Privacy Policy
Last updated: 2026-06-27 Version: 2.2 Effective: Upon publication on www.swaps.app.
This Privacy Policy describes how Supa Labs OÜ ("Swaps", "we", "us") processes personal data of users of the Swaps service across all surfaces (www.swaps.app, iOS app, Telegram mini app, ChatGPT mini app, agent.swaps.app, @agent.swaps/mcp-server, and email communications).
1. Data controller
The controller of your personal data is:
- Supa Labs OÜ, registry code 17399414, Oru tn 2, Tallinn 10127, Estonia.
- Contact (privacy, data-subject requests, complaints): legal@swaps.app
- DPO / Grievance Officer (LGPD Brazil, DPDP India): legal@swaps.app
We are the controller for the personal data described below. Where we use external service providers (Section 6), those providers act as our processors and process data only on our documented instructions.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account data | email address, display name, language preference | You, at signup |
| Authentication data | auth tokens, OAuth identifier, password hash, and, if you add an account passkey, passkey credential identifier/public-key metadata used by Supabase Auth for passkey sign-in | You + Supabase Auth + your device WebAuthn ceremony where enabled |
| Wallet & transaction context | wallet address you enter, pair selected, amount, chosen provider, timestamp | You, at quote/redirect |
| Usage data | pages viewed, clicks, search queries, session duration, country (from IP geolocation) | Service, automatically |
| Technical data | IP address, browser type, device type, operating system, language, browser fingerprint (used for abuse detection — see probe_fingerprints) | Service, automatically |
| Communication data | support messages, email correspondence, in-app feedback | You |
| Payment data | last 4 of card, billing country, payment processor token (we do not store full card numbers — Stripe does) | Stripe (when you buy Credit packs) |
| Email engagement | delivery status, opens, clicks, bounces, complaints, unsubscribe events | Resend (email processor) |
| Address-report data | blockchain addresses you scan, report results, timestamps | You + on-chain data sources |
| Referral data | referral code used, referred friend's first transaction signal, Credit awards | You + Service |
| Sanctions screening data | country-of-access derived from IP geolocation; provider-side KYC sanctions results are held by the Provider and not transmitted to us by default | Service (country-level) + Provider (person-level, not shared back) |
| Wallet credential metadata (Wallet Service and historical Tempo Passkey Wallet Lab) | credential identifier, credential public key, AAGUID, transports, relying-party identifier (swaps.app), wallet address, wallet row, status, audit-log entries — never seed phrase, private key, passkey secret, session signing key, or any signing material | You + your device WebAuthn ceremony; signing material remains on your device, browser, or password manager |
| Payment Links data (Merchant) | the Merchant's account and business data shared with the Provider to activate a link; the client and line-item details on a payment request; the settlement destination (bank account or crypto wallet address); request reference codes, amounts, status, and timestamps | The Merchant, at link creation/activation |
| Payment Links data (Payer) | limited data the Payer provides on the public /pay page to complete a push payment — self-declared business/individual type and the payment details needed for the chosen rail; the Payer is not KYC'd by Swaps | The Payer, on the public payment page |
| Payroll data (Recipient) | Recipient names, payout destinations (bank account or crypto wallet address), and amounts the Employer enters or approves, processed to route payout instructions to the Provider | The Employer, at payroll-run creation/approval |
We do not knowingly process special categories of personal data (Article 9 GDPR — health, biometric, racial, political, etc.). KYC documents (government ID, selfies, proof of address) are collected by Providers, not by us; we never see or store those documents. Account passkeys for Swaps login are separate from Tempo Passkey Wallet Lab and Wallet Service passkeys. Swaps and Supabase do not receive your biometric data or private passkey material; your device, browser, or password manager controls the local authenticator. For the Tempo Passkey Wallet Lab specifically, see the Terms of Service §24 for the binding limits on what Swaps stores and does not store; for the live (Beta) public Wallet Service, the same non-custodial limits apply — Swaps stores only the public credential metadata and wallet address listed above and never any private key, seed phrase, passkey secret, or session signing key. See the Wallet Service Terms. For Payment Links and Payroll, the Provider (Bridge) processes the Payer's and Recipient's data when it creates, verifies, and settles a transfer under the Provider's own privacy notice; see the Payment Link Terms and the Payroll Terms.
