MercadoBTC
Back to Home
Legal & Compliance

Our commitment
to transparency.

Effective: January 1, 2026 Version 1.0 MercadoBTC Financial
On this page
    Overview

    Privacy Policy

    MercadoBTC ("we," "our," or "us") is committed to protecting the privacy of merchants, users, and visitors who interact with our platform. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data.

    By using MercadoBTC's services, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of our platform.

    Plain English summary: We collect only what we need to operate the service. We don't sell your data. You can request deletion at any time.

    Section 01

    Information We Collect

    We collect information in three ways: information you provide directly, information collected automatically, and information from third parties when applicable.

    Information you provide:

    • Business name, contact name, and email address during merchant onboarding
    • Bitcoin wallet public keys or Lightning node information (never private keys)
    • Communication preferences and support correspondence

    Information collected automatically:

    • Transaction metadata (amounts, timestamps, Lightning invoice hashes)
    • Device type, operating system, and application version
    • IP address and approximate geographic region (country-level only)
    • Error logs and performance diagnostics

    What we never collect:

    • Private keys, seed phrases, or wallet recovery information
    • Government-issued ID numbers (unless required by applicable law)
    • Full payment card data
    Section 02

    How We Use Your Information

    We use the information we collect exclusively to provide and improve the MercadoBTC service. Specific uses include:

    • Authenticating merchant accounts and preventing unauthorized access
    • Processing and recording payment transactions on the Lightning Network
    • Providing customer support and responding to inquiries
    • Sending transactional notifications (receipts, settlement confirmations)
    • Detecting, investigating, and preventing fraudulent or illegal activity
    • Improving platform performance through aggregate, anonymized analytics

    We do not use your data for targeted advertising, profiling, or sale to third parties under any circumstances.

    Section 03

    Data Sharing & Disclosure

    We do not sell, rent, or trade your personal information. We may share data only in the following limited circumstances:

    Service Providers
    Infrastructure vendors (hosting, monitoring) bound by confidentiality agreements
    Legal Obligations
    When compelled by valid court order, subpoena, or applicable law
    Fraud Prevention
    With law enforcement when we have good-faith belief of illegal activity
    Business Transfer
    In the event of a merger or acquisition, with advance notice to users
    Section 04

    Your Rights & Choices

    You have meaningful control over your data. At any time, you may:

    • Access — request a copy of all personal data we hold about you
    • Correction — request that inaccurate information be corrected
    • Deletion — request erasure of your account and associated data, subject to legal retention requirements
    • Portability — receive your data in a structured, machine-readable format
    • Opt-out — unsubscribe from non-transactional communications at any time

    To exercise any of these rights, contact us at the address below. We will respond within 30 days.

    Section 05

    Contact

    For privacy-related inquiries, requests, or concerns, please reach out to our data team directly.

    Privacy Team

    MercadoBTC Financial · Response within 30 days

    privacy@mercadobtc.com
    Overview

    Terms of Service

    These Terms of Service ("Terms") govern your access to and use of the MercadoBTC platform, including its mobile application, web interface, API, and related services (collectively, the "Service"). Please read them carefully before using MercadoBTC.

    By creating an account or using any part of the Service, you agree to be bound by these Terms. If you are using MercadoBTC on behalf of a business, you represent that you have authority to bind that business to these Terms.

    Important: MercadoBTC is a non-custodial payment infrastructure provider. We do not hold, control, or insure your Bitcoin. You are solely responsible for securing your private keys and wallet credentials.

    Section 01

    Eligibility & Account Registration

    To use MercadoBTC, you must:

    • Be at least 18 years of age or the age of legal majority in your jurisdiction
    • Have the legal capacity to enter into a binding agreement
    • Not be located in, or a resident of, any jurisdiction where use of cryptocurrency payment services is prohibited
    • Not be on any government-issued sanctions or watchlist

    You are responsible for providing accurate registration information and maintaining the confidentiality of your account credentials. You must notify us immediately of any unauthorized account access at security@mercadobtc.com.

    Section 02

    Description of Service

    MercadoBTC provides merchants with software infrastructure to generate Bitcoin Lightning Network invoices, display payment QR codes, and track incoming payment confirmations. The Service does not:

    • Hold, custody, or control your Bitcoin at any point
    • Guarantee transaction confirmation times (which depend on the Lightning Network)
    • Provide fiat currency conversion or settlement
    • Act as a financial institution, bank, or money services business

    We reserve the right to modify, suspend, or discontinue any part of the Service at any time with reasonable notice where practicable.

    Section 03

    Fees & Billing

    MercadoBTC charges a flat fee per transaction processed through our platform. Current fee schedules are published on our pricing page and may be updated with 30 days' written notice to active merchants.

    Standard Fee
    0.5% per transaction
    Minimum Charge
    None
    Monthly Subscription
    None (pay-per-use)
    Chargebacks
    Not applicable (Bitcoin is final)

    All fees are deducted automatically at the time of transaction. There are no hidden charges, monthly minimums, or setup fees.

    Section 04

    Prohibited Uses

    You may not use MercadoBTC to process payments for, or in connection with, any of the following:

    • Illegal goods, services, or activities under applicable law
    • Money laundering, terrorist financing, or sanctions evasion
    • Fraudulent transactions or misrepresentation of goods and services
    • Gambling or lottery services where prohibited by law
    • Adult content platforms without age verification systems
    • Any activity that violates a third party's intellectual property rights

    Violation of these prohibitions may result in immediate account suspension and, where required, reporting to relevant authorities.

