Terms of service

Last updated

The agreement between you and Crypto Gate for using Crypto Gate. It matters more than most terms pages, because this service holds your money and crypto payments cannot be reversed.

1. This agreement

These terms are a contract between you (“you”, the account holder or merchant) and Crypto Gate, a company registered in with its registered office at (“we”, “us”, Crypto Gate).

By creating an account, calling our API, or accepting a payment through the service, you agree to these terms, to the acceptable use policy, and to the privacy policy. If you do not agree to all of them, do not use the service.

If you are agreeing on behalf of a company, you confirm you are authorised to bind it, and “you” means that company.

2. What the service is

Crypto Gate is a custodial cryptocurrency payment gateway. It lets you request payment in cryptocurrency, receive that payment, hold a balance, move between supported assets, and pay out to on-chain addresses — through a dashboard, a mobile app, or a REST API.

The service supports the following assets and networks:

  • Bitcoin (BTC), on the Bitcoin network.
  • Ethereum (ETH), on the Ethereum network.
  • Litecoin (LTC), on the Litecoin network.
  • Polygon (MATIC/POL), on the Polygon network.

We may add or remove supported assets and networks. If we remove one, we will give you reasonable notice and a reasonable opportunity to withdraw any balance held in it.

We are not a bank, and we are not an investment service. We do not lend your funds, pay interest on them, or offer any product whose value depends on the performance of an asset. We do not give financial, investment, tax or legal advice.

3. Custody of your funds

This is the most important clause in this document. Read it carefully.

The service is custodial. Cryptocurrency you receive through Crypto Gate is held by us on your behalf. You do not hold the private keys to the addresses your payments arrive at, and you cannot sign a transaction yourself. Moving funds out requires us to act on your instruction.

Your balance is recorded in a double-entry ledger. Every movement is written as a balanced group of entries, your available and pending balances are derived from those entries, and a scheduled job re-derives balances from the ledger and compares them to detect drift. That ledger is our record of what we hold for you.

A ledger balance is a claim against us, not possession of the coins. If we become insolvent, are hacked, lose access to our own keys, or are compelled by a court or regulator to freeze assets, your ability to recover funds depends on facts outside this contract. You should hold no more with us than you are prepared to have at risk, and you should withdraw settled funds to a wallet you control on a regular basis.

[PLACEHOLDER — SEGREGATION AND SAFEGUARDING. Counsel to specify how customer assets are held relative to company assets, whether they are segregated or pooled, what protection (if any) applies on insolvency, and what safeguarding requirements apply in . Do not publish this document without it.]

4. Eligibility and accounts

To open and keep an account you must:

  • be at least 18 years old and legally able to enter into this contract;
  • not be a person, or acting for a person, barred by any sanctions regime that applies to you or to us;
  • use the account for yourself or for a business you are authorised to act for, not for someone else whose identity you have not disclosed to us;
  • give us accurate registration information and keep it current;
  • comply with the acceptable use policy.

[PLACEHOLDER — IDENTITY VERIFICATION. Counsel to specify what customer due diligence, identity verification and ongoing monitoring the service is required to perform, at what thresholds, and what documents may be demanded. The current software does not implement an identity-verification flow; this clause must match what is actually built before launch.]

One account per person or legal entity unless we agree otherwise in writing. You are responsible for everything done through your account, including by anyone you give access to and by any API key you issue.

5. Your security obligations

You must:

  • keep your password, your two-factor authenticator, your recovery codes and your API secrets confidential, and not reuse your password anywhere else;
  • keep two-factor authentication enabled — every path that moves funds out requires a second factor, and disabling it is not an option we offer for those paths;
  • check the sign-in history in your account and tell us immediately, at [email protected], if you see access you do not recognise;
  • revoke API keys you no longer use, and rotate any key you believe has been exposed;
  • verify the destination address before you approve any withdrawal or payout.

We hash API secrets, one-time codes and device identifiers at rest, and we require an emailed code when we see a sign-in from a device we do not recognise. Those measures reduce risk; they do not remove it, and they cannot protect an account whose password and second factor are both in someone else's hands.

6. Receiving payments

You create a payment request for a specific asset, a specific amount and an expiry window. We give you an address and a hosted payment page for it. When a payment arrives we credit it to your pending balance, and we move it to your available balance once the network has confirmed it to the depth we require for that asset.

Deposits are keyed on the on-chain transaction hash so the same payment cannot be credited twice. Amounts are handled as exact decimal values throughout; we do not use floating-point arithmetic for money.

