Privacy policy
This policy describes which personal data is processed when you use KAI-Pay: the website kai-pay.net, the wallet at app.kai-pay.net, the point of sale at kasse.kai-pay.net and the payment pages kai-pay.net/@name.
KAI-Pay uses no user account, no cookies and no analytics or tracking tools. Your recovery words are stored only in encrypted form on your device. For payments, however, the wallet connects directly to services of other providers; sections 2 and 5 list them.
1. Controller and contact
The controller for our processing described below is:
Formsys GmbH
Grafenberger Allee 277–287
40237 Düsseldorf
Deutschland
Contact for privacy requests: kontakt@kai-pay.net
Some features rely on services of other providers that also process data themselves. Section 5 lists them, where available with a link to their own information.
2. What data we process and why
For each processing activity we state the legal basis under Article 6(1) GDPR. “Point (b)” means the processing is necessary for the function you use under our terms of use. “Point (f)” means we rely on a legitimate interest, which we name in each case.
2.1 Visiting the website kai-pay.net
- Data
- IP address, time, requested address and the technical information your browser sends with every request, for example browser type and version.
- Purpose
- Delivering the pages, redirecting to an encrypted connection (HTTPS), forwarding our other domains (kai-pay.org, kai-pay.online, kai-pay.world and the www addresses) to kai-pay.net, protection against attacks.
- Legal basis
- Article 6(1)(f) GDPR. Our interest: providing the website securely and reliably.
- Recipients
- Cloudflare as processor (section 5).
- Retention
- We do not keep our own access logs; no log storage is switched on in our configuration. Cloudflare processes connection data for delivery and protection against attacks under its data processing addendum.
The website contains no JavaScript and loads no content from third-party servers.
2.2 Delivering the wallet and the point of sale
- Data
- Connection data as in 2.1 when you load the app files or the wallet contacts our server.
- Purpose
- Delivering the wallet (app.kai-pay.net) and the point of sale (kasse.kai-pay.net). After the first visit the wallet starts from your browser’s storage (section 3).
- Legal basis
- Article 6(1)(b) GDPR.
- Recipients
- Cloudflare as processor.
- Retention
- As in 2.1.
2.3 Payments, balance and wallet synchronisation
The wallet uses the Breez SDK with the Spark network. The SDK runs in your browser and connects directly, not via our server, to the services named below.
- Data
- Your wallet’s public identity key; amounts, invoices (Lightning invoices) including any note entered, payment and transfer identifiers and times; your Bitcoin deposit addresses, Bitcoin addresses you withdraw to, and the related transactions; your IP address.
- Purpose
- Sending and receiving, showing balance and payment history, synchronising with the network, fee estimates and Bitcoin blockchain queries.
- Legal basis
- Article 6(1)(b) GDPR.
- Recipients
- The Spark operators Lightspark, Breez and Flashnet, which take part in transfers in the Spark network; the Spark service provider Lightspark for Lightning payments, for deposits and withdrawals via the Bitcoin blockchain and for the technical splitting of your balance; mempool.space for Bitcoin blockchain queries; Breez for signing the app in to its services, which uses the KAI-Pay API key.
- Retention
- On your device until you remove the data (section 3). At the providers according to their information (section 5). Entries on the Bitcoin blockchain are permanently public (section 4).
2.4 Paying Lightning addresses and LNURL links
When you enter an address of the form name@domain, the wallet uses Cloudflare’s DNS service (cloudflare-dns.com) to check whether the domain publishes a Bitcoin payment instruction for it (BIP 353). In addition, and likewise for LNURL links, it may contact the server of that domain directly to request an invoice. The DNS service receives the name queried, the recipient’s server receives the amount; both receive your IP address. The recipient decides which server that is. If a QR code contains the identifier of certain merchant payment systems (currently Pick n Pay and Bootleggers), the Breez SDK retrieves the payment details from the cryptoqr.net service.
- Legal basis
- Article 6(1)(b) GDPR.
2.5 Lightning address and payment page
In the wallet you can set up a Lightning address of the form name@breez.tips. The wallet checks with Breez’s LNURL server breez.tips whether the name is available and registers it there for your wallet. The name is public: anyone who knows it can request invoices through it and send you payments.
For every such address, kai-pay.net/@name shows a payment page. When someone opens it, our server retrieves the payment details for this name from breez.tips. When the person enters an amount, our server requests an invoice for that amount there, with the note entered if any, and checks the payment status on request. Our server makes the request to breez.tips; it adds no information about the person opening the page.
- Data
- The chosen name. When a payment page is opened: connection data as in 2.1, amount, note, invoice and payment status.
