All systems operational · 99.99% uptime

Legal · Terms of Service

The deal, in plain clauses.

Effective March 30, 2026. These terms govern use of the latchpay platform. They are written to be read, not skimmed past.

1. The agreement

These Terms of Service are a contract between latchpay, Inc. ("latchpay", "we") and the organization that opens an account ("customer", "you"). By opening an account or using the API, you accept them on behalf of that organization and represent you have authority to do so.

Enterprise customers may have a signed order form or master agreement. Where an order form conflicts with these terms, the order form controls for that customer. Otherwise, this document plus the Privacy Policy is the whole agreement, and it supersedes anything said in a sales call.

2. The service

latchpay provides payout orchestration, settlement, and reconciliation infrastructure: you post payout instructions to one API, and we route, execute, retry, and reconcile them across ACH, Fedwire, SEPA, and RTP, with a line-level ledger of the result.

Three things the service is not:

  • A bank. latchpay is not a bank. Banking services — deposit accounts, funds custody, and access to payment rails — are provided by regulated banking partners, identified in your dashboard.
  • Advice. Nothing in the product, docs, or support threads is investment, legal, or tax advice. Get your own.
  • Real in sandbox. The sandbox simulates rails, returns, and delays for integration testing. Sandbox results carry no monetary value and create no obligation to move money.

3. Accounts & API keys

  • Keep account information accurate and current — we rely on it for compliance and for reaching you when it matters.
  • API keys are credentials to move money. Keep them server-side only, never in client code or public repositories, and roll them immediately on any suspicion of exposure. Key rolling is self-serve and takes effect within seconds.
  • Sandbox and live keys are separate credentials. Never point production traffic at sandbox keys or vice versa; the API will reject the mismatch, but do not rely on that as your only control.
  • Seats are per-person. Shared logins defeat the audit trail, and the audit trail is the point.
  • Whatever happens under your keys and seats is attributed to your organization until the moment you alert us at support@latchpay.xyz that they are compromised.

4. Instructions & execution

An API instruction that is properly authenticated and passes your configured policy controls (approval rules, velocity limits, allowlists) is a binding instruction from you. We execute what your systems tell us to execute; the controls exist so your systems say only what you mean.

Payments are not email. Once a payout has been submitted to a rail, it cannot be recalled except to the extent that rail's own rules allow (for example, ACH reversal rules for limited error cases; Fedwire is effectively final on send). Cancel or amend a payout before it reaches payout.sent, and it costs nothing. After that, the rail's rules — not ours, not yours — decide what is possible.

We may delay or decline execution only for three reasons: a sanctions or screening hit that we are legally required to resolve first, binding legal compulsion, or a published platform incident on our status page. We will not sit on your instructions for commercial reasons.

5. Customer obligations

You agree to:

  • Use the service only for lawful business purposes and payouts you are legally entitled to make.
  • Perform KYC on your own users and recipients as your business and regulators require — we screen against sanctions lists, but knowing your customer is your job.
  • Submit accurate recipient data. Misdirected funds caused by wrong account details you supplied are recoverable only to the extent the rail allows.
  • Not use the service for personal, family, or household purposes. This is business infrastructure, and consumer protection regimes are not designed for it.
  • Comply with sanctions and export control laws, and not submit payouts to sanctioned parties or embargoed jurisdictions.
  • Not use the service for the short list of prohibited verticals: unlicensed money services, unlicensed gambling, sale of controlled substances unlawful at the point of sale, CSAM or human trafficking in any form, and Ponzi or pyramid schemes. If your business is lawful and licensed, you are almost certainly fine; if you are unsure, ask compliance@latchpay.xyz before integrating.

6. Funds & custody

Customer funds are held 1:1 in segregated, bankruptcy-remote accounts at regulated banking partners. They are never commingled with latchpay's operating funds, never lent, and never used as our working capital. Title to your funds stays with you at all times; our ledger records exactly where every cent sits, and you can export it whenever you like. The float is not a business model.

Details of the custody structure and our banking partners are on the Compliance page.

7. Fees

  • Self-serve customers pay per executed payout at the rates on the pricing page; enterprise customers pay per their order form.
  • Returned payouts are not billed. You should not pay us for money that did not move.
  • Network and rail fees (for example, Fedwire charges) are passed through at cost, itemized on your invoice, never marked up.
  • Self-serve pricing changes take effect no sooner than 30 days after notice, and never mid-billing-cycle.
  • Enterprise invoices are net-30. Undisputed amounts more than 15 days overdue can lead to suspension under Section 14.

8. Data protection

Our handling of personal data — including our controller and processor roles, recipient data, and AML retention — is described in the Privacy Policy. Our regulatory posture, audits, and certifications are described on the Compliance page. Both are incorporated into this agreement. Where you require a data processing agreement, our standard DPA (with SCCs) is available from privacy@latchpay.xyz.

