Trust, Security & Global Compliance

Global Privacy Architecture

Luxor Pay is committed to data sovereignty, user privacy, and global regulatory compliance across non-custodial Web3 financial infrastructure and fiat gateway integrations.

Effective Date: August 24, 2026 | Version 2.4

1. Executive Privacy Architecture

Luxor Pay ("Luxor", "we", "us", or "our") operates a global decentralized payment infrastructure and merchant Web3 gateway. This Global Privacy Architecture explains how personal information, technical telemetry, and transactional metadata are processed when you interact with our web applications, developer APIs, payment links, and integrated fiat-to-crypto gateways (including third-party partners such as MoonPay).

Core Privacy Guarantee: Luxor Pay is built on non-custodial Web3 architecture. We do not store, control, or possess access to your private cryptographic keys, wallet seed phrases, or unencrypted financial credentials. You maintain full self-sovereignty over your digital assets at all times.

2. Information We Collect

We adhere strictly to the principle of Data Minimization under international regulations. The data collected depends on how you interact with the Luxor Pay infrastructure:

A. Public On-Chain Information

When executing transactions on the Solana blockchain through our interface, the following data is broadcast to the public blockchain network:

  • Public Wallet Addresses: Cryptographic public keys (e.g., Solana Base58 addresses) used to initiate or receive token payments.
  • On-Chain Metadata: Transaction signatures, timestamp, token amounts (SOL, USDC, LXR, EURC), smart contract interactions, and program instructions.

B. Merchant & Platform Profile Data

For registered merchants utilizing our point-of-sale (POS) and web checkout APIs:

  • Account Identity: Business name, email address, store domain, and tax identification (where mandated by local regulatory frameworks).
  • Authentication Telemetry: Firebase Auth tokens, IP addresses, browser user-agent, session identifiers, and device security metrics.

C. Third-Party Fiat On/Off-Ramp Data (MoonPay & Gateway Partners)

Luxor Pay integrates with regulated Virtual Asset Service Providers (VASPs) and licensed payment processors, including MoonPay Ltd, to facilitate fiat-to-crypto card processing, bank transfers, and local payout solutions.

  • KYC / Identity Verification: Know Your Customer (KYC), Know Your Business (KYB), Anti-Money Laundering (AML), and Identity Verification data (such as passports, government IDs, facial biometric verification, and proof of address) are collected and processed directly by MoonPay in accordance with MoonPay's Privacy Policy.
  • Payment Card & Banking Data: Credit card numbers, CVVs, and bank account details are handled exclusively by PCI-DSS Level 1 compliant processors (MoonPay, Stripe). Luxor Pay never receives, processes, or stores raw payment card numbers.

3. Global Regulatory Frameworks (GDPR, CCPA & CLOUD Act)

Luxor Pay maintains strict legal compliance across major international privacy jurisdictions:

European Union & UK GDPR (Articles 6 & 13)

We process personal data under the following legal bases:

  • Contractual Performance: To provide merchant payment link generation, transaction routing, and POS interface functionality.
  • Legal Compliance: To adhere to international Anti-Money Laundering (AML), Counter-Financing of Terrorism (CFT), and sanction screening mandates (OFAC, EU Sanctions).
  • Legitimate Interests: To detect fraud, prevent malicious network exploitation, optimize application performance, and maintain platform security.

California Consumer Privacy Act (CCPA / CPRA)

California residents possess specific rights regarding their personal information:

  • Right to Know & Access: Request disclosure of personal information collected over the preceding 12 months.
  • Right to Delete: Request deletion of off-chain personal records held in our databases.
  • No Sale of Personal Information: Luxor Pay does not sell, rent, or trade personal user data or merchant metadata to third-party data brokers or advertisers.

US CLOUD Act & International Law Enforcement Requests

In compliance with the US Clarifying Lawful Overseas Use of Data (CLOUD) Act and mutual legal assistance treaties (MLAT), Luxor Pay evaluates all valid subpoenas, court orders, and law enforcement requests. Data disclosures are heavily vetted by legal counsel and strictly restricted to lawfully mandated parameters.

4. Blockchain Immutability & Data Retention

It is important for all users of decentralized financial infrastructure to understand the inherent nature of blockchain technology:

Public Ledger Notice: Transactions broadcast to the Solana network are immutable, public, and permanently stored on decentralized validator nodes across the globe. Neither Luxor Pay nor any third party possesses the technical ability to modify, erase, or mask data recorded on-chain.

Off-chain data (such as merchant account settings and transactional logs) is retained for the minimal duration necessary to satisfy tax accounting laws, regulatory compliance mandates, and fraud prevention protocols (typically up to 5 to 7 years in accordance with global financial record retention standards).

5. Cryptographic Security & Privacy Enquiries

Luxor Pay implements military-grade AES-256 encryption for all data at rest and TLS 1.3 protocol for all transit channels. Our web infrastructure undergoes continuous automated security assessments and third-party code audits.

If you have questions regarding this Privacy Architecture, wish to exercise your data subject rights (GDPR/CCPA), or submit a formal compliance request, please contact our Legal & Privacy Office:

  • Data Protection Officer (DPO): privacy@luxorpay.app
  • Legal & Compliance Desk: legal@luxorpay.app
  • Official Ecosystem Portal: https://luxorpay.app