Privacy Policy

Every category of personal data Blockra holds, why, who else sees it, and how long it is kept — written from the code, not from a template.

Last updated August 2, 2026

This Policy explains what Blockra ("we", "us") does with personal data across the dashboard, the hosted and embedded checkout, the API, and blockra.io.

It was written by going through the database schema and the application code, so it describes what the software actually does today rather than what a payment gateway typically does. Where something is not collected, it says so.

1. Two kinds of people, two different roles

  • Merchants — businesses and individuals with a Blockra account. For their account data, Blockra is the controller.
  • Payers — the customers who pay a merchant through a Blockra checkout. For their data, the merchant is the controller and Blockra is the processor, acting on the merchant's instructions under the Data Processing Agreement.

If you paid a merchant and want your data corrected or erased, contact that merchant. If you cannot reach them, contact us and we will pass it on.

2. What we collect from merchants

Account and identity

  • Email address, name, and a password. The password is handled by Supabase Auth and stored as a bcrypt hash; we never see or store it in plain text.
  • Optional avatar image.

Business profile

  • Business name, legal business name, business type (individual or company), country, and website.
  • Reporting currency, enabled coins, and logo.

Payout destinations

  • Extended public keys (xpubs) for the chains you accept — one per chain. These are watch-only: they derive addresses and cannot sign. We validate on save that anything containing a private component is rejected.
  • Your Stripe account identifier, if you connect Stripe, and your GoCardless organisation identifier and access token if you connect GoCardless. We never receive or store your login credentials for either. Both connections are made by you authorising us on the provider's own site, and both can be revoked from Blockra or from the provider.

Configuration

  • Checkout and receipt settings, theme colours, custom domain, success and cancel URLs, expiry, notification preferences.
  • If you configure your own SMTP server for receipts, the host, port, username and password you supply. These are stored so we can send on your behalf and are used for nothing else.

Security

  • API keys as a SHA-256 hash plus the first eight characters.
  • Two-factor authentication secret and one-time backup codes, if you enable it.
  • A device identifier your browser generates at random, stored by us as a SHA-256 hash, plus the IP address and a label for each device you have verified. This is how we recognise a new sign-in and email you a code. It is not a browser fingerprint — we do not derive identity from your headers.
  • Hashes of one-time email codes, which expire.

Billing

  • Plan, interval, start and renewal dates, and the invoices we issue you.
  • For your subscription's Direct Debit: the billing name and address you give us, your country and billing currency, the bank name and the last two or four digits of the account, the scheme and mandate status, and the outcome of each collection. In New Zealand, Sweden and Denmark, the national identifier the local scheme requires.
  • Your full bank account number and sort code (or local equivalent) never reach Blockra. They are entered on a page hosted by GoCardless, who act as our processor for these collections. We hold a reference to the resulting mandate, not the account details behind it.

What we do not collect from merchants

We do not collect date of birth, home address, identity documents, or biometrics. Earlier versions of Blockra collected some of this for a verification flow that has been removed; the database columns still exist but nothing writes to them and no interface exposes them. They are scheduled for deletion.

3. What we process about payers

On the merchant's behalf, and only what the checkout needs:

  • Email address, where the merchant requires it (for the receipt and to identify a repeat customer).
  • Country, resolved at the CDN edge from the connecting IP. Optional IP-to-country lookup via a third party exists but is disabled by default.
  • For card payments: name, country and postcode, passed to Stripe for the charge; and afterwards the card brand, last four digits, funding type, expiry month and year, and wallet used (e.g. Apple Pay). The card number and security code never touch Blockra's servers — they are entered into fields hosted by Stripe inside the checkout page.
  • For bank payments: the payer's email address, passed to GoCardless to start the authorisation; and afterwards the payment status, currency, amount and expected clearing date. The payer's bank account details never touch Blockra's servers — the bank is chosen and the payment approved on pages hosted by GoCardless and the payer's own bank, under the merchant's GoCardless account.
  • For crypto payments: the deposit address we derived for that invoice, the amount, the asset and network, transaction hashes, and confirmation counts. These are public blockchain facts once the payment is made.
  • Payment record: amount, currency, the exchange rate captured at the time, status and timestamps, the merchant's own reference, and any metadata the merchant attached.
  • A terms-acceptance flag, where the merchant requires it.

We do not ask payers for a street address, a phone number, or a date of birth. We do not place advertising or tracking identifiers on payers.

4. Website visitors

blockra.io sets no cookies of its own and loads no analytics or advertising scripts. What it stores in your browser, and why, is set out in the Cookie Policy.

