Privacy Policy

Last updated: 2026-06-27 Version: 2.2 Effective: Upon publication on www.swaps.app.

This Privacy Policy describes how Supa Labs OÜ ("Swaps", "we", "us") processes personal data of users of the Swaps service across all surfaces (www.swaps.app, iOS app, Telegram mini app, ChatGPT mini app, agent.swaps.app, @agent.swaps/mcp-server, and email communications).


1. Data controller

The controller of your personal data is:

  • Supa Labs OÜ, registry code 17399414, Oru tn 2, Tallinn 10127, Estonia.
  • Contact (privacy, data-subject requests, complaints): legal@swaps.app
  • DPO / Grievance Officer (LGPD Brazil, DPDP India): legal@swaps.app

We are the controller for the personal data described below. Where we use external service providers (Section 6), those providers act as our processors and process data only on our documented instructions.

2. Data we process

CategoryExamplesSource
Account dataemail address, display name, language preferenceYou, at signup
Authentication dataauth tokens, OAuth identifier, password hash, and, if you add an account passkey, passkey credential identifier/public-key metadata used by Supabase Auth for passkey sign-inYou + Supabase Auth + your device WebAuthn ceremony where enabled
Wallet & transaction contextwallet address you enter, pair selected, amount, chosen provider, timestampYou, at quote/redirect
Usage datapages viewed, clicks, search queries, session duration, country (from IP geolocation)Service, automatically
Technical dataIP address, browser type, device type, operating system, language, browser fingerprint (used for abuse detection — see probe_fingerprints)Service, automatically
Communication datasupport messages, email correspondence, in-app feedbackYou
Payment datalast 4 of card, billing country, payment processor token (we do not store full card numbers — Stripe does)Stripe (when you buy Credit packs)
Email engagementdelivery status, opens, clicks, bounces, complaints, unsubscribe eventsResend (email processor)
Address-report datablockchain addresses you scan, report results, timestampsYou + on-chain data sources
Referral datareferral code used, referred friend's first transaction signal, Credit awardsYou + Service
Sanctions screening datacountry-of-access derived from IP geolocation; provider-side KYC sanctions results are held by the Provider and not transmitted to us by defaultService (country-level) + Provider (person-level, not shared back)
Wallet credential metadata (Wallet Service and historical Tempo Passkey Wallet Lab)credential identifier, credential public key, AAGUID, transports, relying-party identifier (swaps.app), wallet address, wallet row, status, audit-log entries — never seed phrase, private key, passkey secret, session signing key, or any signing materialYou + your device WebAuthn ceremony; signing material remains on your device, browser, or password manager
Payment Links data (Merchant)the Merchant's account and business data shared with the Provider to activate a link; the client and line-item details on a payment request; the settlement destination (bank account or crypto wallet address); request reference codes, amounts, status, and timestampsThe Merchant, at link creation/activation
Payment Links data (Payer)limited data the Payer provides on the public /pay page to complete a push payment — self-declared business/individual type and the payment details needed for the chosen rail; the Payer is not KYC'd by SwapsThe Payer, on the public payment page
Payroll data (Recipient)Recipient names, payout destinations (bank account or crypto wallet address), and amounts the Employer enters or approves, processed to route payout instructions to the ProviderThe Employer, at payroll-run creation/approval

We do not knowingly process special categories of personal data (Article 9 GDPR — health, biometric, racial, political, etc.). KYC documents (government ID, selfies, proof of address) are collected by Providers, not by us; we never see or store those documents. Account passkeys for Swaps login are separate from Tempo Passkey Wallet Lab and Wallet Service passkeys. Swaps and Supabase do not receive your biometric data or private passkey material; your device, browser, or password manager controls the local authenticator. For the Tempo Passkey Wallet Lab specifically, see the Terms of Service §24 for the binding limits on what Swaps stores and does not store; for the live (Beta) public Wallet Service, the same non-custodial limits apply — Swaps stores only the public credential metadata and wallet address listed above and never any private key, seed phrase, passkey secret, or session signing key. See the Wallet Service Terms. For Payment Links and Payroll, the Provider (Bridge) processes the Payer's and Recipient's data when it creates, verifies, and settles a transfer under the Provider's own privacy notice; see the Payment Link Terms and the Payroll Terms.

