Privacy Policy
This policy explains what data DUALKEEP ("we", "us") collects and how we use it when you visit dualkeep.com, use the merchant dashboard, or pay through our hosted checkout. We built the platform to work with as little personal data as possible: no advertising trackers, no selling of data, and no collection beyond what running a payment service requires.
1. Data we collect
Merchant accounts. When a business registers we store the account email address, business name, and a salted hash of the password (never the password itself), together with the account's invoices, balance ledger, payout requests, and API credentials.
Buyers (checkout). A hosted checkout session records the order details the merchant supplies, the cryptocurrency chosen, the deposit address we generate, and the on-chain transaction identifiers of the payment. Providing an email address on the checkout page is optional and is used only to send status notifications for that payment.
Technical data. Our servers keep short-lived logs (IP address, user agent, request path) for security monitoring, abuse prevention, and rate limiting.
2. Data we do not collect
- No card numbers or bank credentials: payments are made directly from the buyer's own crypto wallet.
- No advertising or cross-site tracking cookies, and no analytics that sell or share behavioral data.
3. How we use data
- To operate the service: process payments, credit merchant balances, execute payouts, and show transaction history.
- To send transactional notifications (payment confirmations, balance alerts) to addresses that requested them.
- To keep the platform secure: fraud and abuse detection, rate limiting, incident investigation.
- To meet legal, accounting, and tax obligations.
4. Blockchain data
Cryptocurrency transactions are recorded on public blockchains. Once broadcast, a transaction (addresses, amounts, timestamps) is publicly visible, permanent, and outside our or anyone's control. Do not send a payment if you object to this inherent property of blockchain networks.
5. Cookies and local storage
We use a session cookie to keep merchants signed in, a CSRF cookie to protect forms, and browser local storage to remember interface preferences such as the color theme. None of these are used for tracking or advertising.
6. Sharing
We never sell personal data. We share data only with the infrastructure needed to run the service (hosting, content delivery, email delivery, and blockchain data providers), each receiving the minimum necessary, and with authorities where a valid legal obligation requires it.
7. Retention
Account data is kept while the account is active. Transaction records are retained as required for accounting and financial compliance. Technical logs are kept only briefly and then deleted.
8. Security
Sensitive key material is encrypted at rest, all traffic is served over TLS, access to production systems is restricted, and the majority of platform funds are periodically moved to cold storage. Balances are additionally verified by continuous reconciliation between our ledger and on-chain holdings.
9. Your rights
You can request access to, correction of, or deletion of your personal data by contacting us. Deletion is subject to records we are legally required to keep. Depending on your jurisdiction you may also have rights to data portability and to lodge a complaint with a supervisory authority.
10. Children
The service is intended for businesses and is not directed at anyone under 18.
11. Changes
We will post any changes to this policy on this page and update the date above. Material changes are announced to merchants in the dashboard or by email.
12. Contact
Privacy questions and requests: [email protected].
DUALKEEP