Your Data
A breakdown of how Branta protects your privacy.
These tables describe an integration running privacy: 'strict' with ZK destinations, which our integration guides require. In loose mode, destinations are transmitted in plain text.
What Each Party Can See: Payment Gateways
| Data | End Business | Payment Gateway | Branta |
|---|---|---|---|
| Number of Invoices Created | |||
| Invoice Creation Time and Expiry | |||
| Merchant Identity | |||
| Payable Addresses or Invoice Strings | |||
| Amount of Money Moved | |||
| Customer Name, Email, or Phone | |||
| TXID or Payment Hash (After Pay) | |||
| Confirmation or Settlement Status |
Branta's API has no field for shipping addresses, refunds and chargebacks, products or SKUs, or customer purchase history. They are never transmitted.
For how long we keep data, see Data Retention in our Privacy Policy.
What Each Party Can See: Wallets
| Data | Wallet | Branta |
|---|---|---|
| Which Destination Was Checked, and When | ||
| Number of Payments Initiated | ||
| Number of Payments Completed | ||
| Amount of Money Moved | ||
| User Account ID or Email | ||
| Device or Install ID | ||
| Transaction Broadcast or Confirmation |
Branta is never in the custody path. No seed phrases, private keys, xpubs, or wallet descriptors are transmitted, and the API has no field for them.
An encrypted destination is a stable value: Branta cannot read it, but can see that the same destination was looked up more than once, and when.
Wallet lookups hit guardrail.branta.pro over HTTPS. Like any web request, a connecting IP is present at the network layer; Branta does not store or track it, and does not classify Tor, VPN, or direct.
More questions? Audit the code.
Branta SDKs are open source and MIT licensed.