KAI-Pay

Privacy policy

This policy describes which personal data is processed when you use KAI-Pay: the website kai-pay.net, the wallet at app.kai-pay.net, the point of sale at kasse.kai-pay.net and the payment pages kai-pay.net/@name.

KAI-Pay uses no user account, no cookies and no analytics or tracking tools. Your recovery words are stored only in encrypted form on your device. For payments, however, the wallet connects directly to services of other providers; sections 2 and 5 list them.

1. Controller and contact

The controller for our processing described below is:

Formsys GmbH
Grafenberger Allee 277–287
40237 Düsseldorf
Deutschland

Contact for privacy requests: kontakt@kai-pay.net

Some features rely on services of other providers that also process data themselves. Section 5 lists them, where available with a link to their own information.

2. What data we process and why

For each processing activity we state the legal basis under Article 6(1) GDPR. “Point (b)” means the processing is necessary for the function you use under our terms of use. “Point (f)” means we rely on a legitimate interest, which we name in each case.

2.1 Visiting the website kai-pay.net

Data
IP address, time, requested address and the technical information your browser sends with every request, for example browser type and version.
Purpose
Delivering the pages, redirecting to an encrypted connection (HTTPS), forwarding our other domains (kai-pay.org, kai-pay.online, kai-pay.world and the www addresses) to kai-pay.net, protection against attacks.
Legal basis
Article 6(1)(f) GDPR. Our interest: providing the website securely and reliably.
Recipients
Cloudflare as processor (section 5).
Retention
We do not keep our own access logs; no log storage is switched on in our configuration. Cloudflare processes connection data for delivery and protection against attacks under its data processing addendum.

The website contains no JavaScript and loads no content from third-party servers.

2.2 Delivering the wallet and the point of sale

Data
Connection data as in 2.1 when you load the app files or the wallet contacts our server.
Purpose
Delivering the wallet (app.kai-pay.net) and the point of sale (kasse.kai-pay.net). After the first visit the wallet starts from your browser’s storage (section 3).
Legal basis
Article 6(1)(b) GDPR.
Recipients
Cloudflare as processor.
Retention
As in 2.1.

2.3 Payments, balance and wallet synchronisation

The wallet uses the Breez SDK with the Spark network. The SDK runs in your browser and connects directly, not via our server, to the services named below.

Data
Your wallet’s public identity key; amounts, invoices (Lightning invoices) including any note entered, payment and transfer identifiers and times; your Bitcoin deposit addresses, Bitcoin addresses you withdraw to, and the related transactions; your IP address.
Purpose
Sending and receiving, showing balance and payment history, synchronising with the network, fee estimates and Bitcoin blockchain queries.
Legal basis
Article 6(1)(b) GDPR.
Recipients
The Spark operators Lightspark, Breez and Flashnet, which take part in transfers in the Spark network; the Spark service provider Lightspark for Lightning payments, for deposits and withdrawals via the Bitcoin blockchain and for the technical splitting of your balance; mempool.space for Bitcoin blockchain queries; Breez for signing the app in to its services, which uses the KAI-Pay API key.
Retention
On your device until you remove the data (section 3). At the providers according to their information (section 5). Entries on the Bitcoin blockchain are permanently public (section 4).

2.4 Paying Lightning addresses and LNURL links

When you enter an address of the form name@domain, the wallet uses Cloudflare’s DNS service (cloudflare-dns.com) to check whether the domain publishes a Bitcoin payment instruction for it (BIP 353). In addition, and likewise for LNURL links, it may contact the server of that domain directly to request an invoice. The DNS service receives the name queried, the recipient’s server receives the amount; both receive your IP address. The recipient decides which server that is. If a QR code contains the identifier of certain merchant payment systems (currently Pick n Pay and Bootleggers), the Breez SDK retrieves the payment details from the cryptoqr.net service.

Legal basis
Article 6(1)(b) GDPR.

2.5 Lightning address and payment page

In the wallet you can set up a Lightning address of the form name@breez.tips. The wallet checks with Breez’s LNURL server breez.tips whether the name is available and registers it there for your wallet. The name is public: anyone who knows it can request invoices through it and send you payments.

For every such address, kai-pay.net/@name shows a payment page. When someone opens it, our server retrieves the payment details for this name from breez.tips. When the person enters an amount, our server requests an invoice for that amount there, with the note entered if any, and checks the payment status on request. Our server makes the request to breez.tips; it adds no information about the person opening the page.