3. Lawful bases for processing (GDPR Article 6)

PurposeLawful basisNotes
Provide the Service (show quotes, redirect to Provider, run Search reports)Performance of a contract — Art. 6(1)(b)Without this, the Service cannot work
Maintain Account and authenticationPerformance of a contract — Art. 6(1)(b)Includes optional account passkeys where you choose to add one
Detect and prevent fraud, abuse, sanctions evasionLegitimate interest — Art. 6(1)(f) and legal obligation — Art. 6(1)(c)Balancing test recorded internally
Communicate with you (transactional emails)Performance of a contract — Art. 6(1)(b)Account-related, paid product receipts, security alerts
Send marketing / broadcast emailsConsent — Art. 6(1)(a)You opt in. Unsubscribe link in every marketing email
Analytics and product improvementLegitimate interest — Art. 6(1)(f)Aggregate / pseudonymised where possible
Comply with legal obligationsLegal obligation — Art. 6(1)(c)Including AML/CTF screening at our perimeter
Defend legal claimsLegitimate interest — Art. 6(1)(f)
Operate the Tempo Passkey Wallet Lab (Lab access, sync, audit)Consent — Art. 6(1)(a) (lab opt-in) + Legitimate interest — Art. 6(1)(f) for audit loggingLab is allowlisted, hidden, opt-in; consent withdrawable by leaving the Lab
Operate the Wallet Service and store public credential metadataPerformance of a contract — Art. 6(1)(b) + Legitimate interest — Art. 6(1)(f) for audit loggingNon-custodial; only public metadata + wallet address stored. See the Wallet Service Terms
Operate Payment Links — present the request, collect the Payer's chosen rail, and instruct the ProviderPerformance of a contract — Art. 6(1)(b)Merchant and Payer data; the Provider settles under its own notice
Operate Payroll — route the Employer's payout instructions to the ProviderPerformance of a contract — Art. 6(1)(b)Employer bears the lawful-basis duty toward Recipients (see Section 5)

You have the right to object to processing based on legitimate interest at any time (see Section 8).

4. How long we keep data (retention)

CategoryRetentionTrigger to delete
Account dataWhile Account is active + 30 days after deletionYou request deletion, or 24 months of inactivity
Authentication tokensSession lifetime (typically 7-30 days)Logout, expiry, or rotation
Account passkey credential metadata, if you add a passkeyWhile the passkey remains attached to the Account + 30 days after Account deletionYou remove the passkey in Settings, or delete the Account
Wallet Service credential metadata + wallet addressWhile the wallet remains attached to the Account + 30 days after "Remove from Swaps" or Account deletionYou "Remove from Swaps", or delete the Account
Payment Links data (request, client/line items, reference, settlement destination, status)7 yearsEstonian/EU accounting law minimum
Payroll Recipient data (names, payout destinations, amounts) and run metadata7 yearsEstonian/EU accounting law minimum
Transaction metadata (which Provider you chose, when, for which pair — no funds, no amounts of yours)7 yearsEstonian/EU accounting law minimum
Usage data14 months (aggregated/pseudonymised after 30 days)Automatic
Technical data (IP, fingerprint)90 days for abuse-detection, shorter where not justifiedAutomatic
Communication data3 years after last interactionAutomatic
Payment data7 yearsTax law (Estonian Income Tax Act)
Search reportsWhile Account exists + 30 daysAccount deletion
Sanctions screening logs5 years from screening eventEU AML regs (where applicable to Providers' processes we observe)
Marketing engagementUntil you withdraw consentUnsubscribe

If you delete your Account, we delete or anonymise data within 30 days, except data we are required by law to retain (e.g., tax records) or data needed to defend legal claims, which we retain in restricted-access form until the retention period ends.

5. How we use your data — purposes

  1. Show you quotes and route you to your chosen Provider. Your wallet address, pair, and amount are encrypted and handed to the Provider via redirect_init (AES-GCM). The Provider then operates under its own terms.
  2. Maintain your Account and give you a history of your activity.
  3. Process Search Address Reports and Credit pack purchases.
  4. Award referral Credits when your friend transacts.
  5. Operate Payment Links — present a Merchant's request, collect the Payer's chosen rail and the limited payment details needed to complete the push payment, and instruct the Provider to create and settle the transfer. The Provider processes the Payer's data under its own notice. See the Payment Link Terms.
  6. Operate Payroll — process the Recipient data the Employer provides (names, payout destinations, amounts) to route payout instructions to the Provider. The Employer is responsible for its lawful basis toward Recipients. See the Payroll Terms.
  7. Operate the Wallet Service — store and display the public credential metadata and wallet address for a non-custodial passkey wallet you control; display balances; prepare transaction data; submit user-authorized signed transactions; and show status. Swaps never stores private keys, seed phrases, passkey secrets, session keys, or any signing material. See the Wallet Service Terms.
  8. Detect and prevent fraud, multi-account abuse, paid-traffic referral farming, and bot traffic — including by storing browser fingerprints in probe_fingerprints and matching against known abuse patterns.
  9. Screen against sanctions lists — see the Sanctions policy.
  10. Communicate with you — transactional emails (signup, receipts, password reset, security alerts) and, if you opt in, marketing emails (product news, broadcasts).
  11. Analyse and improve the Service — aggregate analytics through Google Analytics 4, Vercel Analytics, and Sentry for error tracking.
  12. Comply with law and respond to lawful requests from authorities.
  13. Defend legal claims if any arise.

