VERSION 2026-09-09
Privacy policy
What stays with the merchant, and what we need to run the service.
1. Who handles your information
This notice covers the Wholly Crypto product website, software distribution and processing-credit service, and describes data kept by self-hosted merchant installations. For privacy questions and requests, use our contact form or the support channel provided with your merchant account.
Each merchant operates its own checkout and controls its customer records. Using our software does not transfer all customer-data responsibilities to us. Contact the merchant about an order, refund or its use of your information. Hosts, networks and other providers may have their own responsibilities and notices.
2. On the merchant server
The application stores console accounts and password hashes, optional encrypted authenticator secrets and hashed one-use recovery codes, sessions, permissions, store and project settings, invoices, public addresses, payment observations, callback delivery history, audit records and optional customer information. Customer fields may include email, name, address, company and VAT ID when supplied through forms or integrations.
Generated wallet secrets and encryption keys stay on the merchant’s infrastructure. Plaintext wallet exports contain highly sensitive recovery material. The merchant controls access, backups, retention and deletion. Password hashing and wallet encryption do not make a compromised server safe.
The console uses an authentication session cookie and local browser storage for preferences such as theme and language. Customer checkout stores the last chosen chain and asset in local browser storage to preselect an available method on a later visit. This preference contains no invoice identifier, payment address, amount or customer details. Clearing this site's browser data removes it. Sessions expire after seven days unless ended earlier. Initial administrator setup records the legal version, acknowledgement time and language locally. Reading this notice is not blanket consent to marketing or unrelated tracking.
3. Processing-credit information
The credit service receives an installation identifier and credential fingerprint, observed public server IP, reported hostname and service domains, application version, operating system, architecture and connection times. Approximate country may be inferred from an IP database. Reported metadata can be inaccurate; the fingerprint identifies an installation credential, not immutable hardware.
It receives opaque invoice identifiers, original fiat amounts and currencies, authorization, settlement and reversal information, fees, credit purchases, payment references, balances and audit history. These support billing, reconciliation, support, security and fraud prevention. Credit purchases are verified with independent blockchain providers. One-time welcome grants are recorded against the activated installation.
Optional merchant billing details include name, billing email, company, VAT/tax ID, postal address and country. Fee and top-up records retain a snapshot. Your first details entered during a top-up are also saved as defaults; later per-payment edits do not overwrite existing defaults. Defaults can be changed in Settings → Fees, without rewriting earlier payments.
Normal billing messages do not send merchant wallet seeds or private keys, customer names, customer addresses or emails, arbitrary order metadata, or IPN/webhook signing secrets. Merchant billing details are distinct from customer data. Information voluntarily sent to support is handled separately. Never send passwords, keys or recovery phrases.
4. Website and service providers
The product site adds no advertising trackers or analytics scripts. The cookie bar saves your Accept or Reject choice in this browser for up to 180 days; both choices leave optional tracking off. Necessary security protections still apply. , or clear your browser storage. Website and download servers may log IP addresses, paths, timestamps, response status and browser/client information for delivery, troubleshooting and security. Preview access may use HTTP Basic Authentication.
The contact form collects your name, email, subject and message so we can answer you. The email also includes the connection IP, contact-page language and hostname, browser language preferences, reported browser/operating system/device category, browser time zone when available, UTC receipt time and a random message reference. Browser details can be inaccurate and do not reveal your computer hostname. We use this context to answer technical questions and assess spam; we do not create a persistent device fingerprint or request precise location. We never include authentication cookies, passwords, Turnstile tokens or unrelated request headers in these emails. It emails these details to our team; the website does not keep a separate message database. Email copies and delivery logs may remain for correspondence, troubleshooting and applicable retention duties. Never send passwords, private keys or recovery phrases. Cloudflare Turnstile checks submissions for abuse. Your browser communicates with Cloudflare, and our server sends the single-use verification token and your IP address to its verification service before accepting a message. Local abuse-control counters use a keyed hash of your IP and expire within two hours; they do not store message text. Cloudflare proxies and protects the product website and may set security cookies depending on enabled features. See its privacy policy and cookie information. Hosting and email providers process information needed to run the infrastructure and correspondence.
Configured blockchain nodes receive queries to discover payments, check balances and broadcast authorized transfers. These may reveal public addresses, transactions and your server IP. Rate and token providers receive market-data queries. Product-site token snapshots and icons are served locally rather than requested from those providers by your browser.
Blockchain records are public, can be copied indefinitely, and generally cannot be erased or corrected by Wholly Crypto. Addresses are not necessarily anonymous. Other websites have their own policies.
5. Purposes, legal bases and sharing
We use service information to provide downloads and account functionality, administer credits and fees, reconcile payments, answer support requests, prevent abuse, protect infrastructure and meet legal obligations. Where applicable law requires a legal basis, we rely as appropriate on performing a contract, legitimate interests in secure operation and fraud prevention balanced against individual rights, and compliance with legal obligations. Optional processing requiring consent must obtain it separately.
We do not sell personal information or build advertising profiles through this site. Access is limited to people and providers who need it for these purposes. Relevant information may be disclosed where required by law, to protect legal rights, investigate abuse or complete a lawful business transfer with appropriate protections and notice. Private billing and account records are not published on the product website.
Providers may process information outside your country. Where required by applicable law, appropriate international-transfer mechanisms and safeguards must be used. Contact us about safeguards relevant to your information. This notice does not claim control over all public blockchain participants.
6. Retention and security
Service records are retained as reasonably needed to operate an account, reconcile payments, investigate incidents, resolve disputes and satisfy applicable accounting and legal obligations. Financial ledgers and necessary audit evidence may remain after an account closes. Retention depends on the record, applicable law and unresolved issues; no automatic deletion deadline is promised where none is implemented.
Merchants determine retention on their own servers and should minimize customer information. Local deletion does not erase credit-service records, independent backups, provider logs or blockchain history. Financial corrections may require new entries instead of overwriting history.
Access controls, encrypted transport, signed billing messages and separated credentials help protect information, but absolute security cannot be guaranteed. Operators must protect backups and respond to incidents, including legally required notifications.
7. Your choices and rights
Billing details are optional unless a transaction or legal requirement makes them necessary. Information essential for authentication, billing and security is required to use those services. You can edit preferences and billing defaults in the console without changing earlier payment snapshots.
Depending on applicable law, rights may include access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaint to a competent data-protection authority. Submit requests through the support channel provided with your merchant account, with enough information to find the account but without passwords or keys. Identity verification may be necessary. Legal retention duties and others’ rights may limit a request. Direct requests about a merchant’s customer records to that merchant.
This business service is not directed at children. Material changes to this notice will be communicated through the website or application as appropriate. A prior acknowledgement is not consent to newly introduced unrelated purposes.