ADAPAY legal
Privacy Policy
1. Controller and contact
The Swile Group LLC, 30 N Gould St Ste R, Sheridan, 82801-6317, US, controls the ADAPAY website, account software, and support processing described in this policy. Contact support@adapay.asia for privacy requests.
A future licensed payment, KYC or settlement operator may be a separate or joint controller for regulated processing. ADAPAY will identify that operator, its role, and the applicable territories before activation.
2. Data we process
- Account and profile data: email address, name, phone number, country, referral or acquisition source, language, preferences, verification state, and account identifiers.
- Authentication and security data: password hash, session records, failed-login and verification events, device security signals, IP address, timestamps, and audit records.
- Device and app data: device model, operating system and version, app version, locale, time zone, notification settings, crash or diagnostic information, and a pseudonymous installation or analytics identifier.
- Wallet data: local wallet provider, Solana mainnet public address, backup-confirmed timestamp, and account link. The recovery phrase and private key are generated and stored on the device only; ADAPAY must never receive them.
- Payment data is not collected in V1. If a licensed partner feature is activated later, ADAPAY will publish the operator, data categories, fees, status model and retention period before use.
- Identity-verification data is not collected in V1. If KYC is introduced later, the provider, workflow, controller roles, retention and user notices will be published before collection.
- Support and deletion-request data: messages, attachments you choose to provide, account email, request status, and communications needed to resolve the request.
- Consent and attribution data: policy version, consent choices and timestamps, campaign or click identifiers, and marketing-delivery records only where a valid optional consent permits them.
3. Purposes and legal bases
- Provide an account, requested support, security notices, and account deletion: contract performance or steps requested before a contract.
- Protect accounts, prevent abuse, keep audit evidence, and maintain service reliability: legitimate interests, balanced against user rights.
- Future KYC, sanctions, fraud, transaction monitoring, tax, accounting, or regulatory reporting, if enabled later: legal obligation or the licensed operator's documented legal basis.
- Product analytics that are not strictly necessary: consent where required. Refusing or withdrawing optional analytics must not block core service access.
- Advertising attribution or sharing with advertising platforms: prior, specific, revocable consent and, on iOS where applicable, App Tracking Transparency permission.
4. Recipients and processors
ADAPAY uses infrastructure, database, security, email, and support providers under access controls and processing terms. The final production processor register, hosting regions, and transfer mechanisms remain a release gate and will be published before launch.
- No Sumsub, KYC, payment or settlement provider is active in V1.
- Solana network tooling and app-store platforms may process technical data under their own terms.
- A future licensed payment or settlement operator is not represented as active.
- Microsoft Clarity: optional website behavioural analytics and session replay. Where required, Clarity runs only with the applicable notice and valid consent. Google Tag Manager server-side, Meta, TikTok, Telegram attribution, and Zalo attribution code paths remain disabled unless their destination is declared and valid marketing consent exists.
- Authorities or professional advisers: only when legally required or necessary to establish, exercise, or defend legal claims.
5. Retention
- Account and profile data: while the account is active, then deleted or irreversibly anonymized within 30 days after a verified deletion request unless a stated legal hold applies.
- Refresh sessions and connected-service tokens: revoked immediately when deletion starts and removed from active systems within 30 days.
- Security and audit logs: up to 12 months unless a live investigation or law requires longer retention.
- Support messages: up to 24 months after the matter closes, unless the user asks for earlier deletion and no legal exception applies.
- Marketing identifiers and consent-dependent events: removed or de-linked within 30 days after consent withdrawal, subject to processor deletion cycles disclosed at collection.
- No KYC or payment records are created in V1. Future regulated records will use the licensed operator's jurisdiction-specific period published before activation.
- Backups: removed through normal encrypted backup rotation within 90 days and not restored to active use after a completed deletion request.
6. International transfers
Data may be processed outside your country. Before public launch, ADAPAY will document production hosting regions and use the transfer mechanism required for each supported territory, such as an adequacy decision, contractual clauses, or another lawful safeguard. Regulated processing will not be enabled where a lawful transfer has not been established.
7. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or human review of a materially significant automated decision. Use the in-app controls, visit https://adapay.asia/delete-account, or email support@adapay.asia.
We may verify identity before acting on a request. We will explain any legal exception and provide the relevant supervisory-authority route where required.
8. Account deletion
A deletion request immediately revokes active sessions when initiated from an authenticated app and removes the local wallet from the device flow. The public web form starts an email-verification flow and does not reveal whether an address has an account.
9. Security and automated controls
ADAPAY uses encryption in transit, access control, session revocation, logging, and integrity or fraud signals. No system is risk-free. Device-integrity signals are one input and must not be the sole basis for a legally significant decision.
10. Age, changes, and complaints
ADAPAY is intended only for people aged 18 or older. We do not knowingly offer accounts to children.
Material policy changes will be dated and, where required, notified in the app before they take effect. Questions or complaints may be sent to the privacy contact above. A jurisdiction-specific regulator and representative will be added to the notice before service is offered where required.