Privacy Policy
Version of test-2026-10-05
This Privacy Policy (the "Policy") explains what personal data the PayMeSafe service processes, why and on what basis, to whom it is transferred, how long it is kept and what rights you have.
1. Data controller
-
The personal data operator is PayMeSafe Test Operator (the "Operator").
- Address: Test address, not a legal address
- Registration details: TEST DATA ONLY — not legal information
-
For any questions about personal data, including to exercise your rights, write to test@example.invalid.
-
The Policy is information for you, not an agreement: you do not need to accept it. Where processing is possible only with your consent, the Operator asks for it separately — with a box next to the action — and you are free not to give it.
-
The Policy applies together with the Terms of Service and the Cookie Policy.
2. What data is processed and why
-
Account.
- Data: email address; password — only as a hash, the password itself is not stored; name; interface language; the username assigned by the service. If you have enabled multifactor authentication — its secret key and backup codes; backup codes are stored as hashes.
- Purpose: to create the account, let you into the service, restore access and contact you.
- Basis: contract (the Terms of Service).
-
Public profile.
- Data: name, username, marks of a confirmed email, completed identity verification and completed deals, registration date.
- Who sees it: other Users and website visitors, including without signing in. Contacts, wallets and documents are not shown in the profile.
- Purpose: so that a partner understands whom they are dealing with.
- Basis: contract.
-
Deals and messages.
- Data: your role in the deal, the details about yourself you entered in the deal, the title, terms and parameters of the deal, revisions of the terms, files, messages in the deal feed, dispute materials.
- Who sees it: your partner in the deal and, in a dispute, the arbiter and the reviewer. Anyone with the invitation link can see the deal terms and how the parties are named in it before signing in.
- Purpose: carrying out deals and reviewing disputes.
- Basis: contract.
-
Invitations.
- Data: the email address of the person you invite to a deal.
- How it is used: the Operator stores the address and sends the invitation to it. The email states who the operator is, where the address came from and why, and contains a link to opt out of invitations. If the recipient opts out, their address is kept in the opt-out list so that no more invitations are sent to it.
- Basis: the legitimate interest of the inviting User and the Operator in delivering the invitation to the recipient; for the opt-out list — the duty to respect the recipient's refusal.
-
Wallet and operations.
- Data: balances, deposit addresses, deposits, withdrawals, locked funds, releases, refunds, fees, withdrawal addresses and blockchain transaction identifiers.
- Purpose: keeping and recording funds, carrying out operations and settling deals.
- Basis: contract; keeping the history of operations — also legal requirements.
-
Blockchain addresses. The addresses from which you top up your wallet and to which you withdraw funds, and the transactions on them, are visible on the network to anyone. This is a property of the blockchain: the Operator cannot hide or delete such records.
-
Identity verification.
- Data: a copy of a document proving your identity, the data in it, the document type, the result and date of the check.
- Purpose: identity verification before withdrawals and AI reviews, compliance with legal requirements.
- Basis: your separate consent to processing of the document copy, given before each upload, and legal requirements.
-
AI review of the terms.
- Data: the text of the deal terms and the deal fields — template, your role, subject and payment amount, deadlines; the results of the check — findings and your decisions on them.
- Purpose: checking the text of the terms at your request.
- Basis: your separate consent to data transfer for AI review, given before each check.
-
Acceptance of documents.
- Data: which document and version you accepted or which consent you gave, the date and time, IP address and browser details.
- Purpose: to confirm that you accepted the document or gave consent.
- Basis: the Operator's legitimate interest and the legal duty to prove consent.
-
Technical data and security.
- Data: IP address; browser and device details — browser type and version, operating system, language, time zone, screen parameters, a technical browser fingerprint; device and session identifiers; service error logs.
- Purpose: to recognise your device, detect sign-ins by others, limit password and code guessing, find and fix errors.
- Basis: the legitimate interest of the Operator and Users in protecting accounts and funds.
-
Draft without an account.
- Data: a deal draft put together before registration and hashes of technical browser data. They are kept for a limited time and then deleted automatically.
- Purpose: to keep the draft until registration and protect the service from abuse.
- Basis: the Operator's legitimate interest.
-
Support requests.
- Data: your email address and the content of the correspondence.
- Purpose: to answer your request.