Data
The chosen name. When a payment page is opened: connection data as in 2.1, amount, note, invoice and payment status.
Legal basis
For setting up the address, Article 6(1)(b) GDPR. For people who open a payment page, Article 6(1)(f) GDPR; our interest: providing the payment page requested and retrieving the invoice requested.
Recipients
Breez (breez.tips); Cloudflare as processor.
Retention
The payment page creates no records on our server. The name registration is held by Breez; its duration follows the provider’s information.

2.6 Contacts and synchronisation between your devices

The Breez SDK stores contacts (name and Lightning address) and additional payment details on your device. Through Breez’s synchronisation service (datasync.breez.technology) it synchronises them with other devices on which the same wallet is open. The records are encrypted in your browser beforehand; the key is derived from your wallet. Breez receives the encrypted records, your IP address and the time.

Legal basis
Article 6(1)(b) GDPR.
Recipients
Breez.
Retention
On your device until you remove the data (section 3); at Breez according to its information.

2.7 Exchange rates in the wallet

To also show amounts in euros or US dollars, the wallet retrieves current rates from a Breez server through the Breez SDK. Your IP address and the time are transmitted. Legal basis: Article 6(1)(b) GDPR.

2.8 Passkey and fingerprint unlock

You can create a wallet with a passkey or unlock the app with your fingerprint (WebAuthn with the PRF extension). Your fingerprint or other unlock method is checked in your device or by your passkey provider; neither the app nor we receive biometric data. The app only receives a value derived from the passkey, which it uses to derive your wallet or decrypt the vault. Depending on your device and settings, passkeys may be synchronised by your operating system’s or browser’s password manager; its terms apply.

For passkey wallets, the Breez SDK uses Nostr relays to store the wallet’s label (“Default” by default) and retrieve it when the wallet is opened. The label is published as a public, unencrypted Nostr message under a key derived from your passkey. The relays used are one run by Breez (nr1.breez.technology) and public relays of other operators (relay.primal.net, relay.damus.io, relay.nostr.watch, relaypag.es, monitorlizard.nostr1.com). The SDK may also publish a list of the relays used there. The relays also receive your IP address. Their operators decide how long they keep messages.

Legal basis
Article 6(1)(b) GDPR.

2.9 Notifications of incoming payments

This processing only takes place if you switch on notifications in the wallet settings.

Data stored
On our server: your browser’s push subscription address (endpoint) with its keys (p256dh, auth), a random identifier, a webhook secret and the language of the notifications.
How it works
For this, your browser sets up a subscription with its push service. The wallet registers a webhook address of our server and the webhook secret with the Spark service provider Lightspark (2.3). For every incoming Lightning payment, Lightspark sends a message signed with this secret to that address. The message may contain further payment details; we only evaluate the amount and do not store the message. Our server thereby learns the amount and time of incoming Lightning payments. Our server encrypts the notification (“Payment received” with the amount) for your browser (Web Push under RFC 8291) and delivers it through the push service of your browser’s maker. The push service receives the endpoint, the time and the message in encrypted form only.
Receipt confirmation
After a notification, your browser reports to our server a random marker of the notification, whether an app window was open and whether the notification could be shown.
Diagnostics
Our server stores diagnostic events: type of event, time, the first four characters of the identifier, the server name of the push service, result and status code, whether an amount was recognised (not the amount), the receipt confirmation details and, for rejected messages, the names of the header fields sent. They contain no IP addresses, amounts or keys.
Request limit
Wallet requests to subscribe, unsubscribe, test and confirm receipt are limited to 20 per minute and IP address. The IP address is used only as a counting key for the limit, which Cloudflare applies on our behalf; our server does not store it.
Legal basis
For notifications, Article 6(1)(b) GDPR. For receipt confirmation, diagnostics and the request limit, Article 6(1)(f) GDPR; our interest: checking delivery, fixing errors and preventing abuse and overload.
Recipients
Cloudflare as processor; Lightspark; the push service of your browser’s maker (section 5).
Retention
The push entry is deleted 400 days after you switch notifications on, or earlier if you switch them off or the push service reports the subscription as invalid. When you switch notifications off, the wallet also removes the webhook registration at Lightspark. Diagnostic events are deleted after 3 days.