3. Lawful bases for processing (GDPR Article 6)
| Purpose | Lawful basis | Notes |
|---|---|---|
| Provide the Service (show quotes, redirect to Provider, run Search reports) | Performance of a contract — Art. 6(1)(b) | Without this, the Service cannot work |
| Maintain Account and authentication | Performance of a contract — Art. 6(1)(b) | Includes optional account passkeys where you choose to add one |
| Detect and prevent fraud, abuse, sanctions evasion | Legitimate interest — Art. 6(1)(f) and legal obligation — Art. 6(1)(c) | Balancing test recorded internally |
| Communicate with you (transactional emails) | Performance of a contract — Art. 6(1)(b) | Account-related, paid product receipts, security alerts |
| Send marketing / broadcast emails | Consent — Art. 6(1)(a) | You opt in. Unsubscribe link in every marketing email |
| Analytics and product improvement | Legitimate interest — Art. 6(1)(f) | Aggregate / pseudonymised where possible |
| Comply with legal obligations | Legal obligation — Art. 6(1)(c) | Including AML/CTF screening at our perimeter |
| Defend legal claims | Legitimate interest — Art. 6(1)(f) | |
| Operate the Tempo Passkey Wallet Lab (Lab access, sync, audit) | Consent — Art. 6(1)(a) (lab opt-in) + Legitimate interest — Art. 6(1)(f) for audit logging | Lab is allowlisted, hidden, opt-in; consent withdrawable by leaving the Lab |
| Operate the Wallet Service and store public credential metadata | Performance of a contract — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f) for audit logging | Non-custodial; only public metadata + wallet address stored. See the Wallet Service Terms |
| Operate Payment Links — present the request, collect the Payer's chosen rail, and instruct the Provider | Performance of a contract — Art. 6(1)(b) | Merchant and Payer data; the Provider settles under its own notice |
| Operate Payroll — route the Employer's payout instructions to the Provider | Performance of a contract — Art. 6(1)(b) | Employer bears the lawful-basis duty toward Recipients (see Section 5) |
You have the right to object to processing based on legitimate interest at any time (see Section 8).
4. How long we keep data (retention)
| Category | Retention | Trigger to delete |
|---|---|---|
| Account data | While Account is active + 30 days after deletion | You request deletion, or 24 months of inactivity |
| Authentication tokens | Session lifetime (typically 7-30 days) | Logout, expiry, or rotation |
| Account passkey credential metadata, if you add a passkey | While the passkey remains attached to the Account + 30 days after Account deletion | You remove the passkey in Settings, or delete the Account |
| Wallet Service credential metadata + wallet address | While the wallet remains attached to the Account + 30 days after "Remove from Swaps" or Account deletion | You "Remove from Swaps", or delete the Account |
| Payment Links data (request, client/line items, reference, settlement destination, status) | 7 years | Estonian/EU accounting law minimum |
| Payroll Recipient data (names, payout destinations, amounts) and run metadata | 7 years | Estonian/EU accounting law minimum |
| Transaction metadata (which Provider you chose, when, for which pair — no funds, no amounts of yours) | 7 years | Estonian/EU accounting law minimum |
| Usage data | 14 months (aggregated/pseudonymised after 30 days) | Automatic |
| Technical data (IP, fingerprint) | 90 days for abuse-detection, shorter where not justified | Automatic |
| Communication data | 3 years after last interaction | Automatic |
| Payment data | 7 years | Tax law (Estonian Income Tax Act) |
| Search reports | While Account exists + 30 days | Account deletion |
| Sanctions screening logs | 5 years from screening event | EU AML regs (where applicable to Providers' processes we observe) |
| Marketing engagement | Until you withdraw consent | Unsubscribe |
If you delete your Account, we delete or anonymise data within 30 days, except data we are required by law to retain (e.g., tax records) or data needed to defend legal claims, which we retain in restricted-access form until the retention period ends.
