Legal
Privacy policy.
What Canopy collects when you use its deposit, routing and settlement service, its API and its MCP server, why, and how long it is kept. Canopy never asks the person paying for a name or email address.
Last updated [CONFIRM: publication date]
1. Who this policy covers
This policy describes how Canopy handles information when you hold a Canopy account, when you pay through a deposit address a business created with Canopy, when you or an AI assistant you use calls Canopy's API or MCP server, and when you visit Canopy's websites.
When you pay a business through Canopy, that business decides why it is taking your deposit and what it records about you on its own side. Its own privacy policy governs that. This policy covers only what Canopy itself receives and keeps.
[CONFIRM: the legal entity that operates Canopy and acts as controller, and its registered address.]
2. Information about account holders
To open and run a Canopy account we store your email address and a link to your sign-in record with our authentication provider. We send one-time verification codes to that address; the codes are stored only as hashes and expire.
We store the wallet addresses you connect or nominate: a wallet you sign in with, the payout wallet funds are delivered to by default, the wallet that authorises your payment routes, and, if you use one, an embedded wallet together with its provider's user identifier.
If you publish a public profile page we store the username, display name, bio, links and wallet address you enter, and they are shown publicly on that page.
For integrations we store your API keys and webhook endpoints. Secret keys are stored only as hashes and cannot be shown again after they are created. Webhook signing secrets are stored encrypted. We also store the website origins you allow to embed checkout.
3. Information about payments
Each payment intent records the deposit address issued for it, the destination wallet, chain and token the funds are delivered to, the amount if one was set, any reference or metadata the business attached, and the business's own identifier for the customer it was created for. Canopy does not ask the person paying for a name, email address or other contact details.
When a deposit arrives we record the transaction: its hash, the sending and receiving addresses, the token, the amount, and the transactions Canopy makes to route and settle it, including the fee deducted and the net delivered.
Blockchain transactions are public. The addresses, amounts and transaction hashes involved in a deposit are visible to anyone on the network it was made on, permanently, whether or not Canopy records them. Canopy cannot remove information from a blockchain.
The business that created a payment intent can see that intent's status, deposit addresses, amounts and transactions, and receives settlement notifications for it carrying the intent, the deposit address, the fee and net amounts, the transaction hash, the chain, and its own reference.
4. AI assistants and the MCP server
Canopy's MCP server lets an AI assistant create deposits and read their status on a Canopy account. When an assistant calls it, Canopy receives only the arguments of each tool call, such as an amount, a destination wallet or an intent identifier, and returns the result. Canopy does not receive your conversation with the assistant, your prompts, or anything else the assistant does not send as a tool argument.
If you connect an assistant through OAuth, we store the connecting application's registration details (its name, redirect addresses and, where it uses one, its client metadata URL), the Canopy account that approved it, and the permissions granted. Authorization codes, access tokens and refresh tokens are stored only as hashes. Authorization codes expire after 60 seconds, access tokens after one hour, and refresh tokens after 30 days or when you revoke the connection.
The assistant's provider handles your conversation under its own terms and privacy policy, not this one.
5. Usage and technical information
When you load a page on Canopy's websites we log the page path, the host of the referring site, whether the request looks like an automated client, and a pseudonymous visitor identifier. That identifier is a keyed hash derived from your IP address and browser user agent; the IP address itself is not written to the page-view log.
To protect the service from abuse we count requests per IP address or per credential in short-lived counters that expire on their own after two rate-limit windows.
Our application logs record operational events. Fields are written only from an explicit allow-list, and wallet addresses in logs are truncated.
We use a session cookie to keep you signed in to the dashboard, which expires after 15 minutes, and our authentication provider's cookies for your sign-in. We do not use advertising cookies or third-party advertising trackers.
6. How we use information
We use the information above to provide the service: to issue deposit addresses, detect deposits, route and settle them to the destination each payment intent names, take Canopy's fee, notify the business concerned, and show account holders their own activity.
We also use it to secure the service, prevent fraud and abuse, comply with legal obligations, operate and debug the service, and send account and service emails. You can unsubscribe from non-essential emails using the link in each one.
We do not sell personal information, and we do not use it for advertising.
7. Service providers
Canopy relies on service providers that process information on our behalf to run the service: Supabase (database and sign-in), Vercel (hosting), Axiom (application logs), Upstash (rate-limit counters), Temporal (background job orchestration), Alchemy and Helius (blockchain access and deposit detection, to which deposit addresses are registered for monitoring), Resend (email delivery), Openfort (embedded wallets), and Relay and Circle (cross-chain delivery, which receive the addresses and amounts of the transfers they carry).
[CONFIRM: that this list is complete, the regions in which each provider stores data, and the transfer mechanism used for any transfer outside the user's country.]
8. Retention
Verification codes, rate-limit counters, OAuth codes and tokens, and dashboard sessions expire on the schedules described above.
Closing a Canopy account unlinks your sign-in and marks the account closed. The account record and its payment history are retained so that past deposits can still be reconciled and so that we can meet legal and accounting obligations. [CONFIRM: retention period for closed accounts and payment records, and whether and when they are erased.]
[CONFIRM: retention period for application and page-view logs.]
Information written to a public blockchain cannot be deleted by Canopy or anyone else.
9. Security
Secret keys, verification codes and OAuth tokens are stored only as hashes, and webhook signing secrets are stored encrypted. Database access is restricted per account. No system is perfectly secure, and you are responsible for the security of your own wallet, keys and devices; Canopy never has custody of them.
10. Your choices and rights
Account holders can view and change their account details, and revoke API keys, from the dashboard. An AI assistant connected through OAuth can be disconnected by removing the connector in the assistant. [CONFIRM: whether the dashboard also lists and revokes connected assistants.] Depending on where you live you may have rights to access, correct, delete or object to the processing of your personal information. To exercise them, contact us using the details below.
[CONFIRM: the jurisdictions whose privacy laws apply and any rights or disclosures specific to them.]
Canopy is not directed at children. [CONFIRM: minimum age.]
11. Changes to this policy
Canopy may change this policy. The version published on this page is the version that applies, and the date at the top shows when it last changed.
12. Contact
Questions about a specific deposit should go to the business you are paying in the first instance. Questions about this policy or your information can be sent to [CONFIRM: privacy contact email].