InvisiPay
  • Home
  • For Merchants
  • Technology
Deck Get Started
  • Home
  • For Merchants
  • Technology
  • Get Started
Legal

Privacy Policy

Last Updated: March 2026  ·  Effective: March 2026

Privacy by design. InvisiPay's core technology — zero-knowledge proofs — means that shielded payment details are never transmitted to or stored by InvisiPay. We only collect the personal data necessary to operate the Services and comply with applicable law.

1. Introduction2. Data Controller 3. Data We Collect4. How We Use Your Data 5. Data Sharing6. International Transfers 7. Data Retention8. Security 9. Your Rights10. Cookies 11. Children12. Changes13. Contact

1. Introduction

InvisiPay, Inc. ("InvisiPay", "we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have in relation to it.

This Policy applies to all products and services offered by InvisiPay, including the InvisiPay website, mobile application, U-Card, Privacy Pay, OTC Exchange, and Invisible Connect API (collectively, the "Services"). By using the Services, you consent to the practices described in this Policy.

We may update this Policy from time to time. If we make material changes, we will notify you by posting the revised Policy on our website or by email. Continued use of the Services after such notice constitutes your acceptance of the updated Policy.

2. Data Controller

InvisiPay, Inc. is the data controller responsible for your personal data collected through the Services. Our contact details are set out in Section 13.

3. Data We Collect

A. Identity & KYC Data

For Services that require identity verification (U-Card, OTC Exchange), we collect:

  • Full legal name and date of birth
  • Government-issued identification document type and number
  • Nationality and country of residence
  • Residential address
  • Profile photograph or selfie (for liveness checks)
  • Source of funds and purpose of account

B. Contact & Account Data

  • Email address and phone number
  • Account login credentials (stored in hashed form)
  • Communication preferences

C. Financial & Transaction Data

  • Blockchain wallet addresses you connect or register
  • U-Card transaction records (merchant name, amount, date, location)
  • OTC Exchange order history
  • Privacy Pay (ZK shielded) transactions: Payment amounts and counterparty details are cryptographically hidden and are NOT accessible to InvisiPay. We only record on-chain commitment hashes and nullifiers as part of protocol operation.

D. Technical & Usage Data

  • IP address and approximate geolocation
  • Device type, operating system, and browser
  • App usage analytics (pages visited, features used, session duration)
  • Error logs and crash reports

4. How We Use Your Data

We use your personal data for the following purposes:

  • Service delivery: Creating and managing your account, processing transactions, issuing and managing your U-Card.
  • KYC/AML compliance: Verifying your identity, screening against sanctions lists, monitoring for suspicious activity, and reporting to relevant authorities as required by law.
  • Security: Detecting and preventing fraud, unauthorised access, and other malicious activity.
  • Product improvement: Analysing usage patterns to improve and develop our Services.
  • Communications: Sending transaction confirmations, security alerts, product updates, and (with your consent) marketing communications.
  • Legal obligations: Complying with applicable laws, regulations, court orders, and requests from regulatory authorities.

5. Data Sharing & Disclosure

We do not sell your personal data. We may share it with:

  • Identity verification providers: Third-party KYC/AML service providers to verify your identity and screen for sanctions.
  • Card network partners: Visa, Mastercard, and the issuing bank or e-money institution for U-Card processing.
  • Payment processors: Banks and payment processors facilitating OTC Exchange transactions.
  • Infrastructure providers: Cloud hosting, database, and security service providers (bound by data processing agreements).
  • Analytics providers: Aggregated, anonymised analytics services to understand product usage.
  • Regulatory authorities: Government agencies, law enforcement, and financial regulators where required by law.
  • Professional advisers: Legal, accounting, and auditing firms under professional secrecy obligations.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity.

6. International Transfers

InvisiPay operates globally. Your personal data may be transferred to and processed in countries outside your home jurisdiction. Where such transfers occur to countries not deemed to provide an adequate level of data protection, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the relevant data protection authority.

