Information we collect
We collect account information such as your email address, authentication provider, and basic profile information when you create or access an Access402 account.
We collect the configuration information you provide for projects and installations, including project names, site or API URLs, adapter types, public wallet addresses, resource metadata, prices, and access rules. Access402 does not need your wallet seed phrase or private key.
When Access402 processes an x402 request, we may record operational information such as the installation and resource involved, environment, amount, asset, network, public payer and receiving wallet addresses, transaction hash, payment or delivery status, error details, and timestamps. Blockchain transactions are also recorded on public networks independently of Access402.
If you contact us, we collect the information submitted in the form, such as your name, email, company, website, message, platform, or anticipated transaction volume. We store a one-way hash derived from the request IP address for spam and rate-limit protection rather than storing the raw address in the contact record.
We may receive identifiers and profile information from Google or GitHub when you choose social login. Those providers control the information displayed during their authorization flow.
How we use information
We use information to authenticate users, operate the dashboard, connect adapters, verify and settle x402 payments, grant access, provide activity records, respond to support or sales requests, prevent abuse, secure the service, troubleshoot errors, and comply with legal obligations.
We do not use your personal information for targeted advertising. We do not knowingly sell personal information or share it for cross-context behavioral advertising.
Credentials and protected content
Installation API keys are scoped to one installation. Access402 stores a cryptographic hash and a short identifying prefix, not a recoverable copy of the plaintext key. The plaintext is shown when the key is created so you can configure the adapter.
An adapter may keep its local copy of a connection key using the security facilities available in that platform. For example, the Access402 WordPress adapter encrypts its saved key when local encryption is available and disables automatic option loading.
Access402 is designed to store rules and operational metadata, not the full content of the pages, files, or API responses you protect. Protected content remains on the site or system where you publish it unless a specific integration clearly states otherwise.
Retention
We retain account and configuration information while your account is active and as reasonably needed to provide the service, resolve disputes, enforce agreements, maintain security, and satisfy legal requirements.
Standard Access402 activity retention is 90 days unless your plan or enterprise agreement specifies a different period. Some transaction information may remain available on public blockchains even after Access402 records are deleted.
Contact requests are retained only as long as reasonably needed to respond, maintain business records, prevent abuse, and meet legal obligations. We may retain limited records of deletion or security events when necessary.
Your choices and rights
You may update account and project information through the dashboard or permanently delete your Access402 account from the Account page. You may also ask us to provide access to or correct personal information associated with you. Depending on where you live, you may have additional rights, including the right to know how information is used or disclosed, obtain a portable copy, object to or restrict certain processing, and appeal a denied request.
We may need to verify your identity before completing a privacy request. Certain information may be retained where required by law, necessary for security, or contained in a public blockchain record that Access402 does not control.
You can revoke Access402 access from Google or GitHub through that provider’s account settings. Revoking provider access does not automatically delete your Access402 account.
Security
We use administrative and technical safeguards intended to protect information, including scoped credentials, access controls, hashing, encryption where appropriate, rate limits, and authenticated database policies. No system can guarantee absolute security.
If you believe an account, credential, or integration has been compromised, revoke the affected key through the dashboard and contact us promptly.
International processing
Access402 and its service providers may process information in countries other than the one where you live. Where applicable, we use available contractual and legal safeguards for international transfers.
Children
Access402 is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Users must also meet any higher minimum age required where they live.
Changes to this policy
We may update this policy as the service or legal requirements change. We will post the revised policy here and update the date at the top. If a change materially affects how we use personal information, we will provide additional notice where required.
Contact
For privacy questions or requests, email support@access402.com. Please do not include wallet private keys, seed phrases, passwords, or installation API keys in your message.
