LOYFIN / LEGAL

Privacy Policy

What we collect, why we use it, who receives it, and the choices you have. Public blockchain records have particular privacy implications.

Version Terms of Service

01Who is responsible for your data

Blockfactory spółka z ograniczoną odpowiedzialnością, at the registered address below, is the controller of personal data we process for Loyfin accounts, operation and security of our Services, our communications and our own legal obligations. Contact support@loyfin.com for privacy requests. This notice covers our website, applications, APIs, wallet-related interfaces, program pages and Markets.

Issuers separately determine how they run loyalty programs, maintain customer ledgers, verify eligibility and deliver rewards. Contact the relevant Issuer about those activities and read its privacy notice. Wallet, funding and other providers may also act as separate controllers for their services. Where we process customer data solely on an Issuer’s documented instructions, the relevant processing agreement governs that processor role; this notice does not replace a required data processing agreement.

02Information we process and where it comes from

Account and identity information: email address, authentication identifiers, account status, associated wallet addresses and account or organisation details supplied by you, your authorised representative or our authentication provider. Privy supplies authentication and wallet infrastructure. We do not need your wallet seed phrase in a support request and you should never send it to us.

Program and transaction information: Issuer and program identifiers, names, descriptions, public images and metadata; wallet addresses; issuance and redemption instructions; amounts, expiry and permission settings; signatures, nonces, operation references, transaction hashes, receipts, market offers and activity. These come from you, your integration, the relevant Issuer, blockchain networks and indexing or RPC providers. A wallet address may identify a person when combined with other information.

Integration and security information: API credential records, authentication and session information, webhook configuration and delivery records, delegated signing permissions and audit records, request timestamps, errors, rate-limit information and relevant device, browser, IP address or network information. Some infrastructure may process an IP address even where an application-level identifier is hashed.

Enquiries and waitlist information: email, name, company, role, intended use, estimated loyalty volume, existing loyalty stack, launch timing, integration preferences, pilot goals, optional wallet address, referral source, browser information and what you send in correspondence. Please avoid sending unnecessary customer data or sensitive information. Payment or identity checks performed directly by a funding provider are governed by its notice; we receive the information needed for our own transaction flow rather than routinely collecting your full card details or identity documents.

Usage information: page visits and coarse product events, such as opening a wallet or completing a checkout step, with limited context such as feature, network or result. Our analytics layer removes URL queries and fragments and replaces private route identifiers. It excludes email addresses, wallet addresses, signatures, API keys, transaction amounts and raw errors from custom event properties. Hosting and security processing is separate from those analytics filters.

03Purposes and legal bases

To create and operate your account, respond to requested enquiries, provide wallet and integration functionality, process instructions, display transaction outcomes and deliver service messages, we rely on performance of our agreement with you or steps you request before entering it (GDPR Article 6(1)(b)). Where you act for a business that is our customer, our basis for processing your work contact details and activity is our legitimate interest in administering that business relationship (Article 6(1)(f)).

To secure the Services, detect abuse, investigate failures, prevent unauthorised instructions, maintain auditability and establish or defend claims, we rely on legitimate interests in protecting users, systems and legal rights (Article 6(1)(f)), and legal obligation where a specific law requires processing (Article 6(1)(c)). We consider necessity, proportionality and the effect on individuals rather than treating legitimate interests as unrestricted permission.

For accounting, legally required records, lawful regulatory disclosures and responses to binding legal requests, we rely on applicable legal obligations (Article 6(1)(c)). For optional product analytics we rely on your consent (Article 6(1)(a)). We request any consent required before optional marketing or device storage. Consent can be withdrawn without affecting the lawfulness of earlier processing. A service enquiry or waitlist submission is used to answer or follow up on that request, not as blanket consent to unrelated advertising.

Information needed to authenticate you or execute an instruction is necessary to provide that function; without it we may be unable to provide the account, integration or transaction. Optional enquiry fields and analytics choices are not a condition of using core features. We do not use personal data for solely automated decisions producing legal or similarly significant effects. Automated security checks may restrict requests; contact support if you believe a restriction is mistaken.

04Public blockchains and program content

Transactions broadcast to public blockchains expose wallet addresses, amounts, token and contract identifiers, activity and any included data to anyone. Network participants, explorers and other people may copy, analyse, combine or retain those records worldwide. Public data can reveal relationships and spending patterns even without a name. We cannot delete or change records from independently operated blockchains, explorers or copies held by others.

Program names, Issuer profiles, token metadata, uploaded program images, market offers and public activity may be visible through Loyfin and public storage or caches. Do not include personal or confidential information in public fields or blockchain payloads. Removal from our interface does not reliably remove cached or onchain copies. This technical limitation does not eliminate our duty to assess a rights request or remove personal data from systems we control when required.

05Who receives information

We share information as necessary with authentication and wallet infrastructure providers, including Privy; hosting, database, storage, monitoring and analytics providers, including Vercel and Supabase where used; email delivery providers, including Resend; and blockchain access or indexing providers, including Alchemy or the RPC provider for the selected network. Their access is limited according to the service and their role. Authorised personnel and professional advisers may access information needed for their work.

