Privacy policy
This policy describes how personal data is processed when you use x402-trust.com. Last updated: 2026-09-12.
1. Controller
Jonas FuchßAm Heidewald 20
33332 Gütersloh
Germany
E-Mail: support@x402-trust.com
The controller is the natural person who decides on the purposes and means of the processing of personal data on this website.
2. The short version
- No cookies, no tracking, no analytics scripts, no advertising, no profiling.
- Our request logs contain no IP addresses (since 2026-09-09); referrers are stored as origin and path only, never with your search terms.
- IPs appear only in rare payment events (fraud prevention) and in transient rate-limit buckets in memory.
- Payments settle in USDC on public blockchains; wallet addresses and transaction hashes are public there by design.
- You can reach us at support@x402-trust.com for any privacy request.
3. Hosting and content delivery
This service is self-hosted on hardware under our physical control in Germany. The site is delivered through Cloudflare (Cloudflare Inc., USA) as a reverse proxy: your connection, including your IP address, passes through Cloudflare's edge so the page can be delivered and protected against abuse. Cloudflare processes this data on our behalf under its self-service Data Processing Addendum and is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6 (1) f GDPR (secure and efficient delivery of the service).
4. Server access logs
Every HTTP request is recorded in an append-only log with: timestamp, method, path, status code, response time, user agent, a flag whether a payment header was present, and the referrer reduced to origin and path (query strings are stripped, so search terms never reach the log). Request records deliberately carry no IP address. Request bodies and API responses are never logged.
Payment events (verify/settle outcomes of paid API calls) additionally record the payer wallet address, the transaction hash, and the client IP address. These events are rare and security-relevant: they are how failed settlements can be reconciled and fraud investigated.
Retention: the log is rotated monthly and compressed; archives are deleted no later than 12 months after creation. A compressed legacy archive of request logs predating 2026-09-09 still contains IP addresses and is covered by the same 12-month deletion schedule.
Legal basis: Art. 6 (1) f GDPR. Our legitimate interest is the secure operation of the service, fraud prevention, and settlement reconciliation.
5. Rate limiting
To keep the service usable for everyone, per-IP counters are kept in volatile memory for abuse control. They are never written to disk and disappear on restart.
6. Payments and blockchain data
Paid API calls are settled through the x402 protocol: USDC payments on the Base blockchain, processed by the Coinbase Developer Platform as payment facilitator. Your wallet address and the resulting transaction hash are recorded on a public blockchain and are visible to anyone; we store them in our settlement records and aggregate them into the public trust statistics you see on this site. Legal basis: Art. 6 (1) b GDPR (contract performance).
Please note: data written to a public blockchain cannot be corrected or deleted afterwards. This is a technical property of the medium, not a policy choice; the erasure right of Art. 17 GDPR does not reach immutable public ledgers.
7. Search queries and embeddings
When you use semantic search (the web search page or the paid API), the query text is sent to Venice AI (USA) to compute a numerical embedding for matching; no account or identity data is included. We additionally keep an anonymized demand telemetry: hour-bucketed timestamps, normalized query text (URLs lose their own query string, anything email-shaped is dropped), and a bot flag derived from the user agent without storing it. No session identifiers are persisted anywhere. Legal basis: Art. 6 (1) f GDPR (understanding demand to improve the catalog) and Art. 6 (1) b GDPR for paid calls.
8. Watch subscriptions
If you buy an endpoint watch, we store the delivery configuration you provide (webhook or Slack URLs, which may contain tokens) plus the bearer secret for your watch, until the watch expires or you cancel it. Legal basis: Art. 6 (1) b GDPR.
9. E-mail
Support mail is hosted at mailbox.org (a German provider). Mails you send us are kept while your request is being handled and afterwards only within statutory retention periods. Legal basis: Art. 6 (1) b and f GDPR.
10. Local storage, no cookies
This site sets no cookies. Your light/dark theme choice is stored in your browser's localStorage only and is never transmitted to us; it counts as a technically necessary, user-initiated preference under § 25 (2) TDDDG.
11. Data about third-party services
The product itself processes publicly available data about third-party x402 endpoints: resource URLs, advertised prices, and payTo wallet addresses taken from public listings and public blockchains. If a wallet address in our data belongs to you and you have questions, contact us at support@x402-trust.com.
12. Recipients at a glance
- Cloudflare Inc. (USA): content delivery, DDoS protection. EU-US Data Privacy Framework.
- Coinbase Developer Platform (USA): payment settlement facilitation. EU-US Data Privacy Framework.
- Venice AI (USA): embeddings for semantic search queries.
- mailbox.org (Germany): e-mail hosting.
- Public blockchains (Base): payment settlement data, public by design.
13. Your rights
You have the right, at any time and free of charge, to: access your stored personal data (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to the blockchain limitation above and statutory retention), restriction of processing (Art. 18), and data portability (Art. 20). Where processing is based on Art. 6 (1) f GDPR, you have the right to object for reasons arising from your particular situation (Art. 21). Given consent can be withdrawn at any time with future effect (Art. 7 (3)).
You also have the right to lodge a complaint with a supervisory authority, in our case the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), or the authority of your habitual residence.
For any of these, write to support@x402-trust.com.
14. Security
All traffic to this site is encrypted via TLS. Note that data transmission on the internet (for example plain e-mail) can have security gaps; complete protection against access by third parties is not possible.
15. No automated decision-making
We do not use personal data for automated decision-making or profiling within the meaning of Art. 22 GDPR. Trust scores on this site evaluate technical endpoints, not people.
Source: adapted from templates by e-recht24.de. Last updated: 2026-09-12.