This Policy explains what Blockra ("we", "us") does with personal data across the dashboard, the hosted and embedded checkout, the API, and blockra.io.
It was written by going through the database schema and the application code, so it describes what the software actually does today rather than what a payment gateway typically does. Where something is not collected, it says so.
1. Two kinds of people, two different roles
- Merchants — businesses and individuals with a Blockra account. For their account data, Blockra is the controller.
- Payers — the customers who pay a merchant through a Blockra checkout. For their data, the merchant is the controller and Blockra is the processor, acting on the merchant's instructions under the Data Processing Agreement.
If you paid a merchant and want your data corrected or erased, contact that merchant. If you cannot reach them, contact us and we will pass it on.
2. What we collect from merchants
Account and identity
- Email address, name, and a password. The password is handled by Supabase Auth and stored as a bcrypt hash; we never see or store it in plain text.
- Optional avatar image.
Business profile
- Business name, legal business name, business type (individual or company), country, and website.
- Reporting currency, enabled coins, and logo.
Payout destinations
- Extended public keys (xpubs) for the chains you accept — one per chain. These are watch-only: they derive addresses and cannot sign. We validate on save that anything containing a private component is rejected.
- Your Stripe account identifier, if you connect Stripe, and your GoCardless organisation identifier and access token if you connect GoCardless. We never receive or store your login credentials for either. Both connections are made by you authorising us on the provider's own site, and both can be revoked from Blockra or from the provider.
Configuration
- Checkout and receipt settings, theme colours, custom domain, success and cancel URLs, expiry, notification preferences.
- If you configure your own SMTP server for receipts, the host, port, username and password you supply. These are stored so we can send on your behalf and are used for nothing else.
Security
- API keys as a SHA-256 hash plus the first eight characters.
- Two-factor authentication secret and one-time backup codes, if you enable it.
- A device identifier your browser generates at random, stored by us as a SHA-256 hash, plus the IP address and a label for each device you have verified. This is how we recognise a new sign-in and email you a code. It is not a browser fingerprint — we do not derive identity from your headers.
- Hashes of one-time email codes, which expire.
Billing
- Plan, interval, start and renewal dates, and the invoices we issue you.
- For your subscription's Direct Debit: the billing name and address you give us, your country and billing currency, the bank name and the last two or four digits of the account, the scheme and mandate status, and the outcome of each collection. In New Zealand, Sweden and Denmark, the national identifier the local scheme requires.
- Your full bank account number and sort code (or local equivalent) never reach Blockra. They are entered on a page hosted by GoCardless, who act as our processor for these collections. We hold a reference to the resulting mandate, not the account details behind it.
What we do not collect from merchants
We do not collect date of birth, home address, identity documents, or biometrics. Earlier versions of Blockra collected some of this for a verification flow that has been removed; the database columns still exist but nothing writes to them and no interface exposes them. They are scheduled for deletion.
3. What we process about payers
On the merchant's behalf, and only what the checkout needs:
- Email address, where the merchant requires it (for the receipt and to identify a repeat customer).
- Country, resolved at the CDN edge from the connecting IP. Optional IP-to-country lookup via a third party exists but is disabled by default.
- For card payments: name, country and postcode, passed to Stripe for the charge; and afterwards the card brand, last four digits, funding type, expiry month and year, and wallet used (e.g. Apple Pay). The card number and security code never touch Blockra's servers — they are entered into fields hosted by Stripe inside the checkout page.
- For bank payments: the payer's email address, passed to GoCardless to start the authorisation; and afterwards the payment status, currency, amount and expected clearing date. The payer's bank account details never touch Blockra's servers — the bank is chosen and the payment approved on pages hosted by GoCardless and the payer's own bank, under the merchant's GoCardless account.
- For crypto payments: the deposit address we derived for that invoice, the amount, the asset and network, transaction hashes, and confirmation counts. These are public blockchain facts once the payment is made.
- Payment record: amount, currency, the exchange rate captured at the time, status and timestamps, the merchant's own reference, and any metadata the merchant attached.
- A terms-acceptance flag, where the merchant requires it.
We do not ask payers for a street address, a phone number, or a date of birth. We do not place advertising or tracking identifiers on payers.
4. Website visitors
blockra.io sets no cookies of its own and loads no analytics or advertising scripts. What it stores in your browser, and why, is set out in the Cookie Policy.
