have conditions and exceptions under the law, and we may keep data we need for legal obligations, to resolve disputes or to prevent fraud. Using them won't affect how we treat you.
9.2Making a request
Merchants can see and update most of their data in the Dashboard. For anything else, email privacy@402pay.co and describe your request with enough detail for us to find your data, such as a receipt or the business involved. We will confirm who you are before we act, using information we already hold, so we may ask a merchant to write from the email address they sign in with, or a payer to share a receipt.
Where the law allows, you can have an authorized agent make a request for you, with your signed permission, and we may check it with you. We don't charge for requests unless they are clearly unfounded or excessive, and we reply within the time the law allows, usually 30 days, or 45 days under U.S. state laws, extended where the law permits. If we process your data for a merchant, we will pass your request to them.
9.3Residents of U.S. states
California, Colorado, Connecticut, Virginia and other states give their residents rights over personal data. In the last 12 months, we collected the categories of personal data described in Section 2, from the sources listed there, for the purposes in Section 3, and disclosed them for business purposes to the recipients in Section 4. We have not sold personal data or shared it for cross-context behavioral advertising, and we don't use sensitive personal data to infer anything about anyone. We treat a Global Privacy Control signal from your browser as a request to opt out of sale and sharing. If we decline your request, you can appeal by replying to our decision, and if we turn down your appeal, you can contact your state attorney general.
9.4The European Economic Area, Switzerland and the United Kingdom
Digital Workers, LLC d/b/a 402pay.co is the controller of the personal data this notice covers, and the table in Section 3 gives the legal basis for each use. Where we rely on our legitimate interests, you can object, and where we rely on consent, you can withdraw it at any time without affecting what we did before. You can also complain to the data protection authority where you live or work, or where you think a breach happened, though we would welcome the chance to address your concern first.
10How we protect it
We hold as little sensitive data as we can and protect what we do hold, with encryption in transit and at rest, recovery phrases encrypted before they leave the browser, passwords and other secrets stored only as hashes, and access for our staff limited to those who need it. Our Data Processing Agreement lists them in detail. No system is perfectly secure, so if a breach affects your personal data, we will tell you and the authorities as the law requires.
11How long we keep it
We keep personal data for the periods in the table above. When a merchant closes their account, we delete or anonymize their data, except what we must keep for legal and tax reasons, to resolve disputes or to prevent fraud. When we no longer need data, we delete it securely.
12Cookies and local storage
We don't use advertising cookies or third-party trackers. We use only a few entries of our own, each needed for the Services or to remember a choice you made:
- a cookie that keeps you signed in to the Dashboard;
- a cookie that links a sign-up to the browser it started in, for up to a day, so only that browser can finish it without your password;
- a cookie that recognizes a browser you've signed in with, for up to 90 days after your last sign-in there, so failed sign-ins from elsewhere can't lock you out of it;
- a cookie that ties a passkey sign-in to the browser that started it, for up to 5 minutes, so no other browser can finish it;
- a cookie that remembers the business you opened last;
- a cookie that remembers your cookie choices, so we ask only once; and
- local storage entries that remember your theme, the language and appearance you pick at checkout, and choices you make in our developer documentation, such as your code language and checklist progress, and session storage that keeps your place in sign-up and carries your email address between the sign-in pages until you close the tab.
Anything beyond these, such as cookies that measure how the site is used, is set only if you allow it, and you can change your choice at any time in . You can also clear cookies in your browser settings, though clearing the first one signs you out.
The security check on the sign-up, sign-in and password reset pages runs in Cloudflare's own frame and reads only what it needs to tell people from bots. It keeps accounts secure, so it isn't one of these choices.
13Children
The Services are not meant for anyone under 18, and we don't knowingly collect personal data from children. If we learn that we have, we will delete it promptly. If you believe a child has given us personal data, contact us at privacy@402pay.co.
14Changes to this notice
We may update this notice by publishing a new version here, and we will tell merchants about material changes before they take effect, by email or in the Dashboard. Each version applies to data collected while it is in effect. This notice is part of our Terms of Service.
15Contact us
Digital Workers, LLC d/b/a 402pay.co is responsible for the personal data this notice covers. For questions about this notice, how we use personal data or your rights, email privacy@402pay.co. For anything about your account, email support@402pay.co. To report a security vulnerability, email security@402pay.co.