CryptoXTS
Product Pricing Docs Blog Contact
Merchant login Request access
Menu
Product Pricing Docs Blog Contact Merchant login Request access
On this page
Who we are Information we collect What we deliberately don't collect How we use your information How information is shared Blockchain data is public Data retention How we secure your data Your rights Cookies & analytics Children's privacy Changes to this policy Contact us

Privacy policy

Last updated: August 4, 2026
Draft template, not legal advice. This page was written to match CryptoXTS's actual product (invite-only access, commission structure, supported coins, security controls) so it's ready to refine — but it hasn't been reviewed by a lawyer. Have one check it against your jurisdiction's requirements (data protection law, payments regulation, tax treatment of crypto) before publishing it live.

Who we are

CryptoXTS operates an invite-only crypto payment gateway that lets approved merchants accept Bitcoin (BTC), Litecoin (LTC), USDT (TRC20 / ERC20 / BEP20), Ethereum (ETH) and BNB. This policy explains what information we collect when you use the admin panel, the API, or a CryptoXTS-powered checkout page, and what we do with it.

Information we collect

Because access is invite-only rather than open signup, we collect less than a typical consumer platform — but here's the full list:

  • Account information: name, email address, and password (stored hashed, never in plain text) provided when your access request is approved.
  • Transaction data: invoice amounts, the coin and network selected, wallet addresses generated for checkout, and on-chain transaction identifiers once a payment is broadcast.
  • Withdrawal and wallet data: wallet addresses you add and verify as trusted destinations, and your withdrawal history.
  • Security and session data: login IP address, device/browser information, timestamps of logins and sensitive actions (recorded in your account's audit log), and two-factor authentication status.
  • Support communications: anything you send us through a support ticket, including message content and any files you attach.
  • Domains and integration settings: domains you register for checkout use, API key usage, and webhook endpoint URLs you configure.

What we deliberately don't collect

We don't ask for card numbers, bank account details, or government ID as part of normal operation — checkout is crypto-only, and access approval is handled manually rather than through an automated KYC document flow. We also never take custody of the private keys to your wallets; checkout settles directly on-chain to addresses you control.

How we use your information

Account and transaction data exists to run the service: generating checkout pages, matching incoming payments to the right invoice, calculating commissions, sending the email notifications you'd expect (payment received, withdrawal confirmed, login from a new IP), and responding when you contact support. Security data — login IPs, 2FA status, audit log entries — exists specifically to detect and stop unauthorized account access.

How information is shared

We do not sell merchant or customer data. Information is shared only where the service genuinely requires it:

  • With blockchain networks themselves — this is inherent to how crypto payments work and is covered separately below.
  • With infrastructure providers (hosting, email delivery) strictly to operate the platform, under confidentiality obligations.
  • With analytics providers — specifically Google Analytics on public marketing pages (home, blog, docs, contact). See Cookies & analytics below.
  • With law enforcement or regulators, only where we're legally compelled to respond to a valid request.
  • With you, the merchant — your customers' payment status and wallet addresses are visible in your own dashboard, since you need that to run your business.

Blockchain data is public

This is worth calling out on its own: once a payment is broadcast, the receiving address, the amount, and the transaction hash are permanently visible on the relevant public blockchain — that's true of any crypto payment, on any platform, and isn't something CryptoXTS controls or can undo. We don't publish additional identifying information alongside on-chain data, but the on-chain record itself is not private.

Data retention

We keep account and transaction data for as long as your account is active, and for a reasonable period afterward to satisfy accounting, tax, and fraud-investigation obligations. Deactivating your account (available from your Profile page) stops active use immediately; full deletion requests are handled case by case where retention isn't legally required.

How we secure your data

Passwords are hashed, withdrawals require two-factor authentication plus an emailed code, sessions can be bound to your login IP, and every sensitive action — settings changes, withdrawal approvals, domain edits — is written to an audit log you can review. Trusted wallet addresses go through a verification step before they're eligible for withdrawals. No system is unbreakable, but these controls exist specifically to make account takeover hard.

Your rights

You can review and update your profile information, download your transaction history from the dashboard, and deactivate your account at any time. Where local law grants additional rights — access, correction, deletion, portability — contact us and we'll handle the request, noting that on-chain transaction data can't be altered or deleted once broadcast.

Cookies & analytics

We use a small number of functional cookies — keeping you logged in, remembering your light/dark theme preference, and recognizing a trusted login IP for a limited time.

On public marketing pages (home, blog, developer docs, contact, and similar), we also use Google Analytics 4 (measurement ID G-MPRMYGYP4K) to understand aggregate traffic — for example which pages are visited, roughly where visitors are located, and which devices or browsers are used. Google may set its own cookies or use similar local storage as part of that measurement. We configure Analytics for site measurement only; we do not use it to serve third-party ads on CryptoXTS.

We do not load Google Analytics on the merchant admin panel or on customer checkout pages. We don't run separate third-party advertising trackers on those surfaces either.

You can limit Analytics in your browser (for example with tracking protection, an ad blocker, or Google's own opt-out tools). Functional cookies required to stay signed in may still be necessary for the panel to work.

Children's privacy

CryptoXTS is a business tool for merchants and isn't directed at children. We don't knowingly collect information from anyone under the age of 18.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page and, for significant changes, notify account holders by email.

Contact us

Questions about this policy or a request regarding your data can be sent through our Contact us page, or through support after signing in.

CryptoXTS

Invite-only crypto payment infrastructure for BTC, LTC, USDT, ETH and BNB — built for merchants who take security seriously.

Product

Checkout Payment links API docs

Resources

Blog Contact us Request access Merchant login

Legal

Privacy policy Terms of use
© 2026 CryptoXTS. All rights reserved. Invite-only · Non-custodial checkout · BTC · LTC · USDT · ETH · BNB