- Legal basis
- For setting up the address, Article 6(1)(b) GDPR. For people who open a payment page, Article 6(1)(f) GDPR; our interest: providing the payment page requested and retrieving the invoice requested.
- Recipients
- Breez (breez.tips); Cloudflare as processor.
- Retention
- The payment page creates no records on our server. The name registration is held by Breez; its duration follows the provider’s information.
2.6 Contacts and synchronisation between your devices
The Breez SDK stores contacts (name and Lightning address) and additional payment details on your device. Through Breez’s synchronisation service (datasync.breez.technology) it synchronises them with other devices on which the same wallet is open. The records are encrypted in your browser beforehand; the key is derived from your wallet. Breez receives the encrypted records, your IP address and the time.
- Legal basis
- Article 6(1)(b) GDPR.
- Recipients
- Breez.
- Retention
- On your device until you remove the data (section 3); at Breez according to its information.
2.7 Exchange rates in the wallet
To also show amounts in euros or US dollars, the wallet retrieves current rates from a Breez server through the Breez SDK. Your IP address and the time are transmitted. Legal basis: Article 6(1)(b) GDPR.
2.8 Passkey and fingerprint unlock
You can create a wallet with a passkey or unlock the app with your fingerprint (WebAuthn with the PRF extension). Your fingerprint or other unlock method is checked in your device or by your passkey provider; neither the app nor we receive biometric data. The app only receives a value derived from the passkey, which it uses to derive your wallet or decrypt the vault. Depending on your device and settings, passkeys may be synchronised by your operating system’s or browser’s password manager; its terms apply.
For passkey wallets, the Breez SDK uses Nostr relays to store the wallet’s label (“Default” by default) and retrieve it when the wallet is opened. The label is published as a public, unencrypted Nostr message under a key derived from your passkey. The relays used are one run by Breez (nr1.breez.technology) and public relays of other operators (relay.primal.net, relay.damus.io, relay.nostr.watch, relaypag.es, monitorlizard.nostr1.com). The SDK may also publish a list of the relays used there. The relays also receive your IP address. Their operators decide how long they keep messages.
- Legal basis
- Article 6(1)(b) GDPR.
2.9 Notifications of incoming payments
This processing only takes place if you switch on notifications in the wallet settings.
- Data stored
- On our server: your browser’s push subscription address (endpoint) with its keys (p256dh, auth), a random identifier, a webhook secret and the language of the notifications.
- How it works
- For this, your browser sets up a subscription with its push service. The wallet registers a webhook address of our server and the webhook secret with the Spark service provider Lightspark (2.3). For every incoming Lightning payment, Lightspark sends a message signed with this secret to that address. The message may contain further payment details; we only evaluate the amount and do not store the message. Our server thereby learns the amount and time of incoming Lightning payments. Our server encrypts the notification (“Payment received” with the amount) for your browser (Web Push under RFC 8291) and delivers it through the push service of your browser’s maker. The push service receives the endpoint, the time and the message in encrypted form only.
- Receipt confirmation
- After a notification, your browser reports to our server a random marker of the notification, whether an app window was open and whether the notification could be shown.
- Diagnostics
- Our server stores diagnostic events: type of event, time, the first four characters of the identifier, the server name of the push service, result and status code, whether an amount was recognised (not the amount), the receipt confirmation details and, for rejected messages, the names of the header fields sent. They contain no IP addresses, amounts or keys.
- Request limit
- Wallet requests to subscribe, unsubscribe, test and confirm receipt are limited to 20 per minute and IP address. The IP address is used only as a counting key for the limit, which Cloudflare applies on our behalf; our server does not store it.
- Legal basis
- For notifications, Article 6(1)(b) GDPR. For receipt confirmation, diagnostics and the request limit, Article 6(1)(f) GDPR; our interest: checking delivery, fixing errors and preventing abuse and overload.
- Recipients
- Cloudflare as processor; Lightspark; the push service of your browser’s maker (section 5).
- Retention
- The push entry is deleted 400 days after you switch notifications on, or earlier if you switch them off or the push service reports the subscription as invalid. When you switch notifications off, the wallet also removes the webhook registration at Lightspark. Diagnostic events are deleted after 3 days.
2.10 Point of sale
The point of sale at kasse.kai-pay.net holds no keys and cannot send money. It stores the merchant’s Lightning address in the browser of the point-of-sale device. For each payment it requests an invoice for the amount directly from the browser at the LNURL server breez.tips (with the note “Kasse”) and checks its payment status. For entry in euros it retrieves the current rate directly from mempool.space. These providers receive the IP address of the point-of-sale device.
