Privacy Policy
Effective 22 September 2026. This policy covers the SkullPay website, merchant portal, API and platform-hosted checkout operated by Bones R&D.
Two kinds of people, two roles
Merchants create portal accounts and integrate SkullPay into their stores. For merchant account data we are the controller. Payers pay a merchant through a SkullPay checkout. For payer data we act as the merchant's processor; the merchant's own privacy notice governs why that data is collected. The technical model is documented in detail in our API documentation.
Merchant account data (we are the controller)
- What: email address, name, password hash, two-factor enrolment (TOTP secret encrypted at rest, passkey public keys), team memberships, sign-in events with a keyed hash of the IP address and the user agent, and the merchant workspaces you create.
- Why: to provide the portal, secure your account, notify you about security events and respond to support requests (performance of contract; legitimate interest in security).
- How long: for the life of your account; sign-in events for 12 months; deleted within 30 days of account closure except where retention is required by law.
Payer data (we are the merchant's processor)
- Invoice and payment records — amounts, merchant order reference, deposit address, transaction ids and counterparty addresses. These contain no direct identifiers and are retained as financial records.
- Email address (only if the payer opts in to status notifications, or the merchant supplies it) and, optionally, a name, IP address and user agent recorded as consent evidence. Stored only as AES-256-GCM ciphertext with HMAC blind indexes; never in logs, webhooks or the public checkout API. Purged after the merchant's retention period (90 days by default).
- Rights. Access, portability, erasure and “do not sell/share” requests are fulfilled through the merchant, who has one-click tools for each. Erasure crypto-shreds identifiers while keeping anonymised ledger records. If you contact us directly at privacy@skullpay.co we will route your request to the merchant and help ensure it is honoured.
What we do not do
- No advertising, tracking pixels, analytics scripts or third-party cookies on skullpay.co. The site has no JavaScript at all.
- No sale or sharing of personal data for cross-context behavioural advertising.
- No profiling or automated decisions with legal effect. The optional AML screening flags transactions for a human merchant decision.
Cookies
The portal sets one strictly necessary, HttpOnly session cookie. The hosted checkout and the website set none.
Sub-processors
- Cloudflare — hosting, storage, queues and operational logs (route patterns only; no bodies, tokens or emails).
- Resend — transactional email (account verification, security notices, payer status emails where enabled).
- Public blockchain data providers (mempool.space, blockstream.info, litecoinspace.org, public EVM RPCs, TronGrid, Solana RPC, TON Center) receive deposit addresses only. Merchants may substitute their own endpoints.
- CoinGecko — exchange rates; no personal data.
International transfers
Data is processed on Cloudflare's global network. Where data leaves the EEA/UK we rely on standard contractual clauses and the providers' own transfer safeguards.
Security
Field-level encryption for secrets and PII, hashed credentials, two-factor authentication with step-up for sensitive changes, tamper-evident audit ledgers, strict transport security and content-security policies. Report issues via our disclosure policy.
Your rights and contact
Depending on where you live you may have rights to access, correct, delete, restrict or port your data, to object to processing and to lodge a complaint with a supervisory authority. Merchants can exercise them from the portal's account page; anyone can write to privacy@skullpay.co. We will respond within 30 days.
Changes
We will post changes here and, for material changes, email merchant account holders in advance.