Effective September 15, 2026
This summary is for convenience. The full policy below is what applies.
Q+Pay is operated by Q+Pay LLC ("Q+Pay", "we", "us"), 30 N Gould St Ste N, Sheridan, WY 82801, USA. For personal data we collect to run our own service, we are the controller. Contact details are at the end of this policy.
This policy covers useqpay.com, the Q+Pay dashboard, hosted checkout and receipt pages, the Q+Pay API, the Q+Pay Shopify app and the Q+Pay WordPress plugins (together, the "Service").
When you buy from a merchant, the merchant decides what to collect about you for their own business, and their own privacy policy applies to that. Where we handle data only to deliver a merchant's payment request, such as a shipping address the merchant asks for, we do so on the merchant's behalf.
Every payment is a public Qubic transaction. For each Q+Pay payment we store the paying wallet address, the receiving address, the amount and the transaction hash, and link them to the payment request. This information is public on the network and cannot be removed from it by anyone, including us.
When a merchant installs the Q+Pay Shopify app we store the shop address, installation details, the access credentials Shopify issues (encrypted), and, for each order paid with Qubic, the order number and identifiers needed to match the payment. We do not store Shopify customers' names, email addresses or postal addresses.
When a site uses a Q+Pay WordPress plugin, the site sends us what is needed to create a payment request: the price, currency, what is being paid for, the site name and the page to return to. For paywalls, it also sends a one-way hash that ties the payment to the visitor's browser; we cannot turn it back into anything that identifies the visitor. Cookies the plugins set on a merchant's site are controlled by that site.
| Purpose | Data used | Legal basis (EU/UK) |
|---|---|---|
| Creating payment requests, confirming payments, showing merchants their sales, and sending receipts and alerts | Account, payment, shipping, email and blockchain data | Performing our contract with you |
| Connecting your store or site through the Shopify app, WordPress plugins or API | Store, site and API key data | Performing our contract with you |
| Answering support requests | Support messages and reply email | Performing our contract; legitimate interests |
| Keeping the Service secure, preventing fraud and abuse | Logs, IP addresses, wallet and payment data | Legitimate interests |
| Understanding overall usage, such as total payment volume | Aggregated payment data | Legitimate interests |
| Meeting legal obligations and responding to lawful requests | Any relevant data | Legal obligation |
We do not use your data for advertising, and we do not make automated decisions that have legal or similarly significant effects on you.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
We use one cookie, and a few values stored in your browser, only to make the Service work. We do not use advertising or analytics cookies.
| Name | Type | Purpose |
|---|---|---|
x402_dashboard_session | Cookie (strictly necessary) | Keeps you signed in to the dashboard |
x402_dashboard_lang, x402_dashboard_currency, x402_dashboard_theme | Browser storage | Remember your language, currency and theme |
x402_wallet_login | Browser storage | Remembers that you use wallet sign-in |
x402_referred_by | Browser storage | Remembers a referral link you followed |
You can clear these at any time in your browser settings. If you clear the session cookie, you will need to sign in again.
Our servers are in Germany, in the European Union. Some of the services listed in section 5 operate in other countries, including the United States. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on safeguards such as the European Commission's Standard Contractual Clauses.
We protect data with encrypted connections (HTTPS), signed session cookies, one-way hashing of API keys, encryption of stored Shopify credentials, services that run with restricted permissions, and regular backups. No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict how we use it, and to withdraw consent. You can also complain to your local data protection authority.
We will respond within the time the law requires. We cannot delete information from the Qubic network, and we may keep records we are legally required to keep.
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
We may update this policy. We will post the new version here with a new effective date and, for material changes, tell merchants in the dashboard or by email before the change takes effect.
Q+Pay LLC
30 N Gould St Ste N, Sheridan, WY 82801, USA
Email: support@useqpay.com
Merchants can also reach us through the Support tab in the dashboard.