BlockAck.comMerchant console
Sign inGet started

PRIVACY POLICY

Privacy at BlockAck

This policy describes how BlockAck processes information when merchants visit the site, create accounts, connect public wallet information, use APIs, and contact support.

Effective and last updated: September 24, 2026
ContactPrivacyTerms

Important: This document is a product-specific baseline, not legal advice. It cannot eliminate all legal risk. BlockAck should have qualified counsel review it for the operator’s legal entity, location, customers, and launch jurisdictions before accepting production users.

1. Scope and roles

This policy applies to BlockAck.com and the BlockAck merchant platform. For merchant account and service-operation data, BlockAck generally acts as a controller or business. For personal data a merchant submits about its customers through the API, the merchant determines the purpose and is responsible for providing notices, obtaining a lawful basis, honoring rights, and limiting collection. BlockAck processes that data to provide the service.

2. Information we collect

  • Account data: name, email address, verification state, authentication records, plan, and support communications.
  • Merchant configuration: store names, environment, callback URL, public wallet addresses or extended public keys, provider identifiers, and encrypted provider credentials. Never submit seed phrases or private keys.
  • Payment operations: invoice amounts and currencies, metadata supplied by merchants, public blockchain transaction identifiers, addresses, confirmations, payment state, callback delivery, and risk-review records.
  • API and security data: API-key identifiers and hashes, permissions, usage counters, request timing, hashed network identifiers used for rate limiting, errors, and audit/security events.
  • Device and analytics data: pages viewed, approximate location derived by service providers, browser/device details, referral information, and analytics identifiers. Google Analytics is currently loaded across the application and may use cookies or similar technologies.

3. How we use information

We use information to create and secure accounts; provide stores, invoices, monitoring, callbacks, billing, support, and risk indicators; meter usage; prevent abuse; diagnose reliability; communicate service changes; enforce agreements; comply with law; and improve product performance. We do not use merchant public keys to spend funds and do not sell personal information for money.

4. Legal bases

Depending on location, processing may rely on performance of a contract, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations. Merchants must establish their own lawful bases for customer data they submit.

5. How information is shared

Information may be shared with infrastructure and service providers needed to operate BlockAck, including Vercel, Supabase, Google Cloud, Google Analytics, email delivery providers, and BTCPay-related infrastructure; with professional advisers; in a corporate transaction; or when reasonably required by valid law, security, fraud prevention, or protection of rights. Public blockchain data is inherently public and may be copied by third parties beyond BlockAck’s control.

6. International transfers and retention

Providers may process data in countries other than yours. Where required, appropriate transfer mechanisms should be used. We retain information for as long as needed to provide and secure the service, satisfy legal/accounting obligations, resolve disputes, and enforce agreements. Account deletion may not immediately remove backups, security logs, public blockchain records, or records we must retain. Specific retention schedules must be finalized before production launch.

7. Security

We use access controls, scoped credentials, encryption for supported secrets, tenant isolation, and monitoring. No system is completely secure. Merchants are responsible for endpoint security, API-key handling, callback verification, wallet backups, private keys, and restricting submitted metadata.

8. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, portability, restriction, or objection, and may withdraw consent where processing depends on consent. You may also complain to a regulator. Contact support@blockack.com. We may verify identity and may deny or limit requests where permitted by law.

9. Cookies and analytics

Authentication and security features may use necessary cookies. Google Analytics is optional and loads only after you select “Accept analytics.” You may reject it without losing service access. Your choice is stored in your browser. Clearing site storage resets the choice. Google may process analytics identifiers and device, referral, page-view, and approximate-location information subject to its terms.

10. Children, changes, and contact

BlockAck is a business service not directed to children, and users must be legally able to contract. We may update this policy and will post the new date; material changes may require additional notice or consent. Questions and requests: support@blockack.com.

© 2026 BlockAck.com
ContactPrivacyTerms
Bitcoin-first, non-custodial paymentsNon-custodial by design
Optional analytics

We use Google Analytics only with your permission to understand site usage. Necessary authentication and security storage are unaffected.

Privacy Policy