This Privacy Policy explains what information PayHub ("we", "us") collects when you use arcaud.com and the PayHub dashboard, and how it's used.
| Data | Why we collect it |
|---|---|
| Name, email, password (hashed) | Account creation and login |
| Receiving wallet addresses | Routing customer payments to you — these are public blockchain addresses, not sensitive by nature |
| API credentials (API key, private key) | Authenticating your integration. Your private key is stored encrypted at rest |
| Authorized IP addresses you configure | Optional IP allow-listing for your API key |
| Invoice and transaction metadata (amounts, reference IDs, timestamps, transaction hashes) | Operating the payment-detection and reconciliation features |
| Your customers' name/email, if you choose to submit them when creating an invoice | Displayed on the checkout page and included in webhook payloads sent back to you |
| IP address and browser user-agent of dashboard visits | Security, fraud prevention, session management |
We do not collect credit card numbers, bank account details, or wallet private keys belonging to your customers. PayHub never has access to your own wallet's private key — only the receiving address, which is public information on the blockchain by design.
We query public blockchain-explorer APIs (BscScan for BEP20, TronGrid for TRC20) using your configured wallet addresses to detect payments — these are public blockchain addresses, not personal data. We do not sell your data to third parties. If Binance Pay is enabled on your account in the future, transaction data necessary to process that payment method will be shared with Binance's Merchant API.
We retain account and transaction data for as long as your account is active, and for a reasonable period afterward for accounting, fraud-prevention, and legal-compliance purposes. Database backups are retained for 14 days on a rolling basis.
You can access or update most of your account information directly from the dashboard. To request a copy of your data, or to request deletion of your account (subject to our legitimate need to retain transaction records for compliance purposes), contact support@arcaud.com.
Passwords are hashed and never stored in plain text. API private keys are encrypted at rest. All traffic to the Service is encrypted in transit via HTTPS. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to the Service.
We may update this Privacy Policy from time to time. Material changes will be announced through the dashboard or by email.
Questions about this policy can be sent to support@arcaud.com.