Privacy Policy

Last updated: June 27, 2026

This Privacy Policy explains how pay-castle ("we," "us," or "our") handles information when you use pay-castle.com (the "Service"). We built the Service to need as little of your data as possible. By using the Service you agree to this Policy and our Terms of Service.

The short version: We do not collect your card number, government ID, or private keys — Coinbase handles payment and identity verification, not us. To start a purchase, your browser sends us the wallet address, asset, amount, and network you chose, and your network (IP) address, which we forward to Coinbase only to create your secure checkout session. We don't sell your data.

1. Who we are

pay-castle is the operator of the Service and the controller of the limited information described below. You can reach us at support@pay-castle.com.

2. Information we collect

Information you provide to start a purchase

  • Wallet address you paste or connect, and the asset, amount, and network you select. We need these to request your Coinbase checkout session and to build the checkout link.

Information collected automatically

  • Network (IP) address. Coinbase requires the real end-user IP to create an onramp session (for fraud and compliance), so our server reads your IP from the request and forwards it to Coinbase for that purpose.
  • Basic server logs. For security and reliability we may log operational metadata such as the time of a request, the selected network/asset, your IP, and an error code if something fails. We do not log secrets or full session tokens.

If you contact us

  • Our contact forms open your own email application and send your message directly to support@pay-castle.com; we receive whatever you choose to include (such as your name, email, and message). We use it only to respond to you.

3. Information we do NOT collect

We do not collect or store your payment card numbers, bank details, Apple Pay credentials, government-issued ID, selfie/biometric data, or KYC documents — these are submitted by you directly to Coinbase within Coinbase's checkout. We also never have access to your wallet's private keys or recovery phrase, and we never take custody of your funds or crypto.

4. How we use information

  • To create your single-use Coinbase onramp session and generate your checkout link;
  • To validate your wallet address for the network you chose;
  • To secure the Service (rate limiting, abuse prevention, debugging); and
  • To respond to messages you send us.

We do not use your information for advertising profiling, and we do not sell or rent your personal information.

5. Sharing with Coinbase and others

To provide the onramp, we share the data needed to create your session — your wallet address, selected asset/network, and IP address — with Coinbase. Coinbase's handling of your information (including any KYC and payment data you give it) is governed by the Coinbase Privacy Policy. We may also share information where required by law, to protect our rights or users' safety, or with service providers that host or operate the Service under confidentiality obligations. We do not otherwise sell or share your personal information.

6. Cookies and analytics

The Service is designed to function without advertising cookies or cross-site trackers. We use only what is strictly necessary to operate the site (for example, standard request handling). If we add privacy-respecting, aggregate analytics in the future, we will update this Policy first.

7. Data retention

We keep operational logs only as long as needed for security and reliability, then delete or anonymize them. We do not retain a store of your purchases, since the transaction itself is completed and recorded by Coinbase and on the blockchain, not by us. Email correspondence is kept as needed to handle your request.

8. Security

The CDP API secret used to authorize Coinbase sessions is stored only server-side and is never exposed to your browser. Each purchase uses a single-use session token that expires within five minutes. We serve the Service over HTTPS with strict security headers, restrict our API to our own domains, and rate-limit sensitive endpoints. No method of transmission is perfectly secure, but we work to protect the limited data we handle.

9. Your rights

Depending on where you live (for example, under the California Consumer Privacy Act or the GDPR), you may have rights to access, correct, delete, or restrict use of your personal information, and to not be discriminated against for exercising them. Because we hold very little personal data, the most effective route is usually to contact support@pay-castle.com; we will respond as required by applicable law. For data Coinbase holds (such as KYC and payment records), please contact Coinbase directly.

10. Children

The Service is not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.

11. International users

The Service is operated for users in the United States. If you access it from elsewhere, you do so on your own initiative and are responsible for compliance with local laws, and your information may be processed in the United States.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Your continued use after a change takes effect constitutes acceptance.

13. Contact

Questions or requests about privacy? Email support@pay-castle.com.