NexusTRC ("we", "us", "our") operates the NexusTRC payment gateway platform accessible at nexustrc.app. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Services Covered
This policy applies to:
- NexusTRC Gateway — A TRC-20 (USDT) cryptocurrency payment gateway that enables merchants to accept USDT payments, manage wallets, configure webhooks, and access payment APIs.
- RBSM (Resilient Browser Session Manager) — A local desktop browser management and automation utility with hardware-isolated sessions, proxy routing, and cryptographic offline HWID licensing.
2. Data We Collect
2.1 NexusTRC Account Data
When you register for NexusTRC, we collect:
- Email address — used as your account identifier and for login.
- Password — stored as a bcrypt hash. We never see or store your plain-text password.
- IP address — logged for rate limiting and security (failed login tracking). Not used for tracking or analytics.
2.2 Payment & Wallet Data
- TRON wallet addresses — public blockchain addresses you add to receive payments. These are public by nature on the TRON blockchain.
- Payment transactions — amounts, transaction IDs, status, timestamps, and buyer email (if provided at checkout).
- Invoice records — subscription and plan purchase history.
- Webhook configurations — URLs you configure to receive payment notifications (encrypted at rest).
2.3 API Keys
- API key hashes — we store a SHA-256 hash of your API key, not the key itself. The plain-text key is shown once at creation and never stored.
2.4 RBSM License & Hardware ID (HWID) Data
- License Email — your email address provided at checkout is used exclusively to generate, cryptographically sign, and deliver your license file.
- Hardware ID (HWID) — an anonymized hardware identifier hash (e.g.
XXXX-XXXX-XXXX-XXXXgenerated locally by therbsm -hwidcommand) is processed during activation to bind the cryptographic license key to your designated machines. - Steganographic Asset Attribution — injected browser runtime assets dynamically encode an invisible, zero-width watermark representing the licensee's HWID and username for forensic tracking in the event of unauthorized leak, extraction, or redistribution.
- Security Blacklists — entities identified in intellectual property theft, unauthorized redistribution, or payment fraud (including IP addresses, TRC-20 wallet addresses, HWIDs, and associated emails) are stored in a persistent security blacklist to prevent unauthorized access.
- Zero Telemetry on Local Browser Data — the RBSM binary operates entirely locally on your machine. We do not collect, track, log, or transmit your browser cookies, browsing history, automation macros, scraped payloads, or proxy credentials to our servers.
2.5 Browser Data
- Push notification subscriptions — if you opt in to browser push notifications, we store a browser subscription endpoint to deliver payment alerts. You can revoke this at any time via your browser settings.
- Service worker cache — the browser service worker caches static assets (icons, scripts) for offline performance. This data stays on your device and is not sent to us.
3. How We Use Your Data
- Service delivery — to operate the payment gateway, process payments, verify blockchain transactions, and deliver webhook notifications.
- Account management — authentication, subscription management, and customer support.
- Security — rate limiting, brute-force protection, and fraud prevention.
- Website analytics & optimization — to measure public storefront visitor volume, documentation usage patterns, referral sources, and checkout conversion rates.
- Legal compliance — if required by applicable law or judicial process.
4. Cookies & Analytics Disclosures
- Essential Cookies — we use first-party, secure cookies strictly for session authentication and CSRF security token verification.
- Google Analytics (Public Pages Only) — we use Google Analytics (via gtag.js) exclusively on our public-facing storefront and documentation pages (such as our home page, documentation, product showcase, and checkout flow) to collect aggregate statistical information. This includes non-personally identifiable metrics such as device type, browser family, approximate geographic country/region, referring URL, time spent on pages, and navigation paths.
- Strict Exclusion of Authenticated & Private Areas — Google Analytics is strictly disabled and excluded across all authenticated, internal, or administrative areas of our platform. It is never loaded on user dashboards, TRON wallet managers, API key portals, transaction logs, or administrator panels. We never transmit wallet private keys, customer financial ledgers, or internal dashboard operations to third-party analytics services.
- No Sale or Behavioral Advertising — we do not sell, rent, or trade your personal data, nor do we run third-party advertising or cross-site behavioral tracking networks.
- Opt-Out Options — you may opt out of Google Analytics tracking at any time by configuring your browser's cookie settings or by installing the official Google Analytics Opt-out Browser Add-on.
5. Third-Party Services
We interact with the following services to provide our functionality:
- Google Analytics (Google LLC) — website performance and traffic measurement on public-facing storefront pages. Google's data handling is subject to the Google Privacy Policy.
- Tronscan / TronGrid — blockchain APIs used to verify TRON/USDT transactions. These are public blockchain lookups; no personal data is sent beyond wallet addresses (which are public on-chain).
- Google reCAPTCHA — used on the registration page to prevent automated signups. Google's Privacy Policy applies to their service.
- Cloudflare — if used as a reverse proxy, Cloudflare's Privacy Policy applies.
6. Data Storage & Security
- Data is stored in a SQLite database on our server infrastructure.
- Passwords are hashed with bcrypt. Webhook secrets are AES-encrypted at rest.
- All connections are encrypted via TLS 1.2+ (HTTPS). HTTP requests are redirected to HTTPS.
- API key plaintext is never stored — only a SHA-256 hash is retained.
- We implement rate limiting, account lockout after failed attempts, and request ID tracking for audit purposes.
7. Data Retention
- Account data — retained while your account is active. Deleted upon account deletion request.
- Payment records — retained for 7 years for financial record-keeping (standard for payment services).
- Webhook delivery logs — retained for 30 days, then automatically purged.
- Audit logs — retained for 90 days for security purposes.
- Rate-limit / security logs — IP addresses are rotated out within 24 hours.
8. Your Rights
You have the right to:
- Access — request a copy of all personal data we hold about you.
- Rectification — update or correct inaccurate data.
- Deletion — request deletion of your account and personal data (subject to legal retention requirements for financial records).
- Export — request your data in a machine-readable format.
- Revoke push notifications — disable browser notifications at any time via browser settings.
To exercise these rights, contact us at support@nexustrc.app.
9. Children's Privacy
NexusTRC is not directed at individuals under 18. We do not knowingly collect data from minors.
10. International Data Transfers
NexusTRC is operated from servers that may be located outside your country of residence. By using our services, you consent to the transfer of your data to these locations. We apply the same security standards regardless of location.
11. Changes to This Policy
We may update this Privacy Policy from time to changes. Material changes will be communicated via email to registered users or announced on our website. The "Last Updated" date at the top reflects the most recent revision.
12. Contact
For questions about this Privacy Policy or your personal data, contact us at:
Email: support@nexustrc.app
Website: https://nexustrc.app