Last updated: 9/26/2026
This policy explains how XcrowPay protects personal and transaction data processed while providing escrow, payment, payout, and dispute services.
We classify data into account data, transaction data, payout data, support/dispute data, and operational security logs, and apply controls according to sensitivity.
Access is restricted by role and least privilege. Administrative actions are logged for auditability and incident review.
Data is stored on managed cloud infrastructure with security controls. Data in transit is protected using HTTPS/TLS. Sensitive credentials are managed via protected environment configuration.
We monitor critical events and investigate suspicious activity. Where required by law, we notify affected users and regulators within applicable timelines.
We use trusted third-party providers for payment processing, communications, and infrastructure. These providers are selected based on security, reliability, and compliance considerations.
Data is retained only as long as needed for service delivery, legal obligations, anti-fraud controls, and dispute handling, then archived or deleted according to internal retention rules.
Users can manage profile details, notification preferences, and request support for account data concerns through official channels.