Legal
Privacy policy
Last updated: 12 July 2026
This policy describes how AuraPay Global handles information when you use our payment gateway, Telegram bot, Mini App, merchant tools, and websites. Related documents: Terms of Service and Cookie Policy.
1. Who we are
AuraPay Global (“AuraPay”, “we”, “us”, or “our”) operates a Web3 payment gateway for TON and USDT (and related product features) through our websites (including www, app, api, pay, docs, and status.aurapayglobal.com), our Telegram bot @AuraPayGlobalBot, and the AuraPay Mini App / dashboard.
This Privacy Policy explains what information we process when you use AuraPay, why we process it, and the choices available to you. By using AuraPay, you acknowledge this policy.
2. Scope
This policy applies to our marketing site, login flows, web dashboard, Telegram Mini App, bot interactions, merchant APIs, hosted checkout, status page, and related support channels. It does not cover third-party wallets, blockchains, Telegram itself, Google, email inbox providers, or other services you access outside AuraPay; those providers have their own policies.
3. Information we collect
The data we process depends on how you sign in and which features you use:
- Account & identity: Telegram user id and profile fields provided by Telegram; Google account identifiers (such as Google subject id, name, and email) if you use Continue with Google; email address and display name if you use email/password signup; password is stored only as a one-way hash (we cannot read your plaintext password).
- Email verification: one-time codes and related delivery metadata when you verify an email address (sent via our email provider).
- Wallet data: blockchain addresses you connect via TonConnect / Tonkeeper (and other supported networks when enabled); linked wallet status; jetton / token wallet references needed for balances and transfers.
- Transaction & product data: payment requests, invoices, amounts, currencies, memos/reference codes, swap quotes you request, Stars ledger entries, cheques, shop/cart/order records, referrals, giveaways, merchant webhook configuration, and support tickets you submit.
- Technical & security data: IP address, device/browser type, approximate location derived from IP, timestamps, rate-limit signals, and diagnostic logs needed to secure and operate the service.
- Cookies & similar tech: session cookies after authentication; short-lived cookies for email verification flows; theme preference (bright/dark) stored locally in your browser. See our Cookie Policy for details.
4. How we use information
We use information to:
- Authenticate you and maintain a secure session across AuraPay hosts (for example www and app.aurapayglobal.com).
- Operate payments, invoices, hosted checkout, swaps, Stars, shop, giveaways, referrals, cheques, and merchant webhooks.
- Send transactional emails such as verification codes (not marketing unless you separately opt in).
- Show balances, history, and status for transactions you initiate or receive.
- Prevent fraud, abuse, spam, and unauthorized access; enforce rate limits and security controls.
- Provide customer support and investigate disputes or incidents.
- Publish non-personal system health signals on our status page.
- Improve reliability, performance, and product experience.
- Comply with law and respond to lawful requests where required.
5. Legal bases (where applicable)
Where privacy laws require a legal basis (for example GDPR-style regimes), we typically rely on: performance of a contract (providing the gateway you request); legitimate interests (security, abuse prevention, product improvement); and consent where we ask for it (such as optional marketing communications, if offered).
6. Wallets, keys, and on-chain data
AuraPay does not ask for, store, or have access to your seed phrase or private keys. Transfers are signed in your wallet application (for example Tonkeeper).
Blockchain networks are public ledgers. Addresses, amounts, and transaction hashes you broadcast are visible on-chain and may be indexed by AuraPay and third-party explorers. That publicity is inherent to public blockchains, not a separate disclosure by AuraPay.
8. Sharing and processors
We do not sell your personal information. We share data only with service providers who help us operate AuraPay, under appropriate safeguards, including for example:
- Hosting and edge delivery (e.g. Vercel).
- Database and infrastructure (e.g. Supabase / PostgreSQL).
- Transactional email delivery (e.g. Resend) when email verification is enabled.
- Blockchain RPC and indexing providers (e.g. Toncenter and similar).
- Identity providers you choose (Telegram; Google if you use Google sign-in).
- Optional partners you enable (for example fiat on-ramp providers when that feature is active).
- Professional advisors or authorities when required by law or to protect rights and safety.
9. International transfers
Our infrastructure may process data in multiple countries. Where required, we use appropriate transfer mechanisms and contractual protections with processors.
10. Retention
We retain account, wallet-link, invoice, and transaction records for as long as needed to provide the service, resolve disputes, maintain security, and meet legal or accounting obligations. Email verification codes are short-lived. Support tickets and logs may be kept for a shorter operational period unless a longer retention is required for an investigation.
11. Security
We use industry-standard measures such as encrypted transport (HTTPS), hashed passwords, signed session cookies, access controls, and rate limiting. No method of transmission or storage is 100% secure; you are responsible for securing your devices, Telegram account, Google account, email account, password, and wallet.
12. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or restrict certain personal data, or to object to certain processing. To exercise rights, contact us as described below. We may need to verify your identity and may retain limited data where the law allows (for example fraud prevention or legal claims).
You can disconnect wallets in-product where available, sign out in the app or by clearing cookies, and stop using the bot or Mini App at any time.
13. Children
AuraPay is not directed to children under 18 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will take appropriate steps.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of AuraPay after an update means you acknowledge the revised policy. For material changes, we may provide additional notice in-product or via the bot when practical.
15. Contact
Privacy questions and requests: open @AuraPayGlobalBot and use /support (help chatbot), or email support@aurapayglobal.com (help@aurapayglobal.com reaches the same inbox).
Our public website is https://www.aurapayglobal.com.