Last updated: August 29, 2026
1. Who we are
This policy explains how Safewire Technologies Ltd (“Safewire”, “we”, “us”) handles personal data when you use the Safewire app, portals, and related services (the “Services”). Safewire Technologies Ltd is incorporated in the United Kingdom, registered address 20-22 Wenlock Road, London N1 7GU, United Kingdom. Safewire Technologies Ltd is the controller of the personal data described here, and is the publisher of the Safewire apps on Google Play. Where a provider handles data for us — such as our identity-verification provider — it does so on our instructions, and we remain responsible for it.
2. The short version
- Your keys and funds are yours — we never have them, so they are not “data we hold”.
- We collect what we need to run the network: contact details, verification results, device data, and transaction records.
- Identity documents and selfies are collected by our verification provider, who handles them on our instructions. We do not store the documents themselves.
- The backup we hold on our servers is encrypted and we cannot read it. If you also save a recovery file to your own Google Drive or iCloud, that file is NOT encrypted unless you set a recovery-key password — so set one.
- We never sell personal data.
3. What we collect
Account and contact data. Your phone number (verified by one-time code), email address (verified), the name you provide, your country, and your verification level.
Identity verification. When you verify your identity, our verification provider (currently Sumsub) collects your identity documents and a selfie/liveness check, and a precise location reading, acting on our instructions as our processor. We receive the verification result and limited confirmed details (such as name, date of birth, document type, and country). Where a transfer or a regulatory filing requires it, we DO retain your name, date of birth and residential street address in a separate access-controlled compliance store — see Retention below. For merchants, business-verification (KYB) documents you upload are stored by us.
Wallet and transaction data. Your public wallet addresses, transaction records, payment and settlement details, and related records the network keeps. Blockchain addresses and transactions are public by the nature of blockchains.
Device and app data. Device identifiers, push-notification token, app version, language, IP address (used to infer your country for regional defaults), and diagnostic and crash data.
Optional backups. If you enable recovery features, we store encrypted recovery data that we cannot read; only factors you control can unlock it. If you connect a cloud provider (for example Google Drive), your recovery key file is stored in your own cloud account, not with us. If you use the app-data backup, your in-app contacts, labels and preferences are stored with us so they can be restored.
Support. Communications you send us.
3A. Location
We use location in two separate ways, and you can decline both.
- Finding merchants near you. If you tap “Locate me” on the map, the app reads your position and sends it to us rounded, so it identifies a neighbourhood rather than an address. We use it only to answer that request. The map works without it.
- Identity verification. When you verify your identity, our verification provider reads a precise location as a fraud-prevention signal, on our instructions. This happens only during verification, which is optional.
4. What we do not collect
- Your private keys or Secret Recovery Words — they never leave your device in readable form.
- Your card numbers (card purchases are handled by Unlimit under its own terms).
- Your bank account details.
5. How we use data
- To provide, operate and support the Services;
- To verify participants and apply the network's standards — preventing fraud, financial crime, and abuse, and applying usage limits by verification level;
- To keep complete and accurate records of network activity;
- To notify you about your account and transactions;
- To troubleshoot, secure, and improve the Services;
- To comply with applicable law, and to establish or defend legal claims.
We rely on your consent, the performance of our terms with you, our legal obligations, and our legitimate interest in running a safe network, as applicable law provides.
6. Who we share data with
- Verification provider (Sumsub) — identity and business verification;
- Credential services — issuance and verification of the digital credentials you hold in the app;
- Unlimit — if you buy stablecoin by card, under its own terms;
- Messaging providers (for example Twilio) — your phone number, to deliver verification codes and service messages;
- Google/Firebase — push notifications and crash diagnostics;
- Infrastructure providers (hosting and blockchain data services) — these receive public wallet addresses and transaction data, not your identity records;
- Your own cloud provider — only if you connect one, and only your encrypted recovery file, in your account;
- Merchants you pay — the facts of the payment (amounts, your wallet address, transaction reference), never your identity documents;
- Authorities — where required by law, legal process, or to report suspected unlawful activity.
We do not sell personal data.
7. Blockchains are public
Transactions you make are recorded on public blockchains that nobody — including Safewire — can edit or erase. Rights to correction or deletion cannot apply to on-chain records; they apply to the data we hold.
8. International transfers
We and our providers process data in Canada and other countries. Where required, we use appropriate safeguards for cross-border transfers.
9. Retention
We keep personal data while your account is active and afterwards as needed for the purposes above — in particular, records of transfers and the identity details attached to them are retained for five years under Canadian anti-money-laundering rules, and ten years where Sint Maarten rules apply; our security and audit records are kept for seven years, which is longer than the five the law requires and is our own standard. Verification records are retained per our provider's terms. Audit records use protected, hashed identifiers.
10. Your rights
Subject to applicable law, you can ask us for access to or correction of your personal data, ask us to delete it (legal retention duties and the public nature of blockchains limit this), and withdraw consent where processing rests on consent. Contact compliance@safewireworld.com. You can also complain to the Office of the Privacy Commissioner of Canada or your local data-protection authority.
To close your account altogether, see Deleting your Safewire account — it sets out how to ask, what we delete, what we must keep and for how long, and what nobody can delete. Read it first: deleting your account destroys the encrypted backup of your wallet key that we hold, so if you have not written down your Secret Recovery Words, nobody — including us — can restore your wallet or the funds in it.
11. Security
We protect data with encryption in transit and at rest, hardware-backed key storage on your device, and strict access controls. No method of transmission or storage is completely secure; keep your device, PIN, passkeys and Secret Recovery Words safe.
12. Children
The Services are for people aged 18 and over.
13. Changes
We may update this policy; material changes will be notified in the app before they take effect.
14. Contact
Safewire Payments Ltd, 205-50 Lonsdale Ave, Office 2383, North Vancouver, British Columbia, Canada V7M 2E6.
Privacy and data requests: compliance@safewireworld.com · Support: support@safewireworld.com.