Przejdź do treści
Prawo

Subprocessors

Every third party a Payora instance contacts, what it is for, and what it actually sees.

Ostatnia aktualizacja 16 lipca 20262 min czytaniaSekcje: 8

1. How to read this list

Most of these see no personal data at all. A blockchain data provider is asked about a public address or a transaction; a price feed is asked what a coin costs. Only the first group below sees anything tied to a person.

2. Infrastructure and analytics

2.1 Cloudflare

CDN, DNS and TLS in front of the domains. Sees request metadata, including your IP address.

2.2 Astrina

Web analytics counter, site 7, served from our own subdomain stats.payora.money. Serving it first-party does not change who processes the data: page views and request metadata still reach Astrina. No advertising, no cross-site tracking.

3. Blockchain data providers

Queried to detect deposits. They see a public address or a transaction query, and no personal data.

3.1 By network

TonCenter for TON. Etherscan V2 for Ethereum and the other EVM chains. TronGrid for Tron. Blockstream and mempool.space for Bitcoin. litecoinspace and BlockCypher for Litecoin. BlockCypher and Blockchair for Dogecoin, plus equivalent providers for DASH, DGB and Bitcoin Cash. Public RPC endpoints for Solana, the XRP Ledger, and Horizon for Stellar.

4. Price feeds

Binance, OKX and CoinGecko, used to quote fiat-priced invoices. They see a price query and no personal data.

5. Optional, only if you enable them

These are off unless the merchant turns them on and supplies their own credentials.

5.1 Stripe

Card payments. If you enable it, Stripe processes the card payment under your own Stripe account and its terms. Payora never stores card numbers.

5.2 Telegram Bot API

Payment notifications sent to your own bot. Sees the notification content you configure.

6. Your own endpoints

Outbound webhooks go only to the URL you configure, over https, pinned to a validated IP, with private, CGNAT and NAT64 ranges denied. Nothing is sent anywhere else.

7. Email

Transactional notifications only, never marketing. Delivery depends on the SMTP provider the Operator configures, and an Operator may run an instance with no SMTP configured at all.

8. Zmiany

The Operator will give notice of intended changes to this list so that merchants can object. See the Data Processing Agreement for how that works.

Last updated: 16 July 2026. If we make material changes to this page, the updated version will be posted here.

FAQ

Najczęściej zadawane pytania

Proste odpowiedzi, w tym te niewygodne: przechowywanie, opłaty i co się dzieje, gdy coś pójdzie nie tak.

Centrum pomocy

Which subprocessors see personal data?

Only a few. Cloudflare sees request metadata including your IP because it fronts the domains, and the analytics counter served from stats.payora.money records page views, which Astrina processes. Blockchain data providers and price feeds receive no personal data, only a public address or a price query.

Which blockchain providers does Payora query?

TonCenter for TON, Etherscan V2 for Ethereum and EVM chains, TronGrid for Tron, Blockstream and mempool.space for Bitcoin, litecoinspace and BlockCypher for Litecoin, BlockCypher and Blockchair for Dogecoin, equivalents for DASH, DGB and Bitcoin Cash, and public RPC for Solana, XRP and Stellar.

Are Stripe and Telegram always used?

No. Both are optional and off by default. They are only contacted if the merchant enables them and supplies their own credentials. Payora never stores card numbers.

Where do webhooks go?

Only to the URL you configure. Outbound webhooks are https-only and pinned to a validated IP address, with private, CGNAT and NAT64 ranges denied, so a webhook cannot be pointed at internal infrastructure.

Na co odpowiada ta strona