Your privacy matters to us. This Privacy Policy explains how Cygnus Pay ("the Platform", "we", "us", "our") collects, uses, stores, and protects your information when you use our services at cygnuspay.org, app.cygnuspay.org, api.cygnuspay.org, and docs.cygnuspay.org.
| Data | Purpose | Required |
|---|---|---|
| Username | Account identification | Yes |
| Email address | Account recovery, notifications | Yes |
| Password | Authentication (stored as bcrypt hash, never plaintext) | Yes |
| 2FA secret | Two-factor authentication (if enabled) | Optional |
| Payment link details | Title, description, amount, currency | When creating links |
| Withdrawal addresses | Processing on-chain withdrawals | When withdrawing |
| Data | Purpose | Retention |
|---|---|---|
| IP address | Login history, security, abuse prevention | 12 months |
| User agent | Device/browser identification for security | 12 months |
| Login timestamps | Security audit trail | Indefinite |
| Transaction records | Platform operation, user history | Indefinite |
When you use on-chain features, the following data is inherently public on the blockchain:
We do not control blockchain data. Once a transaction is broadcast to a blockchain network, it is publicly and permanently visible.
| Purpose | Legal Basis |
|---|---|
| Operating the Service | Performance of service |
| Processing transactions | Performance of service |
| Account security | Legitimate interest |
| Preventing fraud and abuse | Legitimate interest |
| Complying with legal obligations | Legal compliance |
| Sending service notifications | Performance of service |
| Platform improvement | Legitimate interest |
We do NOT use your information for targeted advertising, selling to third-party data brokers, marketing without consent, or profiling for non-security purposes.
| Measure | Implementation |
|---|---|
| Password hashing | bcrypt with automatic salting |
| 2FA | TOTP-based (time-based one-time passwords) |
| Session management | Secure server-side sessions |
| Backup encryption | Fernet symmetric encryption |
| Admin audit logs | All administrative actions logged |
| Access control | Role-based access (user, admin) |
In the event of a data breach that affects your personal information, we will investigate immediately, notify affected users within 72 hours, take steps to mitigate impact, and report to relevant authorities as required by law.
We do not sell, rent, or trade your personal information to third parties under any circumstances.
We may share your information only in limited circumstances: law enforcement requests (with valid legal process), legal compliance, fraud prevention, with your explicit consent, and your username is visible to transaction counterparties in payment links.
Depending on your jurisdiction, you may have the following rights: Access (request a copy of your data), Correction (update your information via Settings), Deletion (request account deletion — blockchain data cannot be deleted), Data Portability (export your transaction history), and Objection (object to data processing for specific purposes).
To exercise your rights, contact us via Discord or through the Settings page at app.cygnuspay.org.
We use only essential session cookies for maintaining your login session, CSRF protection, and remembering preferences. We do not use Google Analytics, Facebook Pixel, third-party advertising trackers, or cross-site tracking cookies.
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion + 30 days |
| Transaction records | Indefinite (legal/compliance) |
| Login history (IP, user agent) | 12 months |
| Encrypted backups | 30 days (auto-rotated) |
| Admin audit logs | Indefinite |
| Deleted account data | Purged within 30 days |
Cygnus Pay is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we discover that a child under 18 has created an account, we will promptly delete it.
Your data may be processed in jurisdictions different from your own. By using the Service, you consent to the transfer and processing of your data in these jurisdictions, subject to the protections described in this Policy.
The Platform interacts with third-party blockchain networks (Bitcoin, Ethereum, Polygon, etc.). Transactions are publicly visible on block explorers and wallet addresses are pseudonymous but potentially traceable. We cannot delete or modify blockchain data and are not responsible for the privacy practices of third-party blockchain networks.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date, communicated via the Platform if material changes are made, and effective immediately upon posting.
For privacy-related questions or requests:
© 2026 Cygnus Pay. All rights reserved.