Legal
Privacy Policy
Last updated: 19 August 2026
See also our Terms of Service.
This Privacy Policy explains how CAMP Investment Technologies Pte. Ltd. ("CAMP", "we", "us", or "our"), operating the TransX402 brand, collects, uses, and shares information when you use the TransX402 product series.
It applies to our hosted platform (transx402.com, dashboard.transx402.com, api.transx402.com, docs.transx402.com), the TransX402 Paywall WordPress plugin, npm packages (@transx402/client, @transx402/server), and official examples we publish.
See also our Terms of Service.
Effective date: 19 August 2026
1. Roles: who is responsible for what
Privacy responsibilities depend on how you interact with TransX402:
- Merchants (dashboard account holders) are generally the data controller for information they collect from their own website visitors, including paywall and payment records stored in WordPress or their own systems.
- CAMP / TransX402 is the data controller for merchant account data and for payment-facilitation data processed through our hosted API and dashboard.
This policy describes both roles where relevant.
2. Information we collect
2.1 Merchant account data (hosted platform)
When you register through the merchant dashboard, we collect:
- Email address and name you provide during registration
- Website URL (if provided)
- Wallet address verified through Sign-In with Ethereum (SIWE)
- API key metadata (hashed secrets, prefixes, sandbox/live mode, last-used timestamps)
- Webhook URL and webhook secret (if configured)
- Allowed origins for publishable or direct-settlement integrations
- Session cookie (
transx402_session, HttpOnly, SameSite=Lax, up to 7 days) to keep you signed in - SIWE nonces stored temporarily in Redis (about 10 minutes) for authentication
2.2 Payment facilitation data (API)
When a payment is verified or settled through our facilitator, we process:
- Payer wallet address and merchant wallet address
- Payment amount, token, and network
- Transaction hash and resource URL (the paid content or endpoint)
- Optional description supplied by the integration
- Webhook delivery logs (URL, request/response bodies, delivery status) when you configure webhooks
This data is stored in our PostgreSQL database as part of providing the service.
2.3 WordPress plugin (merchant-controlled)
If a site owner uses the TransX402 Paywall plugin:
- Payment history (payer wallet, transaction hash, post ID, amount, network) is stored in the merchant's WordPress database (
wp_transx402_payments) - Plugin settings (API key, merchant wallet, defaults) are stored in WordPress options
- After a successful payment, the plugin sets an HttpOnly, SameSite=Lax access cookie on the merchant's domain (Secure on HTTPS) so return visits can unlock content without paying again
- Payment payloads and transaction hashes are sent to the TransX402 API (or an admin-configured allowlisted facilitator URL) when a visitor pays
The WordPress site owner decides how long to retain local records and must disclose cookies and payment processing to their visitors where required by law.
2.4 npm SDKs and merchant integrations
@transx402/clientruns in the browser or agent environment. It does not include built-in analytics or local telemetry storage. It sends payment-related data to the facilitator endpoint configured by the merchant integration when a user pays.@transx402/serverruns on the merchant's server, holds the merchant's API key server-side, and forwards settlement requests to our API. It does not add separate telemetry beyond what the merchant's deployment logs.
2.5 Marketing and documentation sites
transx402.com and docs.transx402.com do not use third-party advertising trackers or marketing analytics cookies in the current deployment. We do not collect email addresses through the marketing site itself.
Standard web server and CDN logs may record IP addresses, user agents, and requested URLs for security and operations.
2.6 Operations and security
Our API and hosted services may generate:
- Request logs for debugging and security
- Error reports through Sentry when
SENTRY_DSNis configured in our deployment - Infrastructure metrics (for example, Prometheus endpoints for operations)
We host production infrastructure on servers we operate (PostgreSQL, Redis, and application services). See our deployment documentation for architecture details.
3. How we use information
We use the information above to:
- Provide, secure, and improve the TransX402 services
- Authenticate merchants and manage API keys
- Verify and settle x402 payments and deliver webhooks
- Communicate about your account, security incidents, or service changes
- Comply with legal obligations and enforce our Terms of Service
We do not sell personal information. We do not use merchant or payer data for third-party advertising.
4. Legal bases (where applicable)
Depending on your jurisdiction, we process data based on:
- Contract — to provide services you request
- Legitimate interests — to secure our platform, prevent abuse, and improve reliability
- Legal obligation — where required by applicable law
- Consent — where you explicitly agree (for example, when a merchant enables paywalls and wallet interactions on their site)
5. Sharing and subprocessors
We share information only as needed to operate TransX402:
- Blockchain networks — settlement data is submitted on-chain and becomes public on the relevant network
- Block explorers — transaction hashes may be linked in the WordPress admin (Basescan, OnchainFolio testnet explorer). Visitor data is not sent to explorers from paywall pages; admin links are operator-only
- Infrastructure providers — hosting, database, and cache services used to run our platform
- Error monitoring — Sentry, when enabled, for aggregated error diagnostics
We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate safeguards.
6. International transfers
CAMP is incorporated in Singapore. Our services may be accessed globally. Data may be processed in jurisdictions where our infrastructure or subprocessors operate. We take reasonable steps to protect data consistent with this policy.
7. Retention
We retain merchant account and payment facilitation records for as long as your account is active and as needed to provide the service, comply with law, resolve disputes, and enforce agreements.
WordPress plugin: uninstalling the plugin removes the plugin's payment table and settings from the merchant's WordPress site (uninstall.php). Records already stored on our hosted API remain subject to our retention practices unless deletion is requested through contact below.
Session and nonce data: SIWE nonces expire quickly; session cookies expire within the configured lifetime.
8. Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, or restrict processing of personal data, or to object to certain processing.
- Merchants can update account details through the dashboard and contact us for account-related requests.
- Payers who interact with a merchant's paywall should contact the merchant first, because the merchant controls their site, local WordPress records, and access cookies.
- For requests directed to CAMP as the platform operator, contact us at campinvestment.com/contact.
We may need to verify your identity before fulfilling requests.
9. Security
We use administrative, technical, and organizational measures appropriate to the nature of the data, including hashed API key storage, HttpOnly session cookies, server-side secret handling in recommended integrations, and access controls on production systems. No method of transmission or storage is completely secure.
You are responsible for securing your API keys, WordPress admin access, and server environments.
10. Children
TransX402 is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe we have collected such information.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on transx402.com/privacy and update the effective date. Material changes may also be communicated through the dashboard or other appropriate channels.
12. Contact
Data controller (hosted platform): CAMP Investment Technologies Pte. Ltd. (UEN 202340504H), operating the TransX402 brand.
Registered office: 7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987
Contact: campinvestment.com/contact