Privacy policy$1
The Russian version of this document is the legally binding one. Translations are provided for convenience.
This page says what data we collect and why. Without wording like “for the purposes of improving the quality of services”, behind which anything at all can hide.
01In short
- We do not sell your data and do not pass it to advertising networks.
- We do not store your Telegram or Google passwords — sign-in goes through them.
- Identity documents are seen only by the staff who carry out that check. They are not passed anywhere else.
- We count site visits on our own server rather than handing them to Google.
- Blockchain records are public and are deleted by nobody — us included.
02What data we collect
On sign-in
- Telegram:the numeric identifier, the username, the name, the profile photo and the interface language.
- Google:the account identifier, the email address, the name and the profile photo.
Passwords to those accounts are never passed to us — in any form. Telegram and Google send back a signed reply that only confirms who you are.
While it is in use
- Balance, operations, top-up addresses, issued cards.
- The IP address and sign-in time — for the security log.
- Correspondence with support.
- The chosen language, theme and display currency.
During identity verification
- Name, date of birth, nationality, address.
- An identity document and your photograph.
This data is requested only when issuing a card and for operations above the set thresholds.
03Why they are needed
| Data | Reason |
|---|---|
| Telegram or Google identifier | To know whose account it is |
| Name and photograph | To show you inside the app |
| Restoring access | |
| Operations and balance | To run the account |
| IP and sign-in time | To notice a sign-in that was not yours |
| Documents | A legal requirement on card issuing |
| Correspondence | To help and to remember the context |
We neither collect nor ask for data beyond what is listed.
04On what basis
- Performance of the agreement:without an identifier and a record of operations an account cannot work.
- A legal requirement:identity verification and anti-money-laundering.
- Legitimate interest:fraud protection and the security log.
- Your consent:everything optional — and it can be withdrawn.
06The blockchain is public
Every blockchain transfer is visible to everyone and stays there forever: the amount, the addresses, the time.
07How long we keep it
| Data | Period |
|---|---|
| Account and balance | While the account is open |
| Records of operations | 5 years after the account is closed |
| Identity verification documents | 5 years after the account is closed |
| Sign-in log | 12 months |
| Correspondence with support | 3 years |
The five-year periods are not set by us: anti-money-laundering law requires them. We cannot delete such records earlier, even at your request.
08Your rights
- Find outwhat data about you exists, and get a copy of it.
- Correctinaccurate information.
- Deleteyour data — except what we are obliged to keep by law.
- Restrictprocessing while a dispute is under way.
- Take awayyour data in machine-readable form.
- Withdraw consentfor everything optional.
- Complainto the data-protection supervisory authority.
Write to support — we answer within 30 days. To protect against requests from other people, we may ask you to confirm that the account is yours.
10Visit statistics
We count site trafficon our own server— with Umami on the subdomainumami.nexuspayme.com. The data goes neither to Google Analytics nor to any other external service.
Only anonymous information is collected: the page address, where you came from, the device type and the country. No name, no identifier, no way to trace it back to a person.
11How we protect it
- All traffic to the server runs over TLS — it cannot be read on the way.
- The Telegram and Google signature is checked on the server: a reply forged in the browser will not pass.
- A session is time-limited and is revoked on sign-out.
- Staff access to verification documents is granted only where the work requires it and is recorded.
- Most of the crypto is kept in wallets with no permanent network connection.
Absolute protection does not exist, and promising it would be dishonest. If a leak does happen, we will tell the people affected and the supervisory authority within 72 hours of learning about it.
12Contact us
For questions about data, write to support inside the app:t.me/nexuspaymybot.
Responsible for data protection:name and email. Operator:legal entity name and address.