Outpay

Privacy Policy

Effective date: July 20, 2026
Last updated: July 20, 2026

Effective date: July 20, 2026 Last updated: July 20, 2026

Drafting notice: This document must be reviewed against Outpay’s production infrastructure, vendor contracts, data flows, retention controls, and applicable laws by qualified privacy counsel before publication. Remove this notice after approval.

1. About this Privacy Policy

Outpay is a product owned and operated by Adelecte, a incorporated under the laws of India (“Adelecte,” “Outpay,” “we,” “us,” or “our”).

Outpay provides non-custodial checkout, blockchain-payment verification, merchant-dashboard, API, webhook, and related services for supported digital assets, including USDC payments on the Base network.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use:

  • the Outpay website;
  • merchant accounts and dashboards;
  • hosted checkout pages;
  • checkout links;
  • APIs and software development tools;
  • webhooks and integrations;
  • documentation;
  • support services;
  • communications from Outpay; and
  • any other Outpay product or service that links to this Privacy Policy,

collectively, the “Services.”

It also explains the privacy rights and choices that may be available to you.

2. Scope

This Privacy Policy applies to personal information relating to:

  • merchants and prospective merchants;
  • merchant owners, employees, contractors, and representatives;
  • customers and other persons using an Outpay checkout;
  • developers using Outpay APIs or integrations;
  • website visitors;
  • support requesters;
  • business partners and vendors; and
  • other persons whose information Outpay processes in connection with the Services.

In this Policy, a business using Outpay is referred to as a “Merchant,” and a person attempting or completing a payment through an Outpay checkout is referred to as a “Payer.”

This Policy does not govern the independent privacy practices of:

  • Merchants;
  • wallet providers;
  • cryptocurrency exchanges;
  • blockchain protocols;
  • stablecoin issuers;
  • third-party websites;
  • third-party applications; or
  • other services that Outpay does not control.

Those organizations may process your information under their own privacy policies.

3. Our privacy roles

Our legal role depends on the context in which information is processed.

3.1 Outpay as an independent controller or business

Outpay generally determines why and how personal information is processed when we use information for:

  • account registration;
  • merchant onboarding;
  • authentication;
  • billing;
  • platform administration;
  • security;
  • fraud and abuse prevention;
  • sanctions and legal compliance;
  • service analytics;
  • product development;
  • customer support;
  • communications;
  • enforcing our agreements; and
  • protecting Outpay, Merchants, Payers, and third parties.

For these activities, Adelecte generally acts as the controller, business, data fiduciary, or equivalent entity under applicable privacy law.

3.2 Outpay acting for a Merchant

When Outpay processes Payer information solely to create, display, operate, or maintain a checkout on a Merchant’s instructions, the Merchant may be the controller or business and Outpay may act as its processor, service provider, contractor, or data processor.

The Merchant is responsible for:

  • providing any legally required privacy notice;
  • establishing an appropriate legal basis;
  • determining which customer information is collected;
  • responding to customer privacy requests;
  • entering into an appropriate data-processing agreement with Outpay where required; and
  • ensuring that its use of Outpay complies with applicable law.

3.3 Independent processing of checkout information

Even when Outpay processes checkout information for a Merchant, we may independently process limited information where necessary to:

  • secure the Services;
  • detect fraud or abuse;
  • verify blockchain transactions;
  • investigate incidents;
  • enforce our Terms;
  • satisfy legal obligations;
  • comply with sanctions requirements; or
  • protect the rights and safety of users and third parties.

4. What personal information means

Personal information” or “personal data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual or household.

Information may be personal information even when it does not directly contain a person’s name.

For example, a wallet address, transaction hash, device identifier, or IP address may be personal information when it can reasonably be connected to an identifiable person.

Personal information generally does not include information that has been lawfully anonymized or aggregated so that it cannot reasonably be linked to an individual.

5. Information you provide directly

We may collect information that you provide when you:

  • create an account;
  • register or update a Merchant profile;
  • configure a checkout;
  • add a receiving wallet;
  • invite a team member;
  • use an API or integration;
  • complete a compliance review;
  • contact support;
  • respond to a survey;
  • communicate with us; or
  • otherwise use the Services.

This may include:

5.1 Account and identity information

  • full name;
  • email address;
  • telephone number;
  • username;
  • profile image;
  • account identifier;
  • authentication-provider identifier;
  • password-derived authentication information;
  • multi-factor authentication settings;
  • role and account permissions; and
  • login and session information.

