Legal

Privacy Policy

This Privacy Policy explains how usaepya collects, uses, and protects your personal information when you use our payment gateway and related services.

Effective Date: January 1, 2026Last Updated: June 15, 2026

1Data We Collect

We collect information you provide directly: name, email address, business details, billing information, and API credentials when you register or use usaepya services.

We automatically collect technical data including IP addresses, browser type, device identifiers, log files, and usage metrics when you interact with our platform or APIs.

We may also collect transaction data processed through our payment gateway, including amounts, timestamps, and merchant/customer identifiers necessary to complete and record payments.

2How We Use Your Data

To provide, operate, and improve our payment processing services, authenticate users, process transactions, and send service-related communications.

To detect and prevent fraud, comply with legal obligations, enforce our Terms of Service, and protect the rights and safety of usaepya, merchants, and end users.

We do not sell your personal data to third parties for marketing purposes.

3Cookies & Tracking

We use strictly necessary cookies to maintain sessions and secure authentication, analytics cookies (e.g., aggregate page-view metrics) to improve our platform, and preference cookies to remember your settings.

You may control or disable non-essential cookies via your browser settings or our cookie consent manager. Disabling strictly necessary cookies may impair platform functionality.

For full details, see our Cookie Policy at usaepya Cookie Policy.

4Third-Party Sharing

We share data with trusted sub-processors — including cloud infrastructure providers, fraud detection services, and banking partners — solely to deliver our services, under strict data processing agreements.

We may disclose data when required by law, court order, or regulatory authority, or to protect against imminent harm.

Our current sub-processors include AWS (cloud hosting), Stripe Atlas-compatible banking rails, and industry-standard KYC/AML verification vendors.

5Your Rights (GDPR & CCPA)

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request erasure of your data, subject to legal retention obligations.
  • Portability: Receive your data in a structured, machine-readable format.
  • Opt-Out (CCPA): California residents may opt out of any sale of personal information (we do not sell personal data).
  • Objection / Restriction: Object to or restrict certain processing activities.

6Data Retention

We retain account and transaction data for a minimum of 5 years to comply with financial regulations (AML, PCI-DSS, and applicable tax laws), unless a longer period is required by law.

Upon account closure, personal data not subject to legal retention is deleted or anonymized within 90 days.

7Security

usaepya employs industry-standard safeguards: TLS 1.3 encryption in transit, AES-256 encryption at rest, PCI-DSS Level 1 compliance, and role-based access controls.

Despite these measures, no system is completely secure. We encourage you to use strong, unique passwords and notify us immediately at [email protected] if you suspect unauthorized access.

8Children's Privacy

Our services are directed solely to businesses and individuals aged 18 or older. We do not knowingly collect personal data from anyone under 18.

If we become aware that a minor's data has been collected, we will delete it promptly.

9Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice on our platform at least 14 days before taking effect.

Continued use of usaepya services after the effective date constitutes acceptance of the revised policy.

10Contact & Data Controller

usaepya Inc. is the data controller for personal data processed under this policy.

For privacy inquiries, rights requests, or complaints, contact our Data Protection Officer at: [email protected] or by mail at usaepya Inc., 1209 Orange Street, Wilmington, DE 19801, United States.

Questions about this policy?

Reach our Data Protection Officer at [email protected] or visit our Contacts page.

usaepya

Payments Built for Developers, Trusted by Merchants.

[email protected]1-800-555-0199
1234 Gateway Blvd, Suite 200
Los Angeles, CA 90001, USA

Stay Updated

Get the latest API updates, developer news, and payment insights delivered to your inbox.

No spam. Unsubscribe anytime.

© 2026 usaepya. All rights reserved.

PCI DSS Level 1
SOC 2 Certified