- Legal basis
- Article 6(1)(b) GDPR.
- Recipients
- Breez (breez.tips); mempool.space; Cloudflare as processor for delivery.
- Retention
- The point of sale creates no records on our server. The merchant address stays in the browser until you choose “Andere Adresse” (other address) or delete the site data.
3. Devices, permissions and connections
Wi-Fi and mobile networks transmit data; network operators may process connection data independently. KAI-Pay does not use location data.
The wallet requests browser permissions only when you start the relevant function. Purpose, scope and alternative:
- Camera: only for scanning QR codes. The image is analysed in your browser and not transmitted. Alternative: paste the payment request.
- Clipboard: read only when you tap “Paste”. Alternative: enter it by hand.
- Notifications: only if you switch on notifications (2.9). Alternative: check incoming payments in the open wallet.
- Passkey and fingerprint: only if you create a passkey wallet or set up fingerprint unlock (2.8). Alternative: 12 words and PIN.
An operating-system or browser permission does not automatically replace legally required privacy consent.
Storage on your device
We do not set cookies. The website kai-pay.net stores no information about you on your device; your browser may merely cache its files. The wallet and the point of sale store the following in your browser’s storage (localStorage, IndexedDB and cache storage):
- Vault (wallet)
- Your recovery words, encrypted (AES-GCM, 256 bits) with a key from your PIN (PBKDF2 with 600,000 iterations) and/or from your passkey for fingerprint unlock. For passkey wallets only a marker with the passkey’s identifier, no words.
- Failed PIN attempts (wallet)
- Number of failed attempts and waiting time until the next attempt.
- Settings (wallet)
- Language, unit, currency, appearance and whether you have confirmed the backup of your words.
- Contact changes (wallet)
- The last seen Lightning address per contact and the time of a change, so that the wallet warns about changed addresses for 24 hours.
- Push entry (wallet)
- Only with notifications switched on: identifier, webhook secret and webhook identifier.
- Wallet database (wallet)
- Breez SDK data such as payment history, contacts and wallet state.
- App files (wallet)
- Program files so that the wallet starts quickly and also without a network connection (service worker). They contain no information about you.
- Merchant address (point of sale)
- The Lightning address for which payments are collected.
The legal basis for storing and reading this information is section 25(2) no. 2 TDDDG, because it is strictly necessary for the function you expressly requested; for further processing, Article 6(1)(b) GDPR. There is no non-essential access to your device; we therefore do not ask for consent.
“Remove wallet from this device” in the settings deletes the vault, failed PIN attempts and the wallet database and unsubscribes from notifications. Settings, contact changes and app files remain stored until you delete the site data in your browser. At the point of sale, “Andere Adresse” (other address) removes the merchant address.
4. Wallet and network data
We do not transmit seeds (recovery words) or private keys to our servers. Public addresses, transaction identifiers and metadata may still be personal data. Public blockchain records are ordinarily persistently accessible to third parties and cannot technically be erased by us. This does not remove duties to minimise data, assess lawful processing or erase data within our control.
Do not place names, contact details or confidential content in public transaction fields, invoice notes or the name of your Lightning address.
The Spark operators take part in transfers in the Spark network and process the data listed in 2.3 for this purpose.
5. Recipients, international transfers and sources
The overview below identifies each recipient’s task, data categories, processing country and legal basis, and its provider and role where these are established. Processors act under contractual instructions; independent providers issue their own information. EU hosting alone does not exclude third-country access.
Cloudflare
- Provider
- Cloudflare, Inc., USA.
- Task
- Hosting and delivery of kai-pay.net, app.kai-pay.net, kasse.kai-pay.net and the forwarding domains; running our server programs; storage for push entries and diagnostic events; request limiting.
- Data categories
- Connection data (2.1, 2.2), payment page requests (2.5), push entries and diagnostic events (2.9).
- Role
- Processor under Cloudflare’s data processing addendum.
- Country and safeguards
- USA and a worldwide server network. Cloudflare states that it is certified under the EU-U.S. Data Privacy Framework, for which an adequacy decision of the European Commission exists. For transfers not covered by it, Cloudflare’s data processing addendum provides for EU standard contractual clauses; it is publicly available. You can also obtain a copy of the safeguards via kontakt@kai-pay.net.
- Legal basis
- Depending on the purpose, see 2.1, 2.2, 2.5, 2.9 and 2.10.
- Information
- Cloudflare privacy policy, Cloudflare sub-processors.
Breez
- Provider
- Breez, provider of the Breez SDK.