Outpay should not store passwords in readable form.

5.2 Merchant information

  • business name;
  • trading name;
  • registered legal name;
  • business address;
  • jurisdiction;
  • website;
  • industry;
  • business description;
  • support information;
  • ownership information;
  • authorized representatives;
  • tax or registration identifiers;
  • Merchant branding;
  • payout-wallet details; and
  • account configuration.

5.3 Verification and compliance information

Where required, we may collect:

  • government-issued identification information;
  • business registration documents;
  • beneficial ownership information;
  • director or controller information;
  • proof of address;
  • source-of-funds information;
  • source-of-wealth information;
  • transaction explanations;
  • sanctions-screening results;
  • compliance-review records; and
  • related correspondence.

We will seek to collect such information only where reasonably necessary for legal, compliance, fraud-prevention, or risk-management purposes.

5.4 Billing information

We may collect:

  • billing name;
  • billing address;
  • tax information;
  • subscription details;
  • invoice records;
  • fee calculations;
  • payment status; and
  • limited information returned by a billing provider.

Where a third-party billing provider processes payment-card or banking information, Outpay may not receive or retain the complete payment credentials.

5.5 Support and communication information

We may collect:

  • messages sent to support;
  • email correspondence;
  • complaint details;
  • troubleshooting information;
  • attachments;
  • survey responses;
  • meeting notes; and
  • records of actions taken to resolve a request.

6. Checkout and transaction information

When a checkout is created, viewed, attempted, or completed, we may collect:

  • checkout-session identifier;
  • Merchant identifier;
  • order or invoice reference;
  • product or service description;
  • amount requested;
  • supported digital asset;
  • blockchain network;
  • destination wallet address;
  • sending wallet address;
  • transaction hash;
  • token-contract address;
  • transaction amount;
  • block number;
  • block timestamp;
  • confirmation count;
  • checkout expiration time;
  • payment status;
  • failure or mismatch information;
  • refund-related information;
  • webhook-delivery status;
  • Merchant-provided metadata;
  • Payer-provided contact information;
  • IP address;
  • device and browser information; and
  • security and fraud signals.

A Merchant may choose to provide additional metadata. Merchants must not use checkout metadata to submit unnecessary or highly sensitive information.

7. Information collected automatically

When you access or use the Services, we may automatically collect:

  • IP address;
  • approximate location derived from IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language and regional settings;
  • referring page;
  • pages viewed;
  • buttons or features used;
  • timestamps;
  • session duration;
  • cookie and local-storage identifiers;
  • request and response metadata;
  • API request information;
  • authentication events;
  • error and crash information;
  • network and performance information;
  • webhook events;
  • rate-limit events;
  • security alerts; and
  • suspected fraudulent or abusive activity.

We may associate this information with your account, Merchant, checkout, device, or other identifiers.

8. Information from third parties

We may receive information from:

8.1 Merchants

A Merchant may provide:

  • a Payer’s name;
  • email address;
  • customer identifier;
  • order reference;
  • transaction details;
  • billing information;
  • product information; or
  • other checkout metadata.

8.2 Authentication providers

When you use a third-party login service, we may receive information such as:

  • your name;
  • email address;
  • profile image;
  • provider account identifier; and
  • authentication confirmation.

We do not receive your third-party account password.

8.3 Blockchain networks and infrastructure providers

We may collect or receive:

  • wallet addresses;
  • transaction hashes;
  • transfers;
  • token information;
  • smart-contract events;
  • block data;
  • confirmation information;
  • transaction status;
  • network identifiers; and
  • related public blockchain data.

8.4 Compliance and security providers

We may receive:

  • sanctions-screening results;
  • wallet-risk indicators;
  • fraud scores;
  • device-risk indicators;
  • abuse reports;
  • identity-verification results; and
  • cybersecurity intelligence.

8.5 Service providers and business partners

We may receive information from providers supporting:

  • cloud hosting;
  • databases;
  • communications;
  • billing;
  • analytics;
  • authentication;
  • customer support;
  • logging;
  • monitoring;
  • error reporting; and
  • infrastructure security.

8.6 Public sources

We may collect information from:

  • public blockchain records;
  • corporate registries;
  • sanctions lists;
  • government databases;
  • public websites;
  • court records;
  • professional directories; and
  • other lawfully accessible sources.

