Data Protection Policy

    Last updated: 9/26/2026

    1. Purpose

    This policy explains how XcrowPay protects personal and transaction data processed while providing escrow, payment, payout, and dispute services.

    2. Data Classification

    We classify data into account data, transaction data, payout data, support/dispute data, and operational security logs, and apply controls according to sensitivity.

    3. Access Control

    Access is restricted by role and least privilege. Administrative actions are logged for auditability and incident review.

    4. Storage and Encryption

    Data is stored on managed cloud infrastructure with security controls. Data in transit is protected using HTTPS/TLS. Sensitive credentials are managed via protected environment configuration.

    5. Monitoring and Incident Response

    We monitor critical events and investigate suspicious activity. Where required by law, we notify affected users and regulators within applicable timelines.

    6. Third-Party Processors

    We use trusted third-party providers for payment processing, communications, and infrastructure. These providers are selected based on security, reliability, and compliance considerations.

    7. Retention and Deletion

    Data is retained only as long as needed for service delivery, legal obligations, anti-fraud controls, and dispute handling, then archived or deleted according to internal retention rules.

    8. User Controls

    Users can manage profile details, notification preferences, and request support for account data concerns through official channels.