5. How we use your data — purposes
- Show you quotes and route you to your chosen Provider. Your wallet address, pair, and amount are encrypted and handed to the Provider via
redirect_init(AES-GCM). The Provider then operates under its own terms. - Maintain your Account and give you a history of your activity.
- Process Search Address Reports and Credit pack purchases.
- Award referral Credits when your friend transacts.
- Operate Payment Links — present a Merchant's request, collect the Payer's chosen rail and the limited payment details needed to complete the push payment, and instruct the Provider to create and settle the transfer. The Provider processes the Payer's data under its own notice. See the Payment Link Terms.
- Operate Payroll — process the Recipient data the Employer provides (names, payout destinations, amounts) to route payout instructions to the Provider. The Employer is responsible for its lawful basis toward Recipients. See the Payroll Terms.
- Operate the Wallet Service — store and display the public credential metadata and wallet address for a non-custodial passkey wallet you control; display balances; prepare transaction data; submit user-authorized signed transactions; and show status. Swaps never stores private keys, seed phrases, passkey secrets, session keys, or any signing material. See the Wallet Service Terms.
- Detect and prevent fraud, multi-account abuse, paid-traffic referral farming, and bot traffic — including by storing browser fingerprints in
probe_fingerprintsand matching against known abuse patterns. - Screen against sanctions lists — see the Sanctions policy.
- Communicate with you — transactional emails (signup, receipts, password reset, security alerts) and, if you opt in, marketing emails (product news, broadcasts).
- Analyse and improve the Service — aggregate analytics through Google Analytics 4, Vercel Analytics, and Sentry for error tracking.
- Comply with law and respond to lawful requests from authorities.
- Defend legal claims if any arise.
We do not sell your personal data. We do not "share" your personal data in the CCPA cross-context-behavioural-advertising sense.
6. Who we share data with (processors and recipients)
Personal data is shared only with the following categories of recipients, each bound by a Data Processing Agreement (DPA) and (for transfers outside the EEA) by Standard Contractual Clauses (SCCs) issued by the European Commission under Decision 2021/914.
| Recipient | Role | Data shared | Location | Transfer basis |
|---|---|---|---|---|
| Supabase (Supabase Inc.) | Database, auth, edge functions, storage | Account data, transaction metadata, search reports, fingerprints | Frankfurt, Germany (EU) | Intra-EEA |
| Vercel Inc. | Web hosting, edge runtime | Page requests, IP for routing | US (with EU edge cache) | SCCs |
| Cloudflare Inc. | CDN, WAF, DDoS protection, geo-block | IP, request headers | Global anycast | SCCs |
| Stripe, Inc. | Payment processing (Credit packs) | Payment-method data, billing country | US | SCCs |
| Resend, Inc. | Transactional + broadcast email delivery | Email, name, engagement | US | SCCs |
| Sentry (Functional Software Inc.) | Error tracking | Stack traces, user agent, sometimes IP | US | SCCs |
| Google LLC (GA4) | Analytics | Pseudonymised page-view events | EU + US backend | SCCs + IP anonymisation |
| OpenSanctions | Sanctions list data (used by Providers in their KYC programmes; we may query for country-level cross-checks) | Country-level signals; Swaps does not transmit your personal data for per-address screening at this time (see the Sanctions policy) | EU | Intra-EEA |
| Persona Identities Inc. | (Provider-side) identity verification | We do not transmit. Providers do, on their own. | US | Provider-controlled |
| Bridge (the "Provider") | Payment/payout infrastructure for Payment Links and Payroll: creates, verifies, and settles transfers. Independent controller of the data it processes for KYC/KYB, screening, and execution under its own privacy notice. | For Payment Links: Merchant account/business data, the request and reference, and the Payer's payment details for the chosen rail. For Payroll: Recipient names, payout destinations, and amounts. Lawful basis: performance of a contract (Art. 6(1)(b)); the Provider's own KYC/KYB/screening is its legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)). | US | SCCs |