9. Information we do not require

Outpay does not require your:

  • private key;
  • seed phrase;
  • wallet recovery phrase;
  • wallet password; or
  • exchange password

to provide the Services.

Never submit private keys, seed phrases, recovery phrases, or wallet passwords to Outpay, a Merchant, or anyone claiming to represent Outpay.

Outpay personnel should never ask you to provide this information.

If such information is accidentally submitted, we may remove it from active systems where reasonably possible. However, you should immediately treat the affected wallet as compromised and transfer assets to a newly secured wallet.

10. Sensitive personal information

You must not submit sensitive personal information through checkout descriptions, metadata, support messages, or API fields unless:

  • Outpay specifically requests it;
  • it is strictly necessary;
  • you are legally authorized to provide it; and
  • an appropriate secure transmission method is used.

Sensitive information may include:

  • government identification numbers;
  • financial-account credentials;
  • precise geolocation;
  • health information;
  • biometric information;
  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • political opinions;
  • union membership;
  • sexual orientation;
  • immigration status; or
  • information relating to children.

Outpay may process limited sensitive information when required for authentication, account security, identity verification, sanctions compliance, fraud prevention, or legal obligations.

11. How we use personal information

We may use personal information to:

11.1 Provide the Services

  • create and manage accounts;
  • authenticate users;
  • create and display checkouts;
  • generate payment instructions;
  • detect supported blockchain transfers;
  • match transactions to checkout sessions;
  • update payment statuses;
  • deliver webhooks and notifications;
  • maintain Merchant dashboards;
  • provide APIs and developer tools;
  • calculate fees;
  • maintain records; and
  • provide customer support.

11.2 Secure the Services

  • protect accounts and credentials;
  • detect suspicious activity;
  • prevent fraud and abuse;
  • enforce rate limits;
  • detect malicious requests;
  • investigate security events;
  • prevent unauthorized access;
  • protect infrastructure; and
  • maintain audit records.

11.3 Comply with legal obligations

  • verify identities or businesses where required;
  • screen persons and wallets;
  • monitor transactions;
  • respond to legal process;
  • retain legally required records;
  • investigate prohibited activity;
  • enforce sanctions and geographic restrictions;
  • address regulatory enquiries; and
  • make legally required reports.

11.4 Communicate with you

  • send account and security notices;
  • send payment-status notifications;
  • send checkout-related communications;
  • answer support requests;
  • provide service announcements;
  • request information;
  • send invoices;
  • communicate policy changes; and
  • send marketing communications where permitted.

11.5 Improve and administer Outpay

  • understand feature usage;
  • diagnose errors;
  • monitor performance;
  • improve reliability;
  • develop new features;
  • conduct testing;
  • generate aggregated statistics;
  • plan infrastructure capacity;
  • measure product effectiveness; and
  • manage business operations.

11.6 Protect rights and enforce agreements

  • enforce our Terms of Service;
  • investigate complaints;
  • resolve disputes;
  • protect Outpay’s legal rights;
  • prevent harm;
  • establish, exercise, or defend legal claims; and
  • protect Merchants, Payers, partners, and third parties.

12. Legal bases for processing

Where applicable law requires us to identify a legal basis, we may process personal information on the following bases:

12.1 Performance of a contract

Processing may be necessary to:

  • create and maintain your account;
  • provide requested Services;
  • operate checkouts;
  • verify payments;
  • deliver notifications;
  • provide support; and
  • administer billing.

12.2 Legitimate interests

We may process information for legitimate business interests, including:

  • securing the Services;
  • preventing fraud and abuse;
  • maintaining infrastructure;
  • improving Outpay;
  • understanding product usage;
  • protecting legal rights;
  • supporting Merchants and Payers; and
  • conducting ordinary business administration.

Where required, we balance these interests against your rights and reasonable expectations.

12.3 Legal obligations

Processing may be necessary to comply with:

  • applicable laws;
  • court orders;
  • sanctions requirements;
  • tax and accounting requirements;
  • record-keeping requirements;
  • regulatory enquiries; and
  • valid legal process.

12.4 Consent

We may rely on consent for:

  • optional cookies;
  • certain analytics;
  • marketing communications;
  • specific voluntary features; or
  • other processing where consent is required.

