PRIVACY POLICY

PRIVACY POLICY

READ THIS DOCUMENT CAREFULLY. BY ACCESSING THE RECV SOFTWARE, DASHBOARD, API, OR PUBLIC CHECKOUT PAGES, YOU EXPLICITLY CONSENT TO THE DATA PRACTICES DESCRIBED HEREIN. IF YOU DO NOT AGREE, YOU MUST IMMEDIATELY CEASE ALL USE OF THE SERVICE.

Last Updated: June 14, 2026Effective Date: June 14, 2026

Service Provider and Data Controller

The Service is operated by the operators of the website recv.money (“recv”, “Company”, “we”, “us”). Notices and requests may be submitted to the following contact channels:

01

1. PREAMBLE AND SCOPE

This Privacy Policy (the "Policy") governs how recv ("Company", "we", "us", "our") collects, processes, utilizes, and safeguards information when you ("Merchant", "User", "you") or your end-users ("Customers") interact with our software-as-a-service infrastructure, Telegram bots, API endpoints, and public checkout interfaces (collectively, the "Service").

This Policy is designed to comply with global data protection principles while explicitly acknowledging the inherently public, immutable, and decentralized nature of cryptographic blockchain technology.

02

2. THE FUNDAMENTAL REALITY OF BLOCKCHAIN DATA (CRITICAL NOTICE)

2.1. Public Ledgers: You and your Customers expressly acknowledge that blockchain networks (including but not limited to TON, TRON, Solana, Base, Arbitrum, and BSC) are decentralized, public ledgers.

2.2. No Expectation of Privacy On-Chain: Wallet addresses, transaction hashes (TXIDs), timestamps, transfer amounts, and on-chain memos/comments are permanently recorded and accessible to anyone globally. The Company does not control these networks and cannot erase, obfuscate, or alter on-chain data.

2.3. Data Erasure: Data recorded on a public blockchain cannot be altered or deleted by recv. This limitation applies only to the blockchain record itself. Requests to access, correct, restrict or erase personal data stored in recv-controlled systems remain applicable subject to lawful exceptions, including security, fraud prevention, accounting, dispute and legal-retention requirements.

03

3. CATEGORIES OF DATA WE COLLECT

To operate the "Direct-to-Wallet" routing and notification architecture, we strictly minimize data collection to the following categories:

3.1. Merchant Account Data: When a Merchant authenticates via the Telegram Mini App or Bot, we automatically collect and store Telegram User ID, Telegram Username, and Email address (if voluntarily provided or required for specific billing tiers).

3.2. Operational Infrastructure Data: To facilitate the Service, the Merchant must configure public blockchain destination wallet addresses, preferred default networks, webhook URL endpoints, and associated cryptographic secrets.

3.3. Customer and Transactional Metadata: When a Customer accesses a publicly generated checkout URL, we process invoice metadata (Title, Base Amount, Expiration Time), ephemeral HTTP request data (IP addresses, User-Agent strings), and captured on-chain events via our watchers (TX Hash, Amount, Destination, Observed Timestamp).

NOTE: We do NOT collect Customer names, Customer emails, Customer physical addresses, or any traditional KYC/AML documentation.

04

4. STRICT LIABILITY FOR INVOICE METADATA

4.1. Merchant Data Input: The Service allows Merchants to assign custom "Titles" to invoices. The Merchant agrees NOT to input Personally Identifiable Information (PII) belonging to their Customers into the invoice title, payment comment, or webhook payloads.

4.2. Public Checkout Exposure: Merchant acknowledges that the checkout URL is accessible to anyone holding the link. The public invoice ID, invoice title, payable amount, and destination address are visible on this page. The Company is not liable for PII exposed due to the Merchant's failure to anonymize invoice metadata.

05

5. COOKIES, LOCAL STORAGE AND ANALYTICS

We use strictly necessary storage to maintain authentication, security, language and interface preferences. This includes access tokens stored in localStorage and refresh tokens stored in Secure, HttpOnly cookies.

We also use a first-party attribution cookie named “recv_attr”. It may contain an attribution identifier, campaign parameters, referral code, landing page and referring website. Its maximum lifetime is 90 days.

Where enabled, Google Tag Manager and Yandex Metrica may receive device, browser, page-view, interaction, network and approximate location information under their respective privacy terms. These technologies are not activated for users who require prior consent until the user has provided that consent.

We collect aggregated website performance measurements, including page path, locale, navigation type, LCP, INP and CLS values.

Users may withdraw optional analytics consent at any time through our Cookie Settings. Withdrawal does not affect strictly necessary storage.

06

6. ROLES AND LEGAL BASES FOR PROCESSING

We process account, authentication, workspace, invoice, wallet, API, webhook and subscription data to perform our contract with the Merchant.

We process security logs, session information, IP addresses, user-agent data, audit events, fraud indicators and service diagnostics based on our legitimate interests in securing, maintaining and improving the Service.

We process billing and transaction records to perform the contract and comply with applicable accounting, tax, sanctions and legal obligations.

We process optional analytics and advertising attribution data based on consent where consent is required by law, and otherwise as permitted by applicable law.

For invoice and checkout data submitted by a Merchant concerning its Customers, the Merchant generally determines the purpose of processing and acts as Controller. recv acts as Processor to the extent it processes that data on the Merchant’s instructions. recv acts as an independent Controller for security, abuse prevention, service billing and compliance records.

07

7. DATA RETENTION

We retain personal data in accordance with the following retention schedule:

• Account and workspace data: while the account is active and for up to 24 months after closure.

• Authentication codes: until used or expired, followed by deletion within 30 days.

• Active refresh sessions: until expiration or revocation; session security records may be retained for up to 12 months.

• Invoice, subscription and blockchain reconciliation records: for up to 7 years where required for accounting, tax, dispute or fraud-prevention purposes.

• Webhook delivery and API request logs: up to 12 months.

• Product analytics, UTM attribution and Web Vitals: up to 24 months.

• Backups: until overwritten under the backup rotation schedule, ordinarily within 30 days.

We may retain specific records longer where necessary to establish, exercise or defend legal claims or comply with law.

08

8. SECURITY

API key values are stored using one-way hashes after initial issuance. Access and refresh tokens are cryptographically signed or stored as token hashes, as applicable. Webhook signing secrets must remain available to the Service to sign deliveries and are therefore stored as confidential credentials protected by access controls. No method of storage or transmission is completely secure.

09

9. YOUR PRIVACY RIGHTS

Depending on applicable law, you may request access to, correction of, deletion of, restriction of, objection to, or portability of personal data processed by recv. You may also withdraw consent where processing is based on consent and lodge a complaint with a competent supervisory authority.

Submit requests to [email protected]. We may verify your identity and authority before acting on a request. We will respond within the period required by applicable law.

For California Residents (CCPA/CPRA): In the preceding 12 months, we have collected the categories of personal data described in Section 3 of this Policy. We do not 'sell' or 'share' (for cross-context behavioral advertising) personal data. Residents of California have the right to know, delete, correct, opt out of sale/sharing, limit the use of sensitive personal data, and be free from discrimination for exercising these rights. To submit a request, contact [email protected].

10

10. MODIFICATIONS TO THIS POLICY

We reserve the right to unilaterally update this Privacy Policy at any time. Your continued use of the Service following the posting of an updated Policy constitutes your acceptance of the changes.

This Privacy Policy was drafted to ensure alignment with global standards.