| Tempo Moderato testnet RPC node (Lab only) | Read/broadcast Tempo Moderato transactions you initiate from the Lab | Public-blockchain RPC calls (no personal data beyond your public wallet address) | Operated by the Tempo Moderato testnet operator | Public-blockchain RPC (no DPA applicable) |
| Current active Providers listed in the generated taxonomy, with Onmeta treated as sandbox/pending until runtime proof is complete | Execute your chosen transaction when you choose an available route; DEX protocols may receive only quote/swap context rather than fiat handoff data | Encrypted handoff where applicable: wallet address, pair, amount, optional email reference. Historical/removed providers such as MoonPay, Onramp.money, and Onramper are not active recipients unless reintroduced in taxonomy and runtime. | Each provider's jurisdiction | Each Provider's own DPA + their consent flow |
| Law-enforcement, regulators | When legally compelled | Only what is lawfully required | As required | Legal obligation |
We do not transfer personal data to third parties for their own marketing purposes. We do not engage in profiling that produces legal effects on you.
7. International transfers
Where we transfer personal data outside the European Economic Area (EEA), we rely on one of the following lawful transfer mechanisms:
- EU Standard Contractual Clauses (2021/914) for transfers to US processors (Stripe, Resend, Sentry, Google) and any other non-adequacy country.
- EU-US Data Privacy Framework where the processor is self-certified (we verify on each processor's status page).
- Adequacy decision where the destination country is on the Commission's adequacy list.
We have performed a transfer impact assessment for each US processor and applied supplementary measures (encryption in transit and at rest, contractual rights of audit, no governmental access without notice obligations on the processor).
8. Your rights (EU GDPR, UK GDPR, where applicable)
Subject to limitations under applicable law, you have the right to:
- Access the personal data we hold about you (Article 15).
- Rectify inaccurate or incomplete data (Article 16).
- Erase ("right to be forgotten") data we hold, subject to legal-retention obligations (Article 17).
- Restrict processing while a dispute is resolved (Article 18).
- Data portability — receive your data in a structured, commonly-used, machine-readable format (Article 20).
- Object to processing based on legitimate interest, including profiling (Article 21).
- Withdraw consent at any time without affecting the lawfulness of processing before withdrawal (Article 7(3)).
- Not be subject to automated decision-making producing legal effects on you (Article 22). We do not engage in such automated decision-making.
- Lodge a complaint with a supervisory authority (Section 12).
To exercise any of these rights, email legal@swaps.app. We will respond within 30 calendar days. We may extend by 60 days for complex requests and will tell you in writing if we do. There is no fee unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse.
9. Cookies and similar technologies
The Service uses cookies and similar technologies to operate, secure, analyse, and (with your consent) personalise the experience. Detailed information — categories, purposes, lifetimes, third parties, and how to manage consent — is in the Cookie Policy. On first visit, the cookie consent banner asks you to accept, reject, or customise. You can change your choice at any time from the footer "Cookie settings" link.
10. Security
We implement technical and organisational measures appropriate to the risk, including:
- TLS 1.3 in transit; AES-256 at rest in Supabase (Frankfurt).
- AES-GCM encryption of PII in redirect tokens (
redirect_init); PII never appears in URLs in plaintext. - Row-level security (RLS) on all user-data tables in Supabase.
- Sanctioned-jurisdiction geo-block at Cloudflare WAF.
- Probe fingerprinting and rate-limits to detect automated abuse.
- No silent fallbacks — errors surface; no fake data substitution.
- Account passkeys use WebAuthn through Supabase Auth. Only public credential metadata is used server-side; biometric and private passkey material remains on your device, browser, or password manager.
