
Privacy Policy
Effective date: August 24, 2026
Xbit Innovations LLC ("we," "us," "our") operates XRPay, a payment gateway and off-ramp platform. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you install the App, use the Xaman xApp off-ramp, or interact with a store that uses our services.
1. Who This Policy Covers
This Policy applies to:
- Merchants — BigCommerce store owners who install and configure the App
- xApp Off-Ramp Users — Xaman wallet holders who use the XRPay xApp to convert XRPL assets to fiat USD
- Shoppers — customers who pay through a checkout powered by the App
- Waitlist subscribers — individuals who sign up for early access at our public landing page
2. Information We Collect
From Merchants (via BigCommerce OAuth)
- BigCommerce store hash, store name, and store domain
- Merchant email address (provided by BigCommerce during install)
- BigCommerce API access tokens (stored in our access-controlled database and used to read/update store data)
- Merchant settlement addresses and, when the optional app-generated operational-wallet feature is enabled, the wallet's encrypted seed/private-key material
- App configuration: settlement preferences, POS settings, Telegram bot tokens
- Transaction history: order IDs, amounts, payment statuses, XRPL transaction hashes
- B2B wholesale listings, orders, and inventory managed within the App
- POS employee records: names and PIN hashes (for in-store register access)
From xApp Off-Ramp Users (KYC & Bank Linking)
- Identity data (KYC): Full legal name, date of birth, residential address, Social Security Number (SSN), and government-issued ID — collected and processed by our regulated partner Bridge.xyz as required by US financial regulations
- Bank account data: Bank name, routing number, and account number (US ACH), IBAN and BIC/SWIFT (international), or wire transfer details — used solely to route fiat withdrawals
- Off-ramp transaction records: XRPL wallet address, token amounts, conversion rates, fees, ACH transfer IDs, and settlement timestamps
- XRPL trustline balances (read-only, fetched at session time to populate the withdrawal UI)
KYC identity data is collected, stored, and processed primarily by Bridge.xyz under their own privacy policy. Xbit Innovations LLC retains only the Bridge customer ID, KYC status, and transaction records necessary to provide the service.
From Shoppers (at checkout)
- Email address (passed from BigCommerce checkout for confirmation purposes)
- XRPL wallet address used for payment (recorded from public blockchain data)
- Transaction amounts and blockchain transaction hashes
From Waitlist Subscribers
- Email address and optional store name (submitted via the landing page form)
We do not collect passwords, credit card numbers, or any data beyond what is listed above. SSN and government ID are processed exclusively by Bridge.xyz and are never stored on Xbit Innovations LLC infrastructure.
3. How We Use Your Information
- To authenticate your BigCommerce store and maintain your App installation
- To generate payment requests, QR codes, and verify on-chain settlement
- When you enable an app-generated operational wallet, to provision the wallet and perform wallet setup or transactions you request or authorize, including trustline, settlement, refund, treasury, payout, and automated-sweep functions
- To update order statuses and sync payment results back to your BigCommerce store
- To provide the merchant dashboard, analytics, B2B marketplace, POS register, and tax ledger
- To operate the xApp off-ramp: verify identity via Bridge.xyz, link bank accounts via Plaid, initiate ACH withdrawals, and record transaction history
- To comply with US financial regulations (BSA/FinCEN) applicable to fiat off-ramp services
- To send one launch notification to waitlist subscribers (opt-in at time of submission)
- To detect and prevent fraudulent or unauthorized activity
- To comply with applicable legal obligations
We do not use your data for advertising or sell it to any third party.
4. Data Storage & Security
All data is stored in a PostgreSQL database hosted on Railway (EU/US region). Sensitive values — including integration API tokens and seeds for app-generated operational wallets — are encrypted at rest. Access is restricted to authorized systems and personnel. When a wallet operation that you request or authorize requires signing, the App may decrypt an operational-wallet seed in server memory to sign and broadcast the transaction. Administrator multi-factor authentication is required to export an operational-wallet seed.
