PRIVACY & DATA
Privacy Policy
We aim to collect less, explain clearly, and use information only to provide and protect PayGlass.
- Effective
- September 29, 2026
- Last updated
- September 29, 2026
- Privacy contact
- contact@rootdata.com
Scope and our role
This Privacy Policy applies to the PayGlass website, accounts and community features. “PayGlass,” “we,” or the “Service” means the operator of the PayGlass service. By using the Service, you acknowledge that you have read this Policy. If you do not agree, please stop using the relevant features.
PayGlass is an information, comparison and community service for crypto payment cards. It is not a bank, card issuer, wallet or payment processor. The Service does not collect full payment card numbers, security codes, wallet private keys or seed phrases, and does not execute payments or on-chain transactions for you.
Product, fee and volume information shown in card profiles primarily comes from public, partner or licensed sources and is separate from account information collected from users.
Information we collect
We process information only as needed to provide, protect and improve the Service. What we collect depends on the features you use.
- Account and identity information: email address, a cryptographic hash of your password, display name, avatar, biography, registration time and recent login time. We do not store passwords in plain text.
- Google sign-in information: if you choose Google sign-in, we receive a unique Google account identifier, verified email address and display name to create or link a PayGlass account.
- Verification information: when sending email codes, we process the email address, a cryptographic hash of the code, its purpose, attempt count, and issue and expiry times.
- Community and feedback information: watchlists, ratings, reviews, votes, feedback and reports you submit, plus status records needed to moderate them.
- Uploads: avatars are processed, resized for display and stored in object storage.
- Usage and technical information: pages viewed, event time, a random visitor identifier, login and security events, and IP address, request details and service logs used for rate limiting, abuse prevention and troubleshooting.
How we use information
We use this information to:
- create and manage accounts and provide password sign-in, Google sign-in, sessions, email verification and profile features;
- save watchlists, display community ratings and reviews, and handle feedback, reports and moderation;
- measure aggregate use of pages and features and improve search, comparison, content quality and the product experience;
- detect unusual sign-ins, spam, automated abuse and other security risks, and enforce service rules;
- send verification codes, account security or service-required notices, and respond to questions and rights requests;
- meet applicable legal requirements, resolve disputes and protect the legitimate interests of users, PayGlass and the public.
We do not sell personal information or use cross-site advertising trackers to build advertising profiles.
Cookies and local storage
PayGlass uses necessary cookies and browser storage to maintain sessions, remember theme preferences, complete Google sign-in security checks, track email verification progress and create anonymous usage statistics. Session cookies use safeguards such as HttpOnly and SameSite. The one-time Google sign-in verification cookie normally expires within 10 minutes.
Your browser may store a randomly generated visitor identifier, theme and interface preferences. Usage events do not require your real name or email, and the server irreversibly hashes the visitor identifier again before storage. You can clear or restrict cookies and local storage in your browser, but sign-in, saved preferences or some security features may stop working.
Public content and your choices
Approved reviews may publicly display your display name, avatar, rating, review text and publication time. Your email address is not shown with reviews. Avatars are normally displayed from publicly reachable image addresses, so do not upload identification documents, contact details or other sensitive images.
Before submitting a review or profile, make sure it does not contain information you do not want to make public. You can edit profile information. Contact us using the details below to request deletion or correction of published content.
Service providers and sharing
We do not sell or rent personal information for third-party marketing. To operate the Service, we may disclose or transfer information as necessary to:
- Google, which provides Google sign-in and related identity verification. Google’s handling of information in its services is governed by its own privacy policy.
- Email providers that deliver verification codes, account security and service-required messages for us.
- Cloud infrastructure providers that supply hosting, databases, caching, logs and avatar object storage.
- Language and content-processing providers. To support a bilingual experience, the text of an approved public review may be sent to a third-party artificial intelligence service for translation. Account email addresses and passwords are not sent with review text.
- Professional advisers, law enforcement or regulators when required by law, to respond to valid process, investigate abuse or protect legal rights.
Providers may process information only for the assigned purpose and are subject to contractual duties or their applicable data-protection responsibilities. Because providers can operate in different countries, information may be processed outside your region.
Retention
We do not keep every record indefinitely. Email verification records are normally cleared about one day after expiry; sign-in and anti-abuse records are retained for a limited security period; page-visit statistics are normally kept for about 90 days; and general operational audit logs are normally kept for about 30 days.
Account details, watchlists, reviews and feedback are retained while needed to provide account or community features. They are then deleted, anonymized or retained in necessary part according to your deletion request, service continuity, security, dispute resolution, backup cycles and legal obligations.
Security
We use technical and organizational measures appropriate to the risks, including hashing passwords and session tokens, encryption in transit, restricted administrative access, request rate limits, audit logs and backups.
No internet transmission or storage system can be guaranteed completely secure. Use a strong, unique password, never share verification codes, and contact us promptly if you suspect unauthorized account use.
Your rights
Subject to applicable law, you may request access to, correction or deletion of, or restrictions on the processing of, your personal information, and may object to certain processing. You can also sign out, clear browser storage or stop submitting community content.
- Send requests from the email address associated with your account so we can verify identity and prevent unauthorized disclosure or deletion.
- We may retain necessary records for legal obligations, security investigations, fraud prevention, dispute handling or service integrity, and will explain an applicable reason if a request must be limited or denied.
- If you believe processing violates applicable law, you may complain to a data-protection or consumer-protection authority with jurisdiction where you live.
Children, updates and contact
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can verify and take appropriate steps to delete it.
We may update this Policy as features, providers or legal requirements change. Material changes will be highlighted on the website. The date at the top shows when the current version became effective.
For questions about this Policy, personal information or a rights request, email contact@rootdata.com.
Contact privacy→