Privacy Policy
Last updated 11 October 2026
Draft
Summary
- We receive payment-event metadata from your applications: route, method, host, path, amounts, network, your receiving address, a request id and a transaction hash.
- We discard query strings before anything is stored. We never receive payer or wallet identity.
- Raw events are deleted after 30 days. Daily totals stay until you delete the project or your account.
- We don't sell data, run ads or use analytics trackers. Email goes through Resend.
- You can export everything, or delete everything, from your account at any time.
Who we are
Requestway ("we") runs the website, dashboard and ingest API described in the Terms. TODO (owner): add the legal entity name, registered address and, if appointed, an EU/UK representative.
For your account data, we decide how it is used and act as a controller. For the payment events your applications send, we process them to provide the service to you, on your instructions, and act as your processor; you are the controller of that data.
Payment events we receive
When you install our Laravel package or Node reporter with a project key, or post to the ingest API yourself, your application sends us one record per x402 payment outcome. Each record can contain:
| Field | Example |
|---|---|
| Event type and time | payment.settled, 2026-10-11T12:34:56+00:00 |
| Route label and HTTP method | market-data, GET |
| Host and path of the requested URL | api.example.com, /premium-data |
| Mode | enforce or observe |
| Amounts | price in USD, amount in the asset's smallest unit, asset symbol |
| Network | eip155:8453 |
Your receiving address (pay_to) | 0xabc… |
| Request id | an id your application chooses |
| Settlement transaction hash and pending flag | for settled payments |
| Failure stage and reason | for failed payments, e.g. verify, insufficient_funds |
| Source | which package sent it, e.g. laravel-x402 |
We also record which of your project's keys (live or test) sent each event. The sending server's IP address reaches our infrastructure as part of the HTTP connection; we use it for rate limiting and abuse prevention and do not store it with events. Our hosting provider's access logs may record it briefly (TODO (owner): confirm log retention).
Route labels, request ids and failure reasons are chosen by your application. Please don't put personal data in them.
What we discard, and what we never receive
- Query strings and fragments. Query strings routinely carry tokens, emails and customer ids. Our Node reporter strips them before an event leaves your process. Our Laravel package sends the full URL, and our ingest endpoint splits it on arrival and discards the query string and fragment before anything is written to storage; the raw URL is never persisted. Any credentials embedded in a URL are discarded the same way.
- Payer and wallet identity. Neither package sends the payer's address or any wallet other than your own receiving address, and the ingest endpoint ignores any such field if one is sent.
- Fields we don't recognise. Discarded on arrival.
- Request and response bodies, headers and cookies of your application's traffic, and the IP addresses of your users. The packages don't send them.
Your account
When you use the dashboard we process:
- Profile: name, email address and, if you upload one, an avatar image. Avatars are re-encoded, which strips location and other metadata.
- Sign-in: a password hash (never the password), and if you use two-factor authentication, an encrypted TOTP secret and encrypted recovery codes.
- GitHub, if you sign in with it: your GitHub user id, username, avatar URL and the verified email address GitHub shares. We request only the
read:useranduser:emailscopes and do not access your repositories. - Sessions: for each signed-in browser, its IP address, user agent and last activity time, so you can see and end sessions.
- Known devices: the browser and operating system family you sign in from (for example "Firefox on macOS"), so we can email you about a sign-in from a new one. No versions, no IP address, no cookie.
- Projects and keys: project names, SHA-256 hashes of your keys, the last four characters for display, and when each key was created and last used.
Endpoint tester
When you run the endpoint tester we store, with your project: the HTTP method and URL you entered, when the test ran, the payment requirements your endpoint returned (network, amount, asset and receiving address), the outcome of each step, and, for a paid test, the testnet transaction hash. We don't store your endpoint's response bodies or headers beyond those payment fields. Our servers make the requests, so your endpoint will see our IP address and the user agent RequestwayEndpointTester/1.0 (+https://requestway.com/docs#tester). Paid tests are real transactions on a public testnet: the transaction, our test wallet's address and your receiving address are visible on that chain, as with any blockchain transaction. Test records are deleted with the project or your account.