You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.

12.5 Protection of vital interests

In exceptional circumstances, we may process information where necessary to protect a person’s life, safety, or vital interests.

13. Merchant responsibilities

Merchants using Outpay must:

  • provide an accurate privacy notice to their customers;
  • collect only information reasonably necessary for the transaction;
  • have a lawful basis for providing personal information to Outpay;
  • obtain legally required consent;
  • honour applicable privacy rights;
  • use secure integration methods;
  • limit employee and contractor access;
  • avoid placing sensitive data in checkout metadata;
  • maintain accurate customer records;
  • notify Outpay of relevant privacy requests;
  • promptly report suspected incidents; and
  • enter into a data-processing agreement where legally required.

A Merchant must not instruct Outpay to process information unlawfully.

Outpay may reject or suspend processing instructions that we reasonably believe violate applicable law, our policies, or the rights of an individual.

14. Public blockchain information

Blockchain networks are generally public, distributed, and resistant to alteration.

When a transaction is broadcast, information such as the following may become publicly visible:

  • sending wallet address;
  • receiving wallet address;
  • transaction hash;
  • token type;
  • token-contract address;
  • amount;
  • network;
  • block number;
  • timestamp;
  • smart-contract interactions; and
  • transaction history.

This information may be:

  • viewed by anyone;
  • copied by third parties;
  • indexed by search or analytics services;
  • combined with other information;
  • transferred internationally;
  • retained indefinitely; and
  • used to associate a wallet with an individual or organization.

Outpay does not control blockchain validators, node operators, indexers, explorers, or other network participants.

Outpay cannot delete, modify, obscure, reverse, or guarantee the confidentiality of information already recorded on a public blockchain.

A successful request to delete information from Outpay’s off-chain systems will not remove corresponding public blockchain records.

15. Automated processing and risk analysis

Outpay may use automated systems to:

  • detect blockchain payments;
  • match transfers to checkouts;
  • assign payment statuses;
  • detect duplicate or mismatched payments;
  • identify suspicious account activity;
  • identify sanctioned or high-risk wallets;
  • detect fraud, abuse, or prohibited activity;
  • prioritize security investigations; and
  • decide whether additional review is required.

These systems may use:

  • account information;
  • transaction details;
  • public blockchain history;
  • IP and device information;
  • behavioural signals;
  • provider-generated risk indicators; and
  • compliance information.

Automated results may cause:

  • a payment to remain pending;
  • a transaction to be flagged;
  • additional verification to be requested;
  • a wallet or checkout to be restricted;
  • a notification to be delayed;
  • an account to be reviewed; or
  • access to be temporarily suspended.

Where required by applicable law, you may request information about relevant automated processing, object to qualifying decisions, or request human review.

Outpay does not guarantee that automated payment or risk assessments are error-free.

16. How we disclose personal information

We may disclose personal information as described below.

16.1 Merchants and Payers

We may provide Merchants with information needed to:

  • identify a checkout;
  • verify a transaction;
  • associate payment with an order;
  • provide support;
  • handle refunds;
  • investigate mismatches; or
  • resolve disputes.

A checkout may display Merchant information to a Payer, including:

  • Merchant name;
  • logo;
  • support details;
  • product description;
  • receiving wallet;
  • requested amount; and
  • payment instructions.

16.2 Service providers

We may disclose information to providers supporting:

  • hosting;
  • cloud infrastructure;
  • databases;
  • authentication;
  • blockchain nodes and RPC services;
  • blockchain indexing;
  • transaction monitoring;
  • fraud prevention;
  • sanctions screening;
  • billing;
  • email delivery;
  • customer support;
  • analytics;
  • logging;
  • performance monitoring;
  • error reporting;
  • data storage;
  • cybersecurity; and
  • professional services.

These providers may process information only for contracted purposes, subject to applicable agreements and legal obligations.

16.3 Professional advisers

We may disclose information to:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • consultants; and
  • other professional advisers

where reasonably necessary to obtain advice, manage risk, comply with law, or protect legal rights.

16.4 Authorities and legal process

We may disclose information where we reasonably believe disclosure is required or permitted to:

  • comply with law;
  • respond to a subpoena, warrant, court order, or other valid process;
  • respond to a regulatory authority;
  • comply with sanctions requirements;
  • report suspected unlawful activity;
  • investigate fraud or security incidents;
  • protect the rights or safety of a person;
  • enforce our agreements; or
  • establish, exercise, or defend legal claims.

