Privacy Policy
Last updated: September 25, 2026 · Version 2026-09-25
1. Who we are
This policy explains how Zaptrain, a sole proprietorship based in California, United States ("Zaptrain", "we", "us") handles personal information when you use zaptrain.com, the merchant dashboard, the hosted payment and checkout pages, the REST API and the MCP integration (together, the "Service"). It covers two groups of people: merchants who have a Zaptrain account, and payers — a merchant's customers who receive or pay an invoice (see section 3).
The Service is operated from the United States and is intended for merchants in the United States and other countries where its use is lawful. Contact for anything in this policy: support@zaptrain.com.
2. Merchants: what we collect and why
2.1 Information you give us
- Account: business name, email address and a password. The password is hashed by our authentication provider (Supabase); we never see it in clear text. Sign-in is by email and password only — we do not use Google, GitHub or other social login.
- Merchant profile: brand name, brand color, logo, default invoice memo.
- Customer records: the names and email addresses of the people you invoice, if you choose to enter them — both are optional; an email is only needed if you want Zaptrain to send the invoice. You confirm you are entitled to share them with us.
- Invoices: line items, amounts, taxes, memos, due and expiry dates, and payment status.
- Lexe wallet credentials: the receive-only client credentials you paste in Settings. They are encrypted with AES-256-GCM before being stored, decrypted only in memory when we create an invoice or read its payment status, and deleted immediately when you disconnect the wallet or delete your account.
- API keys, OAuth clients and webhooks: the keys you create, the AI assistants or apps you authorize, and the webhook URL you register. We keep a log of the events we sent to that URL — the full event payload, which includes the invoice details and the customer name and email on that invoice, along with the time, the delivery attempts and your endpoint's response code — for 90 days, after which it is deleted automatically.
- Checkout sessions: when you use hosted checkout we store the session, the customer email you pass to it, your own reference, any metadata you attach, and the return and cancel URLs you supply. The metadata field is free-form and goes into our database as you send it, so do not put personal information there that you do not need.
- Support messages: if you contact us through the support page or by email, we keep your name (optional), your email address, the topic you selected, your message and our reply. When you are signed in we also attach which account you were using. We do not store your IP address or browser with the message; your IP is used only briefly, and not kept, to rate-limit the form.
2.2 Information collected automatically
- Server logs: IP address, browser type, requested pages and API endpoints, response status and timing. We use these for security, rate limiting and debugging. We do not run advertising trackers.
- Page-view analytics: we use a cookieless analytics service to count visits to our pages — the page address, referring site, country, browser, operating system and device type. It sets no cookies and does not store your IP address; visitors are counted with a hash that changes daily and cannot identify you. Payment and checkout links are recorded without the invoice identifier, and query strings are removed before anything is sent.
- Cookies: a session cookie that keeps you signed in and operational cookies needed for the Service to work. No advertising or cross-site tracking cookies, so no cookie banner is shown.
- Email send status: whether our email provider accepted each invoice email we send on your behalf, or reported a failure. We do not track whether an email was opened.
- Terms acceptance: which version of the Terms of Service, this Privacy Policy and the Risk Disclosure you accepted at signup, and when.
- Copies of invoice emails: we keep the full content of invoice emails we send for 90 days so you can view and resend them; after that only the subject, recipient and send status remain.
2.3 Information from your Lexe wallet
Using the credentials you provide, we ask your Lexe wallet to create Lightning payment requests (BOLT11) and we read back their payment status (paid, expired, canceled) and amounts. Lexe also sends us signed webhook notifications about those invoices. When you open the dashboard or ask an integration for it, we also read your wallet's current Lightning balance to display it; we do not store balance history. We do not receive your other transactions or anything that identifies a payer, and we cannot move funds.
2.4 Why we use it
- to run the Service: create invoices, host payment pages, track payments, send invoice and receipt emails on your behalf, and send payment notifications (webhooks) to the URL you configured, which include the invoice details and the customer name and email on that invoice;
- to charge our platform fee, which is calculated per paid invoice and collected by Lexe (we record the fee amount per invoice and any promotional rate you are enrolled in);
- to secure accounts, prevent abuse and enforce our Terms;
- to answer support requests and send service notices (we do not send marketing email without your consent); and
- to comply with law and respond to lawful requests.
3. Payers: if you received or paid an invoice
If a business sent you a Zaptrain invoice or payment link, that business is responsible for your data and for the sale; Zaptrain processes your information on its behalf as a service provider. What we hold about you:
- your name and email address as entered by the merchant, and the contents of the invoice;
- copies of the invoice, reminder and receipt emails we sent you on the merchant's behalf (the full content for 90 days, then only the subject, recipient and send status);
- whether and when the invoice was paid — but not who paid it: Lightning payments do not carry the payer's identity, wallet or address;
- your IP address when you open the payment or checkout page, used only for rate limiting and abuse prevention.
