Privacy Policy

This Privacy Policy explains how Paynet ("we", "us") collects, uses, and protects personal data when you use our website, merchant dashboard, payment APIs, hosted checkout, and fiscal receipt services. It applies to merchants, their staff, and to customers who pay through Paynet-powered checkouts.

Data controller

The Paynet platform is owned and operated by Digital Brains LLC ("Դիջիթալ Բրայենս" ՍՊԸ), a limited-liability company registered in the Republic of Armenia, Taxpayer ID 00486212, registered address: 26/3 V. Sargsyan St., Yerevan 0026, Armenia. Digital Brains LLC is the data controller responsible for the personal data described in this policy. Company website: https://digitalbrains.am. For any privacy request, contact [email protected].

1. Who we are

Paynet operates a payment aggregation platform in the Republic of Armenia. For merchant account data, Paynet is the data controller. For payment data processed on behalf of merchants during checkout, Paynet acts as a processor for the merchant.

2. Data we collect - merchants

Account data: your name, email address, phone number, company name, password (stored as a hash) and, if you turn on two-factor authentication, the secret used to generate your codes.

Verification data: legal name, legal form, tax identification number (TIN), registered address, and the documents you upload (state registration certificate, TIN certificate, identity document of the authorised person). Documents are stored on a private disk on our own server and backed up nightly. When you submit them, a copy is attached to an internal notification email sent to our operations mailbox. They are visible only to our staff.

Billing data: unit purchases, the payment rail used (bank transfer or Whop) and its references, and the unit ledger that records every unit granted, bought or consumed.

Integration data: your domains, payment provider credentials (stored encrypted), API keys (stored as hashes), webhook endpoints and signing secrets, and connect tokens issued to your plugins.

Security data: sign-in history and trusted devices, including IP address and browser, an audit log of security-relevant actions, and the new-device sign-in emails we send you.

Optional data: a Telegram chat ID if you connect Telegram notifications, and a referral code if you arrived through a referral link.

3. Data we collect - paying customers

When a customer pays through a Paynet checkout we process: the order reference and description, amount and currency, the customer's email address and name where the merchant or customer provides them, the IP address and browser user agent at the moment the payment is created, the chosen payment method, the payment status, and the transaction reference returned by the payment provider. Where a fiscal receipt is issued, we also process the order line items (names, quantities, prices).

Card numbers and card security codes are entered on the payment page of the bank or wallet provider and never reach Paynet. The Sandbox test provider accepts only test card numbers that are not real cards.

4. Fiscal receipt data

Where the merchant has activated the e-HDM service, receipt data (items, quantities, prices, tax regime) is transmitted to the State Revenue Committee electronic cash register system as required by Armenian tax law. The transmission uses the merchant's own SRC certificate and includes the merchant's SRC registration number and TIN. Receipt identifiers and verification QR codes are stored so receipts can be re-displayed.

5. Why we process data

To provide the Services under our contract with the merchant; to comply with legal obligations (tax, accounting, anti-money-laundering); to secure the platform (fraud prevention, abuse detection, login alerts); and, with consent where required, to send service communications.

6. Sharing and recipients

Payment data is shared with the bank or wallet provider selected for the transaction (an ARCA member bank, Idram, Telcell or Arca QR) to execute the payment. Fiscal data is shared with the State Revenue Committee where e-HDM is activated.

We also use the following service providers. Cloudflare sits in front of our website as a proxy and provides the Turnstile check on our sign-up, sign-in, password reset and contact forms; it sees request metadata such as IP address and browser. Sentry receives error reports from our application, including request metadata and IP address, but not user identities or form contents by default. Whop acts as merchant of record when you buy units by card and processes that card payment under its own terms. Telegram delivers notifications to merchants who have opted in. Email is sent from our own mail server.

We do not sell personal data and do not share it with advertisers.

7. International transfers

Our application and database run on a server we operate in a data centre in Germany (European Union). Some of the providers named above (Cloudflare, Sentry, Whop, Telegram) process data outside Armenia. Where that happens we rely on their published data protection commitments and send only what the service needs.

8. Retention

Account data is kept for the life of the account. Transactions, fiscal receipts and the unit ledger are kept for the life of the account and afterwards for as long as Armenian accounting and tax law requires. Raw request and response exchanges with payment providers are kept for 30 days. Payment timeline and event logs are kept for two years. Webhook delivery records are kept for 90 days. Failed background job records are kept for 30 days. Sign-in sessions expire after about two weeks of inactivity. Verification documents are deleted when you replace them and when the account is purged after closure.

You can close your account from Settings (Danger zone). Closure deactivates the account immediately, and personal data that is no longer needed is deleted in line with the periods above, except for records the law requires us to keep.

9. Security

All traffic to Paynet uses HTTPS. Payment provider credentials and fiscal certificates are encrypted at rest with AES-256. Passwords are stored as hashes. API keys are stored as SHA-256 hashes and the raw key is shown only once, when it is created. Webhooks are signed with HMAC-SHA256. Administrator access requires two-factor authentication, and merchants can turn it on for their own accounts. A Content Security Policy is enforced on every page. Security-relevant actions are logged. We do not guarantee uninterrupted availability; current status is published at paynet.am/status.

10. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to certain processing, and request a copy of data you provided. To exercise these rights, write to [email protected]. Paying customers should direct requests about their purchase data to the merchant they bought from; we assist merchants in fulfilling such requests.

11. Cookies

The website and dashboard use only cookies that are needed to run the service: paynetam_session keeps you signed in (about two weeks); XSRF-TOKEN protects forms against cross-site request forgery; paynet_locale remembers your language; paynet_ref remembers the referral link you arrived through (30 days) so the referring merchant can be credited; sidebar:state remembers whether the dashboard sidebar is collapsed. Your light or dark theme choice is kept in your browser's local storage, not in a cookie. Cloudflare may set its own cookies when you use a form protected by Turnstile. We do not use advertising, analytics or cross-site tracking cookies.

12. Changes and contact

We may update this Policy from time to time; material changes are announced on the website or by email. The current version always applies.

Privacy questions or requests? Contact us at [email protected]