I'm curious if you have analytics collection on the first use case since it seems like a pretty risky privacy violation in terms of user tracking but honestly not far beyond shenanigans that bigger players pull (Facebook/Amazon).
But I'm really curious about the second use case - the no code approach is really nice and flexible for sending payment requests over alternative media (i.e. discord) but it feels like this might open the door a bit more to phishing users via redirection - do you happen to have any security ruminations on that topic that you've made public or be willing to share?