Trust center

Know who handles each part of a payment.

XRPay connects merchant records, payment status, and settlement visibility. Direct wallet routes and provider-backed card, bank, conversion, or payout routes do not carry the same custody, identity, timing, or dispute rules.

What XRPay handles

  • Merchant, customer, order, payment-status, and settlement records needed to operate the service.
  • Integration credentials encrypted at rest and access-controlled within the merchant organization.
  • Signed sessions, webhooks, and audit records used to authorize and reconcile activity.

What XRPay never asks for

  • A wallet seed phrase, recovery phrase, or private key on a customer payment page.
  • A merchant wallet recovery phrase as part of ordinary checkout configuration.
  • Provider passwords when a supported OAuth or provider-hosted authorization flow is available.

What providers handle

  • Identity checks and eligibility decisions for regulated card, bank, conversion, and payout routes.
  • Payment credentials entered on provider-hosted or provider-controlled interfaces.
  • Their own fees, processing times, disputes, reversals, limits, and geographic coverage.

Settlement and dispute boundaries

Direct supported wallet payment

The customer authorizes a ledger transfer to the address configured for the transaction. Confirmed on-chain transfers are irreversible; a refund is a separate outbound transfer. Wallet and network requirements still apply.

Provider-backed route

The provider may collect identity or payment information, convert value, and control processing or payout timing. Its eligibility, pricing, disputes, reversals, and settlement rules continue to apply.

Verify or report