- Wallet seed phrases or private keys are NEVER requested, transmitted, or stored. Anyone claiming to be Swaps and asking for these is impersonating us.
In the event of a personal-data breach likely to result in risk to your rights and freedoms, we notify the Estonian Data Protection Inspectorate within 72 hours and notify you without undue delay where required by Article 34 GDPR.
11. Children
The Service is not directed to persons under 18. We do not knowingly collect personal data from anyone under 18. If you become aware that a person under 18 has provided personal data to us, please email legal@swaps.app and we will delete it promptly.
12. Supervisory authorities
You have the right to lodge a complaint with the data protection supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement. Our lead authority is:
- Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — https://www.aki.ee/ — Tatari 39, 10134 Tallinn, Estonia.
For non-EU jurisdictions:
- UK — Information Commissioner's Office (ICO), https://ico.org.uk/
- California — California Privacy Protection Agency (CPPA), https://cppa.ca.gov/
- Brazil — Autoridade Nacional de Proteção de Dados (ANPD), https://www.gov.br/anpd/
- India — Data Protection Board of India (post-DPDP Act operationalisation), https://www.meity.gov.in/
We encourage you to contact us first at legal@swaps.app so we can attempt to resolve any concern directly.
13. Jurisdiction-specific notices
13.1 California (CCPA / CPRA)
California residents have, in addition to the rights in Section 8:
- Right to know what categories of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share.
- Right to delete personal information (subject to exceptions).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell personal information. We do not "share" personal information for cross-context behavioural advertising. Therefore, a "Do Not Sell or Share My Personal Information" link is not strictly required, but we provide one in the footer (
/legal/do-not-sell) for transparency. Selecting it will result in our marketing cookie category being disabled for your session and going forward. - Right against discrimination for exercising these rights. We do not offer different prices or service levels based on whether you exercise CCPA rights.
- Right to limit use of sensitive personal information. We do not collect categories of sensitive personal information triggering this right.
To exercise these rights, email legal@swaps.app. We verify identity by reasonable means before processing. Authorised agents must provide written authorisation.
13.2 United Kingdom (UK GDPR)
UK residents have the same data-subject rights as EU residents, governed by the UK GDPR and the Data Protection Act 2018. The lead supervisory authority is the Information Commissioner's Office (ICO). We have not appointed a UK Representative on the basis that our UK processing is below the threshold; we will reassess if our UK traffic grows materially and appoint a representative if required.
13.3 Brazil (LGPD)
Brazilian users have the rights granted by Lei nº 13.709/2018 (LGPD). Our DPO (Encarregado) is reachable at legal@swaps.app. Lawful bases under LGPD parallel those of GDPR (contract execution, consent, legitimate interest, legal obligation). Supervisory authority is ANPD.
13.4 India (DPDP Act 2023)
Indian users have the rights granted by the Digital Personal Data Protection Act, 2023, including access, correction, erasure, grievance redressal, and nomination. Our Grievance Officer for DPDP purposes is reachable at legal@swaps.app and aims to respond to grievances within 30 calendar days. Categories of personal data we process for Indian users are the same as Section 2; lawful purposes are described in Section 5 and Section 3.
13.5 Switzerland (FADP)
Swiss residents are governed by the revised Federal Act on Data Protection (FADP, 2023). Our processing of Swiss personal data follows the same standards as for EU/EEA personal data. The Swiss FDPIC is the supervisory authority.
14. Automated decision-making
We do not engage in automated decision-making producing legal effects on you or similarly significantly affecting you (Article 22 GDPR). Fraud and abuse detection is automated but always combined with human review before any Account-level action (suspension, ban).
15. Changes to this policy
We may update this Privacy Policy. When we do, we change the "Last updated" date and, for material changes, notify you by email (where you have an Account) and via an in-product banner. Continued use of the Service after a material change constitutes acceptance.
Contact for all privacy matters: legal@swaps.app Controller: Supa Labs OÜ · Registry 17399414 · Oru tn 2, Tallinn 10127, Estonia