The relevant Issuer and its authorised integration may receive operation results, wallet and program references, and webhook information needed to administer the program. Other users can see public program, market and blockchain information. When you choose funding, bridging or other external services, providers such as MoonPay, Coinbase, Stripe or Relay may process data under their own terms and notices. The providers presented depend on the selected feature and availability.

We may disclose information where necessary to comply with law, protect rights or security, or respond to a valid request from competent authorities. In a merger, reorganisation or business transfer, relevant information may be disclosed subject to appropriate confidentiality and lawful use; we will notify you of a material controller change as required. We do not sell personal data or share it for cross-context behavioural advertising.

06International processing

Providers and their authorised subprocessors may process data outside Poland and the European Economic Area, including in the United States. For transfers subject to GDPR restrictions, the applicable mechanism must be an adequacy decision covering the recipient or appropriate safeguards such as European Commission standard contractual clauses, with supplementary measures where necessary. Contact support for information about the mechanism and a copy of applicable safeguards, subject to lawful redactions.

Public blockchain publication is different from a private transfer to a contracted processor: independent participants worldwide may access the information, and we cannot require every participant to sign a processing agreement. Review the public-data section before authorising publication. These Terms and this notice do not constitute a blanket consent to restricted international transfers.

07Retention and security

We retain identifiable data only as long as reasonably needed for the purposes described, including operating your account, completing transactions, investigating incidents, resolving disputes and meeting legal recordkeeping duties. The period depends on the data, transaction and applicable limitation or statutory retention period. Account closure does not immediately delete legally required financial records, relevant security evidence or records needed for an outstanding claim.

We assess enquiry information against the continuing relationship or request, integration records against operational and audit needs, and security records against investigation and prevention needs. Backups may retain deleted records until their normal replacement cycle; retained backup data remains protected and is not kept for ordinary active use. Public blockchain records may persist indefinitely outside our control. Contact us for the retention criteria applicable to your records.

We use access controls and technical safeguards appropriate to our processing, including controls on wallet permissions and restricted handling of credentials. No system guarantees absolute security. Protect your email account, devices, wallet access and API keys and tell us promptly about suspected compromise. We will assess personal data breaches and make notifications where required by law.

08Browser storage and analytics choices

Loyfin and authentication or wallet providers use browser storage and similar mechanisms needed for sessions, security, wallet functionality and saving your preferences. Blocking necessary storage may prevent those functions from working. A requested external wallet or funding feature may involve that provider’s own storage and privacy choices.

Optional Vercel Web Analytics measures page views and limited product events only after you choose Allow analytics. You can choose Reject analytics and continue using Loyfin. The analytics implementation does not use advertising cookies; this does not mean that all authentication, infrastructure or third-party processing is anonymous or storage-free. We save your analytics choice in your browser so it can be respected on later visits.

Use Analytics settings in the site footer to allow or reject analytics at any time. Rejecting stops future optional analytics from this browser; it does not automatically erase previously collected information. Your preference applies to this browser and may need to be set again after clearing storage or on another device. Contact support to exercise rights relating to earlier information.

09Your rights

Subject to the applicable legal conditions, you may request access and a copy of your personal data, correction, erasure, restriction of processing, and portability of data processed by automated means on consent or contract grounds. You may object to processing based on legitimate interests on grounds relating to your situation, and object to direct marketing at any time. You may withdraw consent as easily as giving it without affecting earlier lawful processing.

Send requests to support@loyfin.com. We may ask for proportionate information to verify your identity or authority, but never your seed phrase or private key. We normally respond within one month; if complexity or number of requests requires up to two additional months, we will explain the extension within the first month. Requests are normally free, subject to statutory exceptions for manifestly unfounded or excessive requests. If we cannot fulfil a request, we will explain the reason and available remedies.

You may complain to the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych; uodo.gov.pl), or to the competent supervisory authority where you live, work or believe an infringement occurred. You do not have to contact us first. You also retain judicial remedies. If a request concerns an Issuer’s separate processing, we will identify the relevant role where possible so you can contact the appropriate controller.

10Age limits and changes to this notice

Loyfin is intended for people aged 18 or older. We do not knowingly offer accounts to children. If you believe a child has supplied personal data, contact us so we can investigate and take appropriate action.

We may update this notice to reflect changes in processing or law. The version date identifies the current text. We will provide an appropriate prominent notice of material changes and seek fresh consent where required before new consent-based processing. A revised notice does not itself authorise a use for which another legal basis or notice is required.

Company & contact

Blockfactory spółka z ograniczoną odpowiedzialnością
ul. Floriana Stablewskiego 13/2, 60-213 Poznań, Poland

KRS 0000987962 · NIP 7792543090 · REGON 522861809
Share capital: PLN 5,000

support@loyfin.com

Polish National Court Register ↗

Polish data protection authority ↗ · Privy Privacy Policy ↗

Loyfin is live.Read the introduction