This is an unofficial English translation provided for convenience. The legally binding version is the Russian one: /ru/legal
Document 1

Terms of Service

Last updated: September 4, 2026 · Unofficial English translation

CoinRail is a payment gateway for accepting and sending cryptocurrency (Bitcoin, Litecoin, and USDT on the TRON network). These Terms govern the use of the service by merchants. By registering, you accept them in full.

⚠ Translation notice
This is an unofficial English translation provided for convenience. The legally binding version of all Coinrail legal documents is the Russian version at coinrail.net/ru/legal. In case of any discrepancy, the Russian text prevails.
◆ The essentials in one paragraph
The service stores an encrypted copy of the secret phrase (seed) of each of your projects — without it, payouts cannot be signed via the API. You can retrieve your phrase in the dashboard at any time under your PIN and control the funds independently of the service, using any external wallet. Every disclosure of the phrase is recorded in an audit log. Crypto transfers are irreversible; the merchant is responsible for the correctness of payout details.

1Definitions and service model

The Operator is the team running the CoinRail service (coinrail.net). The service is not a legal entity or a financial institution and is not tied to any jurisdiction. A Merchant is a registered person using the service to accept and send cryptocurrency. The Service is a software payment gateway: address generation, payment pages, webhooks, payouts via API.

CoinRail works exclusively with cryptocurrencies (BTC, LTC, USDT on the TRON network, XMR) and performs no operations with fiat money, does not exchange crypto for fiat, is not an exchange or a financial institution, and does not take deposits. The service provides technical infrastructure for accepting and sending crypto payments.

At the same time the service operates the merchant's wallets and stores their keys as described in section 2. In this respect the model is custodial, and the merchant should assume that funds on project wallets remain within the Operator's technical control until withdrawn.

2Key storage model

CoinRail operates a custodial hybrid model. A separate secret phrase (seed) is generated for each merchant project; receiving addresses are derived from it and payouts are signed with it. How the model works:

  • the service stores an encrypted copy of the secret phrase in its database (symmetric AES-256-GCM encryption). Decryption happens on the Operator's server at the moment a transaction is signed;
  • the copy is required technically: API payouts are initiated by your server without human involvement, and a transaction cannot be signed without the key;
  • the merchant may retrieve their secret phrase at any time in the dashboard (confirmed by PIN) and from that moment control the project's funds independently of the service. The phrase is standard BIP39 (24 words), but recovery requires a wallet where the derivation path is set manually: addresses are derived at m/44'/0'/0' for Bitcoin, m/44'/2'/0' for Litecoin and m/44'/195'/0' for USDT on TRON. For Bitcoin and Litecoin the addresses themselves are native segwit (P2WPKH, bech32); wallets that auto-detect the path look for native segwit at m/84' by default and will show such a wallet as empty — this is not a loss of funds, merely a mismatch of the search scheme. TRON addresses are standard for the network, but the m/44'/195'/0' path must also be set manually;
  • the Operator is technically able to decrypt the secret phrase of any project. This is a direct consequence of the custodial model;
  • every disclosure of a secret phrase — whether by the merchant or by the Operator — is recorded in the audit log with the project, wallet and time.

Losing access to the dashboard does not mean losing funds, provided you saved the secret phrase in advance: with it you can restore the wallet in external software without the Operator — setting the derivation path manually as described above. We strongly recommend retrieving the phrase, saving the derivation path together with it, and keeping both offline right after onboarding.

Payout limits. Payouts initiated via the API are subject to per-transaction and per-calendar-day limits, separately for each coin. Base values are set by the Operator (by default — 0.5 BTC per transaction and 2 BTC per day; 50 LTC per transaction and 200 LTC per day; 20,000 USDT per transaction and 100,000 USDT per day). The merchant may set stricter personal limits in the dashboard; values above the base ones are ignored. Payouts from the Telegram bot have a separate, narrower daily limit. Requests above the effective limit are rejected. The limits constrain operations through the service and do not restrict direct control of the funds via the secret phrase.

3Irreversibility of transactions

Blockchain operations are irreversible. Once a transaction is sent, it cannot be cancelled, reversed or disputed. In particular:

  • a transfer to a wrong or mistaken address results in a loss of funds with no possibility of recovery;
  • the Operator does not verify the correctness of addresses and amounts entered by the merchant and bears no responsibility for input errors;
  • responsibility for the correctness of payout details rests entirely with the merchant.

4Pricing and subscription

Access to the service is provided by subscription. Three plans are available: Solo — USD 39 per month, Pack — USD 99 per month, Agency — USD 199 per month. Annual payment equals the price of ten months. Prices are in USD; payment is accepted in cryptocurrency at the exchange rate at the moment of payment.

The Operator takes no percentage of the merchant's transactions (0% of turnover). Turnover is unlimited, except for the payout limits (see section 2).

