Privacy Policy
Last updated: 19 August 2026
1. Who is responsible for your data
Demo Operator Ltd. (the “Operator”, “we”) operates the Paythara service and is the data controller for the personal information described here. Identity verification and custody are performed by our regulated payment services provider (the “Provider”), which processes your information under its own privacy policy, presented to you during verification.
2. What we collect
- Account information — your name, email address and password (stored only as a cryptographic hash).
- Transaction information — recipients you save (names, bank or mobile-money details, and for United States bank payouts the account holder's postal address, which the payment provider requires to open the payout account), the transfers you make (amounts, currencies, rates, fees, references, statuses and timestamps), and your virtual account details.
- Verification outcome — the Provider's customer reference for you and the current status of your verification (for example: in review, approved).
- Technical information — sign-in sessions and the log records needed to run and secure the Service.
3. What we deliberately do not hold
Your identity documents — passport, ID card, proof of address, photographs — go directly to the Provider through its hosted verification flow. They never reach our servers and we cannot access them. We also do not store your stablecoin balances (we fetch them from the Provider when you view them) and we never see or store your card or bank credentials.
4. Why we process your information
- To provide the Service — executing transfers, showing balances, sending service messages (performance of our contract with you).
- To meet legal obligations — identity verification, sanctions screening, transaction monitoring, record-keeping and regulatory reporting under anti-money-laundering law.
- To keep the Service secure — fraud prevention, session management and abuse detection (our legitimate interest).
We do not sell your personal information and we do not use it for third-party advertising.
5. Who we share it with
- The Provider — the details needed to verify you, execute your transfers and operate your accounts.
- Payout partners — the recipient and amount details needed to deliver a specific payout.
- Authorities — where anti-money-laundering, tax or other law requires reports or responses to lawful requests.
- Service infrastructure — hosting and email providers acting under our instructions.
6. How long we keep it
Financial records — including identity-verification outcomes and transaction records — must by law be retained for a number of years after your relationship with us ends (commonly five years under anti-money-laundering law; the exact period depends on the Operator's jurisdiction). We keep them for that period and then delete or anonymise them. Information without a legal retention duty is deleted when no longer needed.
7. Security
Passwords are stored only as salted cryptographic hashes. Access to production systems is restricted, transfers of data are encrypted in transit, and every consequential action in the Service is recorded in an audit log.
8. Your rights
Depending on your jurisdiction, you may have the right to access the personal information we hold about you, correct it, receive a copy, object to certain processing, or request deletion. Deletion requests cannot override legal retention duties (section 6) — where records must be kept, we restrict them instead of erasing them. To exercise a right, contact us at the support address in the footer; you may also have the right to complain to your data-protection authority.
9. Cookies
The Service sets three strictly-necessary cookies and no others: your sign-in session, the language you have chosen, and whether you prefer the light or dark theme. The last two hold a preference and nothing else. Both are sent to our server with every request, because the page is rendered there in your language and theme. The language you choose is also saved to your account, and that saved choice is what the emails we send you are written in — the interface itself follows the cookie, so on a new device it starts from your browser's language until you choose again. There are no advertising or cross-site tracking cookies, which is why there is no cookie banner.
10. International transfers
The Provider and our hosting infrastructure may process information in countries other than yours. Where that happens, we rely on the safeguards recognised by the privacy law that applies to you, and the Provider does the same under its own policy.
11. Changes and contact
We will post any changes to this policy here and, for material changes, tell you in the app or by email. Questions and requests: the support address in the footer of every page.