We may challenge requests that we reasonably consider invalid, excessive, unlawful, or inconsistent with applicable rights.

16.5 Corporate transactions

Information may be disclosed in connection with:

  • financing;
  • due diligence;
  • restructuring;
  • incorporation or reorganization;
  • merger;
  • acquisition;
  • investment;
  • transfer of assets;
  • sale of the Outpay business;
  • insolvency; or
  • a similar corporate transaction.

Any recipient will be required to process personal information consistently with applicable law.

16.6 With your direction or consent

We may disclose information when you request, authorize, or consent to the disclosure.

17. Subprocessors

Outpay may use subprocessors to provide and secure the Services.

Our Subprocessor List should identify, as applicable:

  • each material provider;
  • the service it provides;
  • its processing location; and
  • the categories of information involved.

Merchants may contact us to request the current Subprocessor List.

Where required by contract or applicable law, we will provide notice of material changes to subprocessors and an appropriate mechanism to raise reasonable data-protection objections.

18. Sale, sharing, and advertising

Outpay does not sell personal information for monetary consideration.

As of the effective date of this Policy, Outpay does not:

  • rent personal information;
  • operate as a data broker;
  • sell personal information as defined by applicable privacy law; or
  • share personal information for cross-context behavioural advertising.

Outpay does not use Payer transaction data to target third-party advertisements.

We may use service analytics to understand and improve Outpay. Where analytics or similar technologies require consent, we will seek consent before using them.

If these practices change, we will update this Policy and provide any legally required notices and opt-out mechanisms before beginning the new activity.

19. Communications

19.1 Operational communications

We may send communications necessary to provide the Services, including:

  • login alerts;
  • security notices;
  • payment notifications;
  • checkout notifications;
  • billing messages;
  • service updates;
  • compliance requests;
  • support responses; and
  • legal notices.

You may not be able to opt out of essential operational communications while maintaining an active account.

19.2 Marketing communications

Where permitted, we may send:

  • product announcements;
  • feature updates;
  • educational content;
  • event invitations; or
  • promotional messages.

You may unsubscribe using the mechanism included in the communication or by contacting us.

Unsubscribing from marketing does not stop essential operational communications.

20. Cookies and similar technologies

Outpay may use:

  • cookies;
  • local storage;
  • session storage;
  • software development kit identifiers;
  • pixels;
  • tags;
  • server logs; and
  • similar technologies.

These technologies may be used for:

20.1 Strictly necessary purposes

  • authentication;
  • session management;
  • security;
  • fraud prevention;
  • load balancing;
  • network routing;
  • saving privacy preferences; and
  • maintaining checkout functionality.

20.2 Functional purposes

  • remembering settings;
  • maintaining interface preferences;
  • supporting language choices; and
  • improving user experience.

20.3 Analytics purposes

  • understanding site usage;
  • measuring feature adoption;
  • diagnosing performance problems; and
  • improving the Services.

20.4 Advertising purposes

Outpay does not currently use cookies to provide cross-context behavioural advertising.

Where legally required, non-essential technologies will not be activated until you provide consent.

You may manage available choices through Outpay’s cookie settings or your browser settings. Blocking strictly necessary technologies may prevent parts of the Services from functioning.

A separate Cookie Policy should identify the actual technologies, providers, purposes, and expiration periods used in production.

21. Browser privacy signals

Some browsers provide signals such as:

  • Do Not Track;
  • Global Privacy Control; or
  • other opt-out preference signals.

Where applicable law requires us to recognize a valid browser-based opt-out signal, we will process it as required for the browser or device from which the signal is received.

Because Outpay does not currently sell personal information or share it for cross-context behavioural advertising, such signals may not change our present processing practices.

22. International processing and transfers

Outpay and its service providers may process personal information outside the country or region where you live, including in Canada, United States of Amercica and India.

The privacy, data-protection, surveillance, and government-access laws of those jurisdictions may differ from those in your home jurisdiction.

Where required, we use recognized safeguards for international transfers, which may include:

  • adequacy decisions;
  • standard contractual clauses;
  • contractual data-protection terms;
  • transfer-risk assessments;
  • data-processing agreements;
  • access controls;
  • encryption;
  • supplementary technical measures; or
  • another legally recognized transfer mechanism.

