Documents

TgPay Crypto Privacy Policy

Revised September 11, 2026.

1. About this policy and how to contact us

This policy explains what personal data we process when you use the TgPay Crypto wallet, our Telegram bot, Merchant API, and support, why we need it, and how to contact us about its processing.

In this policy, “we” and “the service” mean TgPay Crypto.

For questions about personal data, email law@tgpaycrypto.com. You can also contact us through More → Support in the app. Please state that your request concerns personal data.

This policy describes data processing and does not replace the service's terms of use. Where separate consent is required for a particular type of processing, using the app does not replace that consent.

2. What data we process

The data we process depends on the features you use. For example, a backup email is optional, and we do not ask every user for verification documents when they first sign in.

Telegram data and preferences

When you interact with the bot and Mini App, we receive your Telegram ID, name, username if you have one, language, and available account information, such as Telegram Premium status. The app may display your profile photo if Telegram makes it available.

We store your language, display currency, notification, and interface preferences, along with account creation and activity information. We receive your phone number when you share your contact during verification; opening the app alone does not automatically share it with us.

Transactions and wallet use

We process balance and transaction information: asset, amount, fee, time, status, crypto wallet addresses, network, transaction IDs, senders and recipients, and any comments or other data you provide when making a transaction.

Depending on the features you use, this includes information about checks, invoices, subscriptions, giveaways, exchanges, Earn, and purchases of Telegram Stars, Premium, and gifts. For subscriptions and giveaways, we may process the channel, group, and participant IDs needed to provide these features.

If another user sends you funds or names you as a recipient, we may receive your Telegram ID or username and transfer details before you first contact our bot.

Account security

We process your backup email if you have added one, its verification details, linked devices and sessions, security settings, attempts to confirm transactions, and changes to security factors.

Your PIN is sent to the server for verification. We store a cryptographic representation of it for future checks, rather than the PIN in plain text.

Face ID and other biometrics used to confirm transactions work through Telegram and your device's operating system. We do not receive face images or fingerprints for this feature: the server verifies a separate confirmation secret and stores its hash and information about the linked device. This is separate from the selfie and liveness check used for identity verification.

Verification and source of funds

Verification involves processing your phone number, first and last name, patronymic if provided, date of birth, and country of residence. Depending on the check, we may need an identity document, images of it, a selfie or liveness check materials, proof of your residential address, and source of funds documents.

Verification may be required to access certain features or lift restrictions. If the required information is not provided, the relevant feature or transaction may remain unavailable.

Support requests and Agent commands

We process the text of your requests, conversation history, images and other attachments you send, ratings of responses, and account and transaction data needed to address your question. If you include information about another person in a message, that information may also be processed.

Merchant API and third-party apps

When you create a merchant app, we process its name, link to its owner, webhook settings, access permissions and API token information, invoices, payouts, subscriptions, and activity log. We also record acceptance of the Merchant API terms.

3. Where data comes from

We receive data from you, through Telegram, from other parties to transactions, from apps you connect, and from services that help with verification, transaction screening, and security. Some information about crypto transactions is available on public blockchains.

The app uses browser local storage and session storage for authentication, preferences, device management, and restoring the interface state. Deleting this data on your device does not delete your account on the server or your transaction history.

4. Why we use data

We use it to:

  • provide account access and carry out the transactions you choose;
  • keep records of funds, display history, and deliver notifications;
  • confirm actions, restore access through a backup email, and protect your account;
  • verify identity, check the source of funds, and detect fraud and suspicious transactions;
  • respond to requests and process Agent commands;
  • operate Merchant API and the integrations you connect;
  • find errors and keep the service running;
  • handle disputes and official requests, and meet applicable recordkeeping and data retention obligations.

The legal basis depends on the purpose and applicable law: performance of a contract to provide the service; legal obligations for the relevant checks, recordkeeping, and disclosures; legitimate interests, where this basis is permitted, to prevent fraud and maintain security; and consent where required.

5. Protecting data

We protect the service through access controls, session and confirmation factor checks, security event logs, and encrypted backups. Access to operational tools is limited according to the role of the employee or service.

No method of storing or transmitting data eliminates all risk. Account security also depends on how you protect your Telegram account and device.

6. Retention periods

Retention periods depend on the type of data, processing purpose, pending transactions, disputes, and applicable legal requirements. Different periods may apply to transaction history, verification data, support requests, and technical logs. Stopping use of the app does not mean all related records are immediately deleted.

7. Your requests and rights

You can contact us to request access to, correction or deletion of, or a copy of your data, or to request restriction of or object to processing. The scope of these rights and the grounds for exercising them depend on applicable law. If processing is based on consent, you can withdraw it; this does not affect the lawfulness of processing before withdrawal.

Use the contact details in section 1 to make a request. We may ask you to confirm that you are the account holder. The app does not currently offer self-service account deletion; the support team handles these requests. Deletion may not cover information that must be retained to meet applicable obligations or resolve a dispute.

Objecting to processing. Where applicable law provides this right, you can separately object to processing based on legitimate interests and ask us to explain the grounds for an automated restriction.

You can also contact the competent data protection authority where applicable law provides for this.

8. Age

The service is intended for adults. Verification checks that you are at least 18 years old. If you believe we have received a minor's data, let us know using the contact details in section 1. Such a request requires an individual review, including consideration of completed transactions and record retention obligations.

9. Changes to this policy

The current version will be available in the app with its effective date. If a change in processing requires notice or separate consent, we will follow the relevant procedure. Continued use of the app does not itself replace consent where it is required.

See also: TgPay Crypto AML/KYC Policy · TgPay Crypto Terms of Use · About