StesPay (hereinafter, the "Platform," "we," or "our") is committed to protecting the privacy and security of personal data. This Privacy Policy describes how we collect, use, share, and protect information through our API, website, and dashboard (SaaS).
By using our services, you (the "Merchant") agree to the practices described in this policy. Furthermore, the Merchant agrees to maintain its own privacy policy visible to its end users.
1. Information We Collect
A. Merchant Data (Your Customers)
When a business registers on our platform, we collect:
- Registration Information: Company name, legal representative's name, corporate email, phone number, and country of operation.
- Verification Data (KYC): To comply with anti-money laundering (AML) laws, Stripe Connect will securely request official identification, tax records, and the Merchant's bank account details. Note: The Platform does not store these sensitive documents; they are processed directly by Stripe.
- Technical Credentials: IP addresses, activity logs within the Dashboard, and generated API keys.
B. End-Buyer Data (Third-Party Customers)
When a consumer makes a purchase on a third-party website using our API, our infrastructure automatically processes:
- Transaction Information: Purchase amount, currency, date, time, and product/service description.
- Basic Contact Data: Email address provided for sending receipts.
- Payment Data: Credit or debit card information (number, CVC, expiration date). Important: This data is transmitted in encrypted form via Stripe Elements. Our Supabase database never stores or has access to full card numbers.
2. Use of Information
We use the collected information strictly for the following financial and operational purposes:
- To set up, operate, and maintain the Merchant's Stripe Connect account.
- To securely process international payments and calculate the per-transaction fee applicable to the Merchant's active plan (Starter 5.5% + $0.40 USD, Growth 4.5% + $0.40 USD, Professional 3.5% + $0.40 USD — all with a $0/month subscription).
- To validate API credentials and mitigate attempts at fraud, money laundering, or illicit activities.
- To send automated transactional notifications and critical alerts via email (e.g., transfer confirmations or declined card alerts).
- To generate monthly fee invoices and receipts in PDF format.
3. Data Transfer and Sharing with Third Parties
We do not sell or rent merchant or buyer data to third-party companies. We share information only with essential service providers under strict confidentiality agreements:
- Stripe Inc.: Primary processor managing the payment gateway, connected accounts, and international bank balances.
- Supabase / PostgreSQL: Provider of our cloud database infrastructure and secure execution of encrypted Edge Functions.
- Zoho Corporation: Email infrastructure provider used exclusively to dispatch system alerts from info@stespay.com.
4. Data Security
We implement bank-grade technical and administrative security measures to protect information:
- Encryption: All communication between third-party websites, our backend, and Stripe takes place via secure HTTPS/TLS protocols.
- Data Isolation (RLS): Our database uses Row-Level Security (RLS) policies, ensuring that no merchant can view another business's transactions, balances, or API keys.
- Tokenization: Credit card data is instantly tokenized on Stripe's servers, eliminating the risk of data leaks on our local servers.
5. User Rights (Access, Rectification, and Deletion)
Both Merchants and End Buyers have the right to access, correct, or request the deletion of their personal data from our records.
- The Merchant may modify their profile information and credentials directly from the Dashboard.
- To request the permanent deletion of an account or the erasure of a buyer's data history (provided that applicable financial laws regarding tax record retention allow it), a formal request must be sent to: info@stespay.com.
6. Modifications to this Policy
We reserve the right to update this Privacy Policy at any time to reflect regulatory changes or technical improvements to the API. The date of the last modification will be indicated at the beginning of the document. Continued use of the API following an update constitutes acceptance of the new terms.