5. Why we process it, and on what basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Provide the service | Account, business profile, xpubs, configuration | Performance of a contract |
| Take and watch payments | Payment records, addresses, chain data | Contract (merchant); processor for payer data |
| Send transactional email | Email address, message content | Contract |
| Secure the service | Device hashes, IP addresses, key hashes, MFA, rate-limit counters | Legitimate interests — keeping accounts and the platform secure |
| Bill for plans | Plan and billing dates | Contract |
| Support | Whatever you send us | Contract and legitimate interests |
| Meet legal obligations | Records of transactions | Legal obligation |
We do not process special-category data. We do not sell personal data, and we run no advertising.
6. Automated decision-making and AI
There is none. Blockra performs no profiling, no risk scoring, no automated decisions producing legal or similarly significant effects, and no machine-learning inference on your data.
Blockra contains no artificial intelligence or machine-learning component of any kind. No personal data — yours, your customers', or your support messages — is sent to any AI or LLM provider, or used to train any model. If that ever changes, this Policy will be updated before it does, and it will say exactly what changed.
7. Who else sees the data
We use a small number of processors. Each is contracted, each receives only what its function needs, and all are contacted from our servers rather than from your browser except where noted.
| Processor | What it does | What it sees |
|---|---|---|
| Supabase | Database and authentication hosting | Account, payment and configuration records; password hashes |
| Railway | API hosting | Requests in transit and application logs |
| Cloudflare | Hosting for the dashboard, checkout and website; custom checkout domains | Served content; visitor IP at the edge; country header |
| Stripe | Card processing, under the merchant's own Connect account | Card details entered by the payer, billing name, country, postcode, email, amount |
| GoCardless | Direct Debit collection of Blockra subscriptions; and bank payments at a merchant's checkout, under the merchant's own connected account | Bank account details entered by the payer or merchant, billing name and address, email, amount |
| Resend | Transactional email delivery | Recipient email address and message content |
| Upstash (Redis) | Rate limiting | IP address or account identifier, and counters |
| mempool.space, litecoinspace.org, an Ethereum RPC provider, TronGrid | Reading the blockchains | Deposit addresses and transaction data, which are public |
| Frankfurter | Foreign-exchange rates | No personal data — rates only |
| CoinGecko | Crypto prices | No personal data — prices only |
| ip-api.com | IP-to-country fallback, off by default | IP address, only if enabled |
If a merchant configures their own SMTP server, their receipts go through that server instead of Resend.
We also disclose data where we are legally required to, and to professional advisers under duty of confidence. If the business is sold or reorganised, data may transfer to the buyer under the same protections.
8. International transfers
Our processors operate internationally, so personal data may be processed outside the UK and EEA. Where it is, transfers rely on an adequacy decision or on Standard Contractual Clauses with the processor.
Blockchain data is inherently public and global. An address and the amount sent to it are visible to anyone, permanently, and are not something we can restrict, transfer under safeguards, or delete.
9. How long we keep it
- Account data — for as long as the account exists.
- Payment records — retained for record-keeping and tax after an account closes, with personal identifiers stripped (see below).
- Security records — device entries and IP addresses while the device stays trusted; one-time codes expire in minutes; rate-limit counters expire in seconds.
- Support email — for as long as needed to deal with the matter and a reasonable period after.
When you delete your account, we check that nothing is in flight, then remove your user and account records and anonymise the payment and customer rows attached to them: identifiers are stripped and the amounts and dates are kept as a financial record. Deletion is refused while payments are still open, so nothing is lost mid-flight.
We cannot delete anything from a blockchain. Addresses and transactions stay on-chain forever, by design and beyond anyone's control.
10. Your rights
If you are in the UK or EEA you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to portability. You can withdraw consent where processing relies on it, without affecting what came before.
Much of this is self-service: the dashboard lets you edit your profile, change your email, manage devices and two-factor authentication, and delete your account outright. For anything else, email support@blockra.io and we will respond within one month.
If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office (ICO), ico.org.uk.
11. How it is protected
Set out in full in the Security Policy. In summary: transport encryption everywhere, passwords hashed by Supabase Auth, API keys stored only as hashes, optional two-factor authentication, email verification of new devices, row-level security on the database, signed webhooks, and a guard that refuses to deliver webhooks to internal addresses.
The one that matters most is architectural: your crypto never passes through us, so a breach of Blockra cannot move it.
12. Children
Blockra is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, email support@blockra.io and we will delete it.
13. Changes
We will update this Policy as the service changes, and the "last updated" date at the top will change with it. Material changes are notified by email or in the dashboard.
14. Contact
Blockra
support@blockra.io