Payments Privacy
Version: 12 September 2026 · Vaultion Group Inc.
Accounts and checkout records
Vaultion Group Inc., registered in Seychelles, operates this service. Send privacy requests to [email protected]. This notice covers the merchant dashboard, hosted checkout and payment-linked escrow. The merchant’s website separately processes its own customer and order information.
We process merchant email addresses, account identifiers, merchant assignments, access state and access-change history to provide and secure merchant access. Sign-in codes are protected with a keyed hash and session tokens are stored hashed. Cloudflare processes the email recipient and sign-in message for delivery.
Checkout records include merchant/product identifiers, descriptions, order references, USD amounts, payment preferences, public wallet addresses, token amounts, quote evidence, session/attempt identifiers, transaction hashes, receipts and delivery status. Escrow adds the agreement reference, parties, contract, fee proof, escrow identifier and settlement history. These records support order matching, reconciliation, duplicate detection and support.
The WooCommerce gateway sends an order number and order-derived total, not billing names, customer emails, postal addresses or cart line items. Merchants control descriptions and references in custom products and shortcodes and should avoid unnecessary personal information in them.
The separate escrow form asks for party names, contact email addresses and agreement details. These are supplied in that form, not taken from the WooCommerce billing record. The existing escrow notification service stores pending invitations, subscriptions and delivery state in Cloudflare KV and sends messages through Resend. Both parties receive escrow updates from creation without a confirmation step, and every email carries an Unsubscribe link.
The hosted service stores API keys hashed. Callback secrets must remain usable for signing and are not stored as hashes alone. WordPress keeps connection credentials in server configuration or non-autoloaded options, plus Vaultion metadata and notes with orders. Keep those credentials and backups confidential.
Hosting, public networks and other services
Cloudflare provides hosting, D1 storage, request protection, operational logs and merchant sign-in email. It processes technical request data needed for these services. The merchant’s hosting provider, your wallet and blockchain RPC providers separately process requests needed to serve checkout and inspect or submit transactions.
Blockchain addresses, amounts, transaction hashes and escrow events are public and cannot be erased by Vaultion. Creating an escrow can publish its agreement metadata to IPFS through Pinata. Evidence submitted through the escrow interface can also be public. Do not upload private credentials or information you are unwilling to publish. Dispute reviewers process the evidence needed to review a case under the escrow process.
Kraken supplies public ETH/USD and USDC/USD trades. Price requests name the market pair and trade count; they do not contain account emails, merchant identifiers, order references or buyer addresses. Signed status notifications go to the merchant’s reviewed callback receiver. Operational alerts contain aggregate service health information rather than customer order details.
These providers and public networks may process information outside your country. The plugin does not collect wallet private keys or recovery phrases. The hosted sign-in and payment recovery features use necessary storage rather than advertising cookies.
Cookies, browser storage and retention
The merchant portal uses a ten-minute challenge cookie and an eight-hour session cookie, marked Secure, HttpOnly and SameSite=Strict. Signing out revokes that session. Expiry is enforced even when scheduled cleanup is delayed. Expired challenge, session and rate-limit rows are removed by scheduled cleanup.
Checkout saves payment attempt and transaction references in local storage for recovery. A payment-linked escrow also saves its fee and creation transaction references on vaultion.org. Clearing browser storage removes those local hints, not server or blockchain records.
Request-abuse controls use network IP information. Sign-in and edge throttle keys are hashed; this is a security measure, not a claim that the underlying requests are anonymous. Infrastructure may retain request logs under its configured settings.
Account, payment, receipt, callback and access-history records currently have no general automatic deletion schedule. They remain available for reconciliation, security and support until reviewed for deletion. Logs and backups are managed separately; deleting an active record does not immediately erase every backup. We do not promise a fixed deletion period that the service cannot enforce.
Your requests and changes
Email [email protected] to request access, correction, account closure or deletion. We verify your authority before disclosing or changing information. We will explain what can be removed and any records retained, including the reason. Account closure and record deletion are separate actions. Public blockchain and independently replicated IPFS records cannot be deleted by Vaultion.
Removing the plugin does not erase WooCommerce orders, saved connection options or hosted records. Merchants should review their own retention and privacy disclosures. The plugin supplies suggested text in the WordPress Privacy Policy Guide; it does not publish a store policy automatically.
This page is updated when the service’s data handling changes. The date below identifies this version of the disclosure.