You may contact us for additional information about applicable transfer safeguards, subject to confidentiality and security restrictions.

23. Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to:

  • provide the Services;
  • maintain transaction and audit records;
  • comply with legal obligations;
  • prevent fraud and abuse;
  • resolve disputes;
  • enforce agreements;
  • support security investigations;
  • satisfy tax and accounting obligations; and
  • establish or defend legal claims.

Our anticipated standard retention periods are:

| Information category | Standard retention period | | ------------------------------------------------------------- | ---------------------------------------------------------------------------------------: | | Merchant account, profile, agreements, and billing records | Active account period plus 7 years | | Checkout, payment, transaction, fee, and audit records | 7 years from the transaction or account closure | | KYB, identity-verification, sanctions, and compliance records | 5 years after the relationship or relevant transaction, or longer where legally required | | Authentication, API, access, and security logs | Up to 24 months | | Fraud and abuse investigation records | Up to 7 years after the investigation closes | | Support communications | 3 years after the request is closed | | Marketing preferences and consent records | While active and up to 3 years after withdrawal | | Abandoned or incomplete onboarding records | Up to 90 days, unless needed for security or compliance | | Non-essential analytics identifiers | Up to 13 months unless a shorter period is disclosed | | Encrypted backup copies | Generally overwritten within 90 days |

We may retain information for a longer period where:

  • required by law;
  • required by a regulator;
  • necessary for litigation;
  • necessary to investigate fraud or abuse;
  • subject to a legal hold;
  • necessary to protect a person; or
  • deletion would undermine the security or integrity of the Services.

We may retain anonymized or aggregated information that cannot reasonably identify an individual.

Deleting information from active systems may not immediately remove copies from encrypted backups. Backup information will be isolated from normal use and removed through the ordinary backup lifecycle.

Public blockchain information may remain available indefinitely and is outside Outpay’s control.

24. Security

We use administrative, technical, and organizational safeguards designed to protect personal information according to its sensitivity.

These safeguards may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • access controls;
  • least-privilege permissions;
  • multi-factor authentication;
  • environment separation;
  • credential management;
  • network protections;
  • audit logging;
  • monitoring and alerting;
  • vulnerability management;
  • dependency and patch management;
  • secure development practices;
  • provider due diligence;
  • incident-response procedures;
  • employee confidentiality obligations; and
  • backup and recovery controls.

No internet, cloud, wallet, blockchain, or information-storage system is completely secure.

We cannot guarantee that unauthorized access, loss, misuse, alteration, disclosure, or destruction will never occur.

You are responsible for:

  • securing your devices;
  • protecting authentication credentials;
  • enabling available security features;
  • restricting account access;
  • securing API keys and webhook secrets;
  • maintaining wallet security; and
  • notifying us promptly of suspected compromise.

25. Security incidents

If we discover a security incident involving personal information, we will:

  • investigate the incident;
  • take reasonable containment and remediation measures;
  • preserve relevant evidence;
  • assess the likely risk to affected individuals;
  • notify affected persons where required; and
  • notify regulators or authorities where legally required.

Notification timing and content may depend on:

  • the nature of the incident;
  • the information involved;
  • the risk of harm;
  • law-enforcement restrictions;
  • remediation status; and
  • applicable law.

Security concerns may be reported to legal@outpay.tech.

26. Your privacy rights

Depending on where you live and applicable law, you may have the right to:

  • know whether we process your personal information;
  • receive information about our processing;
  • access personal information;
  • obtain a copy of personal information;
  • correct inaccurate or incomplete information;
  • request deletion or erasure;
  • request restriction of processing;
  • object to certain processing;
  • withdraw consent;
  • request data portability;
  • opt out of marketing;
  • opt out of qualifying sales or targeted advertising;
  • limit certain uses of sensitive information;
  • object to or request review of certain automated decisions;
  • nominate another person to exercise rights in specified circumstances;
  • appeal the denial of a request;
  • challenge our compliance; and
  • complain to a privacy or data-protection authority.

These rights are not absolute.

We may refuse or limit a request where permitted or required because:

  • we cannot verify the requester;
  • the information relates to another person;
  • retention is legally required;
  • the information is subject to privilege;
  • disclosure would create a security risk;
  • the request is manifestly unfounded or excessive;
  • the information is required to prevent fraud;
  • the information is needed for legal claims;
  • an applicable exemption applies; or
  • we are processing the information solely for a Merchant.

