MochiPay Payment Assistant Privacy Policy
Effective date: 8 October 2026. This policy covers the MochiPay Chrome Payment Assistant extension, version 1.0.1.
The MochiPay website privacy policy also applies to merchant accounts and hosted payment services.
MochiPay website privacy policy
Single purpose
The extension helps an authenticated MochiPay merchant create payment requests, share payment links and QR codes, view recent orders and receive optional payment-status notifications.
Information used
A one-time connection code is sent over HTTPS to MochiPay to establish access. A revocable connection token is stored in the browser's local extension storage. It is not stored in Chrome sync. The extension never requests or stores your merchant API Secret, private keys or recovery phrase.
Amounts, currencies, payment methods and optional order notes you enter are sent to MochiPay to create the requested orders. Merchant display name and status, order identifiers, amounts, notes, payment links and payment states are returned to display your account and orders. MochiPay's server may retain standard access and security logs, including request IP addresses. Avoid putting unnecessary personal information in order notes.
Language preference, notification preference, recent order status and an unresolved creation request are stored locally to operate the interface, detect payment transitions and recover interrupted requests.
What the extension accesses
Network access is limited to https://mochi.bz. The extension does not read browsing history, web page contents, cookies, messages, contacts or clipboard contents. Copy link writes only the selected payment link to the clipboard when you click it. Opening the dashboard or a guide uses an ordinary website tab subject to the website's own practices.
Use, sharing and Limited Use
We use extension data only to provide and secure its stated merchant payment-assistance features. Extension data is not sold, used for advertising, used to build advertising profiles, or disclosed to data brokers. Service providers involved in operating MochiPay may process necessary information under appropriate access controls. Disclosures required by law or necessary to protect against abuse may also occur.
The use and transfer of information received by the MochiPay Payment Assistant adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Notifications
Notifications are off by default and require your permission. An enabled notification can show the received crypto amount and order reference on your desktop. Turn notifications off in the extension settings or your operating system. The extension performs periodic HTTPS status checks while connected, even when notifications are off. It does not use an external analytics or notification service.
Security, retention and removal
Connections are scoped to receiving-payment creation and reading. Pairing codes expire after 10 minutes; connections expire after 90 days and can be revoked in the merchant dashboard. Codes and tokens are stored as hashes on the server. A token grants access to payment requests: protect your browser profile.
Disconnecting clears the extension's local connection and order cache after revocation succeeds. Uninstalling removes local extension data; revoke the connection in your dashboard as well. These actions do not delete existing merchant orders or service records, which remain subject to MochiPay's service retention and account-deletion practices. Contact MochiPay to request deletion or ask about your data.
Contact and changes
For questions or deletion requests, use the contact options on the MochiPay community and contact page.
MochiPay community and contact page
Material changes to extension data practices will be disclosed through the extension, its listing or this policy before the affected use begins.