Privacy Policy

Version 1.4.0 · Effective August 25, 2026

1. Who We Are

Payflip is a mobile app for sending and receiving digital assets from a smart wallet built into the App. Payflip is owned and operated by Flip Labs Global LLC, a Delaware limited liability company with its registered office at 16192 Coastal Highway, Lewes, DE 19958, County of Sussex, United States ("Payflip", "we", "us"). Flip Labs Global LLC is the data controller responsible for the personal information described here. This policy lays out, in plain terms, what personal information we collect when you use the App, why we collect it, who we share it with, and what say you have over it.

Questions? Email us at support@payflip.xyz.

2. Information We Collect

Here's what we collect, and why.

  • Your account details: the email you sign in with. If you use Google, that's the email and maybe the name on your Google account; on iOS you can sign in with Apple instead. If you pick Apple's "Hide My Email" option, Apple hands us a private relay address (one ending in @privaterelay.appleid.com) rather than your real one, and we'll treat that relay address as your account email.
  • If you start as a guest, none of that. A guest account has no email and no third-party identifier attached; it's just a wallet and the preferences on your device. Link an email later and the account details above start to apply.
  • Your wallet: the public address of the smart wallet Privy sets up for you the first time you sign in.
  • Your profile: a display name and picture, if you want them. To set a picture you'll grant photo-library access, but we only ever read the one image you tap, and it goes straight to Cloudinary (more on them below), which hosts it for you. We don't browse or index your library. You can also save your wallet QR code to your photos from inside the App; that's a one-way save to your own library, and the image never leaves your device.
  • Your preferences: the chain and token you'd like to receive funds in, the currency you'd like amounts shown in, whether you want marketing email or push, and your other App settings.
  • Your transaction history: a record of what you've sent and received, the counterparty addresses or emails, amounts, fee breakdowns, chains, transaction hashes, and timestamps. We keep these so your history view works and so support can actually help when something goes sideways.
  • Your card top-ups, but only our half of them. When you buy digital assets with a card, we record the amount, the status, and the transfer that lands in your wallet. The identity documents and card details that the purchase requires go to MoonPay, the provider running the checkout, and never reach us. We don't receive, see, or store your card number or your ID.
  • Reports you file: if you report another user's name or handle, we keep the report, the category you picked, any details you wrote, who was reported, and that it came from you, so a reviewer can act on it and so we can spot patterns of abuse.
  • Your device: details like brand, model, OS and version, App version, language, and whether it's a physical device or an emulator. We log a timestamp each time you sign in and hold on to your current session plus the one right before it, so you can review them under Settings > Devices & Sessions. If you've turned on push, we also store a push token (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS).
  • What lives on your phone: your auth token sits in the operating system's secure keystore (iOS Keychain or Android Keystore), and we cache things like your profile, preferences, and the supported-token list in encrypted on-device storage so the App opens quickly. That data stays on your device and is wiped when you sign out or delete the App.
  • Network basics: when your device talks to our backend, we see the usual request metadata, your IP address, user-agent, and timing, normally kept only in short-lived server logs.
  • Diagnostics: crash and performance reports, collected through Firebase Crashlytics, so we can find and fix what breaks. These carry a pseudonymous account identifier and a shortened form of your wallet address. We deliberately do not attach your email address to them.

One thing we never get hold of: your private signing key. Privy generates and keeps it in their secure environment, and it's never sent to our servers.

3. How We Use Your Information

We use what we collect to:

  • Run the App for you, sign you in, route and settle your transactions, show your balances and history, and send the notifications you asked for.
  • Keep things safe and honest, chase down bugs, review reports about other users, head off abuse and fraud, and meet our legal obligations, including sanctions screening. Some of that screening is automated, and it can result in a transaction being refused or an account being suspended; email us and a person will look at it.
  • Stay in touch, answer the emails you send to support@payflip.xyz and let you know about important changes to the Service or these documents. These are service messages and you can't opt out of them while you have an account, because they're part of running it.
  • Send you marketing, but only if you ask for it. Marketing email and marketing push are both off unless you turn them on, and you can turn them back off at any time in the App's notification settings. Turning them off never affects the service messages above.
  • Make the App better by looking at how people use it in aggregate, so we know what to fix and what to build next.

We don't sell your personal information, we don't share it for cross-context behavioural advertising, and we don't use it to build advertising profiles.

4. Third Parties We Share Information With

Payflip works because a handful of other companies each handle a specific job. Every one of them has its own privacy practices, and their policies apply alongside this one.

  • Privy, our sign-in and embedded-wallet provider. Gets your email or OAuth identifier and holds the signing material for your wallet. Without Privy, sign-in and signing don't work. https://www.privy.io/legal/privacy-policy.
  • Alchemy, for RPC, gas sponsorship, and bundling. Gets the user operations we submit on your behalf, including your wallet address and call data. It does not get your email. https://www.alchemy.com/privacy-policy.
  • MoonPay, if you top up with a card. The checkout is theirs, reached through Privy's funding flow, and you deal with them directly: they collect your name, address, date of birth, identity document, and card details to run their own verification and take the payment. None of that comes to us. They receive your wallet address so the assets can be delivered. https://www.moonpay.com/legal/privacy_policy.
  • Google, if you sign in with Google. Google verifies you and shares your email and (optionally) name with Privy. We don't store the OAuth token. https://policies.google.com/privacy.
  • Apple, if you use Sign in with Apple on iOS. Apple verifies you and shares either your real email or a private relay address (ending in @privaterelay.appleid.com), plus your optional name the first time only, with Privy. We don't store the OAuth token, and the Apple button doesn't appear on Android. https://www.apple.com/legal/privacy.
  • Firebase Cloud Messaging and Apple Push Notification service. If you've enabled push, the relevant one receives a device token so we can send you notifications. On its own, that token doesn't identify you.
  • Firebase Crashlytics, also Google, for crash and performance reporting. Receives the diagnostic data described in section 2, tied to a pseudonymous account id rather than your email. https://firebase.google.com/support/privacy.
  • Expo, which serves over-the-air updates to the App. When your device checks for an update it reveals its IP address and basic build and device details to Expo's update service. https://expo.dev/privacy.
  • Cloudinary, where profile images are hosted. When you set a picture, your device uploads it straight to Cloudinary using a short-lived signed URL from our backend; Cloudinary stores it and hands back a public link, which we save to your account so the image renders for you and your contacts. It does not get your email or wallet address. https://cloudinary.com/privacy.
  • CoinGecko, for token prices. Our backend pulls prices from CoinGecko, and that lookup carries nothing specific to you.
  • The blockchains and bundlers themselves. When you send, your transaction data (wallet addresses and amounts included) is broadcast on-chain, where it's public.
  • Block explorers. Tap "open in explorer" and you leave the App for the explorer's site, which may log your IP address.
  • Our cloud hosting and database providers, which handle the information described here only as far as they need to in order to run the Service.

