ZemiaxPay
Privacy notice
Last updated: September 23, 2026
This notice explains which personal data ZemiaxPay processes when offering merchant accounts, invoices, and a checkout for receiving crypto payments.
Controller and stated address
David Axel Centeno Solis, an individual operating ZemiaxPay from Mexico.
Address provided by the controller: Chichi Suárez, Fracc. Acacias, Mérida, Yucatán, C.P. 97306, México
For privacy questions and requests about your data: privacy@zemiaxpay.com
Data we process
- Account and contact information supplied by a merchant or user, such as name, email address, phone number when requested, and business details.
- Invoice and payment information, including order reference, description, amount, currency, asset and network, public receiving address, transaction identifier, and confirmation status. A merchant may provide payer contact details for payment notices.
- Messages, topic and screenshots you send to checkout support, together with the invoice or selection reference and each message timestamp. Screenshots are automatically removed after 30 days. Do not share identity documents, seed phrases, or private keys.
- Technical and security information needed to operate the site, such as an IP address or its hash, user agent, access records, authentication session, and language or theme preferences stored in the browser.
Amounts and payment details may qualify as financial or asset-related personal data. The flows described here do not deliberately request sensitive personal data; avoid including it in free-text fields. We receive data directly from users and merchants, and public blockchain data when a transaction is observed. A transfer recorded on a public blockchain may be visible to parties outside ZemiaxPay.
Purposes
We use data to create and manage accounts, generate and display invoices and links, observe and reconcile payments, communicate status, respond to support requests, protect the service, and meet applicable legal obligations. These purposes are necessary for the requested service. We do not use the data described here for advertising or sales prospecting; if we add an optional purpose, we will update this notice and request any required consent.
Recipients and transfers
The merchant who created an invoice receives the information needed to identify its payment and handle the order. Technical providers operating hosting, email, and connectivity may process data on the controller’s behalf as needed to provide the service. Information written to a public blockchain is available under that network’s rules. We may disclose information to competent authorities when required by law. This notice offers no additional commercial transfer option; before making a transfer that requires consent, we will ask for the data subject’s choice.
Cookies and browser storage
The merchant panel uses necessary session and CSRF cookies to maintain authentication and protect requests. Checkout may store language and theme choices. To reopen a support conversation, this browser stores its ID and an access credential. If sending is not confirmed, it also temporarily keeps the message text, screenshot attachment and retry ID. Access expires after 30 days; the browser removes expired data when you return to checkout, and you can clear it sooner in site settings. If local storage is blocked, checkout tries session storage; if both fail, you may lose access when you leave or reload. Avoid shared devices. Disabling the session cookie may prevent access to the panel.
Retention and security
There is no single retention period for every data category. We retain data for the time needed to provide the service, handle transactions, resolve issues, and meet applicable legal or contractual obligations. Invoices and transactions are not automatically deleted when a session or link expires; ZemiaxPay cannot erase records from a public blockchain. Cancellation requests are assessed against applicable blocking and retention periods. We apply access controls and technical safeguards.
Your rights and how to exercise them
You may request access, correction, cancellation, or objection (ARCO), limit the use or disclosure of your data, and revoke consent where applicable. Email privacy@zemiaxpay.com with your name, a way to reply, the right you seek to exercise, and a description of the data involved. To protect your data, we may ask you to verify your identity or authority before disclosing information or making changes. Do not send identity documents in your first message; we will explain how to verify identity if needed.
We will communicate our decision within twenty business days after receiving a complete request and, if applicable, implement it within the following fifteen business days. Each period may be extended once for an equal period when justified. Exercising ARCO rights is free, except for reproduction or delivery costs allowed by law.
Changes to this notice
We will publish an updated version on this page and communicate material changes by email or another direct means when required by law and when we have a valid contact.