CryptoXTS operates an invite-only crypto payment gateway that lets approved merchants accept Bitcoin (BTC), Litecoin (LTC), USDT (TRC20 / ERC20 / BEP20), Ethereum (ETH) and BNB. This policy explains what information we collect when you use the admin panel, the API, or a CryptoXTS-powered checkout page, and what we do with it.
Because access is invite-only rather than open signup, we collect less than a typical consumer platform — but here's the full list:
We don't ask for card numbers, bank account details, or government ID as part of normal operation — checkout is crypto-only, and access approval is handled manually rather than through an automated KYC document flow. We also never take custody of the private keys to your wallets; checkout settles directly on-chain to addresses you control.
Account and transaction data exists to run the service: generating checkout pages, matching incoming payments to the right invoice, calculating commissions, sending the email notifications you'd expect (payment received, withdrawal confirmed, login from a new IP), and responding when you contact support. Security data — login IPs, 2FA status, audit log entries — exists specifically to detect and stop unauthorized account access.
We do not sell merchant or customer data. Information is shared only where the service genuinely requires it:
This is worth calling out on its own: once a payment is broadcast, the receiving address, the amount, and the transaction hash are permanently visible on the relevant public blockchain — that's true of any crypto payment, on any platform, and isn't something CryptoXTS controls or can undo. We don't publish additional identifying information alongside on-chain data, but the on-chain record itself is not private.
We keep account and transaction data for as long as your account is active, and for a reasonable period afterward to satisfy accounting, tax, and fraud-investigation obligations. Deactivating your account (available from your Profile page) stops active use immediately; full deletion requests are handled case by case where retention isn't legally required.
Passwords are hashed, withdrawals require two-factor authentication plus an emailed code, sessions can be bound to your login IP, and every sensitive action — settings changes, withdrawal approvals, domain edits — is written to an audit log you can review. Trusted wallet addresses go through a verification step before they're eligible for withdrawals. No system is unbreakable, but these controls exist specifically to make account takeover hard.
You can review and update your profile information, download your transaction history from the dashboard, and deactivate your account at any time. Where local law grants additional rights — access, correction, deletion, portability — contact us and we'll handle the request, noting that on-chain transaction data can't be altered or deleted once broadcast.
We use a small number of functional cookies — keeping you logged in, remembering your light/dark theme preference, and recognizing a trusted login IP for a limited time.
On public marketing pages (home, blog, developer docs, contact, and similar), we also use Google Analytics 4 (measurement ID G-MPRMYGYP4K) to understand aggregate traffic — for example which pages are visited, roughly where visitors are located, and which devices or browsers are used. Google may set its own cookies or use similar local storage as part of that measurement. We configure Analytics for site measurement only; we do not use it to serve third-party ads on CryptoXTS.
We do not load Google Analytics on the merchant admin panel or on customer checkout pages. We don't run separate third-party advertising trackers on those surfaces either.
You can limit Analytics in your browser (for example with tracking protection, an ad blocker, or Google's own opt-out tools). Functional cookies required to stay signed in may still be necessary for the panel to work.
CryptoXTS is a business tool for merchants and isn't directed at children. We don't knowingly collect information from anyone under the age of 18.
If this policy changes materially, we'll update the date at the top of this page and, for significant changes, notify account holders by email.
Questions about this policy or a request regarding your data can be sent through our Contact us page, or through support after signing in.