1. Introduction
This Privacy Policy applies to:
- Checkout users making cryptocurrency payments
- Merchants using the dashboard, API, and webhooks
2. Data Cloakd Collects
Cloakd collects the following data:
- Wallet addresses (customer and merchant)
- Transaction metadata (amount, blockchain network, timestamp, status)
- Merchant configuration data (payment settings, preferences)
- API keys (hashed and stored securely)
- Webhook URLs
- IP addresses (for security and rate limiting only)
- Basic analytics (page views, usage patterns)
Merchant onboarding data (merchants only):
- Business name and website URL
- Contact email address
- Business vertical / industry category
- Owner or director name
- Country of business registration
This business information is collected as part of Cloakd's Know Your Business (KYB) process for AML/CFT compliance purposes. It applies to merchants only, not to checkout customers.
3. Data Cloakd Does NOT Collect
Cloakd explicitly does not collect from checkout customers:
- Private keys or seed phrases
- Credit card data
- Identity documents or government-issued IDs
- Personal customer profiles or accounts
Cloakd does not require user accounts for checkout. Checkout payment data is pseudonymous. Cloakd does not perform identity verification (KYC) on end customers.
Cloakd never holds custody of funds or private keys for any party.
4. How Data Is Used
Data collected by Cloakd is used to:
- Operate the checkout and process payments
- Provide APIs and webhooks to merchants
- Monitor payment status and blockchain confirmations
- Security and fraud prevention
- Rate limiting and abuse prevention
- Service improvement and analytics
5. Data Sharing
Cloakd does not sell user data.
Data may be shared only with:
- Infrastructure providers (hosting, databases)
- Blockchain services and liquidity providers
- Only to the extent necessary to operate the service
No data is shared for marketing or advertising purposes.
6. Data Retention
Retention periods depend on the type of data:
- Merchant KYB data and transaction records: retained for a minimum of 5 years from the date of the business relationship, in accordance with Dutch AML law (Wwft).
- Checkout transaction data: retained for as long as necessary for merchant reporting and legal compliance, then archived or deleted.
- API keys and webhook configuration: retained for the duration of the merchant relationship and deleted upon account closure.
- IP address logs: retained for up to 90 days for security purposes.
Merchants may request deletion of data that is not subject to legal retention obligations. Contact us at info@cloakd.ai for data deletion requests.
7. Security Measures
Cloakd employs security measures including:
- Encryption of data in transit and at rest
- Hashing of API keys and secrets
- Access controls and authentication
- Regular security monitoring
While we implement industry-standard security practices, no system is completely secure. Users are responsible for securing their own wallets and private keys.
8. User Rights
Depending on your jurisdiction, you may have the right to:
- Access your data
- Correct inaccurate data
- Request deletion of your data
- Object to data processing
To exercise these rights, contact us at info@cloakd.ai.
9. Changes to Policy
Cloakd may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
Continued use of the service after changes are posted constitutes acceptance of the updated policy.
10. Contact
For privacy questions or concerns, contact us at info@cloakd.ai.