We do not sell your personal data. We do not "share" your personal data in the CCPA cross-context-behavioural-advertising sense.

6. Who we share data with (processors and recipients)

Personal data is shared only with the following categories of recipients, each bound by a Data Processing Agreement (DPA) and (for transfers outside the EEA) by Standard Contractual Clauses (SCCs) issued by the European Commission under Decision 2021/914.

RecipientRoleData sharedLocationTransfer basis
Supabase (Supabase Inc.)Database, auth, edge functions, storageAccount data, transaction metadata, search reports, fingerprintsFrankfurt, Germany (EU)Intra-EEA
Vercel Inc.Web hosting, edge runtimePage requests, IP for routingUS (with EU edge cache)SCCs
Cloudflare Inc.CDN, WAF, DDoS protection, geo-blockIP, request headersGlobal anycastSCCs
Stripe, Inc.Payment processing (Credit packs)Payment-method data, billing countryUSSCCs
Resend, Inc.Transactional + broadcast email deliveryEmail, name, engagementUSSCCs
Sentry (Functional Software Inc.)Error trackingStack traces, user agent, sometimes IPUSSCCs
Google LLC (GA4)AnalyticsPseudonymised page-view eventsEU + US backendSCCs + IP anonymisation
OpenSanctionsSanctions list data (used by Providers in their KYC programmes; we may query for country-level cross-checks)Country-level signals; Swaps does not transmit your personal data for per-address screening at this time (see the Sanctions policy)EUIntra-EEA
Persona Identities Inc.(Provider-side) identity verificationWe do not transmit. Providers do, on their own.USProvider-controlled
Bridge (the "Provider")Payment/payout infrastructure for Payment Links and Payroll: creates, verifies, and settles transfers. Independent controller of the data it processes for KYC/KYB, screening, and execution under its own privacy notice.For Payment Links: Merchant account/business data, the request and reference, and the Payer's payment details for the chosen rail. For Payroll: Recipient names, payout destinations, and amounts. Lawful basis: performance of a contract (Art. 6(1)(b)); the Provider's own KYC/KYB/screening is its legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)).USSCCs
Tempo Moderato testnet RPC node (Lab only)Read/broadcast Tempo Moderato transactions you initiate from the LabPublic-blockchain RPC calls (no personal data beyond your public wallet address)Operated by the Tempo Moderato testnet operatorPublic-blockchain RPC (no DPA applicable)
Current active Providers listed in the generated taxonomy, with Onmeta treated as sandbox/pending until runtime proof is completeExecute your chosen transaction when you choose an available route; DEX protocols may receive only quote/swap context rather than fiat handoff dataEncrypted handoff where applicable: wallet address, pair, amount, optional email reference. Historical/removed providers such as MoonPay, Onramp.money, and Onramper are not active recipients unless reintroduced in taxonomy and runtime.Each provider's jurisdictionEach Provider's own DPA + their consent flow
Law-enforcement, regulatorsWhen legally compelledOnly what is lawfully requiredAs requiredLegal obligation

We do not transfer personal data to third parties for their own marketing purposes. We do not engage in profiling that produces legal effects on you.

7. International transfers

Where we transfer personal data outside the European Economic Area (EEA), we rely on one of the following lawful transfer mechanisms:

  • EU Standard Contractual Clauses (2021/914) for transfers to US processors (Stripe, Resend, Sentry, Google) and any other non-adequacy country.
  • EU-US Data Privacy Framework where the processor is self-certified (we verify on each processor's status page).
  • Adequacy decision where the destination country is on the Commission's adequacy list.

We have performed a transfer impact assessment for each US processor and applied supplementary measures (encryption in transit and at rest, contractual rights of audit, no governmental access without notice obligations on the processor).

8. Your rights (EU GDPR, UK GDPR, where applicable)

Subject to limitations under applicable law, you have the right to:

  • Access the personal data we hold about you (Article 15).
  • Rectify inaccurate or incomplete data (Article 16).
  • Erase ("right to be forgotten") data we hold, subject to legal-retention obligations (Article 17).
  • Restrict processing while a dispute is resolved (Article 18).
  • Data portability — receive your data in a structured, commonly-used, machine-readable format (Article 20).
  • Object to processing based on legitimate interest, including profiling (Article 21).
  • Withdraw consent at any time without affecting the lawfulness of processing before withdrawal (Article 7(3)).
  • Not be subject to automated decision-making producing legal effects on you (Article 22). We do not engage in such automated decision-making.
  • Lodge a complaint with a supervisory authority (Section 12).

To exercise any of these rights, email legal@swaps.app. We will respond within 30 calendar days. We may extend by 60 days for complex requests and will tell you in writing if we do. There is no fee unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse.