How we use data
- To show you your analytics and run the service.
- To keep accounts and the service secure: authentication, rate limiting, abuse prevention and security emails.
- To send transactional email: verification, password reset, security notices, key changes, your first event, export links and account deletion. A new-sign-in notice includes the browser, operating system and IP address of that sign-in so you can recognise it. We don't send marketing email or newsletters.
- To meet legal obligations.
We don't sell personal data, use it for advertising, build profiles, or use your event data to train machine-learning models.
Lawful basis
Where data-protection law such as the GDPR or UK GDPR applies, we rely on:
- Contract for running your account and providing the service you signed up for;
- Legitimate interests for security, fraud and abuse prevention, rate limiting and improving reliability, which we balance against your rights and keep to the minimum needed;
- Legal obligation where the law requires us to keep or disclose information;
- Your instructions as controller for payment events, which we process only to provide the service to you.
Sub-processors and third parties
| Who | Purpose | Data |
|---|---|---|
| Resend | Sending transactional email | Your email address, name and the content of the email |
| TODO (owner): hosting provider | Servers, database and backups | All data described here |
| GitHub | Sign-in, only if you choose it | The OAuth exchange; GitHub's own privacy policy applies to your GitHub account |
| Discord | Internal operations alerts to Requestway staff in a private server | Your email address, name and GitHub username when you sign up or change security settings; project names; the IP address of a sign-in from a new device or a locked-out sign-in; error messages. Never API keys, passwords or payment event contents. |
| Have I Been Pwned (Pwned Passwords) | Rejecting passwords known from data breaches | The first five characters of a SHA-1 hash of a new password. The password and full hash never leave our servers. |
We will update this list before adding a sub-processor that handles your data.
Retention
| Data | Kept for |
|---|---|
| Raw payment events | 30 days, then deleted. They are stored in monthly partitions, and a partition is dropped once every event in it is past the retention period, so an event can remain for up to about two months in the worst case. |
| Daily totals (count and USD per route, type and day) | Until you delete the project or your account |
| Account, projects and key hashes | Until you delete them or your account |
| Sessions | Until you sign out or the session expires; "keep me signed in" lasts up to 400 days |
| Password reset links | 60 minutes |
| Data exports | 24 hours after they are ready, then deleted |
| Backups | TODO (owner): state backup retention |
| Email delivery logs at Resend | According to Resend's retention |
| Operations alerts in Discord | Up to 90 days, then deleted from the channel |
Security
Traffic is encrypted in transit with TLS. Project keys are stored only as hashes and shown once. Two-factor secrets and recovery codes are encrypted at rest. Sign-in, two-factor and password-reset endpoints are rate limited, and sensitive account actions ask you to confirm it's you. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as the law requires.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive it in a portable format, and to withdraw consent where we rely on it. You can do most of this yourself:
- Access and portability: Account → Your data → Request export. You get a ZIP of your account, projects, daily totals and raw events in JSON and CSV.
- Correction: Account → Profile.
- Deletion: delete a project from its settings, or your whole account from Account → Delete account. Deletion is immediate and includes events and totals.
For anything else, email [email protected]. We will respond within one month. If you're unhappy with our answer you can complain to your local data-protection authority.
If you are an end user of an application that reports to Requestway, that application's operator is the controller of the payment events; please contact them first. We will help them respond.
International transfers
TODO (owner): state where data is hosted and, if it leaves the UK/EEA, the safeguard used (for example, Standard Contractual Clauses). Resend, GitHub and Discord are based in the United States.
Children
The service is for developers and businesses and is not directed at anyone under 16. We don't knowingly collect data from children.
Changes to this policy
We'll post updates here with a new date, and email account holders about material changes before they take effect.
Contact
Privacy questions and requests: [email protected].