Privacy Policy

Last updated: 13 August 2026

GenesisPay is a non-custodial payment service operated by Genesis Technologies FlexCo in Vienna, Austria (“GenesisPay”, “we”, “us”). This policy explains what personal data we process when you use genesispay.finance, our checkout and payment pages, our dashboard, our APIs and SDKs, and what rights you have. We are the controller for the processing described here unless stated otherwise. You can reach us at dev@genesis.co.at.

Two things make GenesisPay different from a conventional payment processor, and both matter for your privacy. First, we are non-custodial: we never hold your funds and never control your private keys — payments move directly from payer to seller. Second, payments settle on the Base blockchain, a public network. Data recorded on a public blockchain is replicated worldwide and cannot be altered or deleted by us or anyone else. Section 4 explains exactly what ends up there.

1. Who this policy covers

  • Sellers — businesses and individuals who create an account to accept payments.
  • Payers — people who pay a GenesisPay payment link, subscription or invoice, with or without an account.
  • Agent operators — people who fund a GenesisPay account and let an AI agent pay from it under limits they set.
  • Visitors — anyone browsing our website or documentation.

2. What we collect

Account and sign-in data

When you create an account, we store your email address, an optional display name, and the identifiers of the sign-in methods you use. Authentication is handled by our provider Privy (Privy, Inc., USA): depending on the method you choose, Privy processes your email address, a social-login identifier, or a wallet address, and may create an embedded wallet for you. Privy’s own privacy policy applies to the data it processes as our processor.

Business and verification data (sellers)

Sellers who want to accept live payments provide a business profile — business name, address, country, and tax ID — and go through business verification (KYB). A KYB submission can include documents you upload and free-text notes. We store the review outcome and the reviewer’s notes; on rejection, those notes are shown to you.

Payment data

When a payment is prepared or made we process the payment link and product involved, the amount, currency and stablecoin, the payer’s and seller’s wallet addresses, the transaction hash, timestamps, and the network (chain) used. For invoices and receipts we process the recipient name and email address the seller provides. Where a seller enters a buyer’s personal data (for example on an invoice), the seller is responsible for having the right to use it; we process it to provide the service.

Agent data

For agent accounts we store the account’s funding wallet address, spending policies (limits and allowlists), API keys in hashed form, and a full record of agent payments and approval decisions. This audit trail is a core safety feature of the product and is visible to the account owner.

Technical data

Our servers keep structured logs containing non-secret identifiers — such as link IDs, attempt IDs, chain IDs and transaction hashes — plus IP addresses and user-agent strings in standard infrastructure logs. For regulatory reasons, our edge infrastructure derives an approximate country from your IP address to decide which top-up options may be offered to you (for example, top-ups are not offered in the United Kingdom).

We run no advertising or analytics trackers of our own — there is no tracking pixel, no ad network and no product-analytics vendor on this site. Wallet software brings its own, however: if you connect an external wallet, that wallet’s SDK (for example MetaMask or WalletConnect) contacts its vendor’s own endpoints, including telemetry, under that vendor’s privacy policy. That happens only on the pages where you actually connect or pay.

Cookies

We use one first-party cookie, genesispay_session, a signed session cookie that keeps you logged in. It is strictly necessary for the service and is not used for tracking. Privy sets its own strictly necessary storage to keep your sign-in session. Because we use no optional cookies, we do not show a cookie banner.

3. Why we process it (legal bases)

  • To provide the service — creating accounts, executing payments, issuing receipts and invoices, enforcing agent spending policies, paying out sellers (Art. 6(1)(b) GDPR — performance of a contract).
  • To meet legal obligations — business verification, tax and bookkeeping retention, responding to lawful requests (Art. 6(1)(c) GDPR).
  • Legitimate interests — securing the platform, preventing fraud and abuse, keeping operational logs, defending legal claims (Art. 6(1)(f) GDPR). You may object to processing based on legitimate interests (see Section 8).

4. Blockchain data — public and permanent

When a payment settles, the payer’s wallet address, the seller’s receiving address, the token, the amount and the transaction hash are recorded on the Base blockchain. That record is public, replicated across the network, and cannot be modified or erased — by us, by you, or by anyone. A wallet address is pseudonymous, but it can become personal data if it is linked to you elsewhere. Do not pay from a wallet whose transaction history you are not comfortable being public. Rights that depend on changing or deleting data (rectification, erasure) cannot be exercised against a public blockchain; they remain fully available for the data we hold in our own systems.

5. Who receives your data

We share personal data only with:

  • Processors that run the service — Privy (authentication and embedded wallets), Resend (transactional email such as receipts and invoices), Railway (application hosting and the database), and Cloudflare (private object storage for the verification documents sellers upload). Each is bound by a data-processing agreement.
  • Top-up and wallet providers you choose — if you top up a balance or connect a wallet, the provider you select (for example Transak, MoonPay, Coinbase Wallet, MetaMask, or a WalletConnect-compatible wallet) processes your data under its own terms and privacy policy as an independent controller. We tell you which provider you are being handed to before you use it.
  • The other party to your payment — a seller sees the payment details of their payers (amount, wallet address, transaction hash, and any details the payer provides); a payer sees the seller’s business details on the checkout, receipt and invoice.
  • Blockchain infrastructure — RPC endpoints used to read from and broadcast to the Base network necessarily see transaction payloads and the IP address of the request.
  • Authorities — where we are legally required to disclose data.

We do not sell personal data and we do not share it for advertising.

6. International transfers

Some of our processors are located in the United States. Where personal data leaves the EEA, we rely on the European Commission’s Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework. Data written to a public blockchain is, by its nature, replicated globally (see Section 4).

7. How long we keep it

  • Account data — for the life of your account and up to 30 days after deletion, unless a longer period applies below.
  • Payment, invoice and fee records — 7 years after the end of the relevant business year, as required by Austrian tax and commercial law (§ 132 BAO, § 212 UGB).
  • Verification (KYB) records — for as long as required by the regulations that oblige us to collect them.
  • Server logs — short rotation periods appropriate to security and debugging, after which they are deleted.
  • On-chain records — permanent; we cannot remove them.

8. Your rights

Under the GDPR you can ask us for access to your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), a portable copy (Art. 20), and you can object to processing based on legitimate interests (Art. 21). Write to dev@genesis.co.at; we answer within one month. We do not use automated decision-making that produces legal effects about you — agent spending limits are rules you configure yourself, and over-limit payments are decided by a human.

You also have the right to lodge a complaint with a supervisory authority. Our supervisory authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

9. Security

The strongest protection is structural: we never hold your funds and never store the private keys of a payer’s self-managed wallet, so there is no pool of customer money or keys to breach. Beyond that, traffic is encrypted in transit (TLS), API keys are stored only as hashes, session cookies are signed, agent spending limits are enforced server-side, and access to production systems is restricted. No system is perfectly secure; if a breach affects your data, we will notify you and the authority as the GDPR requires.

10. Children

GenesisPay is not directed at children. You must be at least 18 years old (or the age of majority where you live) to use the service.

11. Changes to this policy

When we change this policy we will update the date at the top, and for material changes we will notify account holders by email or in the dashboard before the change takes effect.

12. Contact

Genesis Technologies FlexCo
Gerhard-Bronner-Straße 1/109, 1100 Vienna, Austria
dev@genesis.co.at