Privacy Policy
Effective Date & Last Updated: 13 July 2026
This Privacy Policy explains how Cray (“Cray,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal data when you visit our websites, create or use a Cray account, use our merchant applications, payment interfaces, APIs or related services (collectively, the “Services”). Cray provides non-custodial technology that enables businesses to accept stablecoin payments. Cray does not hold or control users’ funds, private keys, or digital assets. Transactions are initiated by users and settled through public blockchain networks. By using the Services, you acknowledge the practices described in this Privacy Policy. If you use Cray on behalf of a business, this Policy applies to personal data relating to that business’ owners, representatives, employees, and authorised users
1. Scope and Roles
This Policy applies to personal data Cray processes through the Services and in its business operations. It does not apply to information processed independently by merchants, wallet providers, blockchain networks, exchanges, identity-verification providers, compliance providers, or other third parties under their own terms and privacy policies. Cray currently provides its merchant services to businesses established in the United Arab Emirates. Customers of those merchants may access or use Cray’s payment interfaces from anywhere in the world. Depending on the context and applicable law, Cray may act as a controller of account, service, security, and compliance data, or as a processor/service provider when handling limited data on a merchant’s instructions. Merchants remain responsible for their own collection and use of customer data.
2. Information We Collect
2.1 Information you provide
- ● Account and onboarding information, such as your name, business email address, phone number, business name, role, country, and account credentials or authentication identifiers.
- ● Business verification and compliance information, where required, such as registration details, ownership or control information, identification information, and supporting documents. Some of this information may be collected directly by a verification provider rather than stored by Cray.
- ● Communications and support information, including messages, feedback, inquiries, and records needed to respond to you.
- ● Staff access information, such as an invited staff member’s name, email address, role, and permissions
2.2 Blockchain and payment information
- ● Public wallet addresses, transaction hashes, network and token information, payment amount, payment status, timestamps, and other information available on or derived from public blockchains.
- ● Payment-request and merchant-reference information required to match a blockchain transaction to a merchant payment or order.
- ● Compliance-screening records, including a wallet address, screening time, risk indicators, score or classification, and the resulting decision. We may retain these records whether a payment is approved, rejected, or not completed when necessary for compliance, fraud prevention, audit, or legal purposes.
2.3 Information collected automatically
- ● Device and technical information, such as IP address, browser type, device type, operating system, application version, language, timestamps, and diagnostic or security logs.
- ● Usage information, such as pages or features accessed, session events, error logs, and interactions needed to operate, secure, and improve the Services
- ● Cookies or similar technologies that are strictly necessary for authentication, session management, security, preferences, and core functionality. If we introduce non-essential analytics or advertising cookies, we will provide any notice or choice required by applicable law.
2.4 Information from third parties
- We may receive information from merchants, authorised account users, wallet and authentication providers, blockchain data providers, compliance and sanctions-screening providers, identity or business-verification providers, Shopify and other commerce platforms, infrastructure providers, and public sources. We limit this information to what is reasonably necessary to provide, secure, and comply with obligations relating to the Services.
3. How We Use Information
We use personal data to:
- ● create, authenticate, administer, and support accounts;
- ● provide payment requests, transaction matching, merchant dashboards, staff access, reporting, integrations, and related functionality;
- ● screen wallet addresses and transactions for sanctions exposure, illicit-finance risk, fraud, abuse, and other compliance concerns;
- ● verify merchants and authorised users where required;
- ● maintain security, prevent unauthorised access, investigate incidents, debug errors, and protect users and the Services;
- ● communicate about transactions, service notices, support requests, product changes, and administrative matters;
- ● comply with law, regulation, lawful requests, recordkeeping duties, audits, disputes, and enforcement of our agreements;
- ● improve and develop the Services using aggregated, de-identified, or limited operational information where practicable; and
- ● carry out a merger, financing, acquisition, reorganisation, sale of assets, or similar corporate transaction.
- ● communicate about the Services, and marketing and business communications, where permitted by applicable laws. You may opt out of promotional communications at any time by contacting us
4. Legal Bases for Processing
Where applicable law requires a legal basis, we process personal data as necessary to perform our contract with you; comply with legal and regulatory obligations; pursue legitimate interests such as providing, securing, improving, and protecting the Services; establish, exercise, or defend legal claims; protect vital or public interests where relevant; or based on consent where consent is the appropriate basis. You may withdraw consent at any time, but withdrawal does not affect processing already carried out lawfully and may limit our ability to provide the Services.
5. How we disclose information
We do not sell personal data. We may disclose the minimum information reasonably necessary to:
- ● Service providers and infrastructure partners that support hosting, cloud infrastructure, authentication, wallet technology, communications, customer support, monitoring, security, analytics, and software operations,
- ● Compliance, blockchain-intelligence, identity-verification, sanctions-screening, fraud-prevention, and professional advisers that help us meet legal, risk, audit, and security obligations.
- ● Commerce and integration partners, including Shopify or a merchant’s other authorised platform, to create or match payment requests and update payment- or order-related status.
