Legal

Privacy Policy

Last updated: 2026-05-13 · v0.1 — pending legal review. This Privacy Policy describes how Halfin ("Halfin", "we", "us", or "our") collects, uses, shares, retains, and protects personal data when you visit our website at https://thehalfin.com, register a Merchant account, integrate our API, or otherwise interact with our Services.

01

Who this Policy covers

This Policy applies to:

  • Visitors to the Website.
  • Merchants and their authorized personnel.
  • Beneficial owners and representatives of Merchants.
  • End-Users completing payments via Halfin-powered checkout interfaces.
02

Merchant-controlled data

This Policy does not apply to personal data Merchants process about their own customers using Halfin as a technical service. Merchants are independent data controllers for that data.

03

Data controller

The data controller for personal data collected through the Services is Halfin. Entity details and registered office: [to be inserted before publication].

Privacy questions and rights requests: [email protected]

04

Data we collect — from Website visitors

We collect the following categories of personal data from Website visitors:

  • Technical data: IP address, device type, operating system, browser type and version, screen resolution, language settings, referrer URL, pages viewed, time spent, and similar.
  • Cookies and analytics: identifiers, session data, and behavioral analytics as described in our Cookie Policy.
05

Data we collect — from Merchants during onboarding (KYB)

During onboarding (KYB) we collect:

  • Business information: legal entity name, registration number, jurisdiction of incorporation, registered office, business address, trading name, website, business description, industry codes.
  • Beneficial ownership and control: names, dates of birth, nationality, addresses, identification documents, and ownership percentages for directors, beneficial owners (typically 25%+), and authorized signatories.
  • Identification documents: government-issued ID (passport, national ID, driver's license), proof of address (utility bill, bank statement).
  • Financial information: banking details, payment history, source of funds, source of wealth where relevant.
  • Compliance information: sanctions screening results, PEP status, adverse media findings.
06

Data we collect — from Merchants during ongoing use

During ongoing use of the Services we collect:

  • Transaction data: invoice records, payment records, payout records, wallet addresses, amounts, timestamps, network details, statuses.
  • Dashboard activity: logins, actions taken, API key usage, webhook deliveries, audit log entries.
  • Communications: support tickets, emails, and other correspondence.
07

Data we collect — from End-Users completing payments

From End-Users completing payments we collect:

  • Transaction details: wallet address from which payment originates, amount, timestamp, network.
  • Technical data: IP address, device type, and similar as described above.
  • No KYC by default: End-Users do not register accounts and do not undergo identity verification through Halfin for the purpose of paying an invoice. End-Users completing a transaction are not asked for personal identification documents.
08

Lawful basis for processing

We process personal data on the following lawful bases:

  • Contractual necessity: to provide the Services to Merchants and complete End-User transactions.
  • Legal obligation: to comply with AML, sanctions, tax, accounting, and other regulatory requirements.
  • Legitimate interests: to operate, secure, and improve the Services; to prevent fraud; to enforce these Terms; to defend legal claims.
  • Consent: for optional cookies, marketing communications, and similar purposes where consent is required.
09

Legitimate-interest balancing

Where we rely on legitimate interests, we balance them against the rights and interests of the data subject.

10

How we use personal data

We use personal data to:

  • Provide and operate the Services.
  • Verify the identity of Merchants and their beneficial owners (KYB).
  • Conduct sanctions and PEP screening.
  • Detect, investigate, and prevent fraud, money laundering, and other unlawful activity.
  • Monitor transactions for compliance and risk purposes.
  • Provide customer support and respond to inquiries.
  • Send service notifications, security alerts, and operational communications.
  • Comply with legal obligations and respond to lawful requests from authorities.
  • Defend and exercise legal claims.
  • Improve platform reliability, security, and feature design.
  • Send marketing communications where consent has been provided.
11

We do not sell personal data

We do not sell personal data to third parties.

12

Sharing of personal data — subprocessors

We share personal data with the following categories of recipients. Subprocessors are data processors acting on our behalf:

  • Identity verification and KYB providers: to verify Merchant identity and beneficial ownership.
  • Sanctions and PEP screening providers: to comply with AML and sanctions obligations.
  • Hosting and infrastructure: cloud hosting, CDN, DNS, monitoring.
  • Email and notifications: transactional and operational communications.
  • Analytics: website usage analytics where consent has been obtained.
  • Customer support tooling: ticketing, helpdesk, and live chat.
13

Sharing of personal data — other recipients

All subprocessors are contractually bound to comply with confidentiality, data protection, and security obligations consistent with applicable law. A current list of subprocessors is available on request and will be published as an addendum.