- Task
- Spark operator; signing the app in to Breez services; exchange rates; synchronisation of contacts and payment details; LNURL server breez.tips for Lightning addresses, invoices and payment status (wallet, point of sale, payment page); Nostr relay for passkey wallets.
- Data categories
- IP address and time; data of transfers in the Spark network (2.3); encrypted synchronisation data (2.6); Lightning address name, amounts, notes, invoices and payment status (2.5, 2.10); label of passkey wallets (2.8).
- Role
- As a Spark operator, Breez acts independently. Breez provides the other services as provider of the SDK.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR; when payers open a payment page, Article 6(1)(f) GDPR (2.5).
- Information
- Breez privacy notice.
Lightspark
- Provider
- Lightspark Group, Inc.; headquartered in the USA according to its own information.
- Task
- Spark operator; Spark service provider for Lightning payments, deposits and withdrawals via the Bitcoin blockchain and the technical splitting of the balance (2.3); sending messages about incoming payments if you use notifications.
- Data categories
- IP address and time; data of transfers, Lightning payments, deposits and withdrawals (2.3); the webhook address of our server registered for your wallet and the related webhook secret (2.9).
- Role
- As a Spark operator, Lightspark acts independently. Lightspark provides the other services as their provider.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR.
- Information
- Lightspark privacy policy.
Flashnet
- Task
- Spark operator.
- Data categories
- IP address and time; data of transfers in the Spark network (2.3).
- Role
- Independent controller.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR.
- Information
- Flashnet privacy policy.
mempool.space
- Task
- Bitcoin blockchain queries for the wallet (deposit addresses, transactions, fee estimates); exchange rates for the point of sale.
- Data categories
- IP address and time; Bitcoin addresses and transactions queried.
- Role
- Independent controller.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR.
- Information
- mempool.space privacy policy.
Cloudflare DNS service
- Provider
- Cloudflare, Inc., public DNS service 1.1.1.1.
- Task
- DNS lookup of Bitcoin payment instructions (BIP 353) when paying name@domain (2.4).
- Data categories
- IP address, name queried and time.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR.
- Information
- Privacy commitments for the 1.1.1.1 DNS service.
Payment recipients’ servers
- Task
- Invoices for Lightning addresses and LNURL links of other providers; payment details for QR codes of certain merchant payment systems via cryptoqr.net (2.4).
- Data categories
- IP address, time, address queried and amount.
- Provider and country
- Determined by the payment recipient.
- Legal basis
- Article 6(1)(b) GDPR.
Push services of browser makers
- Provider
- Google, Mozilla, Apple or Microsoft, depending on your browser.
- Task
- Setting up the push subscription by your browser and delivering notifications (2.9).
- Data categories
- Endpoint, time and the encrypted message; during setup, your browser’s connection data.
- Role
- Independent controller.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR.
- Information
- Google, Mozilla, Apple, Microsoft.
Nostr relays
- Provider
- Breez (nr1.breez.technology) and the operators of the public relays relay.primal.net, relay.damus.io, relay.nostr.watch, relaypag.es and monitorlizard.nostr1.com.
- Task
- Storing and retrieving the label of passkey wallets (2.8).
- Data categories
- Public Nostr message containing the label, where applicable a list of the relays used, the public key derived from your passkey, IP address and time.
- Country
- Processing may also take place outside the EU.
- Legal basis
- Article 6(1)(b) GDPR.
Sources
We receive data from third parties in two cases only: messages from the Spark service provider Lightspark about incoming payments (2.9), and invoices and payment status from breez.tips for the payment page (2.5).
6. Your rights and complaints
Subject to statutory conditions, you may request access, rectification, erasure, restriction and portability. Consent may be withdrawn for the future without affecting previous lawfulness. You may object to legitimate-interest processing on grounds relating to your situation, and to direct marketing at any time. Contact: kontakt@kai-pay.net.
You may complain to a supervisory authority, particularly where you live, work or consider a breach occurred. Our competent authority is Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, www.ldi.nrw.de.
Identity checks request only necessary and proportionate information, never a seed (your recovery words).
7. Required data, automation and changes
KAI-Pay requires no account, and you do not have to provide your name or email address. A function cannot operate without necessary connectivity or payment data. Lightning address, contacts, notifications, passkey and fingerprint are optional; the wallet can be used without them.
We make no solely automated decision with legal or similarly significant effects. If such profiling or blocking is introduced, we will first add the legal basis, understandable logic, effects and required safeguards. Material processing changes are communicated before they begin; fresh consent is obtained where needed.