Privacy policy
Effective date: not yet set · Emprise
Overview
Emprise is non-custodial and minimises the data it holds. This policy explains what we collect, why, and your choices. It applies to merchants using the service and to customers who open a hosted payment page.
What we collect
For merchants: account identifiers, API key hashes, webhook secrets, payout addresses, and session and order metadata you create. For payers: the minimal technical data needed to serve and secure the page, such as IP address, referring site, user agent and country, recorded as a page-open event.
On-chain data
Payment transactions are public on their respective blockchains. Emprise reads them to verify payments and records the transaction hash, payer address and amount for the relevant session. We do not control what blockchains publish.
How we use it
To create and verify payment sessions, deliver webhooks to you, secure and rate-limit the service, keep audit and event timelines, and prevent abuse and fraud.
Sharing
We do not sell personal data. We share data with your merchants as needed to operate the service, and with infrastructure providers (such as Cloudflare and RPC node operators) that process data on our behalf under their own terms.
Retention
We keep session, event and audit data for a bounded period consistent with security and legal needs, then delete or anonymise it. Timeline data captured from payers is never exposed publicly.
Security
See our security page. In brief: TLS in transit, encryption at rest, hashed API keys, least-privilege responses, parameterised queries, and secrets that are never logged.
Your rights
Depending on your jurisdiction, you may request access to, correction of, or deletion of your personal data. Contact us at the address below.
Changes
We may update this policy and will note the effective date below.
Questions about this document? Email hello@emprise.app.