27. Exercising your rights

To submit a privacy request, contact:

Privacy Officer Tharun Pranav Sakthivel Email: legal@outpay.tech

Please include:

  • your name;
  • your account email, where applicable;
  • the nature of your request;
  • the Merchant or checkout involved, if relevant; and
  • enough information for us to locate the applicable records.

We may request additional information to verify your identity and authority.

We will not request your private key, seed phrase, or wallet recovery phrase to verify a privacy request.

Where permitted, an authorized agent may make a request for you. We may require evidence of the agent’s authority and may verify your identity directly.

We will respond within the period required by applicable law.

Where permitted, we may charge a reasonable fee or refuse requests that are manifestly unfounded, repetitive, excessive, fraudulent, or abusive.

We will not unlawfully discriminate against you for exercising a privacy right.

28. Requests involving Merchant-controlled information

If your request concerns information collected by a Merchant through an Outpay checkout, you should ordinarily contact the Merchant first.

Where Outpay acts solely as a processor or service provider:

  • we may direct your request to the Merchant;
  • we may notify the Merchant;
  • we may assist the Merchant as required by contract or law; and
  • we may not be authorized to respond independently.

If you cannot identify or contact the Merchant, you may contact us with the checkout identifier and relevant details.

29. Canadian privacy rights

Where Canadian private-sector privacy law applies, you may request:

  • information about the existence of your personal information;
  • access to personal information under our control;
  • information about how it has been used;
  • information about relevant disclosures;
  • correction of inaccurate information; and
  • information about our privacy practices.

You may also challenge our compliance by contacting our Privacy Officer.

Access may be restricted where permitted or required by law, including where disclosure would reveal:

  • another individual’s information;
  • confidential commercial information;
  • legally privileged information;
  • information generated in a dispute-resolution process; or
  • information that could threaten safety or security.

You may also submit a complaint to the applicable federal or provincial privacy commissioner.

30. European Economic Area, Switzerland, and United Kingdom

Where European or United Kingdom data-protection law applies:

30.1 Controller

The controller for Outpay’s independent processing is:

Adelecte Email: legal@outpay.tech

30.2 Representatives

Where legally required, Outpay will in future appoint representatives.

30.3 Rights

You may have rights to:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • consent withdrawal; and
  • protection relating to qualifying automated decisions.

You may object to processing based on legitimate interests. We will stop the processing unless we demonstrate compelling legitimate grounds or require it for legal claims.

You may lodge a complaint with the data-protection authority in your country of residence, place of work, or location of the alleged infringement.

31. California privacy disclosures

This section applies only where Outpay is subject to the California Consumer Privacy Act, as amended.

31.1 Categories collected

During the preceding twelve months, Outpay may have collected the following categories:

| California category | Examples collected by Outpay | | ------------------------------ | ----------------------------------------------------------------------- | | Identifiers | Name, email, account ID, IP address, device identifiers, wallet address | | Customer-record information | Business contact information, billing information, support information | | Commercial information | Checkouts, transaction records, subscriptions, products, fees | | Internet or network activity | Browsing activity, login events, API usage, request logs | | Geolocation information | Approximate location derived from IP address | | Professional information | Business role, organization, Merchant relationship | | Inferences | Fraud, abuse, security, or transaction-risk indicators | | Sensitive personal information | Account credentials and limited compliance information where required |

31.2 Sources

We may obtain these categories from:

  • you;
  • Merchants;
  • your device or browser;
  • authentication providers;
  • public blockchains;
  • infrastructure providers;
  • compliance providers;
  • security providers; and
  • public records.

31.3 Business purposes

We use these categories for the purposes described in Sections 11 and 15, including:

  • providing the Services;
  • authentication;
  • security;
  • fraud prevention;
  • transaction verification;
  • customer support;
  • compliance;
  • analytics; and
  • business administration.

31.4 Disclosures

We may disclose these categories to:

  • Merchants;
  • service providers;
  • contractors;
  • professional advisers;
  • authorities; and
  • parties to a qualifying corporate transaction.

31.5 Sales and sharing

Outpay has not sold personal information for monetary consideration during the preceding twelve months.

Outpay has not shared personal information for cross-context behavioural advertising during the preceding twelve months.