2.10 Point of sale

The point of sale at kasse.kai-pay.net holds no keys and cannot send money. It stores the merchant’s Lightning address in the browser of the point-of-sale device. For each payment it requests an invoice for the amount directly from the browser at the LNURL server breez.tips (with the note “Kasse”) and checks its payment status. For entry in euros it retrieves the current rate directly from mempool.space. These providers receive the IP address of the point-of-sale device.

Legal basis
Article 6(1)(b) GDPR.
Recipients
Breez (breez.tips); mempool.space; Cloudflare as processor for delivery.
Retention
The point of sale creates no records on our server. The merchant address stays in the browser until you choose “Andere Adresse” (other address) or delete the site data.

3. Devices, permissions and connections

Wi-Fi and mobile networks transmit data; network operators may process connection data independently. KAI-Pay does not use location data.

The wallet requests browser permissions only when you start the relevant function. Purpose, scope and alternative:

An operating-system or browser permission does not automatically replace legally required privacy consent.

Storage on your device

We do not set cookies. The website kai-pay.net stores no information about you on your device; your browser may merely cache its files. The wallet and the point of sale store the following in your browser’s storage (localStorage, IndexedDB and cache storage):

Vault (wallet)
Your recovery words, encrypted (AES-GCM, 256 bits) with a key from your PIN (PBKDF2 with 600,000 iterations) and/or from your passkey for fingerprint unlock. For passkey wallets only a marker with the passkey’s identifier, no words.
Failed PIN attempts (wallet)
Number of failed attempts and waiting time until the next attempt.
Settings (wallet)
Language, unit, currency, appearance and whether you have confirmed the backup of your words.
Contact changes (wallet)
The last seen Lightning address per contact and the time of a change, so that the wallet warns about changed addresses for 24 hours.
Push entry (wallet)
Only with notifications switched on: identifier, webhook secret and webhook identifier.
Wallet database (wallet)
Breez SDK data such as payment history, contacts and wallet state.
App files (wallet)
Program files so that the wallet starts quickly and also without a network connection (service worker). They contain no information about you.
Merchant address (point of sale)
The Lightning address for which payments are collected.

The legal basis for storing and reading this information is section 25(2) no. 2 TDDDG, because it is strictly necessary for the function you expressly requested; for further processing, Article 6(1)(b) GDPR. There is no non-essential access to your device; we therefore do not ask for consent.

“Remove wallet from this device” in the settings deletes the vault, failed PIN attempts and the wallet database and unsubscribes from notifications. Settings, contact changes and app files remain stored until you delete the site data in your browser. At the point of sale, “Andere Adresse” (other address) removes the merchant address.

4. Wallet and network data

We do not transmit seeds (recovery words) or private keys to our servers. Public addresses, transaction identifiers and metadata may still be personal data. Public blockchain records are ordinarily persistently accessible to third parties and cannot technically be erased by us. This does not remove duties to minimise data, assess lawful processing or erase data within our control.

Do not place names, contact details or confidential content in public transaction fields, invoice notes or the name of your Lightning address.

The Spark operators take part in transfers in the Spark network and process the data listed in 2.3 for this purpose.

5. Recipients, international transfers and sources

The overview below identifies each recipient’s task, data categories, processing country and legal basis, and its provider and role where these are established. Processors act under contractual instructions; independent providers issue their own information. EU hosting alone does not exclude third-country access.

Cloudflare

Provider
Cloudflare, Inc., USA.
Task
Hosting and delivery of kai-pay.net, app.kai-pay.net, kasse.kai-pay.net and the forwarding domains; running our server programs; storage for push entries and diagnostic events; request limiting.
Data categories
Connection data (2.1, 2.2), payment page requests (2.5), push entries and diagnostic events (2.9).
Role
Processor under Cloudflare’s data processing addendum.
Country and safeguards
USA and a worldwide server network. Cloudflare states that it is certified under the EU-U.S. Data Privacy Framework, for which an adequacy decision of the European Commission exists. For transfers not covered by it, Cloudflare’s data processing addendum provides for EU standard contractual clauses; it is publicly available. You can also obtain a copy of the safeguards via kontakt@kai-pay.net.
Legal basis
Depending on the purpose, see 2.1, 2.2, 2.5, 2.9 and 2.10.
Information
Cloudflare privacy policy, Cloudflare sub-processors.

