Privacy Policy
Fox Pay is operated by TG11 LLC, doing business as Fox Pay. Handling payments means handling data carefully, so this page is specific about what exists, what does not, and where it goes.
1. What Fox Pay never stores
Card numbers, CVVs, expiry dates and bank credentials. Card entry happens on the provider's own hosted page. What comes back to us is a reference and, at most, a brand and the last four digits so you can tell two saved methods apart. There is no card data in this database to lose.
2. What it does store
- Payment records: amount, currency, description, status, timestamps, the merchant, and the provider's reference for each attempt.
- Saved payment methods, if you save one: the provider's token plus a display label — never the instrument itself.
- Account: your TG11 identity (a UUID), email address and display name, and which merchants you have paid.
- Provider events: the signed webhook payloads providers send us, kept so a payment can be reconciled and an event is never processed twice.
- Ledger and audit entries recording what happened to a payment and what an operator or an API key did.
- Merchant credentials (API keys hashed, provider secrets encrypted at rest).
- Operational data: IP address, user agent, request ids and server logs.
3. Where it goes
- To the payment provider you are paying through — the amount, currency, an order reference and whatever they need to take the payment. Their privacy policy governs that leg: Stripe, PayPal, Square, or the crypto processor for a crypto invoice.
- To the merchant you bought from: the payment's status, amount and reference, so they can fulfil the order.
- To TG11 Accounts, for sign-in only.
- Nowhere else, unless the law requires it or we need it to investigate fraud or abuse.
Nothing here is sold, and there is no advertising or third-party tracking on this site.
4. Why we keep it
To take and settle payments you asked for, to show you your own history, to reconcile money with providers and merchants, to detect fraud and abuse, and to meet the record-keeping obligations that come with handling financial transactions.
5. How long
- Payment, ledger and audit records: kept for the period financial record-keeping requires — expect years, not weeks. These are the records that prove what happened to your money.
- Saved payment methods: until you remove them.
- Provider events: kept as long as they may be needed to reconcile, then pruned.
- Server logs: a short operational window.
- Backups: rolling, so deleted rows may persist briefly after they leave the live database.
6. Your controls
- Saved payment methods can be removed from Payment methods; removing one also deletes the provider token.
- Ask [email protected] for a copy of your data, or to close your account. We can delete an account and its saved methods, but we cannot delete the transaction records the law requires us to keep — we will say which is which.
- Cookies here are the session and CSRF cookies needed to sign in, plus your light/dark theme choice. No advertising or analytics cookies.
7. Security
Provider secrets and merchant credentials are encrypted at rest, API keys are stored hashed, webhooks are verified against each provider's signature before anything is believed, and payment amounts are checked against the intent before a payment is marked paid. Tokens are never written to logs. If a breach affects you, we will tell you.
8. Children
Fox Pay is not intended for anyone under the minimum age for digital consent where they live.
9. Where it runs
Fox Pay runs on servers in the United States; providers may process data elsewhere.
10. Contact
Privacy questions, data requests and deletion requests: [email protected].