Privacy & data
Privacy Policy
A clear account of the information LaxoPay handles, why we use it, and the choices available to you.
UAB ZEN.COM, Konstitucijos av. 18B, LT-09308 Vilnius, Lithuania. LaxoPay is an approval based test-mode payments platform. Any live processing availability depends on separate provider and acquirer review.
Privacy contact: [email protected]. Legal and complaints contact: [email protected]. Support contact: [email protected].
Who we are
LaxoPay operates the website at laxopay.com. This notice describes the information the service stores and who can see it. The LaxoPay test workspace currently records test activity only. Questions about this site can also go to [email protected].
Why we use information
We process account and application data to provide the service you request, review and administer merchant access, protect the site and API, comply with legal and regulatory duties, and communicate about your account. We rely on performance of a contract or steps requested before a contract, legal obligations, and legitimate interests in operating a secure service. We ask for consent where applicable law requires it and you can withdraw that consent at any time.
Account information
- Name, email address, and password. The password is stored only as a bcrypt hash. LaxoPay does not keep the password itself.
- An email confirmation token, stored as a hash, which expires after 24 hours.
- A password reset token, stored as a hash, which expires after 1 hour.
- The plan on the account, the role, and whether the email address has been confirmed.
We use the email address to sign you in. When mail delivery works, we also use it to send the confirmation message and the password reset message. If mail cannot be sent, the link is shown once on the screen and the failure is logged without the password.
Merchant application
The application saves each step. It asks for:
- Legal name, trading name, country, website, and whether the business is a sole proprietorship, a company, or a nonprofit.
- Category, a description of the business, and an expected monthly volume band.
- Representative name, role, email, and phone number.
- Payout account holder, payout country, and settlement currency.
The application form does not collect a bank account number. Status, the time of the last update, and any note from the reviewer are stored with the application. An operator can read the application in order to approve it, decline it, or ask for more information.
Dashboard and test payments
- Customers you save, including name and email.
- Payment links, amounts, currencies, and descriptions.
- Test payments: amount in minor units, currency, status, fee, refunds, and the related identifiers. The test card number is used only to choose success or decline. It is not written to the database and it is not sent to a card network.
- API keys. A test secret is shown once and then stored as a hash, with only the prefix kept for display. On approval, a disabled live key is created and its plaintext is discarded.
- Webhook address and signing secret. The secret is stored so LaxoPay can sign events. Keep it private.
- Idempotency keys, stored as a hash together with a hash of the request body, for 24 hours.
Technical data
Sign-in, signup, password reset, and the API are rate limited. The limit record includes the IP address and is deleted after the window expires. Sign-in allows 20 attempts in 15 minutes per IP. Signup and password reset allow 8 attempts an hour per IP. The API allows 180 requests a minute for each signed-in account.
Each response carries an X-Request-Id. Request bodies, passwords, and API keys are not written to the log. In production, the session cookie laxo_session is HttpOnly, Secure, and SameSite=Lax. The server stores a hash of the session, not the cookie value. A session lasts 14 days. The hosted payment page uses a separate cookie, laxo_pay, limited to /pay and kept for 1 hour.
Who receives information
Information is shared with the people and providers needed to run the service: our operating and payment infrastructure provider, hosting and delivery providers, email delivery providers, and professional advisers or authorities where the law requires it. Providers receive only the information needed for their task and must protect it under their agreement with us. We do not sell personal information.
International transfers
Our providers may process information in the European Economic Area or another country. When information leaves the EEA, we use a lawful transfer mechanism and appropriate safeguards, such as an adequacy decision or standard contractual clauses, where required.
Delivery and email
Cloudflare may sit in front of the site to terminate HTTPS, deliver public pages, and protect the connection. Its handling is described in the Cloudflare Privacy Policy. Public pages can be cached; pages behind a session and the API are not served from that cache.
Account email is sent through the configured Gmail mail transport. The message contains the confirmation or reset link and does not contain your password.
What we do not do
LaxoPay does not sell personal information. The site does not load an advertising network, an analytics tag, or a tag manager. Test card numbers are not stored and are not presented to a card network.
How long we keep it
- The account, application, and test ledger remain until you ask us to delete them or we close the account.
- Sessions expire after 14 days. Confirmation links expire after 24 hours. Reset links expire after 1 hour. The pay-page cookie expires after 1 hour.
- A nightly database backup is kept for 14 days, then deleted. A deleted account can remain inside a backup until that backup expires.
Security
Passwords and API secrets are hashed. Session tokens are hashed. Webhooks are signed with HMAC-SHA256. The site is served over HTTPS. The operator role is separate from merchant accounts, and the review screen is not linked in the public header. These are the controls the service actually runs. This page does not claim a certification, a license, or a particular security audit.
Your requests
You can correct application details while the application is still a draft. Subject to applicable law, you may ask for access, correction, deletion, restriction, portability, or objection to a processing activity. Contact [email protected] or [email protected]. We may ask you to confirm that you control the account email before we change or delete anything. Deletion removes the account, the application, and the test ledger we can still reach. A backup copy falls away when that backup passes 14 days.
You may lodge a complaint with the State Data Protection Inspectorate of Lithuania, the supervisory authority for data protection in Lithuania. We would appreciate the opportunity to address your concern first.
Automated decisions
LaxoPay does not make decisions with legal or similarly significant effects using solely automated processing. Merchant applications are reviewed by an operator.
Children
LaxoPay is a business service. It is not directed at children, and we do not knowingly create accounts for children.
Changes
When this notice changes, the date at the top of the page changes with it. Continued use of the site after that date is use under the updated notice.