Skip to content

Privacy Policy

Last updated 11 October 2026

Draft

This is a draft prepared in good faith and has not been reviewed by a lawyer.

Summary

  • We receive payment-event metadata from your applications: route, method, host, path, amounts, network, your receiving address, a request id and a transaction hash.
  • We discard query strings before anything is stored. We never receive payer or wallet identity.
  • Raw events are deleted after 30 days. Daily totals stay until you delete the project or your account.
  • We don't sell data, run ads or use analytics trackers. Email goes through Resend.
  • You can export everything, or delete everything, from your account at any time.

Who we are

Requestway ("we") runs the website, dashboard and ingest API described in the Terms. TODO (owner): add the legal entity name, registered address and, if appointed, an EU/UK representative.

For your account data, we decide how it is used and act as a controller. For the payment events your applications send, we process them to provide the service to you, on your instructions, and act as your processor; you are the controller of that data.

Payment events we receive

When you install our Laravel package or Node reporter with a project key, or post to the ingest API yourself, your application sends us one record per x402 payment outcome. Each record can contain:

FieldExample
Event type and timepayment.settled, 2026-10-11T12:34:56+00:00
Route label and HTTP methodmarket-data, GET
Host and path of the requested URLapi.example.com, /premium-data
Modeenforce or observe
Amountsprice in USD, amount in the asset's smallest unit, asset symbol
Networkeip155:8453
Your receiving address (pay_to)0xabc…
Request idan id your application chooses
Settlement transaction hash and pending flagfor settled payments
Failure stage and reasonfor failed payments, e.g. verify, insufficient_funds
Sourcewhich package sent it, e.g. laravel-x402

We also record which of your project's keys (live or test) sent each event. The sending server's IP address reaches our infrastructure as part of the HTTP connection; we use it for rate limiting and abuse prevention and do not store it with events. Our hosting provider's access logs may record it briefly (TODO (owner): confirm log retention).

Route labels, request ids and failure reasons are chosen by your application. Please don't put personal data in them.

What we discard, and what we never receive

  • Query strings and fragments. Query strings routinely carry tokens, emails and customer ids. Our Node reporter strips them before an event leaves your process. Our Laravel package sends the full URL, and our ingest endpoint splits it on arrival and discards the query string and fragment before anything is written to storage; the raw URL is never persisted. Any credentials embedded in a URL are discarded the same way.
  • Payer and wallet identity. Neither package sends the payer's address or any wallet other than your own receiving address, and the ingest endpoint ignores any such field if one is sent.
  • Fields we don't recognise. Discarded on arrival.
  • Request and response bodies, headers and cookies of your application's traffic, and the IP addresses of your users. The packages don't send them.

Your account

When you use the dashboard we process:

  • Profile: name, email address and, if you upload one, an avatar image. Avatars are re-encoded, which strips location and other metadata.
  • Sign-in: a password hash (never the password), and if you use two-factor authentication, an encrypted TOTP secret and encrypted recovery codes.
  • GitHub, if you sign in with it: your GitHub user id, username, avatar URL and the verified email address GitHub shares. We request only the read:user and user:email scopes and do not access your repositories.
  • Sessions: for each signed-in browser, its IP address, user agent and last activity time, so you can see and end sessions.
  • Known devices: the browser and operating system family you sign in from (for example "Firefox on macOS"), so we can email you about a sign-in from a new one. No versions, no IP address, no cookie.
  • Projects and keys: project names, SHA-256 hashes of your keys, the last four characters for display, and when each key was created and last used.

Endpoint tester

When you run the endpoint tester we store, with your project: the HTTP method and URL you entered, when the test ran, the payment requirements your endpoint returned (network, amount, asset and receiving address), the outcome of each step, and, for a paid test, the testnet transaction hash. We don't store your endpoint's response bodies or headers beyond those payment fields. Our servers make the requests, so your endpoint will see our IP address and the user agent RequestwayEndpointTester/1.0 (+https://requestway.com/docs#tester). Paid tests are real transactions on a public testnet: the transaction, our test wallet's address and your receiving address are visible on that chain, as with any blockchain transaction. Test records are deleted with the project or your account.

