The bright-line rule: AI Gift Pay never needs an account password, email password, wallet seed phrase, private key, wallet connection, remote-access session, browser extension, or unofficial software download. Anyone asking for one while using our name is outside our process.

Where does payment happen?

The storefront and private payment page stay on aigiftpay.com. Before any wallet address appears, the server records the product, USD total, asset, network, destination, crypto amount, token contract where applicable, rate source, and quote expiry.

The QR code is created by the application from that order snapshot. For token payments it may contain only the recipient address, so copy the exact amount separately. Always compare the full address, asset, network, amount, countdown, and token contract shown on the private page before sending.

How is a payment verified?

A transaction ID entered by a customer is a review request—not proof that an order is paid. It cannot automatically trigger fulfillment.

  • The private access token, order reference, product, quote, and protected customer context must match.
  • Transaction identifiers are normalized for the selected chain and blocked from reuse across orders.
  • An authenticated operator checks the authoritative blockchain record for the correct chain, finality, destination, amount, and token contract where applicable.
  • Only the protected order desk can change a matched order to payment verified.
  • A QR scan, browser status, screenshot, wallet notification, or submitted transaction ID never proves payment by itself.

How are codes, keys, and links handled?

Every product page names the deliverable before payment: for example, a gift-card code, retail product key, subscription code, or approved claim link. Orders are fulfilled manually to the order email. We do not deliver shared logins or pre-made accounts and do not ask to sign in as the customer.

Codes and keys are digital bearer items. Keep the delivery email private, redeem through the provider's official website or documented activation screen, and never forward a code to someone claiming they need to “verify” it.

What protects order email and records?

Transactional email is sent through a domain-verified provider. Recipients and message templates are selected by server code, not arbitrary browser input. Order references do not contain a plaintext email address, and the private payment page uses a high-entropy access token whose hash is retained in the order ledger.

Operational records are stored in a server-side order ledger rather than in browser storage. Abuse limits protect order, request, and administrative endpoints.

How do I recognize impersonation?

Use one domain

The intended storefront is aigiftpay.com. Treat lookalike spelling, extra words or hyphens, different top-level domains, and shortened links as suspicious.

  • Type the domain directly or use a saved bookmark.
  • Take a wallet address only from the private aigiftpay.com payment page for that order.
  • Never trust a payment address sent by email, support chat, Telegram, Discord, or social media.
  • Redeem or activate only on the named provider's official domain or official operating-system screen.
  • Stop if the product, edition, region, term, device count, network, or price differs from the order.

Report a security problem

Email the page URL, order reference, transaction ID, and a description to support@aigiftpay.com. Never email passwords, private keys, seed phrases, remote-access codes, or identity documents unless a specific legal requirement has first been explained.

Read the network checklist first

The crypto guides cover address checks, gas, withdrawal fees, quote timing, and the most common wrong-network mistakes.

Open crypto guides