Regulators, law enforcement, and similar: we may disclose personal data to financial intelligence units, law enforcement, tax authorities, and regulators where required by law, court order, or in connection with lawful investigations.

Successors and corporate transactions: in the event of a merger, acquisition, sale of assets, or similar corporate transaction, personal data may be transferred to a successor entity subject to equivalent privacy protections.

Professional advisors: lawyers, accountants, auditors, and similar advisors under confidentiality obligations.

14

International data transfers

Personal data may be transferred to and processed in jurisdictions outside the data subject's country of residence, including jurisdictions that may not provide an equivalent level of legal protection.

Where personal data is transferred to a jurisdiction that does not provide equivalent protection, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, UK International Data Transfer Agreement, or other lawful transfer mechanisms.

15

Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • KYB and AML records: retained for at least five (5) years after the end of the business relationship, or longer where required by applicable law.
  • Transaction records: retained for at least five (5) years after the transaction, or longer where required.
  • Communications: retained for as long as needed for support, dispute resolution, and legal defense.
  • Website analytics: retained according to cookie expiration and analytics provider defaults; see the Cookie Policy.
  • Marketing data: retained until consent is withdrawn.
16

Deletion after retention

After the retention period, personal data is securely deleted or anonymized.

17

Data subject rights

Subject to applicable law, you have the right to:

  • Access: obtain confirmation of whether we process your personal data and a copy of that data.
  • Rectification: correct inaccurate or incomplete personal data.
  • Erasure: request deletion of personal data where the legal basis no longer applies and no overriding obligation requires retention.
  • Restriction: restrict processing in certain circumstances.
  • Objection: object to processing based on legitimate interests.
  • Portability: receive your personal data in a structured, commonly used, machine-readable format.
  • Withdraw consent: where processing is based on consent, withdraw consent at any time without affecting prior processing.
  • Lodge a complaint: with a supervisory authority in your jurisdiction.
18

Exercising your rights

To exercise any of these rights, contact [email protected]. We will respond within the timeframes required by applicable law (typically one month).

We may need to verify your identity before processing a rights request to prevent unauthorized disclosure.

Some rights may be limited where exercising them would conflict with our legal obligations (for example, AML retention duties) or with the rights of other persons.

19

Security

We implement organizational and technical security measures appropriate to the risks of processing, including:

  • Encryption in transit (TLS) and at rest where appropriate.
  • Access controls, including role-based access for personnel.
  • Network segmentation and firewall protection.
  • Logging, monitoring, and intrusion detection.
  • Regular security reviews.
  • Vendor due diligence for subprocessors.
20

Security limitations

No system is fully secure. We cannot guarantee the absolute security of personal data, but we will notify affected data subjects and supervisory authorities of any breach in accordance with applicable law.

21

Cookies and similar technologies

We use cookies and similar technologies on the Website. Details on the categories of cookies used, their purposes, retention periods, and how to manage your preferences are described in the Cookie Policy.

22

Children

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will take steps to delete it.

23

Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Website, by email, or through the dashboard. The "Last updated" date at the top of this Policy reflects the most recent revision.

24

Contact

Privacy inquiries and rights requests: [email protected]

Data Protection Officer (if appointed): [to be confirmed]

Registered office and entity: [to be inserted before publication]

related

Keep reading across the cluster.

Terms of UseThe master agreement governing use of the halfin Services.AML PolicyOur anti-money-laundering controls: KYB, sanctions and wallet screening, monitoring.halfin FAQ — how crypto payments work end to endHow halfin invoicing, checkout, deposit addresses, payouts, conversion, and webhooks work. Browse every question or read the cross-cutting answers.Security and controls at halfinHow halfin protects the money path: HMAC-signed webhooks, scoped API keys, payout approvals with an audit trail, and reorg-aware crediting.Legal centerThe halfin legal center: Terms of Use, Privacy Policy, AML Policy, Cookie Policy and more. All documents are version v0.1 and pending full legal review.Refund PolicyWorking draft of how refunds work in our non-custodial model.Restricted ActivitiesActivities we do not provide Services for.Restricted CountriesJurisdictions where we do not provide Services.Are crypto payments final?Yes — a confirmed on-chain transfer is irreversible and there are no chargebacks. Finality is a property of the chain, which is what makes reconciliation clean.Can I build while onboarding is pending?Yes — build against a sandbox key first. The sandbox is the same API as production with test data, and your full integration is verified before going live.How does halfin attribute operator actions?Each action a person takes in the dashboard is recorded against them, so after the fact you can answer who released a withdrawal or issued an API key.What happens during onboarding review?Onboarding review is the business-verification step before a live key moves real funds. What it establishes, why it scales to your business, and where it is settled.