On the Bitcoin and Litecoin networks the network fees (feeRate) are set and paid by the merchant. On the TRON network the fee is charged not in the coin being transferred but in network resources purchased by the Operator — therefore for USDT (TRC20) payouts the network fee is paid by the Operator, and the merchant is charged a flat per-operation fee: 2.5 USDT when the network fee is covered by rented energy (the typical case), or 4 USDT when it is covered by purchasing network resources outright. The applicable rate is determined by how the network fee was actually paid for the given payout; both rates are published in advance. This is a per-operation fee, not a percentage of turnover: it does not depend on the payout amount. Accepting USDT (TRC20) payments is not subject to the operation fee. The fee accrues after a successful payout and is withheld from the project's funds in the same coin; the available balance shown is always net of accrued and not yet withheld fees, as well as of the amount reserved for the fee on the payout itself. If the project's funds are spread across several network addresses, consolidating them onto one address is a separate operation: the Operator does not perform it on its own initiative and carries it out only upon the merchant's explicit instruction given through the cabinet or the API. Each such transfer is charged at the same two rates as a payout, and its cost is disclosed to the merchant before the operation is confirmed.

New merchants receive a 7-day trial. After a paid period ends, merchants who have previously paid for the subscription get a 7-day grace period, after which access is suspended. Suspension of access does not affect funds on project wallets and does not remove the ability to control them via the secret phrase.

Subscription payments are non-refundable, including upon early termination of use. The Operator may change the plans with advance notice to merchants; continued use after the changes take effect constitutes acceptance.

5Disclaimer of warranties and liability

The service is provided "as is" and "as available", without warranties of any kind, express or implied, including warranties of fitness for a particular purpose, uninterrupted operation, or absence of errors.

To the maximum extent permitted, the Operator is not liable for any losses — direct, indirect, incidental or consequential, including lost profit, loss of data or funds. The service is used solely at the merchant's risk. This applies, among other things, to: compromise or loss of keys and access; errors in transaction details; failures of blockchain networks, nodes or third-party services; unavailability or discontinuation of the service.

Force majeure. The Operator is not responsible for non-performance caused by circumstances beyond reasonable control: natural disasters, war, civil unrest, acts of authorities and changes in law, communication and power failures, hardware or software failures, forks and blockchain network failures.

6Prohibited use

The merchant must not use the service for:

  • any unlawful activity, money laundering, terrorism financing, sanctions evasion;
  • trade in drugs, weapons, explosives, stolen goods or counterfeits;
  • financial pyramids, Ponzi and other fraudulent schemes;
  • human trafficking, exploitation, illegal content;
  • hacking, malware, scraping, circumvention of protections, spam;
  • violation of third-party rights and intellectual property.

Upon detecting a violation the Operator may immediately and without prior notice suspend or terminate access and block transactions.

7Changes to these Terms

The Operator may update these Terms at any time; changes take effect upon publication, and continued use of the service constitutes acceptance. The service is provided without ties to any jurisdiction and without guarantees. To the maximum extent permitted, any claims arising from the use of the service are excluded; by continuing to use the service the merchant accepts these terms in full.

In case of any discrepancy between this translation and the Russian original, the Russian version prevails.

Document 2

Privacy Policy

Last updated: September 4, 2026 · Unofficial English translation

We collect the minimum data required for the service to work. The key exception is the encrypted copy of your project's secret phrase: it is needed to sign payouts via the API. Below is what we collect, why, and who it is shared with.

1What we collect

  • Account data: login (no email required), hashes of the password, secret word and PIN (never stored in plain text);
  • Cryptographic material: the project wallet's secret phrase (seed) — in encrypted form (AES-256-GCM), and the account-level public key (xpub) for address derivation;
  • Technical data: IP address, request timestamps, service logs for abuse protection and diagnostics;
  • Transactional data: addresses, amounts, invoice and payout statuses, webhook settings;
  • Audit log: records of significant actions, including every disclosure of the secret phrase (by whom, for which project, and when).
◆ How keys and passwords are stored
Merchants' secret phrases are stored only in encrypted form; the encryption key is held by the Operator separately from the database. The Operator is technically able to decrypt them — a consequence of the custodial model (see Terms, section 2). The password, secret word and PIN are never stored in plain text — only irreversible cryptographic hashes. Secret phrases themselves are never written to logs.

2Why we use it

Solely to provide and protect the service: authentication, executing and accounting for operations, webhook delivery, fraud and abuse prevention.

3Storage and sharing

We keep only the data needed for the service to operate, and no longer than required. We do not sell data and do not share it with third parties for marketing or commercial purposes. The scope of collected data is kept to the minimum sufficient for the gateway to function.

