1. Scope and operator
This policy describes processing by WaitMoon Labs Inc, a corporation registered in Wyoming, United States under registration number 2025-001656188, with its registered office at 30 N Gould St Ste R, Sheridan, WY 82801, United States. WaitMoon Labs Inc operates the XferAPI website, hosted API, and management console. A managed private deployment may have additional or different processing terms documented in its separate agreement and deployment specification.
2. Information processed
Console identity and authentication
Google sign-in may provide a stable subject identifier, name, email address, and profile image. Email sign-in and password reset process the email address, purpose-scoped verification-code hashes, delivery and attempt information, rate-limit records, and relevant IP data. If a user sets a password, XferAPI stores only a derived bcrypt password hash and the password-change time, never the plaintext password. XferAPI uses this information to create or authenticate a console user, display membership, prevent abuse, and authorize workspace access.
Workspace and ledger data
The service processes workspace membership, invitations, ledger configuration, platform account definitions, API key configuration, accounts, transfers, records, and optional JSON meta submitted by authorized users or backend services.
Billing data
For paid subscriptions, XferAPI processes Stripe customer and subscription identifiers, the selected plan and billing interval, subscription status, billing-period dates, and limited invoice status or payment links. XferAPI does not receive or store complete payment card numbers.
Technical data
The website and service may process IP addresses, request times, user-agent information, error details, and operational logs needed to operate, secure, diagnose, and support the service.
3. Credentials
Console sessions are stored server-side and referenced by an HttpOnly cookie. Email verification codes are stored only as purpose-scoped hashes and expire after a limited period. Passwords are stored only as derived bcrypt hashes. A complete API key secret is shown only when created; XferAPI stores a one-way hash for later authentication. Customers are responsible for protecting passwords and keeping API keys out of browser bundles, mobile apps, source control, and logs.
4. Uses of information
- Authenticate users and authorize workspace and ledger access.
- Execute, recover, and display requested balance operations.
- Operate the management console and service key APIs.
- Protect, troubleshoot, support, and improve the service.
- Respond to product, privacy, support, and commercial messages.
- Comply with legal obligations and protect the service and its users.
5. Service providers and disclosure
Information may be processed by providers used for infrastructure, database hosting, authentication, email delivery, monitoring, and logs. Google processes optional Console sign-in information under Google's terms. Aliyun DirectMail processes recipient addresses and verification or password-reset messages for delivery. Stripe processes XferAPI workspace subscriptions and payment-method information under Stripe's terms and privacy policy; that billing is separate from customer-defined balances inside a ledger. Infrastructure and database providers can vary by hosted region or managed private deployment. XferAPI may disclose information when legally required or reasonably necessary to protect users, customers, or the service. XferAPI does not sell personal information.
6. Managed private deployments
The location of data and the responsibilities of XferAPI, the customer, and infrastructure providers depend on the agreed private-deployment architecture. Those details must be confirmed in the applicable agreement rather than inferred from this public policy.
7. Retention
Hosted data is retained as needed to provide and secure the service, resolve support matters, maintain reconciliation history, and meet legal obligations. No specific deletion or backup schedule should be assumed unless it is documented in a separate agreement.
8. Choices and requests
You may request access, correction, or deletion of personal information associated with the hosted API or console, subject to identity verification, security, reconciliation, backup, contractual, and legal constraints. Workspace owners can manage ordinary membership through the console.
9. International processing
The standard hosted XferAPI service currently operates in the United States, and service data may be transferred to and processed in the United States. Infrastructure, authentication, email, payment, monitoring, and other service providers may process limited data in other locations under their own terms. A managed private deployment follows its agreed deployment specification. If data residency, regional processing, or international transfer terms matter to your organization, contact XferAPI before production use.
10. Security
XferAPI uses scoped authorization, server-side sessions, one-way API key hashes, HTTPS for production service traffic, request correlation IDs, and Console audit events for security-sensitive mutations. Certifications, audit reports, encryption standards, recovery objectives, and service commitments apply only when expressly documented.
11. Contact and changes
This policy may change as the product and deployment model develop. Privacy questions and requests can be sent to [email protected] or by mail to WaitMoon Labs Inc, 30 N Gould St Ste R, Sheridan, WY 82801, United States.