7. Data Retention

We retain your personal data for as long as necessary to provide the Services and fulfil the purposes described in this Policy, and to comply with our legal obligations (typically 5–7 years post-account closure for AML/financial record-keeping requirements). When data is no longer required, we securely delete or anonymise it.

8. Security Measures

We implement appropriate technical and organisational measures to protect your personal data, including:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Two-factor authentication for account access
  • Access controls on a strict need-to-know basis
  • Regular security audits and penetration testing
  • Incident response procedures

While we take all reasonable steps to protect your data, no security system is impenetrable. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

9. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data, subject to legal retention obligations.
  • Right to restrict processing: Request that we limit how we use your data in certain circumstances.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at contact@invisipay.fi with the subject line "DATA REQUEST". We will respond within 15 business days.

10. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to recognise returning visitors, understand how the site is used, and improve the user experience. We use the following types of cookies:

  • Strictly necessary: Required for the website to function (session management, security). Cannot be disabled.
  • Analytics: Collect aggregated, anonymised data about how visitors use the site (e.g., pages visited, time on site).
  • Preference: Remember your language and display settings.

On your first visit, a cookie consent banner allows you to accept, reject, or customise non-essential cookies. You can also manage cookies through your browser settings.

11. Children's Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly. If you believe we have inadvertently collected such data, please contact us at contact@invisipay.fi.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated Policy on our website and, where changes are material, notify you by email or in-app notification. The date at the top of this page indicates when the Policy was last revised.

13. Contact & Data Protection Officer

For privacy-related questions, requests, or complaints, please contact our Data Protection Officer:

InvisiPay, Inc. — Privacy Team
Email: contact@invisipay.fi
Subject line: "PRIVACY ENQUIRY"

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.

法律條款

隱私政策

最後更新:2026 年 3 月  ·  生效日期:2026 年 3 月

隱私由設計保障。InvisiPay 的核心技術——零知識證明——意味著隱私支付的交易詳情從不傳輸至 InvisiPay 或由 InvisiPay 儲存。我們僅收集運營服務及遵守適用法律所必要的個人資料。

1. 簡介2. 資料控制者 3. 我們收集的資料4. 資料使用方式 5. 資料分享6. 跨境傳輸 7. 資料保留8. 安全措施 9. 您的權利10. Cookies 11. 未成年人12. 政策變更13. 聯絡我們

1. 簡介

InvisiPay, Inc.(以下稱「InvisiPay」、「我們」或「本公司」)致力於保護您的個人資料。本隱私政策說明我們收集哪些個人資料、如何使用、與誰分享,以及您就此擁有哪些權利。

本政策適用於 InvisiPay 提供的所有產品與服務,包括 InvisiPay 網站、手機應用程式、U 卡、隱私支付、OTC 兌換及 Invisible Connect API(統稱「服務」)。使用服務即表示您同意本政策所述的做法。

我們可能會不時更新本政策。如進行重大變更,我們將在網站上發佈修訂後的政策或通過電子郵件通知您。在此類通知後繼續使用服務,即表示您接受更新後的政策。

2. 資料控制者

InvisiPay, Inc. 是通過服務收集您個人資料的資料控制者,聯絡方式見第 13 條。

3. 我們收集的資料

A. 身份與 KYC 資料

對於需要身份驗證的服務(U 卡、OTC 兌換),我們收集:

  • 法定全名及出生日期
  • 政府頒發身份證件的類型及號碼
  • 國籍及居住國
  • 居住地址
  • 個人照片或自拍(用於活體驗證)
  • 資金來源及開戶目的

B. 聯絡及帳戶資料

  • 電子郵件地址及電話號碼
  • 帳戶登錄憑據(以加密形式儲存)
  • 通訊偏好設置

C. 財務及交易資料

  • 您連結或註冊的區塊鏈錢包地址
  • U 卡交易記錄(商家名稱、金額、日期、地點)
  • OTC 兌換訂單記錄
  • 隱私支付(ZK 加密)交易:支付金額及交易對手方詳情以密碼學方式隱藏,InvisiPay 無法獲取。我們僅作為協議運作的一部分記錄鏈上承諾雜湊值(commitment hash)及 nullifier。