We use this only to show you the payment page, confirm the payment and send the receipt. We do not use it for marketing or share it with anyone other than the merchant and the providers in section 5. To access, correct or delete it, contact the merchant first; you can also write to support@zaptrain.com and we will act on the request or pass it to the merchant.
4. Integrations you authorize
If you connect an AI assistant or another application to your account through the MCP integration, OAuth or an API key, that application receives the invoice, customer and payment data the API returns. It is governed by its own privacy policy, not this one. You can revoke any integration in Settings; revocation takes effect immediately for new requests.
5. Who we share data with
We do not sell personal information and do not share it for advertising. We share it only with:
- Service providers that process data for us under contract: Supabase (database and authentication), Vercel (application hosting), Fly.io (hosting for the component that talks to Lexe) and Resend (email delivery). All are based in the United States.
- Your Lexe wallet. Lexe is not our processor — you contract with Lexe directly. We transmit invoice amounts, memos and a Zaptrain partner-fee identifier to your wallet using your credentials, and receive payment status back. Lexe's handling of your wallet data is governed by Lexe's privacy policy.
- Integrations you authorize (section 4).
- A server you nominate. If you register a webhook URL, we POST the invoice details and the customer name and email on that invoice to that URL. That server is yours or your vendor's, not ours, and what happens to the data once it arrives is your responsibility.
- Payers and merchants as needed to show a payment page or receipt — for example, a payer sees the merchant's brand name and contact email.
- Authorities and others when required by law, legal process or to protect the rights, safety or security of Zaptrain, our users or the public.
- A successor if the Service is sold or transferred; we will notify you before your data is transferred under a different policy.
6. How long we keep it
- Lexe credentials: deleted immediately when you disconnect the wallet or delete your account.
- Account and profile data: while your account is active, then deleted within 30 days of account deletion.
- Invoices, customer records, fee records and payment status: 7 years from the invoice date, because they are business and tax records for you and for us.
- Copies of emails sent on your behalf: the full content for 90 days; the subject, recipient and send status for as long as the invoice.
- Lexe webhook records and Lightning payment request records: 12 months, for reconciliation and dispute handling.
- Outbound webhook delivery records: 90 days, then deleted automatically.
- Support correspondence: 24 months, so we can pick up a thread you return to.
- Server logs and rate-limit data: up to 30 days.
We may keep data longer where the law requires or to resolve a dispute, and we may keep anonymized statistics indefinitely.
7. Your choices and rights
You can update your profile and disconnect your wallet in Settings, and revoke API keys and integrations there. To delete your account, or to ask for a copy, correction or deletion of your personal information, email support@zaptrain.com from the address on your account (we may ask you to verify it). We respond within 45 days. If we decline a request, we will say why, and you may appeal by replying to our response.
California residents. Under the CCPA you have the right to know what personal information we collect, use and disclose (this policy describes it), to delete it, to correct it, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, do not use or disclose sensitive personal information for purposes other than providing the Service, and do not offer financial incentives for data. An authorized agent may submit a request on your behalf with your written permission.
Residents of other U.S. states, the EEA and the UK. The Service is offered from the United States and is not specifically directed at the EEA or UK. Where local law gives you rights of access, correction, deletion, portability, restriction or objection, you can exercise them by email as above, and where we rely on consent you may withdraw it at any time. Our legal bases where they apply are performance of our contract with you, our legitimate interests in running and securing the Service, and legal obligation.
8. Security
Data is encrypted in transit (TLS) and at rest by our hosting providers; Lexe credentials and signing secrets are additionally encrypted by us with AES-256-GCM using a key held outside the database. Access to production systems is limited to the small number of people who operate the Service. If we learn of a breach that affects your personal information, we will notify you without undue delay and as required by law. No system is perfectly secure; keep your password and credentials private, and revoke Lexe credentials in the Lexe app if you suspect misuse.
9. International transfers
We and our providers process data in the United States. If you use the Service from elsewhere, your data is transferred to and stored in the United States, which may not offer the same data protection as your country. Data you direct us to send elsewhere — for example to a webhook URL you register — is transferred to wherever that server is located, which is your choice, not ours.
10. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children; if you believe we have, email us and we will delete it.
11. Changes to this policy
We may update this policy. For material changes we will email merchants or show a notice in the dashboard before the change takes effect. The version and date at the top of this page identify the current version.
12. Contact
support@zaptrain.com, or use the support form.