Provided by the platform operator. Seek counsel for your jurisdiction — not a substitute for external legal advice.

Privacy Policy

1. Who we are and scope

This Privacy Policy describes how the platform operator of ArtCloud Crypto Pay (“Operator”, “we”) processes information in connection with the managed control plane, merchant cabinet, checkout, APIs, and related services at https://pay.braiora.com.

The Operator is ArtCloud (ООО «АртКлауд»). Full registration details and registered address will be published here when finalized. Privacy contact: admin@artcloud.by.

This notice is an operator product shell for merchants and site visitors. It is not a substitute for external counsel or a jurisdiction-specific DPA. When we process personal data on behalf of a Merchant regarding that Merchant’s buyers, roles (controller vs processor) must be confirmed with counsel for your market.

2. Categories of data

Account and merchant data: email, hashed credentials, merchant profile (slug, display name), plan/subscription status, invite/onboarding metadata, and legal-consent timestamps where collected.

Payment and ledger data: invoice identifiers and amounts, crypto asset type, payment/payout status, destinations you configure, platform fee lines, and related audit events.

Technical and security data: IP addresses, user-agent/device hints as logged, API usage, webhook URLs and delivery outcomes, and security/audit logs needed to operate and protect the service.

Blockchain data: deposit/payout addresses and transaction identifiers (txids). Once broadcast and confirmed on a public chain, such data is inherently public; the Operator does not control ledger visibility.

We do not intentionally collect special-category data. Do not submit sensitive personal data in invoice metadata unless necessary and lawful.

3. Purposes of processing

We process data to: provide and secure the SaaS (accounts, invoices, payouts, autopayout, webhooks); bill and collect SaaS/platform fees; detect abuse and investigate incidents; communicate about the service; improve reliability; and comply with law.

Where GDPR/UK GDPR or similar regimes apply, processing is typically based on contract performance, legitimate interests in securing and operating the service, and legal obligations. A formal legal-basis map for each market will be published when finalized with counsel.

4. Processors and sharing

We use infrastructure processors necessary to run the product, including VDS/hosting and databases for the control plane and payment engine, and Solana RPC (Alchemy on the pay host). Optional tools such as webhook.site may appear only in smoke/test environments—not as a production data destination for merchant traffic.

We do not sell personal data. We may disclose data to advisors or authorities when required by law, or to successors in a corporate transaction subject to appropriate safeguards.

Merchants’ own processors (their shops, CRM, webhook receivers) are outside the Operator’s control; review those parties’ policies separately.

5. Retention and deletion

Account, subscription, invoice, and payout ledger data are kept while the merchant account is active and for a reasonable period after closure for fraud prevention, dispute handling, security, and accounting—unless a shorter or longer period is required by law. A detailed retention schedule will be published when finalized with counsel.

Security and access logs are kept for a limited operational period appropriate to abuse detection. On-chain records remain on the public ledger indefinitely regardless of account closure.

Deletion or export requests may be sent to admin@artcloud.by. Some records may be retained where legally required or where anonymized/aggregated data no longer identifies you.

6. Security, transfers, and rights

We apply access controls, hashed credentials, and infrastructure hardening appropriate to a managed payment control plane. No method of transmission or storage is perfectly secure.

Servers and processors may be located in jurisdictions different from yours. Cross-border transfer mechanisms (for example SCCs or UK IDTA) will be documented with counsel when required for your market.

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object/restrict certain processing. Contact us at admin@artcloud.by. We may need to verify your identity. Complaints may also be lodged with a supervisory authority where applicable.

7. Children, changes, contact

The service is directed at businesses and adult operators. It is not intended for children. Do not create accounts for individuals under the age required by applicable law.

We may update this Privacy Policy by posting a revised version on the legal pages at https://pay.braiora.com. Material changes should be noticed in the cabinet or by email where practicable.

Contact: admin@artcloud.by. Related terms: Terms of Service on the same host. A jurisdiction-specific DPA for EU/UK merchants is pending external counsel and is not shipped in-product.

Seek independent counsel for your jurisdiction. This notice is not a substitute for external legal advice.

Terms of Service · Privacy Policy · Merchant dashboard