How we use data

  • To show you your analytics and run the service.
  • To keep accounts and the service secure: authentication, rate limiting, abuse prevention and security emails.
  • To send transactional email: verification, password reset, security notices, key changes, your first event, export links and account deletion. A new-sign-in notice includes the browser, operating system and IP address of that sign-in so you can recognise it. We don't send marketing email or newsletters.
  • To meet legal obligations.

We don't sell personal data, use it for advertising, build profiles, or use your event data to train machine-learning models.

Lawful basis

Where data-protection law such as the GDPR or UK GDPR applies, we rely on:

  • Contract for running your account and providing the service you signed up for;
  • Legitimate interests for security, fraud and abuse prevention, rate limiting and improving reliability, which we balance against your rights and keep to the minimum needed;
  • Legal obligation where the law requires us to keep or disclose information;
  • Your instructions as controller for payment events, which we process only to provide the service to you.

Sub-processors and third parties

WhoPurposeData
ResendSending transactional emailYour email address, name and the content of the email
TODO (owner): hosting providerServers, database and backupsAll data described here
GitHubSign-in, only if you choose itThe OAuth exchange; GitHub's own privacy policy applies to your GitHub account
DiscordInternal operations alerts to Requestway staff in a private serverYour email address, name and GitHub username when you sign up or change security settings; project names; the IP address of a sign-in from a new device or a locked-out sign-in; error messages. Never API keys, passwords or payment event contents.
Have I Been Pwned (Pwned Passwords)Rejecting passwords known from data breachesThe first five characters of a SHA-1 hash of a new password. The password and full hash never leave our servers.

We will update this list before adding a sub-processor that handles your data.

Retention

DataKept for
Raw payment events30 days, then deleted. They are stored in monthly partitions, and a partition is dropped once every event in it is past the retention period, so an event can remain for up to about two months in the worst case.
Daily totals (count and USD per route, type and day)Until you delete the project or your account
Account, projects and key hashesUntil you delete them or your account
SessionsUntil you sign out or the session expires; "keep me signed in" lasts up to 400 days
Password reset links60 minutes
Data exports24 hours after they are ready, then deleted
BackupsTODO (owner): state backup retention
Email delivery logs at ResendAccording to Resend's retention
Operations alerts in DiscordUp to 90 days, then deleted from the channel

Security

Traffic is encrypted in transit with TLS. Project keys are stored only as hashes and shown once. Two-factor secrets and recovery codes are encrypted at rest. Sign-in, two-factor and password-reset endpoints are rate limited, and sensitive account actions ask you to confirm it's you. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as the law requires.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive it in a portable format, and to withdraw consent where we rely on it. You can do most of this yourself:

  • Access and portability: Account → Your data → Request export. You get a ZIP of your account, projects, daily totals and raw events in JSON and CSV.
  • Correction: Account → Profile.
  • Deletion: delete a project from its settings, or your whole account from Account → Delete account. Deletion is immediate and includes events and totals.

For anything else, email [email protected]. We will respond within one month. If you're unhappy with our answer you can complain to your local data-protection authority.

If you are an end user of an application that reports to Requestway, that application's operator is the controller of the payment events; please contact them first. We will help them respond.

International transfers

TODO (owner): state where data is hosted and, if it leaves the UK/EEA, the safeguard used (for example, Standard Contractual Clauses). Resend, GitHub and Discord are based in the United States.

Children

The service is for developers and businesses and is not directed at anyone under 16. We don't knowingly collect data from children.

Changes to this policy

We'll post updates here with a new date, and email account holders about material changes before they take effect.

Contact

Privacy questions and requests: [email protected].