Legal and compliance
Written for anyone assessing ShyPay: providers, reviewers, counsel, and users who want the unvarnished version. ShyPay is non-custodial software. It never holds customer funds, private keys, or fiat currency, and the regulated activity in the flow sits with an independent licensed provider.
Summary for reviewers
ShyPay, LLC is the company behind ShyPay, and ShyPay is non-custodial software: a self-custody wallet application, in development, that lets a person hold and spend USDC on the Solana network from a wallet whose signing key remains under their control.
- ShyPay never holds customer funds. There is no ShyPay omnibus account, no pooled wallet, and no ShyPay balance sheet position in customer assets.
- ShyPay never holds customer keys or recovery material. Signing uses a 2-of-2 split key: one share on the user's device and one held by the embedded wallet provider in secure hardware. Both are required for every signature. ShyPay holds neither share and cannot sign, alone or in combination with anyone else.
- ShyPay never touches fiat currency. Fiat is exchanged for USDC, and USDC for fiat, by an independent regulated ramp provider that contracts with the user directly.
- ShyPay does not claim a licence. ShyPay is not a bank, a money transmitter, a money services business, an exchange, a custodian, or a broker, and does not hold or claim any financial services authorisation.
- Regulated activity sits with the ramp provider. Identity verification, sanctions screening and transaction monitoring for ramp transactions are performed by that provider under its own licences and programme.
- The settlement ledger is public. Solana transfers are permanently visible on-chain to anyone, which makes the flow auditable rather than opaque.
The diagram in the next section shows where each party sits.
How money flows
The whole model in one line: bank or card, to the regulated ramp provider, to the user's own wallet, to a merchant or another person, and back out through the ramp provider to a bank account.
What happens at each step
- Cash in. The user starts a purchase of USDC inside the app. The ramp provider verifies the user's identity, presents its own terms and quote, takes payment from the user's bank or card, and delivers USDC to the user's own wallet address on Solana. ShyPay is not a party to that payment and does not receive the fiat.
- Hold. The USDC sits at an address controlled by the key on the user's device. ShyPay software displays the balance. It cannot move, freeze, or recover it.
- Spend or send. The user signs a transfer on their device, either to another person or to a merchant that accepts ShyPay, directly or through a checkout running the ProxyPay point-of-sale integration. Settlement is a peer-to-peer transfer on Solana. No ShyPay account sits in the middle.
- Cash out. The user sells USDC to the ramp provider, which quotes the payout, performs its checks, and pays the user's verified bank account. Again, ShyPay does not receive or hold the fiat.
A longer walk-through of each flow, with what every party learns, is on the how it works page.
Where the regulated activity sits
ShyPay is being built to use Dynamic for wallet key management and Ramp Network for buying and selling USDC; these integrations are in development and are subject to those providers’ approval and terms. Naming these services describes an intended architecture; it is not a claim of endorsement, certification, or a signed partnership, and no integration is live today.
- Ramp Network — fiat on-ramp and off-ramp for USDC on Solana, delivered to and taken from the user's self-custody address. The provider would perform customer identity verification (KYC), sanctions and watchlist screening, and transaction monitoring for the transactions it processes, under its own licences and compliance programme, and would contract with the user directly for that service.
- Dynamic (dynamic.xyz) — embedded wallet infrastructure. It would hold one share of a 2-of-2 split signing key in secure hardware; the other share is on the user's device. Both shares are required for every signature, so the provider cannot move user funds on its own, and neither can ShyPay, which holds no share. Dynamic also provides wallet recovery and export of the user's private key.
- Solana — the public settlement network for USDC transfers.
- Circle is the issuer of USDC. ShyPay does not issue, redeem, or back any asset.
ShyPay's own role is the application layer: the interface, the on-device verification of merchant payment requests, and the handoff to those providers. More detail for reviewers is on the partners and providers page.
Non-custodial by construction
This is not a policy choice that could quietly be reversed; it is how the software is built.
- Transfers require a 2-of-2 signature combining the user's device share and the wallet provider's hardware-held share. ShyPay holds no share and can authorise nothing.
- There is no ShyPay-controlled address through which user funds pass in the normal flow.
- ShyPay cannot freeze, seize, claw back, or reverse a settled transfer, and does not represent to users that it can.
- If a user loses both their device and their recovery method, ShyPay cannot restore access; recovery is run by the wallet provider, not by ShyPay. This is stated plainly to users rather than buried.
- Users can export their private key at any time and operate the wallet outside ShyPay entirely.
The corollary is that enforcement against funds is not something ShyPay is able to perform. Where a competent authority requires action against assets, that action has to be directed at the parties that hold them or control the fiat legs.
Prohibited uses
ShyPay must not be used for anything unlawful. The following are prohibited, and are set out in the terms of use so that they bind users of the product:
- Buying or selling illegal goods or services, including controlled substances, weapons prohibited to the user, stolen goods, or child sexual abuse material.
- Money laundering, concealing the proceeds of crime, or structuring transactions to avoid a reporting or verification requirement.
- Sanctions evasion, breach of export controls, or transacting with a sanctioned person, entity, or jurisdiction.
- Terrorist financing.
- Fraud of any kind, including impersonation, use of a funding instrument the user is not entitled to use, and obtaining payment by deception.
- Operating an unlicensed money transmission, exchange, or payment business on behalf of third parties.
- Any other activity that is unlawful in the user's jurisdiction.
