{"summary":"No accounts, no email, no personal identifiers. What we hold is what a payment inherently reveals.","we_collect":["Payment addresses and transaction hashes — these are already public on Base.","Invoice records: id, amount, status, timestamps.","Which data categories were requested, in aggregate, to publish demand stats at /stats.","Standard HTTP access logs (IP, user-agent, path, status) for abuse protection and capacity."],"we_do_not_collect":["Names, emails, phone numbers, postal addresses.","Private keys — the gateway never asks for and never accepts one.","Tracking cookies, advertising identifiers, or third-party analytics beacons."],"third_parties":{"base_rpc":"Public Base RPC nodes are queried to verify payments; they see the queried addresses/hashes.","facilitator":"When the standard `exact` scheme is used, the signed authorization is relayed to a third-party x402 facilitator to be settled on-chain.","no_data_sales":"Request data is never sold or shared for marketing."},"retention":"Invoice and settlement records are retained as accounting records. Access logs are retained only as long as needed for abuse protection.","your_data_is_pseudonymous":"We identify you only by the address you pay from. Use a fresh address if you want unlinkable purchases — nothing here prevents that.","terms":"https://x402.obolpay.xyz/terms"}