Privacy Policy
This policy explains what data Q402 processes when you use the payment interface, trust reports, and receipts, and how that data is handled. Q402 is non-custodial: we do not hold your funds.
01Information we collect
[PLACEHOLDER] Describe the categories of data collected: wallet addresses connected to the interface, transaction metadata, request identifiers, and technical/usage data such as device and browser information.
On-chain identifiers
- [PLACEHOLDER] Wallet addresses submitted to or detected by the payment interface.
- [PLACEHOLDER] Transaction hashes, chain identifiers, and token amounts associated with payment requests.
Usage data
- [PLACEHOLDER] Technical metadata such as IP addresses (used for rate-limiting only), request timestamps, and error logs.
- [PLACEHOLDER] Receipt and trust report identifiers generated by the platform.
02How we use information
[PLACEHOLDER] Explain how collected data is used: operating the service, preventing abuse, enforcing rate limits, generating trust reports, and providing receipts. Clarify that data is not sold or shared for advertising.
- [PLACEHOLDER] To process payment requests and issue verifiable Trust Receipts.
- [PLACEHOLDER] To generate on-chain trust reports for wallet addresses.
- [PLACEHOLDER] To enforce rate limits and prevent abuse of the API.
- [PLACEHOLDER] To respond to support requests submitted by users.
03On-chain data
[PLACEHOLDER] Clarify that blockchain transaction data is public and immutable. Q402 reads and indexes this data but does not control it. Explain that wallet addresses and transaction hashes submitted to the relay are permanently visible on public blockchains.
[PLACEHOLDER] Describe how ERC-8004 registry data is fetched from public smart contracts on BNB Chain and Base, and what that data represents.
04Sharing and disclosure
[PLACEHOLDER] State that Q402 does not sell user data. List the categories of third parties data may be shared with: infrastructure providers (Vercel/KV), public blockchain networks, and law enforcement when legally required.
- [PLACEHOLDER] Infrastructure providers such as Vercel for hosting and key-value storage.
- [PLACEHOLDER] Public blockchain networks as part of normal relay operations.
- [PLACEHOLDER] Law enforcement or regulatory authorities when legally required.
05Data retention
[PLACEHOLDER] Describe how long different categories of data are retained: payment request records, trust receipts, rate-limit counters, and inquiry form submissions. Note that on-chain data is permanent and outside Q402's control.
- [PLACEHOLDER] Payment request and receipt records: retained for [X] days after settlement or expiry.
- [PLACEHOLDER] Rate-limit counters: expire automatically within 60–600 seconds per endpoint.
- [PLACEHOLDER] Inquiry submissions: retained until actioned or deleted upon request.
06Your rights
[PLACEHOLDER] Describe user rights regarding their data: access, deletion, correction, and portability where applicable. Note limitations for on-chain data. Provide the contact address for rights requests.
- [PLACEHOLDER] Access: you may request a copy of data Q402 holds associated with your wallet address.
- [PLACEHOLDER] Deletion: you may request removal of off-chain records. On-chain data cannot be deleted.
- [PLACEHOLDER] Correction: you may request updates to inquiry contact details.
07Contact
[PLACEHOLDER] Provide a contact email address or form for privacy-related requests, including data access and deletion requests. State the expected response time.
[PLACEHOLDER] Contact address: [PLACEHOLDER email] — please include your wallet address in the subject line.