5. Why we process it, and on what basis

PurposeDataLawful basis
Provide the serviceAccount, business profile, xpubs, configurationPerformance of a contract
Take and watch paymentsPayment records, addresses, chain dataContract (merchant); processor for payer data
Send transactional emailEmail address, message contentContract
Secure the serviceDevice hashes, IP addresses, key hashes, MFA, rate-limit countersLegitimate interests — keeping accounts and the platform secure
Bill for plansPlan and billing datesContract
SupportWhatever you send usContract and legitimate interests
Meet legal obligationsRecords of transactionsLegal obligation

We do not process special-category data. We do not sell personal data, and we run no advertising.

6. Automated decision-making and AI

There is none. Blockra performs no profiling, no risk scoring, no automated decisions producing legal or similarly significant effects, and no machine-learning inference on your data.

Blockra contains no artificial intelligence or machine-learning component of any kind. No personal data — yours, your customers', or your support messages — is sent to any AI or LLM provider, or used to train any model. If that ever changes, this Policy will be updated before it does, and it will say exactly what changed.

7. Who else sees the data

We use a small number of processors. Each is contracted, each receives only what its function needs, and all are contacted from our servers rather than from your browser except where noted.

ProcessorWhat it doesWhat it sees
SupabaseDatabase and authentication hostingAccount, payment and configuration records; password hashes
RailwayAPI hostingRequests in transit and application logs
CloudflareHosting for the dashboard, checkout and website; custom checkout domainsServed content; visitor IP at the edge; country header
StripeCard processing, under the merchant's own Connect accountCard details entered by the payer, billing name, country, postcode, email, amount
GoCardlessDirect Debit collection of Blockra subscriptions; and bank payments at a merchant's checkout, under the merchant's own connected accountBank account details entered by the payer or merchant, billing name and address, email, amount
ResendTransactional email deliveryRecipient email address and message content
Upstash (Redis)Rate limitingIP address or account identifier, and counters
mempool.space, litecoinspace.org, an Ethereum RPC provider, TronGridReading the blockchainsDeposit addresses and transaction data, which are public
FrankfurterForeign-exchange ratesNo personal data — rates only
CoinGeckoCrypto pricesNo personal data — prices only
ip-api.comIP-to-country fallback, off by defaultIP address, only if enabled

If a merchant configures their own SMTP server, their receipts go through that server instead of Resend.

We also disclose data where we are legally required to, and to professional advisers under duty of confidence. If the business is sold or reorganised, data may transfer to the buyer under the same protections.

8. International transfers

Our processors operate internationally, so personal data may be processed outside the UK and EEA. Where it is, transfers rely on an adequacy decision or on Standard Contractual Clauses with the processor.

Blockchain data is inherently public and global. An address and the amount sent to it are visible to anyone, permanently, and are not something we can restrict, transfer under safeguards, or delete.

9. How long we keep it

  • Account data — for as long as the account exists.
  • Payment records — retained for record-keeping and tax after an account closes, with personal identifiers stripped (see below).
  • Security records — device entries and IP addresses while the device stays trusted; one-time codes expire in minutes; rate-limit counters expire in seconds.
  • Support email — for as long as needed to deal with the matter and a reasonable period after.

When you delete your account, we check that nothing is in flight, then remove your user and account records and anonymise the payment and customer rows attached to them: identifiers are stripped and the amounts and dates are kept as a financial record. Deletion is refused while payments are still open, so nothing is lost mid-flight.

We cannot delete anything from a blockchain. Addresses and transactions stay on-chain forever, by design and beyond anyone's control.

10. Your rights

If you are in the UK or EEA you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to portability. You can withdraw consent where processing relies on it, without affecting what came before.

Much of this is self-service: the dashboard lets you edit your profile, change your email, manage devices and two-factor authentication, and delete your account outright. For anything else, email support@blockra.io and we will respond within one month.

If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office (ICO), ico.org.uk.

11. How it is protected

Set out in full in the Security Policy. In summary: transport encryption everywhere, passwords hashed by Supabase Auth, API keys stored only as hashes, optional two-factor authentication, email verification of new devices, row-level security on the database, signed webhooks, and a guard that refuses to deliver webhooks to internal addresses.

The one that matters most is architectural: your crypto never passes through us, so a breach of Blockra cannot move it.

12. Children

Blockra is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, email support@blockra.io and we will delete it.

13. Changes

We will update this Policy as the service changes, and the "last updated" date at the top will change with it. Material changes are notified by email or in the dashboard.

14. Contact

Blockra

support@blockra.io