aproxpay.

Privacy Policy

Revision 1.2 — effective July 16, 2026

This Privacy Policy describes how AproxPay ("we", "us", "our") collects, uses, and retains data when you use the AproxPay proxy service, including the API at proxy.aproxpay.com, the CONNECT gateway at gw.aproxpay.com, the published MCP server and client wrappers, and any optional account dashboard (the "Service"). AproxPay is the controller for the processing described here unless a separate agreement states otherwise.

This policy is incorporated into the Terms of Service. Related documents: Acceptable Use Policy, Refund Policy.

1. Privacy by Design: What We Deliberately Do NOT Collect

The core proxy API requires no registration, no account, and no API key, and is engineered to be data-minimal. The optional dashboard uses an account and authentication cookies. In our own proxy application logs and primary service records, subject to the qualifications below:

  • we do not persist your client IP address in plain form in proxy application logs — where an IP-derived value is needed for rate limiting or abuse prevention, the current implementation uses a deterministic cryptographic hash. Network, CDN, authentication, and security providers may process connection IP addresses as described in Section 6;
  • full target URLs — for the destinations you access, we store only a cryptographic hash of the hostname, never the path, query parameters, or fragments;
  • request or response bodies — the content you send or receive through the proxy is never persisted;
  • authentication materialAuthorization, Cookie, and payment-signature headers are never written to logs;
  • we do not write wallet addresses in plain text to general request or abuse logs — abuse and funnel records use a stable cryptographic hash. Plain wallet addresses remain associated with billing records and active session state as described in Sections 2.2 and 2.3.

2. What We Do Collect

2.1. Request metadata

Depending on the request path and record type, we process technical metadata including timestamp, API method and route, response status, request duration, bytes transferred, upstream provider used, a hashed destination hostname, and a client-source attribution label (for example, a header set by our MCP server or an SDK wrapper). Some fields are held in structured application logs while usage and funnel records contain only the fields needed for billing, service analytics, or security.

2.2. Payment and billing records

When you pay via x402, we record: your paying wallet address, the amount, the on-chain transaction hash, the facilitator used, and settlement time. Note that blockchain transactions are public by nature — the same information is independently and permanently visible on the Base network regardless of our records.

2.3. Session records

For session passes we store the paying wallet association, session identifiers, byte caps and usage counters, expiry times, assigned upstream routing state, and a hash of the customer-facing ephemeral session password (never that password itself). Live session state is held in our cache for the duration needed to operate and enforce the session.

2.4. Abuse, security, and compliance events

When our safeguards trigger — blocklist hits, sanctions screening hits, rate anomalies, CSAM-related attempts — we record the event type, the action taken, the hashed wallet and/or hashed destination hostname, and a timestamp.

2.5. Funnel analytics

We record pseudonymized conversion events (e.g., "payment challenge issued", "payment settled") keyed by a stable hashed wallet where available, with a source label, to understand how the Service is used. These hashes remain personal data where they can be linked back to a wallet. No traffic content or destination data beyond the API route is included.

2.6. Dashboard (optional)

If you use the optional web dashboard, our authentication provider may process your wallet signature, email, authentication cookies or local-storage identifiers, device/browser metadata, and connection IP address for login and security. An email address is collected only if you choose an email-based dashboard flow or provide it for support or legal correspondence.

3. How We Use Data

We use the data above solely to:

  • deliver the Service (route requests, enforce byte caps and session TTLs, maintain sticky sessions);
  • bill and account for payments;
  • prevent and investigate abuse, fraud, and security incidents;
  • comply with legal obligations, including sanctions screening and reporting suspected unlawful activity where required or permitted by applicable law;
  • monitor service health and produce aggregate, non-identifying usage statistics.

We do not sell data, use it for advertising, or profile the content of your traffic.

4. Legal Bases (where UK GDPR, EU GDPR, or similar law applies)

  • Performance of a contract — payment, session, routing, and usage data needed to deliver the Service;
  • Legal obligation — records and disclosures required by applicable sanctions, tax, accounting, law-enforcement, or reporting law;
  • Legitimate interests — securing the Service, preventing abuse and fraud, enforcing our terms, maintaining service reliability, handling disputes, and understanding aggregate service usage. We minimise and pseudonymize data where reasonably possible when pursuing those interests.

5. Retention

We determine retention by reference to the purpose of each record, active-session duration, security needs, applicable limitation periods, and legal obligations:

  • live session and cache data is retained for as long as needed to provide and enforce the session, with limited operational records retained afterwards for billing, security, and dispute handling;
  • usage and funnel metadata is retained for service accounting, analytics, and fraud prevention, then deleted or anonymized under our retention schedule;
  • payment, refund, tax, and accounting records are retained for the periods required by applicable law;
  • abuse, sanctions, and legally reportable-event records are retained for the period necessary for security, legal claims, preservation duties, and any applicable statutory recordkeeping requirement;
  • a legal hold or active investigation may require longer retention.

