Privacy Policy
This Privacy Policy explains how KRYX Pay and the KRYX app ("KRYX", "we", "us", or "our") collect, use, share, retain, and protect personal data when customers and merchants use our website, mobile app, dashboard, payment request tools, QR payment flow, and related services.
1. Who We Are
KRYX is a payment request and merchant/customer payment experience. Customers can scan payment QR codes or open payment links, review merchant and amount details, and confirm payments. Merchants can create payment requests, receive payment confirmations, and view transaction activity.
Privacy contact: support@kryxpay.com. Security contact: security@kryxpay.com.
2. Data We Collect
Depending on how you use KRYX, we may collect:
- Account information, such as name, email address, phone number, password status, user role, merchant profile, and account settings.
- Merchant information, such as business name, business contact details, settlement-related metadata, and documents or information needed for onboarding, compliance, fraud prevention, or support.
- Payment request and transaction information, such as merchant, amount, currency, reference, invoice number, request status, payment status, timestamps, and limited card metadata returned by our payment processor, such as card type, bank, last four digits, expiry month/year, reusable authorization status, customer code, and authorization reference.
- Device and security information, such as device type, operating system, app version, IP address, user agent, session identifiers, login events, failed login events, fraud signals, and audit logs.
- Usage and diagnostics data, such as app interactions, crash reports, performance data, and service logs used to keep KRYX reliable and secure.
- Support communications, such as messages you send to us and related records needed to respond.
3. Payment Card Data
KRYX does not store full card numbers, CVV, PIN, OTP, or full PAN. Card entry and payment processing are handled by regulated payment providers such as Paystack. We may store safe payment metadata and encrypted reusable authorization references when needed to support saved-card or FastPay-style payments.
4. Biometrics
If you enable Face ID, Touch ID, fingerprint, or similar biometric confirmation, biometric checks are handled by your device. KRYX does not receive or store your biometric template. We only receive confirmation that the device authentication succeeded or failed.
5. How We Use Data
We use data to:
- Create and manage customer and merchant accounts.
- Create, open, process, cancel, and verify payment requests.
- Show customers the merchant name and amount before payment confirmation.
- Send merchants live payment status updates and transaction records.
- Authenticate users, manage sessions, rotate tokens, prevent unauthorized access, and protect accounts.
- Detect, prevent, and investigate fraud, abuse, security incidents, and technical issues.
- Provide support, respond to requests, and communicate service updates.
- Comply with legal, tax, accounting, payment, and regulatory obligations.
- Improve reliability, performance, and user experience.
6. Sharing Data
We may share data with:
- Payment processors, banks, card networks, and fraud-prevention providers where needed to process and verify payments.
- Hosting, database, analytics, monitoring, email, and support providers that help operate KRYX.
- Merchants and customers involved in a transaction, limited to information needed to identify and complete that transaction.
- Legal, regulatory, law-enforcement, tax, or compliance authorities when required or reasonably necessary.
- Professional advisers, auditors, or business partners under appropriate confidentiality obligations.
We do not sell personal data. We do not use personal data for third-party targeted advertising.
7. Retention and Deletion
We keep personal data only for as long as needed for the purposes described in this Policy, including account operation, payment records, fraud prevention, dispute handling, legal compliance, audit, tax, and accounting requirements.
You can request account deletion by visiting our account deletion page or by emailing support@kryxpay.com. Some records may be retained where required for legitimate legal, security, fraud-prevention, accounting, dispute, or regulatory reasons.
8. Security
We use administrative, technical, and organizational safeguards designed to protect personal data. These include HTTPS, secure token handling, access controls, audit logs, rate limiting, encryption for sensitive stored references, and secure payment processing through third-party payment providers. No system is perfectly secure, but we work to reduce risk and respond quickly to security issues.
9. International Processing
KRYX may use service providers or infrastructure located outside your country. Where data is transferred internationally, we take steps designed to protect it in line with applicable law.
10. Your Rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection to certain processing of your personal data. You may also withdraw consent where processing is based on consent. To make a request, email support@kryxpay.com.
11. Children
KRYX is not intended for children. Users must be legally able to use payment services in their jurisdiction. We do not knowingly collect personal data from children.
12. Changes
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users. The latest version will always be available on this page.
13. Contact
Questions or requests: support@kryxpay.com. Security reports: security@kryxpay.com.