Privacy Policy
Last updated: August 28, 2026
What we collect
BirrPay processes account data (name, email, password hash), tenant and app configuration, payment metadata (amounts, currencies, references, provider references, customer contact data supplied by your apps) and technical logs (IP addresses, user agents) required to operate a payment orchestration service securely.
What we never store
BirrPay does not store raw card numbers or CVV. Card data is collected directly inside provider-hosted components or provider pages; BirrPay receives only references and status. Provider credentials you upload are encrypted at rest with AES-256-GCM and are decrypted only in memory when a charge or verification requires them.
How we use data
To process payments you initiate, to route sessions to your configured providers, to deliver signed webhooks to your endpoints, to detect and prevent fraud and abuse, to provide support, and to meet legal and regulatory obligations. We do not sell personal data.
Security
Secret keys are stored only as SHA-256 hashes and compared in constant time. All endpoints validate input schemas, enforce rate limits and authorization scopes, and every dashboard mutation is written to an audit trail. Webhooks are signature-verified before any state change.
Retention & deletion
Transaction records are retained as required for financial audit and dispute handling. You may request account deletion; personal data is redacted and remaining financial records are kept only as long as legally required.
Contact
Privacy questions: reach us via the contact page.