Legal

Privacy Policy

What we collect, why, how long we keep it, and what we deliberately never ask for. It is a short list, and that is the point of the product.

In effect since

Contents

1. The starting point

Most payment services begin by collecting an identity and then explain how they protect it. We begin by not collecting one. Data that is never gathered cannot leak, cannot be subpoenaed from us, and cannot be sold.

This policy describes what remains, which is the minimum needed to run a card.

2. What we collect

You give us:

  • an email address — the account identifier and the only channel we have for you;
  • a password, stored only as a bcrypt hash, never in readable form;
  • optionally, a two-factor secret, encrypted at rest, and the hashes of your recovery codes;
  • optionally, a shipping address, only if you order a physical card — see section 5;
  • the labels and limits you choose for your cards.

The Service generates:

  • your balance and the ledger behind it — deposits, payments, refunds and fees;
  • your cards: number, expiry, status, spend. The CVV is derived on demand and stored nowhere;
  • deposit records: amount, coin, network, deposit address, transaction hash;
  • 3-D Secure challenges: merchant, amount, code, outcome;
  • security logs: failed sign-in attempts with the IP address they came from, and the last 40 API calls on your account (method, path, status — never bodies).

We never ask for your legal name, date of birth, nationality, identity document, photograph, phone number, tax identifier, employer, source-of-wealth statement, or social media account.

3. Why we hold it, and on what basis

DataPurposeBasis
Email, password hashOperate the account, authenticate you, reset accessPerformance of the contract
Balance and ledgerFund cards, show history, meet accounting dutiesContract; legal obligation
Card dataIssue and authorise paymentsContract
Deposit recordsCredit deposits, reconcile lost notices, sanctions screeningContract; legal obligation
3-D Secure challengesAuthorise online payments, resolve disputesContract
Security and API logsBlock credential-stuffing, investigate abuseLegitimate interest in a secure service
Shipping addressDeliver a physical cardContract

4. How long we keep it

  • Account data — while the account is open. On closure it is deleted.
  • Ledger and deposit records — retained after closure only where financial-record law requires it, and then only in the minimum form required.
  • Shipping address — erased at dispatch. See section 5.
  • Failed sign-in attempts — purged after 1 hour.
  • API call log — capped at the last 40 calls per account; older entries are deleted as new ones arrive.
  • 3-D Secure codes — a code stops being readable once the challenge is resolved or expires.

5. Shipping addresses

A physical card needs somewhere to go. We ask for it, we use it, and then we delete it.

When an order is marked dispatched, the recipient name, street, city, region, postal code, phone number and any delivery note are erased from the order record. What remains is that an order existed and was shipped.

Our carrier holds the address for as long as its own retention rules require. We have no control over that and it is why the address leaves our systems as soon as it has served its purpose.

6. Who else sees it

We share the minimum necessary with:

  • the card issuer and card network that process your payments;
  • our payment provider, which opens deposit addresses and confirms incoming payments;
  • the card producer and carrier, for a physical card only;
  • our email provider, to deliver 3-D Secure codes and account notices;
  • our infrastructure providers, who host the Service.

Each is bound by contract to use the data only to provide its service to us.

We disclose data to a public authority only where legally compelled. Where we are permitted to tell you, we will. We do not sell personal data, we do not share it for advertising, and we run no third-party analytics or advertising trackers on this site.

7. Cookies

We set one cookie, ccsid, which holds your session. It is HttpOnly, Secure and SameSite=Lax, and it exists only so that you stay signed in.

There is no advertising cookie, no analytics cookie, and no cross-site tracker — which is why this site does not greet you with a consent banner.

Your browser also stores a small flag locally so the header can show the right button before the page finishes loading. It never leaves your device.

8. How it is protected

  • Passwords are hashed with bcrypt; they are never stored or logged in readable form.
  • Two-factor secrets are encrypted at rest with AES-256-GCM.
  • Recovery codes are stored as SHA-256 hashes and each works once.
  • Card CVVs are derived on demand and never written to storage — a copy of our database does not contain them.
  • Sign-in attempts are throttled per email address and per IP address.
  • All traffic is served over TLS with a strict content security policy.

No system is perfect. If we become aware of a breach affecting your data we will notify you by email and, where required, the competent supervisory authority, without undue delay.

9. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing, and to receive your data in a portable form.

Most of these you can exercise yourself, immediately: your history is in the dashboard and over the API, your email address is editable in Settings, and closing your account deletes it.

For anything else, raise the request from the account it concerns. We answer within 30 days.

One honest limitation: because we hold no identity information, we authenticate a request only through control of the account. We cannot act on a request from someone who cannot sign in — verifying them would require exactly the identity data this product exists to avoid collecting.

10. Children

The Service is not for anyone under 18. We do not knowingly hold data about a child.

Where the account can be signed in to, closing it from Settings deletes the data immediately and needs nobody's permission. A parent or guardian who cannot sign in cannot be authenticated by us — we hold no identity information to check anyone against. We act on a report that carries enough detail to identify the account, and we close it.

11. Changes

We will post any change on this page and update the date at the top. Where a change materially affects how we use data you have already given us, we will email you at least 30 days before it takes effect.

The other documents