You are responsible for the commercial side of a payment. In particular:

  • A payment that arrives after a request has expired is still credited to your balance. Your webhook receives a payment.late event. Whether you still fulfil the order is your decision, not ours.
  • A payment that arrives for less than the requested amount is credited for what arrived. Deciding what to do about the shortfall is yours.
  • The crypto amount is fixed at the moment the request is created. If the market moves before the payer sends, the fiat value you receive will differ from the fiat value you quoted. That exposure is yours.
  • Refunding a customer is a new outbound payment made by you, at your cost. There is no mechanism to reverse a received payment.

7. Irreversibility and wrong-chain loss

Cryptocurrency settlement is final. There is no chargeback, no reversal and no recall. Once a transaction is confirmed on the network it cannot be undone by us, by you, by the payer, by a bank or by a court order directed at us. If you are used to card payments, this is the single largest difference: the protection you may be used to relying on does not exist here.

Three specific ways funds are lost permanently, none of which we can recover for you:

  • Sending the wrong asset. Sending Litecoin to a Bitcoin address, for example, or any asset to an address for a different asset. The funds are gone.
  • Sending the right asset on the wrong chain. This one catches experienced users. ETH and MATIC/POL exist on multiple networks, and an address can look valid on all of them. Sending an asset on Ethereum to an address we monitor on Polygon — or the reverse — means the funds land somewhere we do not control and cannot reach. They are gone.
  • Mistyped or wrong destination addresses. A payout to an address you entered incorrectly, or to an address controlled by someone else, cannot be retrieved. Always confirm the full address, not only its first and last characters.

We have no ability to recover funds in any of these cases, and we accept no liability for them. Check the asset, the network and the address every time.

We also cannot help with tokens or assets we do not support that are sent to an address we issued. Those are unrecoverable.

8. Withdrawals and payouts

You can withdraw available balance to an on-chain address, or pay out to many recipients in a batch.

  • A second factor is required. Every withdrawal and every payout requires an authenticator code, on the web dashboard and in the app alike.
  • Batches require approval. A bulk payout must be approved before it can be sent, and the approval step is separate from the step that broadcasts it.
  • Nothing broadcasts automatically. No transaction leaves the platform without an explicit human instruction and the checks above.
  • A hold is placed immediately. Requesting a withdrawal reserves the amount against your balance, so the same funds cannot be committed twice while the request waits.

We may delay, hold or refuse a withdrawal where we reasonably suspect fraud, a breach of the acceptable use policy, a sanctions issue, or where we are required to do so by law or by a competent authority. Where we can lawfully tell you, we will.

Network fees are payable on any outbound transaction and are deducted as described at the time you make the request. We do not control network congestion or confirmation times.

[PLACEHOLDER — WITHDRAWAL LIMITS AND TIMING. Minimum and maximum withdrawal amounts, daily limits, and the committed processing window for a withdrawal request. Leave unstated rather than guessed.]

9. Swaps and pricing

Where the service lets you move a balance between supported assets, the rate is derived from a third-party reference price feed. A swap is refused if a price is missing or older than our staleness threshold, rather than executed at a price we cannot stand behind.

A quoted rate is indicative until the swap is executed. We do not guarantee that a rate matches any particular exchange, and we are not responsible for the accuracy of the third-party feed. A completed swap cannot be reversed.

Fiat values shown anywhere in the product are for information only. Your balance is denominated in the crypto asset, not in any currency it is displayed against.

10. Fees

[PLACEHOLDER — FEE SCHEDULE. Settlement fee, payout fee, swap spread, any monthly or minimum charge, and how and when each is deducted. No fee is stated anywhere on this site until it is a real commercial decision; a merchant must never be able to rely on a number we invented.]

Separately from our fees, every on-chain transaction carries a network fee set by the network, not by us. That is payable by you on outbound transactions.

We will give you [NOTICE PERIOD] notice before a fee increase takes effect. Taxes arising on your use of the service are yours to assess and pay; we do not provide tax advice and we do not file on your behalf.

11. API keys and webhooks

An API key authenticates as you. Treat a key as you would a password: we store only a hash of the secret, so we cannot show it to you again after it is issued, and a key you have lost must be revoked and replaced.

Webhooks we send are signed with HMAC-SHA256 over the raw request body. You should verify that signature using a constant-time comparison before acting on a webhook. A webhook is a notification, not a guarantee: your system should tolerate duplicates, out-of-order delivery and retries, and should treat the API as the source of truth.

We may rate-limit API requests, and we may change the API. Where a change is breaking, we will give reasonable notice through the developer documentation and to the contact address on your account.

You must not use the API to circumvent limits, to probe or attack the service, or in a way that degrades it for other users. See the acceptable use policy.