Breez

Provider
Breez, provider of the Breez SDK.
Task
Spark operator; signing the app in to Breez services; exchange rates; synchronisation of contacts and payment details; LNURL server breez.tips for Lightning addresses, invoices and payment status (wallet, point of sale, payment page); Nostr relay for passkey wallets.
Data categories
IP address and time; data of transfers in the Spark network (2.3); encrypted synchronisation data (2.6); Lightning address name, amounts, notes, invoices and payment status (2.5, 2.10); label of passkey wallets (2.8).
Role
As a Spark operator, Breez acts independently. Breez provides the other services as provider of the SDK.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR; when payers open a payment page, Article 6(1)(f) GDPR (2.5).
Information
Breez privacy notice.

Lightspark

Provider
Lightspark Group, Inc.; headquartered in the USA according to its own information.
Task
Spark operator; Spark service provider for Lightning payments, deposits and withdrawals via the Bitcoin blockchain and the technical splitting of the balance (2.3); sending messages about incoming payments if you use notifications.
Data categories
IP address and time; data of transfers, Lightning payments, deposits and withdrawals (2.3); the webhook address of our server registered for your wallet and the related webhook secret (2.9).
Role
As a Spark operator, Lightspark acts independently. Lightspark provides the other services as their provider.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR.
Information
Lightspark privacy policy.

Flashnet

Task
Spark operator.
Data categories
IP address and time; data of transfers in the Spark network (2.3).
Role
Independent controller.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR.
Information
Flashnet privacy policy.

mempool.space

Task
Bitcoin blockchain queries for the wallet (deposit addresses, transactions, fee estimates); exchange rates for the point of sale.
Data categories
IP address and time; Bitcoin addresses and transactions queried.
Role
Independent controller.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR.
Information
mempool.space privacy policy.

Cloudflare DNS service

Provider
Cloudflare, Inc., public DNS service 1.1.1.1.
Task
DNS lookup of Bitcoin payment instructions (BIP 353) when paying name@domain (2.4).
Data categories
IP address, name queried and time.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR.
Information
Privacy commitments for the 1.1.1.1 DNS service.

Payment recipients’ servers

Task
Invoices for Lightning addresses and LNURL links of other providers; payment details for QR codes of certain merchant payment systems via cryptoqr.net (2.4).
Data categories
IP address, time, address queried and amount.
Provider and country
Determined by the payment recipient.
Legal basis
Article 6(1)(b) GDPR.

Push services of browser makers

Provider
Google, Mozilla, Apple or Microsoft, depending on your browser.
Task
Setting up the push subscription by your browser and delivering notifications (2.9).
Data categories
Endpoint, time and the encrypted message; during setup, your browser’s connection data.
Role
Independent controller.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR.
Information
Google, Mozilla, Apple, Microsoft.

Nostr relays

Provider
Breez (nr1.breez.technology) and the operators of the public relays relay.primal.net, relay.damus.io, relay.nostr.watch, relaypag.es and monitorlizard.nostr1.com.
Task
Storing and retrieving the label of passkey wallets (2.8).
Data categories
Public Nostr message containing the label, where applicable a list of the relays used, the public key derived from your passkey, IP address and time.
Country
Processing may also take place outside the EU.
Legal basis
Article 6(1)(b) GDPR.

Sources

We receive data from third parties in two cases only: messages from the Spark service provider Lightspark about incoming payments (2.9), and invoices and payment status from breez.tips for the payment page (2.5).

6. Your rights and complaints

Subject to statutory conditions, you may request access, rectification, erasure, restriction and portability. Consent may be withdrawn for the future without affecting previous lawfulness. You may object to legitimate-interest processing on grounds relating to your situation, and to direct marketing at any time. Contact: kontakt@kai-pay.net.

You may complain to a supervisory authority, particularly where you live, work or consider a breach occurred. Our competent authority is Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, www.ldi.nrw.de.

Identity checks request only necessary and proportionate information, never a seed (your recovery words).

7. Required data, automation and changes

KAI-Pay requires no account, and you do not have to provide your name or email address. A function cannot operate without necessary connectivity or payment data. Lightning address, contacts, notifications, passkey and fingerprint are optional; the wallet can be used without them.

We make no solely automated decision with legal or similarly significant effects. If such profiling or blocking is introduced, we will first add the legal basis, understandable logic, effects and required safeguards. Material processing changes are communicated before they begin; fresh consent is obtained where needed.