1. Introduction & Overview
Welcome to Status402. We respect your privacy and are committed to protecting your personal data. This policy explains how we handle your information when you use the status402.io website, our developer dashboard, and the Status402 payment layer for x402 micropayments. It also describes how we handle data relating to resources you monetise, wallets you connect, and third-party services you choose to integrate.
2. Information We Collect
We collect information to operate the service, settle payments and maintain security:
- Identity & Contact Data: Your name, email address, company details and billing address.
- Technical & Usage Data: IP address, browser type, device identifiers, API keys used, and how you interact with our website and dashboard.
- Transaction Data: Records of x402 requests, amounts, currency (such as USDC), timestamps, resource identifiers, settlement status and on-chain transaction references. Public blockchain records are, by design, permanent and outside our control.
- Connected-Account & Wallet Data: When you connect a wallet, MCP server, API endpoint or third-party account, we receive only the identifiers and scopes you authorise. We request the minimum access needed for the feature you use.
- Cookies: We use essential cookies to run the site and functional cookies to remember your preferences. You can manage these via your browser settings.
3. How We Use Your Data
Status402 uses your information to:
- Provide, route and settle the payments you request.
- Manage your account, registration and authentication.
- Detect fraud, abuse and unauthorised use of paid resources.
- Communicate service updates, security alerts and notifications.
- Fulfil legal, accounting and anti-money-laundering obligations.
- Analyse aggregated trends to improve reliability and pricing.
Data obtained from connected accounts, wallets or resources is used only to deliver or improve the specific features you authorised. We do not use it for advertising, ad personalisation, retargeting, resale, or to train generalised AI/ML models.
4. Data Sharing & Disclosure
We do not sell your data. We only share information with:
- Service Providers: Vetted sub-processors strictly necessary to operate the platform — including hosting, settlement facilitators and analytics — under contractual confidentiality and data-protection terms.
- Resource Providers: When you pay for a resource, we share the minimum information needed for that provider to grant access and reconcile settlement.
- Business Transfers: In the event of a merger, sale or acquisition, with continuity of this policy.
- Legal Compliance: When required by law or regulation, or to protect rights, safety and security.
We do not sell, rent or transfer your data to data brokers, advertising networks or AI-training providers.
5. Limited Use of Connected-Account Data
Our use and transfer of information received from any connected third-party API adheres to that provider's user-data policy, including its Limited Use requirements. Specifically:
- We only use connected-account data to provide or improve the user-facing features you explicitly authorised.
- We do not transfer this data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice.
- We do not use this data to serve advertisements of any kind.
- Humans do not read this data, except with your affirmative consent, when necessary for security purposes such as investigating abuse, to comply with law, or for internal operations on aggregated and anonymised data.
6. Your Rights (UK & EU GDPR)
If you are located in the UK or EU, you have specific rights regarding your data:
- Access & Correction: Request a copy of your data or update inaccurate information.
- Erasure: Request that we delete your personal data, subject to legal retention duties.
- Portability: Move your data to another service.
- Object or Restrict: Limit how we process your information.
- Revoke Connections: Disconnect any wallet, API key or third-party account at any time from your dashboard or directly with the provider.
To exercise any of these rights, contact us at privacy@status402.io.
7. Security
We apply industry-standard safeguards to protect your information. Data is transmitted over TLS, stored encrypted at rest, access-controlled through least-privilege identity management, and audit-logged. Payment credentials and signing material are isolated and never exposed to resource providers. While no online platform is 100% secure, we continuously review our controls and respond promptly to any incident.
8. Data Retention & Deletion
We keep your data only as long as needed to provide the service or meet legal obligations:
- Connected-account data is retained only while your connection is active and the feature requires it.
- Transaction and settlement records are retained for the period required by financial and tax law.
- When you disconnect an account or delete your Status402 account, we delete associated data within 30 days from active systems and within 90 days from backups, except where retention is legally required.
- You may request deletion at any time by emailing privacy@status402.io with the subject line "Data deletion request".
Settlement records written to a public blockchain cannot be deleted or altered by us.
9. Global Transfers
Your data may be processed outside your home country. We ensure that any international transfers are protected by adequate safeguards (such as Standard Contractual Clauses) and comply with UK and EU data protection laws.
10. Protecting Children
Status402 does not knowingly collect data from children under the age of 13. If we discover such data has been collected without parental consent, we will delete it immediately.
11. Contact Us
For questions regarding this policy or your privacy, reach out to us: