Legal
Privacy
What we collect, why, how long we keep it, and who else ever sees it. The short version is that a merchant's business profile is the only substantial personal data in the system by design.
Not yet published. MolnPay is not live and is not processing anyone's data — there are no merchant accounts and no payments. The outline below reflects how the service is being built, not a policy currently in force.
What it will cover.
- What we collect from a merchant
- The business profile a human reviews before live access: legal name, country, website, what the business sells, expected volume, and one named contact. The architecture rule is minimal personal data, and this is the bulk of it.
- What we do not collect
- Your customers are not our users. A payer using a hosted checkout has no account with us, and the wallet service never asks for your end user's identity — you send us your own reference for them, and we never learn who that is.
- On-chain data is public, and permanent
- Addresses, amounts and transaction hashes are visible to anyone, forever, and are not ours to delete. This deserves saying plainly rather than burying: it is the one category of data no privacy policy can promise to erase.
- Sub-processors
- Every third party that touches data on our behalf — infrastructure, chain data providers, email — named individually rather than described as a category.
- Retention and deletion
- How long records are kept after an account closes, which records we are obliged to keep regardless, and how to ask for the rest.
- Your rights, and how to use them
- Access, correction, export and erasure, with a real route to a human rather than an address that is never read.