    Section 05

    Limitation of Liability

    To the maximum extent permitted by applicable law, MercadoBTC and its affiliates, officers, and employees shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of Bitcoin, loss of revenue, or data loss.

    Our total cumulative liability for any claim arising from these Terms or the Service shall not exceed the total fees paid by you to MercadoBTC in the three (3) months preceding the claim.

    Reminder: Bitcoin transactions on the Lightning Network are irreversible. Always verify payment amounts before confirming a transaction. MercadoBTC cannot reverse completed payments.

    Section 06

    Governing Law & Disputes

    These Terms are governed by and construed in accordance with the laws of the applicable jurisdiction in which MercadoBTC is incorporated, without regard to conflict of law provisions.

    Any disputes arising under these Terms shall first be attempted to be resolved through good-faith negotiation. If unresolved within 60 days, disputes shall be submitted to binding arbitration administered by a mutually agreed-upon arbitration body.

    You waive any right to participate in a class-action lawsuit or class-wide arbitration against MercadoBTC.

    Section 07

    Contact

    For questions about these Terms, please contact our legal team.

    Legal Team

    MercadoBTC Financial · Response within 14 business days

    legal@mercadobtc.com
    Overview

    Security Policy

    Security is foundational to MercadoBTC. Because our platform operates on a non-custodial model — meaning we never hold your Bitcoin — the attack surface is fundamentally different from traditional fintech. This policy describes how we protect our infrastructure, your account, and your data.

    🔒 TLS 1.3 Encryption
    🗝️ Non-Custodial
    🧱 SOC 2 Aligned
    👁️ 24/7 Monitoring
    🪲 Bug Bounty Program
    Section 01

    Infrastructure Security

    MercadoBTC's backend infrastructure is designed with security-first principles at every layer:

    • Encryption in transit: All data transmitted between clients and our servers is encrypted using TLS 1.3. Older protocol versions are rejected.
    • Encryption at rest: All stored data is encrypted using AES-256. Database backups are encrypted and stored in geographically distributed locations.
    • Network segmentation: Production systems are isolated from development and staging environments. Strict firewall rules limit inter-service communication.
    • Access controls: Internal systems use role-based access control (RBAC). All access to production environments requires multi-factor authentication and is logged.
    • Dependency management: We continuously scan dependencies for known vulnerabilities using automated tooling and apply patches on a defined schedule.
    Section 02

    Non-Custodial Architecture

    The most important security property of MercadoBTC is what we don't hold. Our platform is fully non-custodial:

    Private Keys
    Never transmitted to or stored by MercadoBTC servers
    Seed Phrases
    Generated and stored exclusively on your device
    Funds
    Always under your direct cryptographic control
    Cold Storage
    Compatible with hardware wallets for high-value balances

    This means that even in the unlikely event of a MercadoBTC server breach, your Bitcoin cannot be stolen from our infrastructure — because it is never there.

    Section 03

    Account Security

    We provide multiple layers of account protection for merchants:

    • Two-factor authentication (2FA): Required for all merchant accounts. We support TOTP authenticator apps. SMS 2FA is not offered due to SIM-swap risks.
    • Session management: Login sessions expire after inactivity. All active sessions are visible in your account dashboard and can be remotely terminated.
    • Login anomaly detection: We flag and challenge logins from unrecognized devices or unusual locations.
    • Password standards: Passwords are hashed using bcrypt with a high cost factor. We never store plaintext passwords.
    • API key security: API keys can be scoped to specific permissions and rotated at any time. Compromised keys can be revoked instantly from the dashboard.
    Section 04

    Incident Response

    We maintain a formal incident response plan. In the event of a security incident that may affect your data:

    • We will notify affected merchants within 72 hours of becoming aware of the incident
    • Notifications will be sent to the primary email address on your account
    • We will provide a clear description of what happened, what data was affected, and what steps we are taking
    • We will post a public incident report for significant events within 14 days of resolution

    Reminder: Because MercadoBTC is non-custodial, no incident on our servers can result in loss of your Bitcoin. The primary risk from a data breach would be exposure of your business contact information and transaction metadata.

    Section 05

    Bug Bounty Program

    We believe in working with the security research community to keep MercadoBTC safe. If you discover a security vulnerability in our platform, we want to hear from you.

    Scope: Our bug bounty covers the MercadoBTC web application, mobile app, and public API. Infrastructure and third-party services are out of scope.

    Rewards: Valid reports are rewarded based on severity (informational, low, medium, high, critical). Reward amounts are determined on a case-by-case basis.

    Rules: Do not access or modify data belonging to other users. Do not perform denial-of-service attacks. Do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it.

    Report a Vulnerability

    PGP-encrypted submissions preferred · We respond within 48 hours

    security@mercadobtc.com
    Section 06

    Security Best Practices for Merchants

    The most common attack vectors target users, not infrastructure. We recommend:

    • Use a dedicated email address for your MercadoBTC account that is not shared with other services
    • Enable 2FA immediately after account creation and store backup codes securely offline
    • Regularly sweep funds from your Lightning hot wallet to cold storage
    • Verify that you are on the official MercadoBTC domain before entering credentials
    • Be skeptical of any communication claiming to be from MercadoBTC that asks for your private key or seed phrase — we will never ask for this
    • Keep the MercadoBTC terminal app updated to receive the latest security patches
    MercadoBTC © 2026 MercadoBTC Financial. All rights reserved.
    Privacy Terms Security