Privacy notice
Legal counsel and the card provider must replace and approve this document before production launch.
Account and payment information
The service stores email or wallet sign-in identities, salted password hashes, account status, encrypted deposit wallet keys, sessions, payment ledger entries, card metadata, encrypted card details supplied by administrators, support requests, and administrative audit records. Theme preferences may be stored on your device. No analytics vendor is enabled.
Card details and wallet secrets
Administrator-supplied card numbers, expiry dates and security codes are encrypted in the service database and can only be revealed to the cardholder after a recent sign-in. Revealed details exist temporarily in component memory and are cleared after 20 seconds, tab visibility loss, or page exit. Card numbers and security codes are never persisted to browser storage or query persistence. The app never requests the private key or seed phrase of your external wallet. Generated custodial deposit keys and issuer reveal links are also encrypted. Email sign-in uses a password stored as a salted hash. Email addresses are login identifiers; email verification and email password reset are disabled. Wallet sign-in uses signed challenges and secure session cookies.
Service providers
Wallet connectivity can contact the configured RPC and wallet connection service. The deposit processor uses verified Arc Mainnet RPC providers. No SMTP email service is enabled. Card issuance uses the configured issuer gateway or administrator-supplied cards. Card details are delivered through authenticated access or an allowlisted issuer page.
Before launch
Legal counsel must finalize the data controller, processing purposes and lawful bases, recipients, international transfers, retention periods, privacy rights, consent flows, incident response, contact details, and jurisdiction-specific obligations.