Privacy Policy

Last updated: January 2025

Overview

OpenPay is open-source, self-hosted payment infrastructure. When you self-host OpenPay, all data stays on your servers. We have no access to your data, your customers' data, or your transaction history.

Data Collection

OpenPay itself does not collect any data from self-hosted instances. The OpenPay project maintains no telemetry, analytics, or phone-home mechanisms. Your payment data, customer data, and configuration remain entirely under your control.

Third-Party Services

When you use OpenPay, you connect it to payment processors (e.g., Paystack) and authentication providers (e.g., Kinde). Each of these services has its own privacy policy. We encourage you to review the privacy policies of any third-party services you integrate with OpenPay.

Cookies

OpenPay uses session cookies for authentication via Kinde. These cookies are necessary for the application to function and are not used for tracking purposes.

Open Source

OpenPay is released under the MIT License. You can audit the source code at any time to verify how data is handled. We welcome security reviews and contributions from the community.

Contact

For questions about this privacy policy, open an issue on GitHub or start a discussion in the community forum.