That said, the gateway cannot technically operate without contacting external services. Below is the list of such services and what exactly becomes known to them:

  • Litecoin. The Operator runs its own Litecoin node. When it is unavailable, and for cross-checking discrepancies, chain state is read via third-party public explorers — Litecoinspace, BlockCypher, Blockchair (with automatic failover). At such moments these services, and their network providers, learn the LTC addresses of your projects, the amounts and request times, as well as our server's IP address. Take this into account when assessing the privacy of LTC operations.
  • Bitcoin. The Operator runs its own Bitcoin node, which is the primary data source. However, requests to third-party explorers cannot be ruled out entirely — mempool.space, Blockstream, BlockCypher are queried when the node is unavailable and when cross-checking discrepancies (the node may not know about deposits that occurred before an address was added to its watch list). At such moments they learn the same information as listed above for Litecoin.
  • USDT (TRON network). The Operator has no node of its own on the TRON network: chain state and token transfers are read via third-party public HTTP providers (primary and fallback, with automatic switching on unavailability or exhausted limits). This means that on every USDT operation — not only on failure, as with BTC and LTC — these services learn your projects' addresses, the amounts and request times, as well as our server's IP address. Assess the privacy of USDT operations accordingly.
  • Exchange rates. External quote sources (CoinGecko and Kraken) are queried to convert amounts to USD. Only coin symbols are transmitted; addresses, amounts and merchant details are not disclosed to them, though these services do see our server's IP address.
  • Telegram. If the merchant enables notifications or payouts via our Telegram bot, the contents of those messages — including addresses, amounts and operation statuses — pass through Telegram's servers and are subject to its rules. Connecting the bot is voluntary; without it this channel is not used.

In addition, data is hosted on the servers of a hosting provider engaged by the Operator. Blockchain queries are public by nature: transactions, addresses and amounts are forever visible to any observer of the network — this is a property of cryptocurrencies themselves, not a decision of the Operator.

4Your rights

You may request information about the data collected about you, its correction or deletion within reason. Requests — via our Telegram bot (see the page footer).

Document 3

AML and Sanctions Policy

Last updated: September 4, 2026 · Unofficial English translation

CoinRail does not participate in unlawful operations and reserves the right to respond to clear abuse of the service.

1Identification

The service operates without mandatory identity verification (no-KYC) — the Operator does not collect identity documents in the normal course of operation. At the same time the Operator retains the right, at its sole discretion, to suspend access or refuse service upon clear signs of abuse.

2Prohibited jurisdictions

The service is not intended for residents and citizens of territories under international sanctions, including: Cuba, Iran, North Korea, Syria, Crimea. The merchant is solely responsible for the legality of using the service in their jurisdiction.

3Operator's rights

Upon clear signs of the service being used for unlawful purposes, the Operator may, at its sole discretion and without prior notice, suspend or terminate access and block operations. The Operator does not monitor merchants in the normal course of operation and does not restrict access arbitrarily in the absence of signs of abuse.

Document 4

Risk Disclosure

Last updated: September 4, 2026 · Unofficial English translation

A short warning about the risks of working with cryptocurrency through a payment gateway with custodial key storage. By using CoinRail you confirm that you understand and accept them.

⚠ Read before you start
Cryptocurrency carries the risk of total loss of funds. The key thing to understand: an encrypted copy of your key is held by the Operator, so on top of the usual crypto risks there is the risk of the service itself being compromised. There is no compensation, insurance or government guarantee for these risks.

1Operator compromise

Because the service stores encrypted secret phrases and holds the encryption key to them, a breach of the Operator's infrastructure, a leak of the encryption key, or bad-faith actions by persons with access to it may lead to the loss of funds on project wallets. This is an inherent property of the custodial model, not a hypothetical assumption. You can reduce this risk by retrieving the secret phrase in the dashboard and not keeping more on the gateway's wallets than your current turnover requires; withdraw accumulated funds to your own cold storage.

2Responsibility for the secret phrase

The secret phrase grants full and perpetual control over the project's funds: phrase rotation is not possible, so a phrase once disclosed remains valid forever. Its theft or disclosure — on your side or the Operator's — means a third party can withdraw everything. By retrieving the phrase in the dashboard, you accept responsibility for its safekeeping.

3Irreversibility of transfers

Crypto transactions cannot be undone. An error in the address or amount leads to a loss of funds. Verify the details before sending — the Operator does not check them.

4Volatility and networks

Cryptocurrency prices are volatile, and the service obtains rates from external sources that may be unavailable or wrong. Blockchain networks may experience delays, congestion, forks and reorganizations affecting the speed and confirmation of operations. These factors are outside the Operator's control.

5Reliance on third-party services

Bitcoin and Litecoin operations rely on the Operator's own nodes, but third-party chain explorers are used when the nodes are unavailable and for cross-checking discrepancies. USDT operations on the TRON network rely on third-party HTTP providers entirely — the Operator has no node of its own on that network (see Privacy Policy, section 3). Unavailability of such a source, its error, or a deliberately distorted response may lead to incorrect payment status display, delayed crediting, and — for USDT — delayed payouts.

6No insurance

Funds are not insured by any state or third party. The Operator is not a financial institution, does not participate in deposit insurance schemes, and provides no guarantee of the safety of funds. No compensation is provided for loss due to any of the causes listed.