Skip to content
BirrPay

Privacy Policy

Last updated: August 28, 2026

What we collect

BirrPay processes account data (name, email, password hash), tenant and app configuration, payment metadata (amounts, currencies, references, provider references, customer contact data supplied by your apps) and technical logs (IP addresses, user agents) required to operate a payment orchestration service securely.

What we never store

BirrPay does not store raw card numbers or CVV. Card data is collected directly inside provider-hosted components or provider pages; BirrPay receives only references and status. Provider credentials you upload are encrypted at rest with AES-256-GCM and are decrypted only in memory when a charge or verification requires them.

How we use data

To process payments you initiate, to route sessions to your configured providers, to deliver signed webhooks to your endpoints, to detect and prevent fraud and abuse, to provide support, and to meet legal and regulatory obligations. We do not sell personal data.

Security

Secret keys are stored only as SHA-256 hashes and compared in constant time. All endpoints validate input schemas, enforce rate limits and authorization scopes, and every dashboard mutation is written to an audit trail. Webhooks are signature-verified before any state change.

Retention & deletion

Transaction records are retained as required for financial audit and dispute handling. You may request account deletion; personal data is redacted and remaining financial records are kept only as long as legally required.

Contact

Privacy questions: reach us via the contact page.