We do not knowingly sell or share the personal information of persons under sixteen years of age.

31.6 California rights

Subject to applicable conditions and exceptions, California residents may request:

  • disclosure of categories and specific pieces of information;
  • deletion;
  • correction;
  • opt-out of sale or sharing;
  • limitation of qualifying sensitive-information use; and
  • equal treatment when exercising their rights.

32. India privacy disclosures

Where India’s Digital Personal Data Protection framework applies, Adelecte may act as a “Data Fiduciary,” and an individual may be referred to as a “Data Principal.”

We will process digital personal data:

  • for lawful purposes;
  • with valid consent where required;
  • for recognized legitimate uses where permitted;
  • with reasonable security safeguards; and
  • only for as long as processing remains necessary or legally required.

Subject to applicable law and commencement provisions, individuals may have rights to:

  • obtain information about processing;
  • request correction;
  • request completion or updating;
  • request erasure;
  • submit a grievance; and
  • nominate another individual to exercise specified rights in the event of death or incapacity.

Requests and grievances may be sent to:

Grievance and Privacy Contact Adelecte Email: legal@outpay.tech

33. Children

The Services are intended for persons who are at least eighteen years old.

Outpay does not knowingly offer accounts to children or knowingly collect personal information directly from children for independent purposes.

Merchants must not use Outpay to intentionally collect or process children’s information unless:

  • the activity is lawful;
  • all required parental or guardian permissions have been obtained;
  • the Merchant has received Outpay’s prior written approval; and
  • appropriate protections have been implemented.

If you believe a child has provided personal information to Outpay, contact us so that we can investigate and take appropriate action.

34. Data accuracy

We take reasonable steps to maintain information that is sufficiently accurate, complete, and current for the purposes for which it is used.

You are responsible for keeping your:

  • account information;
  • Merchant details;
  • support contact;
  • ownership information;
  • wallet address;
  • billing information; and
  • team access

accurate and current.

Outpay is not responsible for inaccurate information supplied by a Merchant, Payer, blockchain network, wallet, provider, or public source.

35. Anonymized and aggregated information

We may create anonymized, de-identified, or aggregated information for:

  • analytics;
  • security research;
  • capacity planning;
  • product development;
  • performance reporting;
  • business intelligence; and
  • industry insights.

We will not attempt to re-identify lawfully de-identified information except:

  • to test whether de-identification controls are effective;
  • where legally permitted; or
  • where necessary to protect security.

36. Third-party services and links

The Services may link to or interoperate with:

  • Merchant websites;
  • wallets;
  • exchanges;
  • blockchain explorers;
  • authentication providers;
  • analytics services;
  • social platforms; and
  • other third-party services.

Outpay is not responsible for the privacy, security, accuracy, availability, or conduct of third-party services.

You should review their privacy policies before providing information or connecting an account.

37. Business users and employee information

If you use Outpay on behalf of an organization, your employer or organization may:

  • manage your account;
  • view your activity;
  • modify your permissions;
  • access information associated with the Merchant account;
  • suspend your access; or
  • request deletion of your access.

Questions about your organization’s use of your information should generally be directed to that organization.

38. Changes to this Privacy Policy

We may update this Policy to reflect changes to:

  • our Services;
  • data practices;
  • subprocessors;
  • legal obligations;
  • security controls;
  • supported jurisdictions; or
  • business operations.

We will post the revised Policy with an updated effective date.

Where required, we will provide additional notice through:

  • the website;
  • the dashboard;
  • email;
  • an account notification; or
  • another appropriate communication channel.

Where consent is legally required for a material new use of personal information, we will request consent before beginning that use.

39. Contact and complaints

Outpay is a product of Adelecte.

Legal entity: Adelecte Privacy Officer: Tharun Pranav Sakthivel Privacy, legal, security, and support enquiries: legal@outpay.tech

We will investigate privacy complaints and respond within the period required by applicable law.

If you remain dissatisfied, you may have the right to submit a complaint to the privacy, data-protection, or consumer-protection authority with jurisdiction over your complaint.

---

© 2026 Adelecte. All rights reserved. Outpay is a product of Adelecte. Non-custodial checkout and payment verification for supported digital assets.

Questions about this document? Contact us at legal@outpay.tech.
© 2026 Outpay. Non-custodial checkout for USDC on Base.