12. Suspension and closure

We may suspend or block an account where we reasonably believe it is being used in breach of these terms or the acceptable use policy, where it has been compromised, where we are required to by law or by a competent authority, or where continuing to operate it would expose us or other users to legal or financial risk.

A block takes effect immediately and ends active sessions and API access at once — an existing API token does not keep working after a block. Where we can lawfully tell you why, we will, and we will tell you what we need in order to lift it.

You may close your account at any time. Withdraw your balance first: closure does not trigger an automatic payout, and we will need a valid destination address for anything remaining.

Some records survive closure. Ledger entries, transaction records and related account data are financial records. We retain them after an account is closed because we are obliged to keep an accurate history of funds we have held, and because they may be needed to answer a later dispute or a lawful request. See the privacy policy.

[PLACEHOLDER — DORMANT AND UNCLAIMED BALANCES. What happens to a balance on a closed or abandoned account, after how long, and under what unclaimed-property rules in .]

13. Availability and support

We aim to keep the service available and correct, and we invest most heavily in the parts that touch money. We do not, in these terms, commit to a specific uptime figure. The service depends on third parties — a blockchain infrastructure provider, an email provider, a price feed — and on the public networks themselves, none of which we control.

We may take the service down for maintenance. Where an outage is planned, we will give notice where we reasonably can.

[PLACEHOLDER — SERVICE LEVEL COMMITMENT. Any uptime target, support response times and remedies, if these are to be offered contractually.]

14. Risk disclosure

You acknowledge that:

  • crypto assets are volatile; their value can fall sharply and without warning, and can fall to zero;
  • crypto assets are largely unregulated in many places, and the consumer protections that apply to bank deposits or card payments generally do not apply here;
  • transactions are irreversible, as set out in section 7;
  • blockchain networks can fork, congest, reorganise or fail, and a transaction can be delayed or dropped for reasons outside anyone's control;
  • holding a balance with a custodian carries counterparty risk, as set out in section 3;
  • the legal and tax treatment of crypto assets can change, sometimes with immediate effect.

Nothing on this site or in the product is financial, investment, tax or legal advice.

15. Liability

Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud or fraudulent misrepresentation, or for death or personal injury caused by negligence.

Subject to that, we are not liable for:

  • loss caused by you sending the wrong asset, the right asset on the wrong chain, or an asset to a wrong or mistyped address;
  • loss caused by a compromise of your credentials, your second factor or your API keys, where the compromise did not result from our breach of these terms;
  • changes in the market value of any crypto asset;
  • the acts, omissions, outages or errors of blockchain networks or of third-party providers;
  • loss of profit, loss of business, loss of goodwill, or indirect or consequential loss.

[PLACEHOLDER — LIABILITY CAP. The aggregate cap on our liability and the period over which it is measured. Counsel to set this, and to confirm it is enforceable in and against the consumer-protection rules that apply to your customers.]

16. Indemnity

You will indemnify us against claims, losses and reasonable costs arising from your breach of these terms or the acceptable use policy, from your use of the service in breach of any law, or from a dispute between you and your own customer about goods or services you supplied. This does not apply to the extent the claim arises from our own breach.

17. Changes to these terms

We may change these terms. The “last updated” date at the top of this page is set by hand when the document changes substantively — it is not generated, because an auto-updating date on a contract is a lie.

For a change that materially affects your rights or obligations, we will give you [NOTICE PERIOD] notice to the contact address on your account before it takes effect. If you do not accept the change, your remedy is to withdraw your balance and close your account before that date.

18. Governing law and disputes

[PLACEHOLDER — GOVERNING LAW. The law that governs this agreement. Not stated here, because guessing it would be worse than leaving it blank.]

[PLACEHOLDER — DISPUTE RESOLUTION AND VENUE. Whether disputes go to named courts or to arbitration, where, under what rules, and whether any class-action waiver or consumer carve-out applies.]

[PLACEHOLDER — COMPLAINTS AND REGULATORY STATUS. The internal complaints procedure and response time, any external ombudsman or dispute scheme customers may escalate to, and any license or registration number under which the service operates. We hold no registration number that we can state here, and we will not invent one.]

If any clause of these terms is found unenforceable, the rest continues to apply. Our not enforcing a term on one occasion does not waive it. You may not assign this agreement without our consent; we may assign it as part of a transfer of the business, on notice to you.

19. Contact

Crypto Gate

Legal notices: [email protected]
Support: [email protected]
Security reports: [email protected]

Before this document goes live

Have counsel qualified in the relevant jurisdiction review the whole of it, fill every bracketed placeholder, and confirm what licensing or registration holding customer funds requires where Crypto Gate operates and where its customers are. Until that is done this page is a draft, not a contract.