Privacy Policy

Last updated: August 1, 2026

This policy explains what data DUALKEEP ("we", "us") collects and how we use it when you visit dualkeep.com, use the merchant dashboard, or pay through our hosted checkout. We built the platform to work with as little personal data as possible: no advertising trackers, no selling of data, and no collection beyond what running a payment service requires.

1. Data we collect

Merchant accounts. When a business registers we store the account email address, business name, and a salted hash of the password (never the password itself), together with the account's invoices, balance ledger, payout requests, and API credentials.

Buyers (checkout). A hosted checkout session records the order details the merchant supplies, the cryptocurrency chosen, the deposit address we generate, and the on-chain transaction identifiers of the payment. Providing an email address on the checkout page is optional and is used only to send status notifications for that payment.

Technical data. Our servers keep short-lived logs (IP address, user agent, request path) for security monitoring, abuse prevention, and rate limiting.

2. Data we do not collect

3. How we use data

4. Blockchain data

Cryptocurrency transactions are recorded on public blockchains. Once broadcast, a transaction (addresses, amounts, timestamps) is publicly visible, permanent, and outside our or anyone's control. Do not send a payment if you object to this inherent property of blockchain networks.

5. Cookies and local storage

We use a session cookie to keep merchants signed in, a CSRF cookie to protect forms, and browser local storage to remember interface preferences such as the color theme. None of these are used for tracking or advertising.

6. Sharing

We never sell personal data. We share data only with the infrastructure needed to run the service (hosting, content delivery, email delivery, and blockchain data providers), each receiving the minimum necessary, and with authorities where a valid legal obligation requires it.

7. Retention

Account data is kept while the account is active. Transaction records are retained as required for accounting and financial compliance. Technical logs are kept only briefly and then deleted.

8. Security

Sensitive key material is encrypted at rest, all traffic is served over TLS, access to production systems is restricted, and the majority of platform funds are periodically moved to cold storage. Balances are additionally verified by continuous reconciliation between our ledger and on-chain holdings.

9. Your rights

You can request access to, correction of, or deletion of your personal data by contacting us. Deletion is subject to records we are legally required to keep. Depending on your jurisdiction you may also have rights to data portability and to lodge a complaint with a supervisory authority.

10. Children

The service is intended for businesses and is not directed at anyone under 18.

11. Changes

We will post any changes to this policy on this page and update the date above. Material changes are announced to merchants in the dashboard or by email.

12. Contact

Privacy questions and requests: [email protected].