Privacy

Privacy is a product feature, not a slogan. ZecPay does not require email or password accounts. This page documents what is stored today.

What we store

  • Public profile fields you enter when creating a page (username, display name, optional bio and avatar URL)
  • Zcash receiving address(es) you supply (Unified and any optional extras)
  • A one-way hash of your manage secret (never the raw secret) so only you can edit the page later
  • Invoice metadata you create (title, amount, optional memo, status)
  • Optional transaction id if you manually mark an invoice paid (operator note, not chain proof)

What we do not store

  • Email addresses or passwords (no account system for creators or payers)
  • Payer identity
  • Seed phrases or private keys
  • Wallet balances
  • Invasive analytics profiles
  • Automatic full histories of shielded payments

Manage access

When you publish a page you receive a manage secret once. Store it offline. Anyone with that secret can edit the page; we only keep a hash of it. Lose the secret and you cannot recover edit access through this app.

Payments

Payments are ZIP-321 requests paid from the payer's own wallet to your address. ZecPay never holds ZEC and is not a wallet.

Hosting notes

Your host (e.g. Vercel) and database provider (e.g. Neon) may log basic connection metadata. Prefer providers and logging policies that match your threat model.