This policy explains how Woldy ("we") handles personal data when you visit woldy.xyz, contact us, or use the Woldy merchant dashboard and API (together, the "Services").

1. Who we are

Woldy builds non-custodial stablecoin payment infrastructure. We are the controller of the personal data described in this policy, and we decide why and how it is processed.

Questions, requests, or complaints: legal@woldy.xyz. We read everything sent there.

2. What this policy does not cover

Woldy is non-custodial payment infrastructure. Some of the most sensitive things in a payment flow never reach us at all, and this is a property of the architecture rather than a policy choice:

  • We never hold your private keys. Keys stay in your own wallet. We cannot access them, recover them, or reconstruct them.
  • We never take custody of your funds. Payments settle into a smart-contract vault controlled by you. We cannot move, freeze, or seize the balance in it.
  • We do not see your customers' card or bank details. There aren't any — payments are made from a wallet, on-chain.

3. What we collect

Account and business data. When you create a merchant account: name, work email, company name, and the details you give us during onboarding checks. Where onboarding requires identity or business verification, we collect what is necessary for that check and no more.

Wallet and vault addresses. Public blockchain addresses you connect or that we generate for your account. These are pseudonymous identifiers, not secrets.

Usage and technical data. IP address, browser and device type, pages viewed, and error diagnostics, collected when you use the dashboard or API. We use this to keep the Services running and secure.

Communications. Anything you send us: support messages, the form you submit to book a call, email threads. If you book a call, we keep what you tell us about your business so the conversation is useful.

Marketing site. The public site at woldy.xyz sets no cookies and stores nothing in your browser. See the Cookie Policy.

4. On-chain data is public and permanent

Transactions processed through Woldy are recorded on public blockchains. Anyone can read them, and no one — including us — can edit or delete them.

That has a consequence worth stating plainly: a request to erase your personal data cannot extend to on-chain records. It applies to data in our own systems. Blockchain addresses are pseudonymous, but they can sometimes be linked to a person or business through other information, and you should treat them accordingly.

5. Why we process it, and on what basis

PurposeBasis
Providing the Services under our agreement with youPerformance of a contract
Onboarding, verification, and fraud preventionLegal obligation and legitimate interests
Security, monitoring, and debuggingLegitimate interests
Responding to your enquiries and support requestsPerformance of a contract and legitimate interests
Product and service updates by email to customersLegitimate interests, with an opt-out in every message
Marketing email to people who asked to hear from usConsent, withdrawable at any time

We do not sell personal data, and we do not use it to build advertising profiles.

6. Who we share it with

  • Service providers who process data on our instructions — hosting, error monitoring, email delivery, and identity-verification providers. They are bound by contract to act only on our instructions.
  • Professional advisers — auditors and lawyers, where necessary.
  • Authorities, where we are legally required to disclose. Note that this can only ever mean data we hold. It cannot mean your funds, which we do not control.
  • A successor, if the business is reorganised, merged, or acquired. You would be told before your data became subject to a different privacy policy.

7. International transfers

Our providers may process data outside the country you are in. Where that happens we rely on an appropriate legal transfer mechanism, such as standard contractual clauses, and we keep a record of which providers those are. Ask us and we will tell you.

8. How long we keep it

  • Account records: for as long as your account is open, then for the period we are required to retain business records.
  • Verification records: for the retention period applicable to those checks.
  • Support and enquiry correspondence: up to 24 months after the last message, unless it relates to an ongoing matter.
  • Technical logs: up to 12 months.

9. Your rights

Depending on where you are, you may have the right to access your data, correct it, delete it, restrict or object to how we process it, receive it in a portable format, and withdraw consent where consent is the basis.

To exercise any of these, email legal@woldy.xyz. We will respond within the period the applicable law allows, and we may need to verify your identity first. If you are unhappy with our response you can complain to your local data protection authority.

The limits in section 4 apply: we cannot delete what is written to a public blockchain, and we cannot delete records we are legally required to keep.

10. Security

We encrypt data in transit and at rest, restrict internal access to those who need it, and log administrative actions. No system is perfectly secure, but the highest-value target in a payment system — custody of funds — is not something we hold in the first place.

You are responsible for your own wallet. If you lose your keys, neither we nor anyone else can restore access to your vault.

11. Children

The Services are for businesses. They are not directed at anyone under 18, and we do not knowingly collect their data.

12. Changes

If we change this policy we will update the date at the top of the page. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.

13. Contact

Write to legal@woldy.xyz for anything in this policy, including a request to access, correct, or delete your data.