Privacy Policy
Last updated: 24 August 2026
1. Who this covers
This policy covers Oxialink, the cryptocurrency payment gateway at oxialink.com, and is written for two different people: the merchant who holds an account with us, and the person paying one of that merchant's invoices. Almost all of it concerns the first, because we deliberately collect almost nothing about the second.
For merchant account data we are the controller. For data a merchant collects from their own customers and holds in their own store, the merchant is the controller and we are not involved.
2. What we collect
Account data: name, email address, an optional company name, a hashed password, and the two-factor secret if you enable it. Never an identity document, because we never ask for one.
Usage and security data: request logs including IP address, timestamps, endpoints and user agent, kept to enforce rate limits, investigate abuse and detect intrusion.
Payment data: invoice amounts, currencies, coins, deposit addresses, transaction hashes, webhook delivery logs, and the withdrawal addresses you nominate.
Optional integrations: if you connect the Telegram bot, your Telegram chat id, stored only to deliver the notifications you enabled and removed when you disconnect.
3. What we do not collect
We do not collect your customers' names, email addresses or postal addresses. A person paying an invoice interacts with the checkout page without identifying themselves; we see the paying wallet address and the transaction, both of which are already public on the blockchain.
We run no advertising trackers and no third-party analytics on the public site. We do not sell personal data, and we do not share it for anyone else's marketing.
4. Why we use it, and on what basis
To perform the contract with you: detecting payments, crediting balances, sending withdrawals, delivering the webhooks you configure, and emailing receipts, password resets and service notices.
For our legitimate interests: keeping the service secure and available, preventing abuse, and debugging. This is what request logs are for, and they are kept for no longer than that purpose needs.
To meet a legal obligation: retaining transaction records, and responding to a valid legal order.
We do not use your data for automated decision-making that produces a legal effect on you, and we do not profile you for marketing.
5. Blockchain data is public and permanent
This one deserves stating plainly, because it is the part people are most often surprised by. Every deposit address, withdrawal and transaction hash exists on a public blockchain. Anyone can read it, anyone can copy it, and nobody can delete it, including us.
Deleting your account removes your data from our systems. It does not and cannot remove anything from a blockchain. If you need on-chain activity not to be linkable to you, that decision has to be made before you transact, not after.
6. Who else sees it
We use a small number of processors to run the service, and none of them receive personal data beyond what their function requires:
- Hosting and infrastructure for the servers and database that run the platform.
- Blockchain node and indexer providers, queried with wallet addresses and transaction hashes, which is inherent to operating on public networks. No account data is attached.
- Exchange rate providers, queried with coin and currency codes only. No personal data at all.
- Email delivery for receipts, password resets and service notices, which necessarily receives your email address.
- Telegram, only if you connect the bot, and only to deliver notifications to you.
We will also disclose data where we are required to by a valid legal order, and will tell you when we do unless we are prohibited from telling you.
7. Where it is processed
Our servers and database are located in France, inside the European Union, so account and transaction data is stored under EU data protection law. Blockchain infrastructure and email delivery are provided by services that may process data outside your own country; where that involves a transfer from a jurisdiction that restricts it, we rely on the transfer mechanisms that jurisdiction provides.
8. Cookies and browser storage
The dashboard stores an authentication token in your browser's local storage so you stay signed in. That is a functional necessity, not tracking, and it never leaves your browser except as the credential on requests to us.
The public site sets no tracking cookies and no advertising cookies. There is nothing to consent to because there is nothing being collected.
9. How long we keep it
Account data: for as long as the account is open, and deleted on request once the balance is zero.
Transaction and invoice records: retained for accounting and audit purposes for the period the applicable law requires, which outlives the account. These are financial records and we cannot delete them on request.
Request and security logs: retained for a rolling period measured in months, not years, and then discarded.
Webhook delivery logs: retained so you can diagnose a failed delivery, then discarded.
10. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a use we base on legitimate interests. Most of this is available without asking: your dashboard shows your account data and your full transaction history, and you can edit or export it yourself.
Two honest limits. We cannot delete financial records we are required to keep, and we cannot delete anything from a blockchain. Everything else, we can.
Write to support@oxialink.com. We will respond within 30 days. If you are not satisfied with the response, you have the right to complain to the data protection authority where you live.
11. Children
The service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has registered, tell us and we will delete the account.
12. Security
Passwords are hashed. API secrets are stored hashed, so a stolen database does not hand over working credentials. Private keys live in an encrypted keystore that never enters the database. Webhooks are signed so you can verify they came from us. Two-factor authentication is available and worth enabling.
No system is perfect. If a breach affects your personal data and creates a real risk to you, we will tell you and the relevant authority without undue delay, and we will say what happened rather than what sounds best. Security reports are welcome at security@oxialink.com, or at support@oxialink.com with SECURITY in the subject line.
13. Changes and contact
Material changes to this policy will be announced on the site and by email before they take effect. Privacy questions, requests and complaints: support@oxialink.com.