Privacy Policy
Last updated: September 8, 2026
CipherPay is a product of Atmosphere Labs. We build open-source payment infrastructure for Zcash (ZEC). Our service enables merchants to accept shielded Zcash payments through hosted checkout pages, APIs, and e-commerce integrations (Shopify, WooCommerce).
From merchants: Email address, API keys, and store configuration (e.g., Shopify domain, webhook URLs). This is the minimum required to operate the service.
From customers (buyers): Standard checkout does not request a buyer name, email, shipping address or phone number. The merchant's shop may collect these separately. Optional event registration asks for a name and email and sends them to the merchant's Luma event. Shopify order authorization may process a customer ID or checkout token. These are not included in payment invoices.
Payment data: We store invoice amounts, currency, payment addresses, transaction IDs, product descriptions and payment status. A merchant-provided incoming viewing key lets CipherPay read incoming amounts and memos for that account; it cannot spend funds. Use a dedicated commerce wallet account to limit visibility. Shielded payment details are hidden from public observers, but incoming amounts are visible to CipherPay and the recipient.
Website operation: We do not use advertising trackers. Essential cookies support language selection and authenticated sessions. Hosting and security providers process network metadata, including IP addresses, to deliver and protect the service.
Our Shopify app requests read_orders and write_orders permissions to create payment invoices and mark orders as paid. We read order amounts and product names to generate invoices. Shopify responses can contain customer information. Payment mappings retain the order ID, invoice ID, amount, currency and status.
Payment session data (order ID, amount, invoice reference) is stored for up to 30 days to support retries and reconciliation. Where durable fulfillment retries are enabled, failed jobs remain until resolved or the shop is deleted. The integration also stores operational access tokens, API keys and webhook secrets in its server-side data store. Uninstall requests remove shop credentials.
We do not sell personal data. Hosting providers and Upstash process service data on our behalf. Resend processes merchant recovery and billing emails when configured. Luma receives attendee details when a buyer chooses an integrated event registration. Shopify receives order payment updates. Merchants receive invoice webhooks.
Invoice data is processed through the Zcash blockchain, which is a public network. However, shielded transactions do not reveal sender, receiver, or amount information publicly.
Prepaid agent sessions expire after 24 hours; Shopify payment mappings expire within 30 days. Optional attendee details are removed after successful registration, after seven days for expired/refunded invoices, or after 30 days otherwise. Merchant invoice records remain while the account is active for payment reconciliation. Account deletion removes related operational records atomically. Minimal transaction-consumption records remain to prevent old deposits being spent again and contain no merchant identity or bearer token. Backups have a separate retention period.
All API communication uses TLS encryption. Webhook signatures are verified using HMAC-SHA256. Backend API keys are stored as hashes; incoming viewing keys and backend webhook secrets use application-level encryption. Integration services restrict access to their operational credentials. CipherPay does not require wallet seeds or spending keys.
You can request access to, correction of, or deletion of your data at any time by contacting us. Uninstalling the Shopify app removes its connection; deleting the CipherPay merchant account removes its invoice and account records, subject to the replay-prevention and backup retention described above.
For privacy questions or data requests: privacy@cipherpay.app