Sanctions
ShyPay will not make the service available to persons or jurisdictions subject to applicable sanctions, and will screen wallet addresses against sanctions lists. The product is in development, so this describes the control being built rather than one operating today.
- Access will be refused to any person located in, ordinarily resident in, or acting on behalf of a person in a jurisdiction subject to comprehensive sanctions.
- Access will be refused to any person appearing on an applicable sanctions or watchlist.
- Wallet addresses will be screened against sanctions lists, and a match will be acted on.
- The regulated provider handling cash-in and cash-out performs its own screening on every transaction it processes, under its own programme.
- Attempting to use ShyPay to evade sanctions is prohibited by the terms of use.
Because ShyPay is non-custodial, it cannot freeze or seize funds held in a user's own wallet. Enforcement against assets has to be directed at the parties that hold them or control the fiat legs.
Payments are irreversible
A payment a user approves settles on Solana and is final. ShyPay cannot reverse it, recall it, or compel its return. Neither can the wallet provider. There is no chargeback mechanism and no dispute process that moves the money back.
- Check the recipient before approving. The recipient and the amount are shown before signing, and approval is a separate, deliberate act for this reason.
- To get money back from a merchant, ask the merchant for a refund. A refund is a new payment the merchant chooses to send, not a reversal of the original.
- If a merchant will not help, contact support@shypayments.com. We will say plainly what we can and cannot do rather than imply a recovery route that does not exist.
- Suspected fraud goes to abuse@shypayments.com.
This is disclosed to users on the security page, in the FAQ and in the terms of use, not only here.
Eligibility, geography and age
Age. ShyPay is intended for people aged 18 or over, or the age of majority where they live if that is higher. It is not directed at children.
Geography. The United States is the planned launch market. That is a plan, not a live service: nothing is available anywhere today. Availability in any market will follow what the regulated ramp provider supports, and we will not publish a country list we cannot stand behind.
Sanctioned jurisdictions. See the sanctions section above.
Screening and monitoring
We want to be precise here rather than flattering to ourselves.
- Performed by the ramp provider: customer identity verification, sanctions and politically-exposed-person screening, transaction monitoring, suspicious activity reporting, and record-keeping for the fiat legs it processes. These are its regulatory obligations and it performs them under its own programme.
- Performed by ShyPay: enforcement of its own terms, handling of abuse reports, and on-device verification that a merchant payment request is validly signed, unexpired, unused, and for the exact asset and recipient it claims.
- Not claimed by ShyPay: ShyPay does not hold itself out as operating a regulated anti-money-laundering programme, and does not claim to screen or monitor peer-to-peer transfers that occur directly between self-custody wallets on a public network.
Cooperation with lawful requests
ShyPay responds to valid legal process from a competent authority, and cooperates with law enforcement, within the limits of what it actually holds.
What it holds is deliberately little: no identity documents, no private keys, no fiat records, and no record of what a user bought. Requests concerning identity, funding instruments, or the fiat legs of a transaction should be directed to the regulated ramp provider, which is the party that holds that information. Requests concerning on-chain activity can in many cases be answered from the public Solana ledger without ShyPay's involvement at all.
Where we are permitted to notify a user of a request about them, we will. Legal process should be sent to legal@shypayments.com.
Public-ledger transparency
USDC transfers made through ShyPay settle on Solana, a public blockchain. Every transfer is permanently visible on-chain, including the sending address, the receiving address, the amount and the time.
Each payment carries a unique reference so the merchant can match it to the sale. Payments are recorded on Solana's public ledger like any other transfer; nothing in the design hides or obscures them. ShyPay is a privacy product in the sense that it does not assemble a merchant-by-merchant spending profile in a user's name, and does not sell or share user data. It is not an anonymity product, it is not a mixer, it applies no obfuscation to transactions, and it must not be described as untraceable. Our privacy approach page states this to users in the same terms.
Reporting abuse or a security issue
- Abuse, fraud, or suspected unlawful use of ShyPay: abuse@shypayments.com.
- Security vulnerabilities: security@shypayments.com, under our responsible disclosure policy. Machine-readable details are at /.well-known/security.txt.
- Legal process and formal notices: legal@shypayments.com.
- Privacy requests: privacy@shypayments.com.
- Provider and partner review: partners@shypayments.com.
Common ownership with ProxyPay
ShyPay and ProxyPay are separate companies under common ownership, and that relationship is disclosed to our providers and partners. They are built to run on separate systems, and ShyPay does not receive merchant records or what you bought.
We disclose this rather than obscure it, and we disclose it to the providers and counterparties we work with as well as on this page. We do not assert that infrastructure separation is complete; it is how the two are being built.
Current stage
ShyPay is in development. There is no public application, no live user, no live merchant, and no live provider integration. No security audit or certification has been carried out or is claimed. This page describes the compliance posture the product is being built to, and is published so that providers reviewing ShyPay can see it before any integration exists.
Company details
ShyPay, LLC
8115 NW Eastside Dr
Weatherby Lake, MO 64152
United States
The same details appear in the terms of use and the privacy policy. The governing law and venue clause has not been settled yet and is marked as outstanding in the terms rather than filled in speculatively.
For that review, or for anything else in this document, write to legal@shypayments.com or partners@shypayments.com.
This document is current as of the date shown above. ShyPay may update it as the product develops, and the updated version will be published on this page.