Privacy Policy
Last updated June 2026
This Privacy Policy explains how Plaidly Labs, Inc. ("Plaidly," "we," "us," or "our") collects, uses, discloses, and safeguards personal data when you use our websites, hosted checkout, merchant dashboard, APIs, and related services (the "Service"). It applies to merchants, developers, and the payers who interact with checkouts powered by Plaidly. It should be read alongside our Terms of Service and Security practices.
A note specific to digital assets: blockchains are public, distributed ledgers. Transaction data we submit to or read from a blockchain — including wallet addresses, amounts, asset types, and timestamps — is recorded on that network, is visible to anyone, and cannot be deleted or altered by us. Please keep this in mind throughout this policy.
1. Data We Collect
Account and identity data
Name, email address, business name, role, billing details, and — where compliance requires it — Know Your Customer / Know Your Business information such as government identifiers, dates of birth, addresses, beneficial-ownership details, and verification documents collected by us or our compliance partners.
Transaction and settlement data
Records of payments, checkout sessions, payment links, payout instructions, fees, refunds, and associated metadata you attach to a transaction (such as order references or customer identifiers you choose to send us).
On-chain data
Wallet and settlement addresses, blockchain network identifiers, transaction hashes, confirmation status, asset types, and amounts. As noted above, this data lives on public ledgers; we read and index it to provide the Service.
Device and usage data
IP address, browser and device characteristics, operating system, pages and API endpoints accessed, timestamps, referral URLs, and diagnostic logs. We collect this through cookies, server logs, and similar technologies to operate, secure, and improve the Service.
Communications
Information you provide when you contact support, respond to surveys, or otherwise communicate with us.
2. How We Use Data
- provide, operate, maintain, and improve the Service;
- create and authenticate accounts and process payments, settlements, and payouts;
- perform identity verification, fraud prevention, sanctions screening, and anti-money-laundering checks;
- monitor on-chain activity and reconcile transactions and balances;
- provide customer support and respond to your requests;
- send service, security, and transactional communications, and — where permitted — product updates;
- detect, investigate, and prevent security incidents, abuse, and other harmful or unlawful activity;
- comply with legal obligations and enforce our agreements.
3. Legal Bases for Processing
Where the EU/UK General Data Protection Regulation applies, we process personal data on these bases: performance of a contract (to provide the Service you request); legal obligation (KYC/AML, sanctions, tax, and accounting requirements); legitimate interests (securing the platform, preventing fraud, improving our products, and operating our business, balanced against your rights); and consent (for certain cookies or marketing, where required, which you may withdraw at any time).
4. How We Share Data
We do not sell personal data. We share it only as described here:
- Service providers and processors — cloud hosting, custody providers, RPC and node providers, identity-verification and compliance vendors, analytics, and communication tools that process data on our behalf under contract;
- Blockchain networks — transaction details are submitted to public ledgers and are inherently visible to anyone, as described above;
- Merchants and payers — where you transact through a Plaidly-powered checkout, relevant transaction data is shared between the merchant and the payer to complete and reconcile the payment;
- Legal and safety — regulators, law enforcement, or other parties when required by law, to comply with legal process, or to protect the rights, property, or safety of Plaidly, our users, or the public;
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
5. Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences (such as your light/dark theme), secure the Service, and understand aggregate usage. Strictly necessary cookies are required for the Service to function; others are optional. You can control non-essential cookies through your browser settings or, where offered, our cookie controls. Disabling some cookies may affect functionality.
6. Data Retention
We retain personal data for as long as needed to provide the Service and for legitimate business and legal purposes. In particular, financial, transaction, and KYC/AML records are typically retained for the periods required by applicable financial-services and anti-money-laundering laws, which often extend several years beyond the end of the relationship. When data is no longer needed, we delete or anonymize it. Note that data already written to a public blockchain cannot be erased by us.
7. Security
We apply technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, monitoring, and key-management practices for custodial wallets. No system is perfectly secure, but we work continuously to reduce risk. For details, see our Security practices.
8. Your Rights
Depending on where you live, you may have rights over your personal data. Under the GDPR, these include the rights to access, rectify, erase, restrict, or object to processing, the right to data portability, and the right to withdraw consent and to lodge a complaint with your supervisory authority. Under the California Consumer Privacy Act (as amended by the CPRA), California residents have the rights to know, access, delete, and correct personal information, to opt out of "sale" or "sharing" (we do not sell personal data), and not to be discriminated against for exercising these rights.
To exercise any right, contact us at [email protected]. We will verify your request and respond within the timeframes required by law. Some data, particularly regulated financial and on-chain records, may be exempt from deletion.
9. International Data Transfers
We operate globally and may process and store personal data in countries other than your own, including the United States. Where we transfer data from the European Economic Area, the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where needed.
10. Children
The Service is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice through the Service or by email. We encourage you to review this page periodically.
12. Contact
The data controller is Plaidly Labs, Inc. For privacy questions or to exercise your rights, email [email protected] or reach us through our support channel. For the broader terms governing the Service, see our Terms of Service.