Privacy Policy

Effective Date: March 8, 2026

1. Introduction

This Privacy Policy applies to:

  • Checkout users making cryptocurrency payments
  • Merchants using the dashboard, API, and webhooks

2. Data Cloakd Collects

Cloakd collects the following data:

  • Wallet addresses (customer and merchant)
  • Transaction metadata (amount, blockchain network, timestamp, status)
  • Merchant configuration data (payment settings, preferences)
  • API keys (hashed and stored securely)
  • Webhook URLs
  • IP addresses (for security and rate limiting only)
  • Basic analytics (page views, usage patterns)

Merchant onboarding data (merchants only):

  • Business name and website URL
  • Contact email address
  • Business vertical / industry category
  • Owner or director name
  • Country of business registration

This business information is collected as part of Cloakd's Know Your Business (KYB) process for AML/CFT compliance purposes. It applies to merchants only, not to checkout customers.

3. Data Cloakd Does NOT Collect

Cloakd explicitly does not collect from checkout customers:

  • Private keys or seed phrases
  • Credit card data
  • Identity documents or government-issued IDs
  • Personal customer profiles or accounts

Cloakd does not require user accounts for checkout. Checkout payment data is pseudonymous. Cloakd does not perform identity verification (KYC) on end customers.

Cloakd never holds custody of funds or private keys for any party.

4. How Data Is Used

Data collected by Cloakd is used to:

  • Operate the checkout and process payments
  • Provide APIs and webhooks to merchants
  • Monitor payment status and blockchain confirmations
  • Security and fraud prevention
  • Rate limiting and abuse prevention
  • Service improvement and analytics

5. Data Sharing

Cloakd does not sell user data.

Data may be shared only with:

  • Infrastructure providers (hosting, databases)
  • Blockchain services and liquidity providers
  • Only to the extent necessary to operate the service

No data is shared for marketing or advertising purposes.

6. Data Retention

Retention periods depend on the type of data:

  • Merchant KYB data and transaction records: retained for a minimum of 5 years from the date of the business relationship, in accordance with Dutch AML law (Wwft).
  • Checkout transaction data: retained for as long as necessary for merchant reporting and legal compliance, then archived or deleted.
  • API keys and webhook configuration: retained for the duration of the merchant relationship and deleted upon account closure.
  • IP address logs: retained for up to 90 days for security purposes.

Merchants may request deletion of data that is not subject to legal retention obligations. Contact us at info@cloakd.ai for data deletion requests.

7. Security Measures

Cloakd employs security measures including:

  • Encryption of data in transit and at rest
  • Hashing of API keys and secrets
  • Access controls and authentication
  • Regular security monitoring

While we implement industry-standard security practices, no system is completely secure. Users are responsible for securing their own wallets and private keys.

8. User Rights

Depending on your jurisdiction, you may have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to data processing

To exercise these rights, contact us at info@cloakd.ai.

9. Changes to Policy

Cloakd may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.

Continued use of the service after changes are posted constitutes acceptance of the updated policy.

10. Contact

For privacy questions or concerns, contact us at info@cloakd.ai.