Additional information about the retention criteria applicable to a category may be requested from legal@aproxpay.com. We will not rely on a general claim of indefinite retention where applicable data-protection law requires a defined necessity review.

6. Third Parties and Other Recipients

We disclose data only to service providers and other recipients necessary to operate, secure, and lawfully provide the Service. Depending on their role and contract, a recipient may act as our processor, our subprocessor, or an independent controller:

Category of recipientRoleData involved
Upstream proxy network providersExit connectivityThey process destination and connection metadata. Encrypted CONNECT payloads are generally opaque to the network; unencrypted HTTP traffic may be visible. They do not receive your account identity from us unless necessary for security, support, or legal compliance.
Payment facilitatorx402 payment verification and settlement, incl. built-in sanctions/KYT screeningWallet address, payment authorization, amount
Sanctions screening providersWallet screening against public sanctions data; IP geolocation for sanctions complianceWallet address; client IP is geolocated in-process against a local database and is not transmitted at request time
Infrastructure and hosting providers (database, cache, CDN/DNS)Storing and serving the records described in Section 2Hashed and plain identifiers where operationally necessary, session state, billing records, and edge connection metadata
Error tracking providerService reliabilitySanitized error reports (no bodies, no plain IPs/wallets)
Authentication provider (dashboard only)Login for the optional web dashboardWallet signature or email, if you use the dashboard

A current list of material service providers and other recipients is available upon written request to legal@aproxpay.com. We may update individual providers within these categories, subject to applicable contractual notice obligations and data-protection law.

We do not control the independent practices of blockchain networks: on-chain payment data is public and outside any party's deletion control.

7. Your Traffic Content

The proxy necessarily processes your traffic to reach its destination. In CONNECT sessions, end-to-end TLS payloads are passed through as an opaque byte stream, although destination and connection metadata remain visible; unencrypted HTTP content is visible in transit. In the fetch-style API, AproxPay terminates the incoming API request, initiates the target request, and may buffer response content transiently to enforce byte caps and produce the response. We do not persist request or response bodies. Destination hostnames are checked for blocklist and compliance purposes and stored only in hashed form in our primary service records.

8. Automated Controls and Review

We use automated rate limits, blocklists, anomaly detection, byte-cap enforcement, and sanctions-related checks. These controls may reject a request, terminate a session, throttle traffic, or suspend a wallet. They use technical signals such as hashed identifiers, requested destinations, traffic rates, payment data, and geolocation results. They are designed to protect the Service and comply with law but can produce false positives.

To request human review of a suspension or sanctions/blocklist decision, contact legal@aproxpay.com with the transaction hash or proof of control of the relevant wallet. We may be unable to disclose security-sensitive detection logic or information restricted by law.

9. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port personal data, and to object to processing. Because the Service is pseudonymous (keyed to wallet addresses and hashes), exercising these rights may require you to prove control of the relevant wallet (e.g., by signing a message).

Note the limits inherent to the design:

  • on-chain records cannot be deleted by anyone, including us;
  • records subject to a legal preservation duty (which may include particular sanctions, abuse-reporting, and financial records) may be exempt from deletion for the required period.

To exercise your rights, contact legal@aproxpay.com. We may request proof of wallet control or other proportionate verification. If United Kingdom data-protection law applies, you may complain to the UK Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/.

10. Security

We use technical and organisational measures intended to protect data, including TLS for public Service endpoints, restricted administrative access, separation of secrets from source code, and hashing of customer-facing ephemeral session passwords. No security measure is absolute, and network and service providers may process connection metadata needed to deliver their services.

11. Children

The Service is not directed at children and may not be used by anyone under 18.

12. International Transfers

Our primary service database is hosted in the United Kingdom. Other recipients described in Section 6 may process data in the United Kingdom, United States, European Economic Area, or other jurisdictions. Where UK or EU data-protection law requires a transfer mechanism, we use or will require an applicable adequacy regulation/decision, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, or another lawful safeguard. Information about the mechanism applicable to a material recipient is available on request.

13. Changes to This Policy

We may update this policy from time to time. Each revision is identified by the Revision number and Effective date at the top of this document; material changes are noted in the changelog below. Continued use of the Service after the effective date constitutes acceptance.

14. Contact

Document changelog

RevisionDateChanges
1.22026-07-16Simplified the draft controller identity to AproxPay.
1.12026-07-16Set UK controller context; removed unsupported fixed retention periods; corrected hashing, pseudonymization, session-state, dashboard, traffic-processing, recipient-role, transfer, security, and automated-control disclosures.
1.02026-07-16Initial version.