- Basis: contract and your request.
-
Cookies. The cookies the service uses are described in the Cookie Policy.
3. Legal bases
-
Contract — the Terms of Service: processing is needed to provide the service to you.
-
Consent — for the document copy in identity verification and for data transfer in an AI review. Consent can be withdrawn (section 8).
-
Law — where the law requires the Operator to keep information or pass it to government authorities.
-
Legitimate interest — protecting accounts and funds, confirming acceptance of documents, delivering invitations, where such processing does not infringe your rights.
4. Who receives the data
-
The Operator does not sell personal data and does not pass it on for advertising.
-
Within the service, data is seen by: your partner in the deal — the deal data; the arbiter and the reviewer — dispute materials; any visitor — the public profile. Employees of the Operator access data to the extent needed for their work.
-
To run the service and on the Operator's instructions, data is received by:
- an AI model provider — currently OpenRouter, Inc. (USA): only for an AI review, only with your consent and only the text of the terms and the deal fields (section 5);
- the email service used to send emails — the recipient's address and the text of the email;
- the hosting provider of the servers the service runs on — the data stored on those servers;
- blockchain network access services — addresses and transaction data, to carry out and check transfers; your name and email address are not passed to them.
-
Government authorities receive data where the law requires it.
5. Cross-border transfer
-
In an AI review, the text of the terms and the deal fields are transferred to an AI model provider — currently OpenRouter, Inc. (USA). OpenRouter forwards the request to the provider of the language model that performs the check.
-
If the text of the terms contains personal data, this is a cross-border transfer of personal data. It takes place only with your consent, given before each check. Details are in the Consent to Data Transfer for AI Review.
6. Retention
-
Data is kept while your account exists.
-
After the account is closed, personal data is deleted or anonymised (section 7). The history of deals and wallet operations remains without personal data for as long as the law requires.
-
If you withdraw consent, processing on its basis stops, and the data obtained on its basis is deleted within the period set by law unless it has to be kept on another basis.
7. Closing the account
-
You can close your account by writing to test@example.invalid from the account's email address. The account is closed if you have no unfinished deals, open disputes, withdrawals in progress, locked funds or wallet balance.
-
On closure, the following are deleted or anonymised: email address, name, password, sessions and devices, multifactor authentication settings, identity document copies, addresses of people you invited, IP addresses and browser details in the records of document acceptance. In deals and the feed, your role in the deal is shown instead of your name.
-
The deals you took part in, their terms, messages and files remain: the other party needs them, and they are needed for accounting. Text you wrote yourself in terms, messages and files is not changed.
8. Your rights
-
You have the right to:
- find out whether the Operator processes your data, what data and why;
- get a copy of your data;
- correct inaccurate data — the name is changed in the profile settings, the rest on request;
- request deletion of your data or the end of its processing — except data the Operator must keep by law;
- withdraw consent;
- complain about the Operator's actions to the data protection authority or to a court.
-
To exercise a right, write to test@example.invalid from the account's email address. The Operator responds within the period set by law.
-
The list of devices signed in to the account is shown in the security settings; you can revoke a device's access there.
9. How data is protected
-
The connection to the service is encrypted.
-
Passwords are stored only as hashes.
-
Identity document copies are kept in closed storage and cannot be opened by a direct link; only employees of the Operator who carry out verification have access to them.
-
Deal files are kept in closed storage and are available to the parties of the deal and, in a dispute, to the arbiter and the reviewer.
-
Keys to deposit addresses are stored encrypted.
-
Signing in and money operations can be additionally protected with multifactor authentication.
10. Automated decisions
-
The service does not make decisions with legal effect for you without human involvement. Identity verification and disputes are reviewed by employees of the Operator; findings of the AI assistant are only suggestions.
-
The service applies only protective measures automatically: it temporarily limits code entry after several mistakes, limits the request rate and ends sessions on signs of someone else's access.
11. Changes to the Policy
-
The Policy and the other documents of the service share one version; its date is shown at the beginning of the document.
-
A new version is published on the website. When a new version is released, you accept the Terms of Service again before continuing to use the service.
12. Contacts
- Operator: PayMeSafe Test Operator
- Address: Test address, not a legal address
- Registration details: TEST DATA ONLY — not legal information
- Personal data questions and support: test@example.invalid