Privacy Policy

Last updated: 14 June 2021 Effective: 14 June 2021

This Privacy Policy explains how WCPAY (“we”, “us”, “our”) collects, uses, stores and protects information when you visit wcpay.us, purchase a licence, or install the WCPAY High-Risk Payment Gateway plugin on your WooCommerce store.

By using our website, plugin or services, you agree to the practices described below. If you do not agree, please stop using the services.

1. Who We Are

WCPAY provides a WooCommerce payment gateway plugin that lets merchants accept card payments and receive instant USDT payouts. We act as a data controller for information collected through our website and licence system, and as a data processor for transaction data passing through the plugin on behalf of the merchant.

For any privacy matter, contact us at support@wcpay.us.

2. Information We Collect

2.1 Information you give us

  • Account and licence data — name, e-mail address, and the domain on which the plugin is activated.
  • Purchase data — plan selected, order number, billing e-mail, and payment status.
  • Support data — messages, attachments and any details you send through our contact form or by e-mail.
  • Payout configuration — the USDT wallet address you enter in the plugin settings.

2.2 Information collected automatically

  • Technical data — IP address, browser type and version, operating system, and referring pages.
  • Usage data — pages visited, time spent, and links clicked on wcpay.us.
  • Licence checks — site URL, plugin version, and WordPress/WooCommerce versions, sent periodically to validate your licence.

2.3 Information we do not collect

We never store full card numbers, CVV codes, or cardholder authentication data. Card details entered at checkout are transmitted directly to our PCI-DSS compliant payment partners and are never written to our servers or databases. We also do not require KYC documents or identity papers from merchants.

3. How We Use Your Information

  • To deliver, activate and maintain your plugin licence.
  • To process purchases and issue receipts.
  • To route card payments to our processing partners and trigger USDT payouts to your wallet.
  • To answer support requests and troubleshoot technical issues.
  • To send service notices such as version updates, security advisories, and licence expiry reminders.
  • To detect fraud, abuse and unauthorised use of licences.
  • To comply with legal obligations and lawful requests from competent authorities.

4. Legal Basis for Processing

Where the GDPR applies, we rely on the following grounds:

  • Performance of a contract — to supply the plugin, licence and payment services you purchased.
  • Legitimate interests — to secure our systems, prevent fraud and improve our products.
  • Legal obligation — to keep accounting records and respond to lawful requests.
  • Consent — for optional marketing e-mails and non-essential cookies, withdrawable at any time.

5. Cookies

We use a small number of cookies:

  • Essential cookies — keep your session active, remember your cart, and secure form submissions. These cannot be disabled.
  • Analytics cookies — help us understand which pages are useful. These load only with your consent.

You can block or delete cookies through your browser settings. Disabling essential cookies may prevent checkout from working.

6. Sharing and Disclosure

We do not sell, rent or trade your personal data. We share information only with:

  • Payment processing partners — to authorise card transactions and settle payouts.
  • Hosting and infrastructure providers — who store data on our behalf under contract.
  • E-mail and support providers — to deliver messages and handle tickets.
  • Authorities — where disclosure is required by law, court order, or to protect our legal rights.

All processors are bound by confidentiality obligations and may use the data only to provide services to us.

7. International Transfers

Our infrastructure and partners may be located outside your country, including outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

8. Data Retention

  • Licence and account data — kept while your licence is active, plus 24 months.
  • Transaction and billing records — kept as long as required by applicable tax and accounting law, typically up to 10 years.
  • Support correspondence — kept for 24 months after the ticket is closed.
  • Server logs — kept for up to 12 months, then deleted or anonymised.

9. Security

We apply technical and organisational measures proportionate to the risk, including TLS encryption in transit, encrypted storage of sensitive fields, restricted internal access on a need-to-know basis, and regular patching of our systems. Card data is handled exclusively by PCI-DSS compliant partners.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you share information with us at your own risk.

10. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of your data, subject to our legal retention duties.
  • Object to or restrict certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting prior processing.
  • Lodge a complaint with your local data protection authority.

To exercise any right, write to support@wcpay.us. We respond within 30 days and may ask you to confirm your identity first.

11. Merchant Responsibilities

If you install the plugin on your store, you remain the data controller for your own customers. You are responsible for publishing your own privacy notice, obtaining any consent required in your jurisdiction, and handling your customers’ data protection requests.

12. Children

Our services are intended for business use and are not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Third-Party Links

Our site and documentation link to external services such as YouTube, GitHub and payment partners. We are not responsible for their privacy practices, and we encourage you to read their policies before sharing information.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our services, technology, or legal requirements. The revision date at the top of this page always shows the latest version. Material changes will be announced on this page and, where appropriate, by e-mail. Continued use of our services after an update means you accept the revised policy.

Contact Us

Questions about this policy, or about the data we hold on you?

We reply to every privacy request within 30 days.

support@wcpay.us