
Privacy Policy
Last updated 22 August 2026
Cashx.ID is a directory of ways to pay someone. You list the payment methods you accept; other people open your page and pay you in whatever app they already have. We never hold, move, or see your money — there is no wallet here and no payment processing, so we hold far less about you than a payments company would.
This page explains what we do hold. It is written to be read, not to be survived. If something here is unclear, email privacy@cashx.id and we will fix the wording.
Cashx.ID is operated by Principle Stash Inc., a Delaware corporation based in Florida, which is the data controller for the information described here.
What you give us
- Your account. An email address, which is how you sign in. If you sign in with Google we also receive the name and profile picture on that Google account.
- Your profile. Your username, display name, bio, avatar and colour choices. These are public by design — they are the page you share.
- Your payment methods. The platform and the handle for each one (a @username, phone number, email, IBAN, or wallet address), plus any label or note you add. These are also public on your page unless you hide the method or lock the page. Locking hides the handle, label and note. It does not hide which platforms you accept: those appear as logos in your page’s link-preview image, which anyone who knows your username can fetch.
- Payment requests. If you create one: the amount, currency, description, due date, and whether it has been marked paid. Marking something paid is self-reported by you and the payer — we do not verify that any money moved.
What we record automatically
- Profile views. When someone opens your page we store a timestamp, the referring URL, and the browser's user-agent string, so you can see how your page is doing.We do not store the visitor's IP address and we do not set an identifier that follows anyone between pages or sites.
- Method taps. Which payment method was tapped, and when. The platform, not the person.
- Email lookups. If you turn on "discoverable by email", we record which signed-in account looked you up and whether it matched, so we can rate-limit that feature and spot anyone fishing for addresses.
- Failed unlock attempts. If your page has a passcode, a failed attempt stores the username together with the visitor's IP address so we can stop brute-force guessing.These are deleted after one hour. It is the only place we keep an IP address.
What we never do
- We do not sell or rent your data. There is nobody to sell it to and no advertising here.
- We do not run third-party analytics, ad pixels, or cross-site trackers. The only cookies we set are the ones that keep you signed in and remember that you passed a page's passcode.
- We do not touch your money, and we never ask for a card number, bank login, or the credentials to any payment app.
How your passcode is stored
If you lock your page with a passcode, we store an HMAC-SHA256 of it keyed to a server secret — never the passcode itself. We cannot read it, recover it, or tell you what it was. Passcodes are short by nature, so treat the feature as a way to keep your page out of casual view rather than as serious security.
Who else is involved
- Cloudflare hosts the site, the database, uploaded avatars, and sends our emails. Your data lives on their infrastructure.
- Google, only if you choose to sign in or link with Google. We request your email address, basic profile, and OpenID identifier — nothing else, and nothing that lets us act on your Google account.
- Have I Been Pwned, if you set a password, to check it has not appeared in a known breach. We send the first five characters of its SHA-1 hash and nothing more, so they never learn your password.
- AI assistants you connect. If you authorise an assistant through our Model Context Protocol server, it can read and change your payment methods and create payment requests on your behalf, for as long as you leave it connected. It cannot see anyone else's private profile. You can disconnect it at any time.
Search engines
Your page is not listed for search engines unless you switch on "Let search engines find me" in your privacy settings. It is off by default. Your page still works for anyone you send the link to — it simply will not turn up in a search. There is deliberately no way to browse, search, or list Cashx.ID profiles: handles are only ever returned for a username someone already knows.
We do not sell your data
In the language California law uses: we do not "sell" your personal information, and we do not "share" it for cross-context behavioural advertising. We have not done so in the past twelve months, and there is no advertising business here that would give us a reason to start. We also do not use your data to train AI models.
Because we run no cross-site tracking, there is nothing for a "Do Not Track" or Global Privacy Control signal to switch off — but if your browser sends one, we honour it as an opt-out of any sale or sharing, which remains none.
Your state privacy rights
Cashx.ID is operated from the United States. Depending on your state — California, Colorado, Connecticut, Virginia, Utah, Texas and a growing list of others — you may have the right to know what we hold about you, to get a copy, to correct it, to delete it, and to not be discriminated against for asking. If you are outside the US, you may have comparable rights under GDPR, UK GDPR, or your local law, including the right to complain to your data-protection authority.
You do not need to invoke a statute with us. Email privacy@cashx.id and we will action it. We will verify you control the account's email address before making changes, and we do not charge for any of this. An authorised agent may act for you with your written permission.
What you can do
- See it. Everything we hold about you is on your dashboard.
- Change it. Edit or delete any payment method, request, or profile field at any time.
- Delete it. Deleting your account removes your profile, payment methods, payment requests and analytics. Ask at privacy@cashx.id and we will confirm when it is done.
- Take it elsewhere. Your public profile is available as JSON at
/api/v1/u/<username>, so your list of methods is never locked in.
Depending on where you live you may also have the right to access, correct, port, or object to our use of your data, and to complain to your local data-protection authority. Email us and we will help rather than make you invoke anything.
How long we keep things
Account and profile data stays until you delete it. Failed unlock attempts are deleted after an hour. Analytics are kept while your account exists and go with it when the account does. Backups may lag a deletion by a short period before they roll over.
Children
Cashx.ID is not for people under 13, and if you are in the EU or UK, not for people under 16. We do not knowingly collect their data; if we learn we have, we will delete it.
Changes
If we change this policy in a way that materially affects you, we will say so on the site before it takes effect. The date at the top always reflects the current version.
Contact
Questions, deletion requests, or anything else: privacy@cashx.id.