Legal
Privacy Policy
PayProbe is built privacy-first. Every tool runs entirely in your browser — your card numbers, keys, and message data are never sent to us or anyone else.
Last updated: June 21, 2026
The short version
- All tools run client-side in your browser. We do not have a backend that receives your inputs.
- We do not collect, store, sell, or share your personal data, payment data, or cryptographic keys.
- The site shows Google AdSense ads (which may set advertising cookies) and uses Cloudflare Web Analytics (cookieless, aggregate). Neither can access the data you enter into the tools.
- A small amount of data (your theme choice and tool preferences) is stored locally in your browser and never leaves your device.
- No account is required, and we never ask you to register or log in.
- You have rights under laws such as the GDPR and CCPA/CPRA — see "Your rights" below — and can contact us to exercise them.
Overview
PayProbe ("PayProbe", "we", "us", or "our") provides free, browser-based utilities for payment, EMV, ISO 8583, cryptography, and blockchain developers. This Privacy Policy explains what information is and is not processed when you use payprobe.io (the "Service").
Our guiding principle is data minimization: the Service is designed so that the sensitive material you work with — card numbers, PINs, cryptographic keys, message payloads, and similar data — is processed entirely within your browser and is never transmitted to us.
Who is responsible for your data (data controller)
For the purposes of the EU and UK General Data Protection Regulation (GDPR) and similar laws, the data controller for the limited processing described in this policy is LLC PayProbe, Avto Varazi 56, Tbilisi, Georgia.
If you are in the European Economic Area or the United Kingdom and we are required to appoint a representative or Data Protection Officer, their contact details are: [EU/UK representative or DPO contact, if applicable].
You can reach us about any privacy matter at [email protected].
Tools run entirely in your browser
Every calculator, decoder, validator, and generator on PayProbe executes locally using JavaScript running in your own browser. When you paste a card number into the Luhn validator, build a TLV string, compute an ARQC, or decode an ISO 8583 message, that input is processed on your device.
We do not operate an application backend that receives these inputs. Because the data is not sent over the network to us, we cannot see it, log it, or store it. Closing or refreshing the tab discards anything held in memory.
Information we do not collect
We do not collect personal information such as your name, email address, or postal address through ordinary use of the tools. We do not require you to create an account, and there is no login.
We do not collect, retain, or transmit the payment data, account numbers, cryptographic keys, or test material you enter into any tool.
We do not sell or rent the data you enter into the tools, and we do not collect it in the first place. The one exception to "no third parties" is the advertising and analytics described in the "Cookies, analytics, and advertising" section: Google AdSense and Cloudflare receive standard technical data about your visit (not your tool inputs) in order to function.
Local storage on your device
To make the Service more convenient, a small amount of non-sensitive data is saved in your browser’s local storage. This includes your light/dark theme preference, certain tool display preferences, and a short list of recently used tools so they are easy to find again.
This information stays on your device. It is not transmitted to PayProbe or to any third party, and it is not used to identify or track you. You can clear it at any time through your browser’s settings, which will simply reset these preferences to their defaults.
This preference storage is strictly necessary to provide functionality you have requested — remembering your display settings and recently used tools — so under the EU ePrivacy Directive and equivalent rules it does not by itself require consent. Separately, the third-party advertising described in the "Cookies, analytics, and advertising" section below may place non-essential cookies; those are governed by the cookie notice and your consent where required.
Cookies, analytics, and advertising
PayProbe itself does not set tracking cookies, and our own preference storage (described above) is not used to profile you. However, to keep the tools free we include two third-party services on the site, neither of which can access the data you enter into the tools.
Advertising: we display ads through Google AdSense. Google may set and read cookies and similar identifiers in your browser to serve and measure ads, and in some configurations to personalise them. Google acts as an independent controller for this processing. You can learn more and manage your choices at policies.google.com/technologies/ads and adssettings.google.com.
Analytics: we use Cloudflare Web Analytics to understand aggregate traffic (such as page views and referrers). It is privacy-focused and does not use cookies, does not fingerprint visitors, and does not track you across other sites.
Where required by law (for example in the EEA and UK), non-essential cookies such as advertising cookies are subject to your consent, which you can give or withdraw using the cookie notice on the site. We recommend reviewing this section with your own legal counsel to confirm your consent setup meets the requirements that apply to your users.
Hosting and server logs
The Service is delivered as static files (HTML, JavaScript, CSS, and assets) from a hosting and content-delivery provider. As is standard for virtually all websites, the hosting provider may automatically process limited technical request metadata — such as IP address, user-agent string, and the time of a request — for the purpose of serving content, security, and abuse prevention.
Under the GDPR, an IP address can constitute personal data. Where that is the case, our legal basis for this processing is our legitimate interest (Article 6(1)(f)) in delivering the Service securely and reliably and in preventing abuse. This metadata is handled by the hosting provider in the course of delivering the page and is not used by PayProbe to build profiles of users or to associate requests with the data you process inside the tools.
These technical logs are retained only for as long as needed for those purposes — typically a short period determined by our hosting provider — after which they are deleted or aggregated. We act as the data controller and our hosting/CDN provider acts as a processor on our behalf under an appropriate data processing agreement.
International data transfers
The sensitive material you enter into the tools is processed locally in your browser and is not transferred anywhere. The limited technical request metadata described above is processed by our hosting and content-delivery provider, Fly.io (operated by Fly.io, Inc., a United States company), with our primary deployment region located in the United States (Ashburn, Virginia).
Because we are established in Georgia and our host is in the United States, your request metadata may be processed outside your country of residence, including outside the EEA and the UK. Where such a transfer involves personal data protected by the GDPR, it is carried out under an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), or to a country recognised as providing an adequate level of protection.
Links to other sites
PayProbe may link to external documentation, standards bodies, and reference material. We are not responsible for the privacy practices of those websites. We encourage you to review the privacy policy of any third-party site you visit.
Children’s privacy
PayProbe is a technical tool intended for payment and software professionals. It is not directed to children, and we do not knowingly collect personal information from anyone, including children under the age of 16.
Your rights
Depending on where you live, you have rights over your personal data. Because PayProbe does not collect or store the data you enter into the tools, in most cases we hold little or no personal data about you to act on — but we will always respond to a request and explain what, if anything, we hold.
If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to access your personal data; to have it corrected or erased; to restrict or object to its processing; to data portability; and, where processing is based on consent, to withdraw that consent at any time. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information is collected and how it is used, to request access to and deletion or correction of that information, and to opt out of the “sale” or “sharing” of personal information. PayProbe does not sell your personal information for money. Note that the use of third-party advertising (Google AdSense) for personalised ads can constitute “sharing” of personal information under the CPRA; you can limit this through your browser/Google ad settings and the cookie notice on the site, and we do not discriminate against you for exercising any of these rights.
PayProbe is established in Georgia, and we process personal data in accordance with the Law of Georgia on Personal Data Protection. Residents of other jurisdictions (for example under Brazil’s LGPD or Canada’s PIPEDA) have comparable rights. To exercise any right, email [email protected]. We may need to verify your request before responding, and we will reply within the timeframe required by applicable law.
Security
Because sensitive data is processed in your browser and not transmitted to us, the most important protection is the local one: only enter real production secrets, keys, or cardholder data into tools when you understand and accept the risk of doing so on your own device. For most workflows we recommend using test or sample data.
We serve the Service over HTTPS so that the application code is delivered to your browser securely.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service or for legal and operational reasons. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be made prominent on the Service.
Contact us
If you have any questions or concerns about this Privacy Policy or our practices, please contact us at [email protected].
Questions about this policy? Email [email protected].