9. Cookies and similar technologies

The Service uses cookies and similar technologies to operate, secure, analyse, and (with your consent) personalise the experience. Detailed information — categories, purposes, lifetimes, third parties, and how to manage consent — is in the Cookie Policy. On first visit, the cookie consent banner asks you to accept, reject, or customise. You can change your choice at any time from the footer "Cookie settings" link.

10. Security

We implement technical and organisational measures appropriate to the risk, including:

  • TLS 1.3 in transit; AES-256 at rest in Supabase (Frankfurt).
  • AES-GCM encryption of PII in redirect tokens (redirect_init); PII never appears in URLs in plaintext.
  • Row-level security (RLS) on all user-data tables in Supabase.
  • Sanctioned-jurisdiction geo-block at Cloudflare WAF.
  • Probe fingerprinting and rate-limits to detect automated abuse.
  • No silent fallbacks — errors surface; no fake data substitution.
  • Account passkeys use WebAuthn through Supabase Auth. Only public credential metadata is used server-side; biometric and private passkey material remains on your device, browser, or password manager.
  • Wallet seed phrases or private keys are NEVER requested, transmitted, or stored. Anyone claiming to be Swaps and asking for these is impersonating us.

In the event of a personal-data breach likely to result in risk to your rights and freedoms, we notify the Estonian Data Protection Inspectorate within 72 hours and notify you without undue delay where required by Article 34 GDPR.

11. Children

The Service is not directed to persons under 18. We do not knowingly collect personal data from anyone under 18. If you become aware that a person under 18 has provided personal data to us, please email legal@swaps.app and we will delete it promptly.

12. Supervisory authorities

You have the right to lodge a complaint with the data protection supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement. Our lead authority is:

  • Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — https://www.aki.ee/ — Tatari 39, 10134 Tallinn, Estonia.

For non-EU jurisdictions:

We encourage you to contact us first at legal@swaps.app so we can attempt to resolve any concern directly.

13. Jurisdiction-specific notices

13.1 California (CCPA / CPRA)

California residents have, in addition to the rights in Section 8:

  • Right to know what categories of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share.
  • Right to delete personal information (subject to exceptions).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell personal information. We do not "share" personal information for cross-context behavioural advertising. Therefore, a "Do Not Sell or Share My Personal Information" link is not strictly required, but we provide one in the footer (/legal/do-not-sell) for transparency. Selecting it will result in our marketing cookie category being disabled for your session and going forward.
  • Right against discrimination for exercising these rights. We do not offer different prices or service levels based on whether you exercise CCPA rights.
  • Right to limit use of sensitive personal information. We do not collect categories of sensitive personal information triggering this right.

To exercise these rights, email legal@swaps.app. We verify identity by reasonable means before processing. Authorised agents must provide written authorisation.

13.2 United Kingdom (UK GDPR)

UK residents have the same data-subject rights as EU residents, governed by the UK GDPR and the Data Protection Act 2018. The lead supervisory authority is the Information Commissioner's Office (ICO). We have not appointed a UK Representative on the basis that our UK processing is below the threshold; we will reassess if our UK traffic grows materially and appoint a representative if required.

13.3 Brazil (LGPD)

Brazilian users have the rights granted by Lei nº 13.709/2018 (LGPD). Our DPO (Encarregado) is reachable at legal@swaps.app. Lawful bases under LGPD parallel those of GDPR (contract execution, consent, legitimate interest, legal obligation). Supervisory authority is ANPD.

13.4 India (DPDP Act 2023)

Indian users have the rights granted by the Digital Personal Data Protection Act, 2023, including access, correction, erasure, grievance redressal, and nomination. Our Grievance Officer for DPDP purposes is reachable at legal@swaps.app and aims to respond to grievances within 30 calendar days. Categories of personal data we process for Indian users are the same as Section 2; lawful purposes are described in Section 5 and Section 3.

13.5 Switzerland (FADP)

Swiss residents are governed by the revised Federal Act on Data Protection (FADP, 2023). Our processing of Swiss personal data follows the same standards as for EU/EEA personal data. The Swiss FDPIC is the supervisory authority.

14. Automated decision-making

We do not engage in automated decision-making producing legal effects on you or similarly significantly affecting you (Article 22 GDPR). Fraud and abuse detection is automated but always combined with human review before any Account-level action (suspension, ban).

15. Changes to this policy

We may update this Privacy Policy. When we do, we change the "Last updated" date and, for material changes, notify you by email (where you have an Account) and via an in-product banner. Continued use of the Service after a material change constitutes acceptance.


Contact for all privacy matters: legal@swaps.app Controller: Supa Labs OÜ · Registry 17399414 · Oru tn 2, Tallinn 10127, Estonia

Related Pages