- ● Merchants and authorised account users, so they can view payments, account activity, staff actions, and other information relevant to their use of the Services.
- ● Authorities, courts, regulators, law-enforcement bodies, or other parties when required by law or when reasonably necessary to protect rights, safety, security, users, the public, or the integrity of the Services.
- ● A buyer, investor, lender, adviser, or successor in connection with an actual or proposed corporate transaction, subject to appropriate confidentiality and data-protection measures.
Our providers may process information only for the services they perform for us or under their own lawful responsibilities. Some third-party services are independent controllers and their privacy policies also apply. We may engage additional service providers from time to time to support the Services. Such providers are subject to appropriate contractual obligations regarding confidentiality, security, and data protection.
6. Shopify and other merchant integrations
When a merchant installs or connects a Cray integration, we may access limited merchant, order, product, market, shipping, configuration, and related platform data through permissions approved by the merchant. We use that access only to operate the integration, create or verify payment requests, associate payments with orders, maintain app configuration, and update relevant payment or order information. Cray is designed not to retain customer, product, order, or shipping data beyond what is necessary to process the relevant request, maintain security, resolve errors or disputes, and satisfy legal or compliance requirements. We retain Cray account information, blockchain payment records, compliance-screening evidence, and limited integration identifiers or logs as described in this Policy.
7. Non-custodial services and public blockchains
Cray does not take custody of private keys, stablecoins, or other digital assets. Wallet technology or key-management functionality may be supplied by third parties under their own terms. You are responsible for protecting access to your wallet and account.
Blockchain transactions are public and may reveal wallet addresses, transaction amounts, assets, timestamps, and transaction history. Although a wallet address may not directly state a person’s name, it may be linked to an identifiable person when combined with other information and may therefore constitute personal data. Cray cannot reverse, edit, suppress, or erase records written to a public blockchain..
Cray does not own, control, operate, or guarantee any blockchain network, validator, node, sequencer, wallet provider, smart contract, RPC provider, or digital asset protocol. Cray is not responsible for blockchain congestion, forks, protocol upgrades, transaction delays, irreversible transfers, outages, or other events occurring on third-party blockchain infrastructure..
Where personal data has become part of a public blockchain, Cray cannot erase, rectify, restrict, or modify that information because it is maintained by decentralized third-party networks outside Cray's control. Any applicable privacy rights apply only to information that Cray directly controls
8. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including while an account is active and afterward where required for legal, regulatory, compliance, tax, accounting, audit, fraud-prevention, security, dispute-resolution, or enforcement purposes.
Retention periods vary according to the type of information, the relationship, legal requirements, risk, and whether information is needed to establish or defend claims. Compliance-screening and payment records may be retained for the period required or permitted by applicable anti-money-laundering, sanctions, financial-crime, commercial, or other laws. Closing or deleting an account does not automatically require deletion of information where retention remains necessary for legal, regulatory, accounting, audit, security, fraud prevention, dispute resolution, or contractual purposes. When retention is no longer necessary, we delete, anonymise, or securely isolate the information, subject to technical limitations and lawful backup cycles. Public blockchain information remains outside Cray’s control.
9. International data transfers
Cray and its providers may process information in countries other than the country where you are located. Those countries may have different data-protection laws. Where required, we use lawful transfer mechanisms and appropriate contractual, technical, and organisational safeguards, including adequacy decisions or contractual protections recognised by applicable law.
10. Security
We implement reasonable administrative, technical, and organisational safeguards designed to protect personal data, including access controls, authentication, encryption where appropriate, monitoring, and service-provider controls. No system, network, or method of storage or transmission is completely secure, and we cannot guarantee absolute security. You must protect your login credentials, devices, wallet access, and recovery methods and notify us promptly of suspected unauthorised access.
11. Your rights and choices
Depending on your location and applicable law, you may have the right to request access to, correction of, deletion of, or a copy of your personal data; restrict or object to certain processing; request portability; withdraw consent; or complain to a competent data-protection authority. These rights may be limited by legal exceptions, identity-verification requirements, Cray’s compliance and recordkeeping obligations, and the technical immutability of public blockchains.
You may update certain account information through the Services. To exercise another right, contact us using the details in Section 15. We may need to verify your identity and authority before acting on a request. If we process information solely on behalf of a merchant, we may direct your request to that merchant.
12. Children
The Services are intended for businesses and adults and are not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, contact us so we can take appropriate action.
13. Third-party links and services
The Services may link to or interoperate with third-party websites, wallets, networks, applications, or services. We do not control their privacy or security practices. Review their notices before providing information or using their services.
14. Changes to this Policy
We may update this Privacy Policy to reflect changes in our Services, practices, providers, or legal obligations. We will post the updated Policy and revise the “Last updated” date. Where required, we will provide additional notice or obtain consent. Your continued use of the Services after an update becomes effective is subject to the updated Policy.15. Contact us Cray is responsible for the personal data covered by this Policy. Questions, requests, or complaints may be sent to:
15. Contact Us
Have questions about your data sovereignty or our privacy practices? Our legal team is ready to assist you.
[email protected]