PayTree

Privacy Policy

Last updated: [EFFECTIVE DATE]

Template, not legal advice. Replace every [BRACKETED] item and have a licensed attorney review this document before you launch.

This Privacy Policy explains what [COMPANY LEGAL NAME] (“PayTree,” “we,” “us”) collects when you use PayTree, and how we use and protect it. It covers two groups of people: account holders who build pages, and visitors who view those pages.

1. Information from account holders

When you create and manage a page, we collect:

  • Account details: your email address, username, display name, bio and photo.
  • Payment details you choose to publish: handles, a Zelle email or phone number, bank routing and account numbers, a card checkout link, a Wise link and wallet addresses.
  • Subscription details: your plan, billing status, and the brand and last four digits of your card. Full card numbers are handled by [BILLING PROVIDER] and are not stored by us.
  • Messages you send to our support team.

2. Information from visitors

When someone views a PayTree page, we record:

  • that the page was viewed;
  • which payment button was tapped, and whether it opened an app or copied details;
  • the time of the action;
  • the website the visitor came from (the domain only), the type of device (mobile, tablet or desktop) and an approximate country.

We do not collect visitors’ names, email addresses or payment information, and we do not store visitor IP addresses or set cookies for analytics. [CONFIRM: matches your logging setup.]

3. Security logs

Our servers keep standard logs, which include IP addresses, for [LOG RETENTION PERIOD, for example 30 days]. We use them to detect abuse and keep the Service running.

4. How we use information

  • To provide, host and secure the Service and your page.
  • To show you statistics about views and taps.
  • To process subscriptions and send receipts and service messages.
  • To prevent fraud, abuse and violations of our Terms.
  • To comply with the law.
  • To improve the Service, using aggregated information that does not identify anyone.

5. Your public page

Everything you add to your page is public to anyone who has your link. The copy buttons give visitors the full value, including your complete bank account number if you add one. Think carefully about what you publish.

6. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We share information with service providers who help us run the Service under contract: [LIST OF PROVIDERS, for example hosting, database, email and billing].

We may disclose information to comply with the law or legal process, to protect rights, safety and security, or in a merger or sale of the business, with notice where required.

7. Cookies and similar technologies

We use cookies that are necessary to keep you signed in and to secure your account. We do not use advertising or cross-site tracking cookies, and visitor analytics do not use cookies.

We honor Global Privacy Control and Do Not Track signals by not recording analytics for visitors who send them. [CONFIRM before launch.]

8. How long we keep information

  • Account data: until you delete your account, then removed within [DELETION WINDOW, for example 30 days] unless the law requires us to keep it.
  • Analytics events: [ANALYTICS RETENTION PERIOD, for example 25 months].
  • Billing records: as long as tax and accounting law require.

9. Your choices and rights

You can update or delete your page details, and export or delete your data, from your account settings or by emailing [CONTACT EMAIL].

Residents of California and other states with privacy laws may have the right to know, access, correct, delete and obtain a copy of their personal information, and to opt out of the sale of personal information or targeted advertising, neither of which we do.

To make a request, email [CONTACT EMAIL]. We respond within 45 days, and we will not treat you differently for exercising your rights. If we decline a request, you may appeal by replying to our response.

10. Security

We use reasonable administrative, technical and physical safeguards, including encryption in transit. No method of transmission or storage is completely secure, so we cannot promise absolute security. Protect your password and tell us right away if you suspect unauthorized access.

11. Children

PayTree is not directed to anyone under 18, and we do not knowingly collect personal information from them. If you believe a child has given us information, contact us and we will delete it.

12. Where information is processed

The Service is operated in the United States and is intended for people in the United States. Information is processed and stored in the United States.

13. Changes to this policy

We may update this policy. We will post the new version here with a new date and, for material changes, notify account holders by email or in the dashboard.

14. Contact us

[COMPANY LEGAL NAME], [MAILING ADDRESS]. Privacy requests: [CONTACT EMAIL].