We may also share information with law enforcement or government authorities when the law, a court order, or the safety of people requires it.

5. On-Chain Activity Is Public

Anything that goes onto a public blockchain, your wallet address, the addresses you transact with, the amounts you send, is visible to anyone, anywhere, and it can't be taken back. Once someone knows your wallet address, they can see everything that address has ever done.

Keep in mind that if you give someone your Payflip email handle, they can look up your wallet address from it inside the App. So share your address or handle with the same care you'd give anything that points back to you.

Sharing a receipt is its own kind of publishing. The receipt image carries the names, handles, and profile pictures of both sides of the payment, along with the amount, date, transaction id, and any note. Sending it to someone hands them all of that, including the other person's details, and it travels wherever they forward it. The link that goes with it is safer, since opening the full receipt in the App requires being a signed-in participant in that payment, but the image is just an image.

6. How Long We Keep Information

We hold on to your account details, wallet address, preferences, and transaction history for as long as your account is open. Diagnostic logs and that short-lived request metadata don't stick around as long, usually 30 to 90 days, and then they're deleted or aggregated. Reports about other users are kept while they're being reviewed and for a period afterwards, so repeat abuse can be recognised.

Ask us to delete your account, from inside the App or at https://payflip.xyz/delete-account, and we schedule it for permanent removal after a 7-day cooldown. Change your mind in those 7 days? Just sign back in and the deletion is cancelled. Once the cooldown passes, we remove or anonymize the personal information tied to your account within a reasonable time, except for the parts we're legally required to keep for compliance, fraud-prevention, or audit reasons. Anything already on-chain is out of our hands and stays on the blockchain.

7. How We Protect Information

We protect your information with safeguards that fit what we do, encryption in transit (HTTPS), a sign-in required to reach the App, and access controls on our own systems.

That said, no system is ever 100% secure, and part of this rests with you:

  • Use a strong, unique password and turn on 2FA for your email.
  • Switch on App Lock and biometrics inside Payflip.
  • Never share your verification codes (OTPs). We will never ask you for one.

If you believe you have found a security flaw in Payflip, please tell us at security@payflip.xyz rather than posting it publicly, and we will work with you on it.

8. Your Rights and Choices

Depending on where you live, you may be able to:

  • See the personal information we hold about you.
  • Have us correct anything that's wrong.
  • Have us delete your information, within the limits the law allows. You can start this yourself, in the App or at https://payflip.xyz/delete-account.
  • Object to, or restrict, certain uses of it.
  • Get a copy in a portable format.
  • Withdraw consent where we relied on it, including turning marketing email and push back off in the App's notification settings.
  • Complain to the data-protection authority in your country.

If you're in California, the rights above cover the ones the CCPA gives you, and we'll add two things it asks us to say plainly: we do not sell your personal information and we do not share it for cross-context behavioural advertising, and we won't treat you differently for exercising any of these rights.

To do any of these, email support@payflip.xyz. We may need to confirm who you are first, and we aim to respond within 30 days.

A couple of caveats: some things can't be removed without ending your ability to use the App at all (your email or wallet address, for example), and as we mentioned, on-chain data isn't something we're able to delete.

9. Children

Payflip is for adults. You have to be at least 18 to use it, the App isn't directed to children, and we don't knowingly collect anything from them. If you think a child has provided information to us, email support@payflip.xyz and we'll delete it.

10. International Users

We and the providers we work with may handle your information in countries other than your own. By using the App, you understand that it may be transferred to, stored in, and processed in places whose data-protection laws differ from the ones where you live.

Where the law calls for it, for instance when moving personal data out of the European Economic Area, the UK, or Switzerland, we and our processors put appropriate safeguards in place, such as Standard Contractual Clauses.

Where we rely on a legal basis to process your information, it is one of these: performing our agreement with you (running your account and your transactions), complying with a legal obligation (sanctions screening and record-keeping), your consent (marketing, and access to your photo library), or our legitimate interests in keeping the Service secure, preventing abuse, and improving how it works.

11. Changes to This Policy

We may update this policy from time to time. When we do, the version number and effective date at the top will change, and for anything material we'll ask you to review and accept it in the App.

12. Contact

For privacy questions, requests, or complaints, email support@payflip.xyz with "Privacy Request" in the subject line. We aim to reply within a few business days. Security issues and vulnerability reports go to security@payflip.xyz.

You can also reach the data controller by post:

Flip Labs Global LLC 16192 Coastal Highway, Lewes, DE 19958 County of Sussex, Delaware, United States EIN 98-1953744 Phone: +1 (402) 876-0931