01Who we are
This policy explains how Norpo handles personal data when you visit norpo.io, use the merchant dashboard, the API or plugins, our Telegram mini app, or pay through a Norpo checkout. For data we process to run your account, Norpo is the controller.
02What we do not collect
We never see or store card numbers, bank credentials or identity documents. Customers enter those directly with the licensed provider they choose. We never receive the recovery phrase or password of a Norpo Wallet: they are created and encrypted on your device.
03What we collect
- Merchant account: e-mail, hashed password, business name and website, payout wallet address, API keys (stored hashed), two-factor settings, and your settings and agreed rates.
- Payments: amount, currency, order reference, payment method and provider chosen, status, deposit addresses and blockchain transaction IDs.
- Customers at checkout: the customer's country (derived from their IP address) to show the right methods, and, for providers that need it, the e-mail address the customer enters, which we pass to that provider.
- Support: messages you send us by e-mail or Telegram.
- Technical: IP address, browser, request logs and security events, used to run and protect the service.
- Telegram mini app: your Telegram user ID and the orders you place.
- Website analytics: only if you accept cookies (see below).
04How we use it
To create and run your account; route payments and settle them to your wallet; send webhooks and notifications; provide support; detect fraud, abuse and attacks; meet legal obligations; and, with your consent, understand how the website is used so we can improve it. We do not sell personal data and do not use it for advertising profiles.
05Legal bases
Where data-protection law such as the GDPR applies, we rely on: performance of our contract with you (running your account and payments); legitimate interests (security, fraud prevention, improving the service); legal obligations; and consent (analytics cookies), which you can withdraw at any time.
06Cookies and analytics
The website uses strictly necessary storage to keep you signed in and remember your cookie choice. Analytics (Yandex Metrica) loads only after you click Accept on the cookie banner. If you decline, nothing is set. To change your choice, clear this site's data in your browser and choose again.
08International transfers
Our servers and providers may be located outside your country. Where we transfer personal data internationally, we take steps to keep it protected as this policy describes.
09How long we keep it
Account data is kept while your account is open. Payment records are kept as long as needed for accounting, disputes and legal obligations, then deleted or anonymised. Server logs are rotated within about 90 days. On-chain records cannot be deleted by anyone.
10Security
We use encryption in transit, hashed passwords and API keys, two-factor authentication for sensitive actions, access controls and monitoring. No system is perfectly secure, so protect your password and keys too.
11Your rights
Depending on where you live, you can ask to access, correct, delete or export your data, object to or restrict certain processing, and withdraw consent. Write to support@norpo.io from your account e-mail. We will answer within 30 days. You may also complain to your local data-protection authority.
12Children
Norpo is for adults only. We do not knowingly collect data from anyone under 18, and we delete it if we find we have.
13Third-party services
Providers, exchanges and other sites linked from Norpo have their own privacy policies, which govern the data you give them.
14Changes
We will post updates here and change the date at the top. Significant changes will also be announced by e-mail or in the dashboard.
15Contact
Privacy questions: support@norpo.io · Telegram: @norpoio.
