1. Introduction & Core Privacy Principles
PoP Protocol ("we", "us", or "our") provides escrow-based automated settlement payment infrastructure for digital commerce on the Pi Network. We are firmly committed to preserving the privacy and data integrity of all merchants, developers, and paying customers who access our hosted checkout (/pay), point-of-sale interfaces, and developer APIs.
This Privacy Policy explains the specific data we collect, how that data is processed strictly for payment execution, and the uncompromising measures we maintain to ensure user privacy in accordance with international data protection standards and Pi Network ecosystem compliance guidelines.
2. Minimal Data Collection: Public Blockchain Telemetry Only
To process commercial checkout sessions, PoP Protocol collects only the absolute minimum public operational data required to confirm payment completion:
- Public Blockchain Identifiers: When a payment is submitted, we record public blockchain telemetry, consisting solely of the payer's Public Wallet Address (a public key beginning with 'G'), the recipient merchant's Public Wallet Address, Transaction Hashes (TxID / TxHash), payment amounts, and transaction memo strings.
- Isolated Sandbox Processing: All sensitive financial information, passphrases, and private cryptographic signatures are processed exclusively within the official Pi Network client sandbox (Pi Browser SDK). PoP Protocol servers never have access to, nor do they process, raw private keys or passphrases.
- Merchant Administrative Profile: For registered merchants, we maintain commercial configuration records, including business names, authorized contact emails, developer webhook URLs, and public settlement wallet configurations.
- Security Logs: Temporary technical log records, such as request timestamps and IP addresses (hashed and anonymized), are maintained solely for defending against automated bot attacks, unauthorized scraping, and distributed denial-of-service (DDoS) threats.
3. Categories of Data We Explicitly Never Collect
To maintain the highest tier of security and escrow settlement compliance:
- We never collect, log, transmit, or retain 24-word Pi wallet passphrases or seed phrases.
- We never collect or store private signing keys or cryptographic keystores.
- We never request or store credit card numbers, CVVs, or personal bank account passwords.
- We never collect biometric identifiers, such as fingerprint or facial recognition scans.
- We never engage in cross-site behavioral profiling or targeted advertising tracking.
4. Strict No Third-Party Data Sharing Policy
PoP Protocol adheres to an absolute zero-monetization policy regarding merchant and customer data:
- No Data Sales or Commercialization: We do not sell, rent, lease, monetize, trade, or share merchant or customer personal or transactional data with third-party advertisers, data aggregators, or marketing brokers under any circumstances.
- Strict Operational Disclosure: Data is shared only with essential infrastructure providers (such as Supabase for database hosting and Vercel for edge routing) strictly under confidentiality and data protection obligations necessary to maintain gateway uptime.
- Legal & Regulatory Disclosures: We will disclose data only if required to do so by a valid, legally binding court order, subpoena, or lawful regulatory request issued by a competent legal jurisdiction.
5. Nature of Public Decentralized Blockchains
Users and merchants acknowledge that the Pi Network is a decentralized public ledger based on the Stellar Consensus Protocol. Transactions verified on the blockchain—including public addresses, transaction amounts, timestamps, and cryptographic transaction hashes—are permanently and publicly accessible to anyone inspecting the ledger. PoP Protocol possesses no technical capability to erase, redact, or modify records permanently embedded in the blockchain ledger.
6. Security Safeguards & Cryptographic Protections
We implement comprehensive defense-in-depth measures to protect application data:
- All web and API traffic is strictly enforced via Transport Layer Security (TLS 1.3) with HSTS headers.
- Merchant API credentials are authenticated through hashed secret keys stored under strict Row Level Security (RLS) policies.
- Rate limiting and automated anomaly detection protect all public checkout endpoints from credential stuffing and replay attacks.
7. Data Subject Rights & Contact Information
Merchants may request access to, correction of, or deletion of their off-chain account information at any time by contacting our compliance and data protection officer: