# Privacy policy

> What personal data Railbed collects from merchants, buyers and visitors, why, who receives it, how long it is kept, and the rights you have over it.

Source: https://railbed.io/privacy/ · Last updated: 2026-09-25 · Railbed by DeepWork

This policy explains how Railbed by DeepWork, operated by DeepWork ("Railbed", "we" or "us"), handles personal data across the website at https://railbed.io, the merchant dashboard at https://app.railbed.io, the hosted checkout, the API and webhooks. We collect little, we do not sell personal data, and we do not use advertising trackers. Where this policy says "you", it means whichever of the following you are.

## Who we are and our role

Railbed deals with three kinds of people, and our role differs for each.

- **Merchants** use the dashboard and API to accept payments. For merchant account data, Railbed is the controller: we decide what is collected and why.
- **Buyers** pay a merchant through a Railbed checkout. The merchant is the business you are dealing with and is the controller of your checkout data. Railbed processes that data on the merchant's behalf, under its instructions and these terms. The on-ramp provider that charges your card is a separate controller for the card payment itself.
- **Visitors** browse https://railbed.io. For the little we process about visitors, Railbed is the controller.

If a law uses different labels, such as "business" and "service provider", read the equivalent roles into the above.

## What we collect

### From merchants

- Business name, account email address and password. The password is stored only as a salted PBKDF2-SHA256 hash, which cannot be turned back into the password.
- The Polygon wallet address you give us for payouts, and the balance we read from the public blockchain to display it.
- Optional settings: a support email address shown to buyers and a checkout brand colour.
- The checkouts and payment links you create, including product names, descriptions and prices.
- API keys, stored only as SHA-256 hashes, and usage records such as when a key was last used.
- Webhook endpoint URLs and their signing secrets, and delivery records for each webhook attempt.
- Records of your use of the dashboard and API, and messages you send us.

### From buyers

- The email address you enter at checkout.
- The payment: amount, currency, description or reference, the provider you chose, its status, and the on-chain transaction IDs once it settles.
- The country derived from your IP address, which Smart Routing uses to rank providers. The IP address itself is not stored with the payment.

You enter your card or wallet details on the provider's page, not ours. Railbed never sees or stores card numbers.

### From everyone

- IP addresses and request details, used transiently for security and rate limiting, and processed in request logs by our hosting provider.
- Emails you send to any of our addresses.

## How we use it

We use personal data to:

- run the service: create accounts, sign merchants in, publish checkouts, create and track payments, deliver USDC to the right wallet and send webhooks
- route each buyer to a suitable provider, using the amount and the buyer's country
- pass a buyer's email address to our payment infrastructure partner and to the chosen on-ramp provider, because they need it to create the payment and send receipts
- keep the service secure: detect abuse, enforce rate limits, verify signatures, investigate incidents
- enforce our [terms of service](https://railbed.io/terms/) and [acceptable use policy](https://railbed.io/acceptable-use/), including reviewing a merchant's business when we have reason to
- answer support, privacy and legal enquiries
- meet legal obligations, including tax, accounting, sanctions and anti-money-laundering requirements, and respond to lawful requests from authorities
- send merchants service messages about their account, such as security notices and changes to these terms

Where a data-protection law asks us to name a lawful basis, we rely on performance of a contract (providing the service to merchants and, on their behalf, to buyers), our legitimate interests (security, abuse prevention, running and improving the service, defending legal claims), compliance with legal obligations, and consent where we ask for it. We do not use personal data for profiling that has legal effects on you, and we do not use it for advertising.

## Who we share it with

We share personal data only with the parties needed to provide the service, by category:

- **Cloud hosting and security.** Cloudflare hosts the service, screens traffic and processes request logs.
- **Payment infrastructure providers.** Our payment infrastructure partner receives the payment amount, the buyer's email address and the merchant's payout wallet address to create the forwarding address and deliver the funds.
- **Licensed on-ramp providers.** The provider a buyer chooses receives the buyer's email address and the payment details. It collects card and identity information directly from the buyer under its own privacy policy.
- **Public blockchain RPC providers.** We query the Polygon network to read wallet balances and confirm settlements. Only wallet addresses and transaction IDs are involved.
- **Merchants.** Each merchant receives the checkout data of its own buyers: email address, amount, reference and status.
- **Professional advisers and authorities.** Lawyers, accountants and auditors under confidentiality, and regulators, courts or law enforcement where the law requires or allows it.
- **A successor.** If DeepWork is involved in a merger, acquisition or sale of assets, personal data may transfer to the successor under this policy.

We do not sell personal data, and we do not share it with advertising networks or data brokers.

## Public blockchain data

Settled payments are recorded on the Polygon blockchain: the forwarding address, the merchant's wallet address, the amount and the transaction ID. That record is public, permanent and outside anyone's control, including ours. It contains no names or email addresses. A wallet address can still be linked to a person by anyone who knows the connection. Deletion requests cannot remove data from the blockchain.

## Cookies and local storage

The marketing site sets no cookies. The dashboard uses one strictly necessary session cookie and one browser storage key. The hosted checkout sets no cookies. There are no advertising or analytics cookies anywhere. The [cookie policy](https://railbed.io/cookies/) lists each item.

## International transfers

Railbed runs on a global network, and our providers and partners operate in various countries. Your personal data may therefore be processed in countries other than your own, including countries whose data-protection laws differ from yours. Where the law requires it, we rely on appropriate safeguards for those transfers, such as contractual clauses approved for the purpose, and you can ask [privacy@railbed.io](mailto:privacy@railbed.io) for more information about them.

## Retention

We keep merchant account data while the account is open. After an account is closed, we keep what is needed for legal, tax, accounting, fraud-prevention and dispute purposes, and delete or anonymise the rest. Payment records are kept on the same basis, because merchants, providers and authorities may need them for disputes and compliance well after the payment. Request logs are held by our hosting provider under its own retention rules. Data on the public blockchain is permanent and is not held by us.

## Security

We protect personal data with HTTPS everywhere, salted password hashing, hashed API keys, signed webhooks, verified payment notifications, rate limiting and access controls. The [security page](https://railbed.io/security/) describes these in more detail. No system is perfectly secure, and you should keep your own passwords, keys and wallet safe.

## Your rights

Depending on where you live, you may have the right to:

- access the personal data we hold about you and receive a copy
- correct data that is inaccurate or incomplete
- delete your data, subject to the retention needs above and the limits of public blockchains
- receive your data in a portable format
- object to, or ask us to restrict, certain processing
- withdraw consent where processing is based on consent
- complain to a data protection authority

To exercise a right, write to [privacy@railbed.io](mailto:privacy@railbed.io). We may need to verify your identity before acting, and we will respond within the time the law allows. We do not discriminate against anyone for exercising their rights.

If you are a buyer, the merchant you paid is the controller of your checkout data, so contact the merchant first. You can also write to us, and we will help or pass the request to the merchant as appropriate. Requests about your card payment or identity check go to the provider that charged you.

## Children

The service is for businesses and adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided data to us, contact [privacy@railbed.io](mailto:privacy@railbed.io) and we will delete it.

## Changes

We may update this policy. The date at the top shows the latest version. For material changes we will notify merchants at their account email address or in the dashboard before the change takes effect.

## Contact

Privacy questions and data requests: [privacy@railbed.io](mailto:privacy@railbed.io). Other questions: see the [contact page](https://railbed.io/contact/).
