Privacy at a glance
We collect information needed to operate merchant accounts, payment orders, blockchain monitoring and security. Customer funds travel on public blockchains directly to configured receiving wallets; blockchain records are public and cannot be deleted by us.
1. Scope
This Privacy Policy applies to the public website, merchant and administrator portals, hosted checkout, APIs, plugins and monitoring components provided as part of the MochiPay Service.
A merchant determines what customer and order information it sends to the Service. Merchants remain responsible for their own privacy notices and legal basis for processing customer information.
2. Information We Process
Merchant and administrator information
Email address, display name, password hash, account status, subscription details, API credentials, login time, login result, IP address and locally resolved country, region or city information.
Order and customer information
Merchant order reference, system order ID, amount, currency, payment method, product type, optional description and product information, customer name, email, phone, company, optional shipping address, customer IP, callback URL and return URL.
Payment and blockchain information
Receiving address, payment amount, asset, network, transaction hash, confirmation count, payment status, timestamps and exchange-rate snapshot. Public blockchain information may be obtained from blockchain nodes or explorers.
Technical information
Request IP, user agent where available, API authentication result, error details, callback attempts, diagnostic logs and other information required to secure and troubleshoot the Service.
3. How We Use Information
- Create and maintain accounts and subscriptions.
- Create payment orders and show hosted checkout instructions.
- Match blockchain transfers, update status and send callbacks.
- Authenticate API calls and protect accounts against abuse.
- Display order history, payment details and local IP-location information to authorized users.
- Maintain, diagnose and improve reliability and security.
- Comply with applicable legal obligations and enforce service terms.
4. Wallet and Credential Data
When a merchant or administrator creates a wallet through the Service, the recovery phrase is displayed during creation and stored in encrypted form in the configured database. API secrets and other sensitive credentials are also protected using the application’s configured security mechanism.
Authorized account holders are responsible for securely recording recovery phrases and controlling access. Do not submit recovery phrases, private keys or API secrets through customer-facing fields, descriptions, callbacks or support messages.
5. Public Blockchain Records
Cryptocurrency addresses, transfers, amounts, token contracts and transaction hashes recorded on a public blockchain are visible to the public. Blockchain data is maintained by decentralized networks, not by us, and generally cannot be altered or erased.
6. When Information May Be Shared
Information may be processed by infrastructure, hosting, database, blockchain-node or network providers needed to operate the Service. It may also be disclosed when required by law, to protect users or the Service, to investigate abuse, or as part of a legitimate business reorganization.
IP location is resolved using the locally installed IP location database configured by the operator. The Service does not need to send each IP address to an external geolocation API for this feature.
We do not sell personal information or customer payment data.
7. Retention
Account, subscription, order, transaction, callback, login and security records are retained for as long as reasonably needed to provide the Service, maintain business and audit records, resolve disputes, protect security and meet legal obligations. Retention periods may differ by record type and applicable law.
Public blockchain data remains subject to the operation of the relevant blockchain even after related application records are removed.
8. Security
We use access controls, credential hashing, encryption for designated secrets, request signing and operational logging intended to protect information. No online service, software or storage system can guarantee absolute security.
You should use a strong unique password, protect API secrets, restrict server access, verify callback and payment data, back up recovery phrases offline and keep wallet software and plugins updated.
9. Access, Correction and Other Choices
Merchants can review or update available profile information through the merchant portal. Depending on applicable law, a person may request access, correction or deletion of eligible personal information. Some records may need to be retained for security, transaction integrity, legal obligations or dispute resolution.
Requests should identify the relevant account or merchant and may require verification. Questions may be submitted through the official contact method published at https://mochi.bz.
10. Children
The Service is intended for merchants and developers able to enter into binding agreements. It is not directed to children, and merchants should not intentionally submit children’s personal information unless they have a lawful basis to do so.
11. Policy Updates
We may update this policy to reflect changes in the Service, security practices or legal requirements. The effective date at the top of the page will be revised when a new version is published.