Privacy Policy

Last updated: May 18, 2026

1. Who we are

Cassia ("we", "us") operates cassiapay.com — a non-custodial stablecoin payment processor. We never hold private keys or take custody of funds. Our registered contact address is [email protected].

2. Data we collect

Account data

Email address and, optionally, a business name. Collected when you register. Used to authenticate you and send transactional emails (magic-link login, invoice notifications).

Wallet extended public keys (xpubs)

The account-level xpub you connect in the Wallets section. We use it to derive unique deposit addresses for each invoice. Private keys never leave your device and are never transmitted to us.

Invoice and transaction data

Invoice amounts, currencies, payment statuses, and on-chain transaction references. Stored to operate the service and calculate commissions.

Usage data

Standard web server logs (IP address, browser type, pages visited) retained for up to 30 days for security and debugging purposes.

3. Cookies

Session cookie (strictly necessary)

An httpOnly JWT stored as a browser cookie named session. Required to keep you logged in. It contains no personal data beyond a random merchant identifier. No consent needed — it is essential to the service.

Analytics cookies (optional — GA4)

When you visit the public landing page, a consent banner is shown. If you click "Accept", Google Analytics 4 (GA4) sets cookies to measure visitor counts and traffic sources. If you click "Decline" or close the banner, no analytics cookies are set (GA4 Consent Mode v2). Your preference is stored in localStorage key cassia_cookie_consent and is not transmitted to us.

4. Product analytics

After you log in, we use PostHog (posthog.com) to understand how merchants use the dashboard — which features are used, where users drop off. Your email address is masked before being sent to PostHog (e.g. seo***@gmail.com). Session recordings are enabled with all input fields masked. Pages that display sensitive information (wallet generation, 2FA setup) are excluded from recordings.

5. Subprocessors

We rely on the following third-party processors:

ProcessorPurposeLocation
VilnaAddress derivation from xpubs; on-chain balance indexingEU
ResendTransactional email delivery (login links)US
Google AnalyticsMarketing page analytics (consent-gated)US
PostHogProduct analytics for logged-in merchantsUS/EU

6. How we use your data

  • To provide and operate the payment processing service
  • To authenticate you and protect your account
  • To calculate and collect commissions
  • To send you transactional emails related to your account
  • To detect fraud and abuse
  • To improve the product (analytics, aggregated only)

We do not sell your data. We do not use your data for advertising.

7. Data retention

Account and invoice data is retained for as long as your account is active and for 3 years after account closure (required for financial record-keeping). You may request deletion of personal data by emailing [email protected]. Deletion of invoice records may be limited by legal obligations.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, or delete personal data we hold about you, or to object to certain processing. To exercise these rights, contact [email protected]. We will respond within 30 days.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email to registered merchants at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the current version.

10. Contact

Questions or requests: [email protected]