Last Updated: July 2, 2026

Introduction

At BillMyAgent, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Information We Collect

Personal Information

We collect information that you provide directly to us, including:

  • Name, email address, and contact information
  • Account credentials and authentication information
  • Payment and transaction information
  • Organization details and business information

Automatically Collected Information

We automatically collect certain information when you use our services:

  • IP address and device information
  • Usage data and API request logs
  • Cookies and similar tracking technologies
  • Error logs and diagnostic information

Payment Link Buyers (Hosted Checkout)

When a buyer opens a merchant's payment link and completes a payment on the hosted checkout, we collect a limited set of information to record and secure the transaction:

  • The buyer's wallet address and the on-chain transaction hash
  • The payment amount and network (Base or Polygon; Base Sepolia for testing)
  • IP address and user-agent, used for anti-abuse and fraud prevention

This data is retained for as long as needed to record the settled payment and to comply with legal and audit obligations. Anti-abuse signals such as IP address and user-agent follow the same log-retention limits described in the Data Retention section below. Wallet addresses and transaction hashes recorded on public blockchains are permanent and publicly visible; BillMyAgent cannot alter or delete on-chain data.

For payment links, the merchant — not BillMyAgent — is the seller and merchant of record for the underlying transaction. Payments settle directly wallet-to-wallet; BillMyAgent does not take custody of funds and is not a party to the sale.

For transaction records associated with a merchant's payment links, we act as a service provider (processor) on the merchant's behalf. Where we process information for our own anti-abuse and fraud-prevention purposes (for example, IP address and user-agent), we act as an independent controller, since we process it to protect our own platform. The distinction follows the purpose of the processing, so the same information may be handled in both roles.

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and manage your account
  • Authenticate API requests and prevent fraud
  • Send you service-related communications
  • Comply with legal obligations and enforce our terms
  • Analyze usage patterns to improve our services

Legal Bases for Processing (GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases for the processing described above:

  • Contract performance: providing the service, managing your account, and recording payments
  • Legitimate interests: anti-abuse and fraud prevention, security logging, improving our services, and complying with legal requirements outside the EU/EEA and UK (such as United States record-keeping, tax, and sanctions obligations)
  • Legal obligation: where EU/EEA or UK law (or the law of a member state) requires us to retain records or respond to lawful requests
  • Consent: marketing communications and non-essential cookies (see our Cookie Policy), which you can withdraw at any time

Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS 1.3 with AES-GCM) and at rest on managed database volumes
  • Database backups independently encrypted with a separate key before they leave our infrastructure
  • API keys hashed with SHA-256; passwords hashed with bcrypt
  • Automated security scanning in CI (secret scanning, static analysis, dependency scanning) and code review
  • Access controls and authentication mechanisms
  • Comprehensive audit logging (402 responses, payment instructions, wallet interactions)
  • Controls aligned with SOC 2 and ISO 27001 (not yet independently certified — see our Compliance page); we handle no card data, so PCI DSS is out of scope by design

For more details, please see our Security page.

Data Sharing and Disclosure

We do not sell your personal information. We may share your information only:

  • With your explicit consent
  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • With service providers who assist in our operations (under strict confidentiality agreements)
  • In connection with a business transfer or merger

Your Rights

You have the right to:

  • Access and receive a copy of your personal information
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information
  • Object to or restrict processing of your information
  • Data portability (receive your data in a structured format)
  • Withdraw consent where processing is based on consent

To exercise these rights, please contact us.

Cookies and Tracking

We use cookies and similar technologies to enhance your experience, analyze usage, and assist with authentication. For detailed information about the types of cookies we use, how we use them, and how to manage your cookie preferences, please see our Cookie Policy.

You can control cookie preferences through our cookie management settings or through your browser settings.

Data Retention

We retain your personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Transaction data may be retained for longer periods as required by law or for audit purposes.

Security and activity logs (including IP address and device information) are retained for up to 180 days for abuse prevention and audit purposes, after which they are automatically deleted. Logs tied to your account are also removed when your account is deleted.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us.