9. Intellectual property

We own the service — the platform, APIs, documentation, and everything we built to run them. You get a non-exclusive, non-transferable license to use them for the term of this agreement, and no other rights.

You own your data: your payout instructions, recipient records, and ledger entries. You can export it at any time, in standard formats, including after termination during the export window in Section 14. We use your data to run the service for you and for the aggregate, de-identified analytics described in the Privacy Policy, and for nothing else.

Feedback and publicity

If you send us feedback or suggestions, we may use them without restriction or obligation — that is the only license you grant us in your direction. We will not use your name or logo in marketing materials without your written consent; there is no logo wall on this site for a reason.

10. Confidentiality

Confidential information travels one way: into performance of this agreement, nowhere else. Each side must guard the other's secrets at least as vigilantly as it guards its own. The duty lasts five years from disclosure; for trade secrets it lasts as long as the secret does. If a court or regulator compels disclosure, the compelled party gives the other a heads-up first wherever the law permits.

11. Warranties & disclaimers

Two commitments, in writing: the platform gets competent, careful operation, and it behaves in material accordance with its documentation. Everything else comes as-is — we disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement to the extent the law allows. Specifically:

  • Payment rails and banking partners are third-party systems. We route intelligently and retry aggressively, but we do not control the Federal Reserve's operating hours or a receiving bank's processing queue.
  • ACH returns exist. A payout that settles can still come back days later under NACHA rules; our reconciliation surfaces this, but no one can warrant it away.
  • We do not warrant uninterrupted service beyond the SLA in your order form, if you have one. Our actual track record is published on our status page.

Performance failures traceable to genuine externalities — disaster, war, state action, or an outage of the rails or banking system itself — are excused for the party they hit (invoices excepted), so long as that party works diligently to get back online.

12. Liability

Indirect, incidental, consequential, and punitive damages are off the table for both sides, as are lost profits and lost revenue. What remains — direct damages — is capped for each party at the amount latchpay billed you across the twelve months preceding the event in question.

Four carve-outs pierce both the cap and the exclusions: fees you owe, a breach of Section 10 (Confidentiality), the defense obligations under Section 13, or fraud or willful misconduct.

One clarification we consider fair: where we executed a payout per your instruction and routed it correctly, we are not liable for delay or loss caused by the rail or receiving institution itself. We answer for our platform; the Federal Reserve answers for Fedwire.

13. Indemnification

Claims rooted in your side of the ledger — your data, your payout instructions, a violation of Section 5 — are yours to defend and make us whole against. We will defend and indemnify you against third-party claims that the service, as provided by us and used as documented, infringes their intellectual property rights. Whichever side is defending hears about the claim promptly, steers the defense, and can count on the other side's reasonable help.

14. Suspension & termination

  • You can leave anytime. Self-serve customers may cancel from the dashboard, effective at the end of the current billing cycle. Enterprise terms are in your order form.
  • Suspension. We may suspend access for a genuine security risk, material legal or regulatory exposure, or fees unpaid 15 days after written notice. We suspend narrowly, restore promptly once resolved, and suspension never touches funds custody.
  • Wind-down. On termination: in-flight payout runs are completed or safely cancelled — never abandoned mid-run; remaining balances are returned to your funding account within 10 business days; your ledger remains exportable for 30 days; and we retain payment records for the AML minimums described in the Privacy Policy, because the law requires it of us regardless of who terminated or why.
  • Sections 9 through 13, 15, and any accrued payment obligations survive termination.

15. Governing law

California law applies to this agreement (its conflict-of-laws rules do not), and the CISG is excluded outright. Disputes go exclusively to the state and federal courts of Santa Clara County, California, whose personal jurisdiction both parties accept.

Housekeeping: if a clause is held unenforceable, the rest stands. A right not exercised is not waived. Handing this agreement to someone else requires consent from the other side — unless the someone else is a successor via merger or a sale of essentially the whole company. The parties are independent contractors — nothing here creates a partnership, agency, or joint venture.

16. Changes to these terms

The terms will evolve with the service. Material revisions come with 30 days' advance email to account owners, and the effective date at the top moves with them. Changes are never retroactive: payouts already executed are governed by the terms in force when you instructed them. If you do not accept a change, you may terminate before it takes effect.

17. Contact

Legal notices to latchpay: legal@latchpay.xyz, or by mail to latchpay, Inc., 2445 Augustine Drive, Suite 150, Santa Clara, CA 95054, USA. Notices to you go to the account owner's email on file, which is one reason Section 3 asks you to keep it current.

Privacy questions belong at privacy@latchpay.xyz; see the Privacy Policy.