Privacy policy

Last updated: 2026

Template only. Replace with a policy drafted for your actual data processing, jurisdiction and legal basis before launch.

What we collect

Why we hold it

To operate your account, settle deposits and withdrawals, meet anti-money-laundering obligations, prevent fraud, and provide support.

Where it lives

Account and transaction data are stored in Supabase (PostgreSQL) with row-level security, so a signed-in session can only ever read its own rows. Passwords are hashed by Supabase Auth and are never stored or transmitted in plain text.

Sharing

We share data with infrastructure and payment providers strictly as needed to run the service, and with authorities where legally compelled. We do not sell personal data.

Your rights

Depending on where you live, you may request access, correction, export or deletion of your personal data. Records we are legally required to retain — transaction history in particular — survive account closure.