xAPGX Protocol Agent Payment GatewayTESTNET · NO REAL FUNDS

Privacy

Privacy Policy

This policy explains how XAPG handles information when you visit the website, sign in, connect a wallet or Agent, and request or authorize a payment.

Scope

This policy applies to XAPG websites, account features, Agent and MCP connections, wallet pairing, payment authorization, verification, and settlement services. A third-party wallet, merchant, Agent client, blockchain, or service provider may apply its own privacy terms to its part of the interaction.

Effective date: 2026-08-31

Information we handle

  • Account identity: the Google account identifier, verified email address, display name, and profile image returned when you choose Google Sign-In.
  • Wallet and Agent connection data: public wallet address, wallet or app name, connection state, Agent or OAuth client identity, API-key metadata, grants, and revocation status.
  • Payment data: merchant resource URL, network, asset, recipient address, amount, authorization and approval status, timestamps, nonce or reference, transaction hash, and error or settlement evidence.
  • Service and security data: request timestamps, IP address and device or browser information that may appear in infrastructure logs, rate-limit events, diagnostics, and security records.
  • Optional analytics: after you consent, public information pages may use Google Analytics to measure aggregate usage. Account, API-key, wallet, authorization, and payment pages are excluded from XAPG analytics.
XAPG does not ask for or receive your wallet seed phrase or private key. Wallet signatures are produced by your wallet or an isolated signing service.

How we use information

  • Authenticate users, maintain sessions, and protect accounts.
  • Pair wallets, authorize Agent clients, apply recipient and payment policies, and show activity to the correct account.
  • Verify signed payment requests, prevent replay or duplicate settlement, submit approved transactions, and reconcile results.
  • Operate, troubleshoot, secure, audit, and improve the service, and comply with applicable legal obligations.

When information is shared

We use infrastructure and integration providers to deliver the service, including Google for identity and cloud hosting, Cloudflare for DNS and network protection, WalletConnect for wallet connectivity, Circle for supported wallet and settlement operations, RPC providers such as Alchemy, and Base or other applicable blockchain networks. We provide only the information reasonably needed for the relevant function.

For an x402 payment, the merchant and its Facilitator may receive the signed payment payload and related transaction metadata required to verify and settle the request. Their handling of that information is governed by their own terms and policies.

We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards. We do not sell personal information.

Blockchain transparency

Public blockchains permanently expose transaction data such as wallet addresses, token amounts, contract interactions, and transaction hashes. XAPG cannot alter or erase information confirmed on a blockchain. Avoid placing personal or confidential information in wallet labels, transaction references, or merchant payloads.

Storage, retention, and security

XAPG uses access controls, encrypted transport, isolated service identities, secret management, signed session cookies, and payment verification controls intended to protect stored and transmitted information. No internet service or blockchain interaction can be guaranteed completely secure.

We retain information for as long as reasonably necessary to provide the service, maintain security and audit evidence, resolve disputes, and meet legal obligations. Retention may differ by record type. Expired or revoked credentials may be deleted or rendered unusable, while public blockchain records remain available independently of XAPG.

Your choices and requests

You can decline or change optional analytics consent, sign out, disconnect a paired wallet, revoke Agent or API access, and remove supported account settings through the product. You may contact us to request access, correction, or deletion of personal information, subject to identity verification and records we must retain for security, legal, or blockchain reasons.

International processing and children

Service providers and blockchain infrastructure may process information in multiple countries. Where required, appropriate safeguards should be applied to international transfers. XAPG is not directed to children, and you must be legally able to authorize the accounts, wallets, and payments you use.

Changes and contact

We may update this policy when the service, providers, or legal requirements change. Material updates will be reflected by a revised effective date or another appropriate notice.

Privacy questions and requests: a@xapg.io