If you configure an external wallet for direct settlement, the App stores its public address but does not require or store that external wallet's private key or seed phrase. Do not provide an external-wallet private key or seed phrase to Xbit Innovations LLC. All communications between the App, third-party services, and XRPL are transmitted over HTTPS/TLS. No storage or transmission method is completely secure, and we cannot guarantee absolute security.
We perform regular dependency audits and follow OWASP security guidelines for web application development.
5. Data Sharing
We share data only in the following limited circumstances:
- BigCommerce — We write order status updates and register storefront scripts via the BigCommerce API as required for the App to function
- XRP Ledger (XRPL) — Payment transactions are submitted to the public XRP Ledger; all XRPL transactions are publicly visible by design
- Xaman (XUMM) — Payment signing requests are routed through Xaman's API; no personal data beyond a payment amount and destination address is shared
- Bridge.xyz — For xApp off-ramp users, KYC identity data (name, DOB, SSN, address, ID) and bank account details are shared with Bridge.xyz as required to process fiat withdrawals. Bridge.xyz is an independent controller of this data under their own privacy policy
- Plaid — Bank account credentials entered during the Plaid Link flow are processed directly by Plaid; Xbit Innovations LLC receives only a tokenized reference used to route ACH transfers (US users)
- ChangeNOW — XRPL wallet address and token amounts are shared with ChangeNOW to obtain swap quotes and execute DEX conversions for non-XRP trustline withdrawals
- Telegram — Store catalog data is delivered to your configured Telegram bot; no shopper personal data is transmitted to Telegram by the App
- Infrastructure and security providers — Data, including encrypted operational-wallet key material when that feature is enabled, is processed by hosting, database, monitoring, and security vendors as necessary to operate and protect the App
- Law enforcement — Only when required by a valid legal process under applicable law
Operational-wallet seeds are not published to XRPL or intentionally disclosed to payment recipients. Signed transaction data is submitted to XRPL and becomes public. We do not sell, rent, or trade personal data to advertisers or data brokers.
6. BigCommerce App Lifecycle & Privacy Requests
XRPay verifies signed BigCommerce callbacks when an app is opened, uninstalled, or a BigCommerce user's access is removed. Privacy requests can be submitted to support@xbitinnovations.com.
- Access — Request a copy of merchant or customer data associated with the App
- Erasure — Request deletion of identifiable data that is not subject to legal retention requirements
- Uninstallation — BigCommerce credentials are invalidated immediately when the signed uninstall callback is received
7. Data Retention & Deletion
- Merchant and transaction data is retained while the App is installed
- Encrypted key material for an app-generated operational wallet is retained while the wallet feature or an authorized transaction function requires it, and until a verified deletion request can be completed, subject to legal, fraud-prevention, backup, and security requirements
- Before requesting deletion of operational-wallet key material, you must export or rotate the wallet credential and move any assets you wish to retain. Deletion of our stored copy does not rotate the on-chain credential, prevent use by anyone who already possesses it, or reverse completed transactions
- Session tokens are invalidated on uninstallation
- Uninstallation disconnects the store immediately; non-regulated store data can be deleted on request
- Waitlist email addresses are deleted upon request or within 12 months if no launch notification is sent
- xApp off-ramp KYC records are retained for a minimum of 5 years as required by US Bank Secrecy Act (BSA) and FinCEN regulations. This retention obligation supersedes deletion requests for regulatory data
- Off-ramp transaction records (amounts, timestamps, XRPL hashes, ACH transfer IDs) are retained for 7 years to comply with financial recordkeeping requirements
- Merchants and off-ramp users may request deletion of non-regulated data at any time by emailing support@xbitinnovations.com
8. GDPR & International Privacy Rights
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data protection laws, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your personal data ("right to be forgotten")
- Restriction — request that we restrict processing of your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
To exercise any of these rights, contact us at support@xbitinnovations.com. We will respond within 30 days.
9. Cookies & Analytics
The App does not use tracking cookies or third-party analytics tools on merchant storefronts. The BigCommerce control panel view of the App may use session cookies to maintain your authenticated session. No behavioral data is collected.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be posted in the App dashboard and on this page with an updated effective date. Continued use of the App after notice of changes constitutes your acceptance.