Back to Zynost Pay

Zynost Pay legal information

Privacy Policy

The information used to operate merchant accounts and payment checkout.

Last updated 7 September 2026

1. Scope and responsibility

This notice covers Zynost Pay merchant accounts, hosted checkout and support. Zynost is led by Muhammad Umar in Pakistan. Contact legal@zynost.com about our handling of account and service data. The merchant you pay separately determines how it handles purchase and fulfilment information.

The research application and UQX may have separate notices. A shared Zynost login does not mean every product uses all of the same data. Do not enter sensitive personal information into a checkout description unless it is genuinely necessary.

2. Information we handle

Account data includes email, account identifiers, authentication records, business name and information submitted for business-profile changes. Merchant configuration includes public payout keys or addresses, branding, API credentials and webhook endpoints. We also process order references, requested amounts, selected networks, payment status, transaction identifiers and billing records.

Technical records can include IP addresses, request times, browser information, error records and security events. Support messages contain information you send us. Optional notifications require a browser or device notification token and your permission. We do not require wallet private keys or seed phrases. If you accidentally disclose one you should treat it as compromised.

3. Purposes and legal grounds

We use the information to authenticate users, operate checkout, derive payment addresses, detect transfers, deliver webhooks, manage service fees, investigate errors and respond to support requests. We also use relevant records to prevent abuse and comply with applicable legal obligations.

Where data-protection law requires a legal basis we rely on providing the requested service, legitimate interests in security and reliable operations, applicable legal obligations or consent where required. Optional notifications can be disabled in the browser or device. We do not sell personal information.

4. Public blockchain information

Blockchain addresses, amounts and transaction histories can be public and linked across services. A public address can still relate to an identifiable person. An xpub can reveal a family of addresses. Avoid posting it publicly.

We can address eligible requests concerning records in our own systems. We cannot erase confirmed public blockchain records or force independent explorers to remove them. Using a different display name does not make blockchain activity anonymous.

5. Service providers and disclosures

Hosting and infrastructure providers help us run the service. The frontend uses Vercel and backend infrastructure uses Hetzner. Transactional email uses Resend. Optional push notifications use Firebase infrastructure. Blockchain RPC providers process the queries necessary for payment detection. Wallet-connection services process connection information when that option is used.

Merchants receive order and payment information needed to fulfil purchases. We may disclose relevant records to professional advisers or authorities where legally required. Providers and infrastructure may operate outside your country. Applicable data-transfer safeguards must be considered where required by law.

6. Storage and security

The application uses browser storage or session mechanisms to maintain login and preferences. Optional browser permissions are under your control. Clearing storage may sign you out. A notification token is used to deliver notifications rather than to access your wallet.

We use access controls and credential-protection measures. No system is guaranteed secure. A breach can expose metadata or compromise payment instructions even if merchant signing keys remain outside our system. Protect your email account and wallet and report suspected compromise promptly.

7. Retention and deletion

We retain account and order information as needed to provide the service and address billing, security, support and applicable legal requirements. Retention depends on the purpose and record type. Backups may retain a previous copy until their normal rotation. A deletion request may require identity verification and an explanation of records we must retain.

Contact legal@zynost.com to request deletion or information about retention for your account. Closing an account does not erase public blockchain activity or a merchant's independent purchase records.

8. Your choices and rights

Depending on applicable law you may request access, correction, deletion, restriction, portability or object to certain uses. Where processing relies on consent you can withdraw it without affecting earlier lawful processing. You may also have the right to complain to your local data-protection authority.

Send requests from the email associated with your account where possible. We may need proportionate information to verify identity. We do not require a wallet seed to process a request. We will address requests within applicable legal time limits. The service is not intended for children under 18.

9. Updates

We update this notice when practices change and show the revision date above. A privacy notice describes data handling rather than replacing consent when consent is legally required. Material changes will be communicated through an appropriate service channel.

Contact

Account or payment issue: support@zynost.com. Legal or privacy request: legal@zynost.com. Never send a seed phrase or private key.