D. 技術及使用資料

  • IP 地址及大概地理位置
  • 設備類型、操作系統及瀏覽器
  • App 使用分析(已瀏覽頁面、已使用功能、會話時長)
  • 錯誤日誌及崩潰報告

4. 資料使用方式

我們將您的個人資料用於以下目的:

  • 服務交付:創建和管理您的帳戶、處理交易、發行和管理您的 U 卡。
  • KYC/AML 合規:驗證您的身份、對制裁名單進行篩查、監測可疑活動,並根據法律要求向相關主管機關申報。
  • 安全防護:偵測和防範欺詐、未經授權訪問及其他惡意活動。
  • 產品改進:分析使用模式,以改善和開發服務。
  • 通訊:發送交易確認、安全提醒、產品更新,以及(經您同意後)行銷通訊。
  • 法律義務:遵守適用法律、法規、法院命令及監管機構要求。

5. 資料分享與披露

我們不會出售您的個人資料。我們可能與以下方分享:

  • 身份驗證服務商:第三方 KYC/AML 服務提供商,用於驗證身份及制裁篩查。
  • 卡組織合作夥伴:Visa、Mastercard 及發卡機構,用於 U 卡處理。
  • 支付處理機構:協助 OTC 兌換交易的銀行及支付機構。
  • 基礎設施服務商:雲端託管、數據庫及安全服務提供商(受數據處理協議約束)。
  • 分析服務商:以匿名化彙總方式提供的使用分析服務。
  • 監管機構:法律要求時向政府機關、執法部門及金融監管機構披露。
  • 專業顧問:受保密義務約束的法律、會計及審計機構。
  • 業務轉讓:若發生合併、收購或資產出售,您的資料可能轉移至繼承主體。

6. 跨境資料傳輸

InvisiPay 在全球範圍內運營。您的個人資料可能被傳輸至您所在司法管轄區以外的國家並在當地進行處理。當此類傳輸涉及未被認定為提供充分資料保護水平的國家時,我們將實施適當保障措施,包括相關資料保護主管機構批准的標準合約條款(SCC)。

7. 資料保留

我們保留個人資料的時間以提供服務及實現本政策所述目的所需時間為準,同時遵守法律義務(通常為帳戶關閉後 5 至 7 年,以滿足 AML/金融記錄保存要求)。當資料不再需要時,我們將安全刪除或匿名化處理。

8. 安全措施

我們採取適當的技術和組織措施保護您的個人資料,包括:

  • 所有傳輸中的資料均採用 TLS/SSL 加密
  • 靜態敏感資料採用 AES-256 加密
  • 帳戶訪問採用雙重驗證
  • 嚴格按需知原則實施訪問控制
  • 定期安全審計及滲透測試
  • 事件響應程序

儘管我們採取了一切合理措施保護您的資料,但任何安全系統均非無懈可擊。若發生影響您權利和自由的資料洩露事件,我們將依法通知您及相關監管機構。

9. 您的權利

根據適用法律,您就個人資料享有以下權利:

  • 查閱權:要求獲取我們持有的您的個人資料副本。
  • 更正權:要求更正不準確或不完整的資料。
  • 刪除權:要求刪除您的資料(受法律保存義務限制)。
  • 限制處理權:在特定情況下要求我們限制使用您的資料。
  • 資料可攜帶權:以結構化、機器可讀的格式接收您的資料。
  • 反對權:反對基於合法利益或直接行銷目的的資料處理。
  • 撤回同意權:如資料處理基於同意,可隨時撤回,不影響撤回前處理的合法性。

如需行使上述任何權利,請發送電子郵件至 contact@invisipay.fi,主旨欄填寫「DATA REQUEST」。我們將在 15 個工作日內回覆。

10. Cookies 及追蹤技術

我們的網站使用 Cookies 及類似追蹤技術,以識別回訪用戶、了解網站使用方式並改善用戶體驗。我們使用以下類型的 Cookies:

  • 必要 Cookies:網站正常運作所必需(會話管理、安全),無法停用。
  • 分析 Cookies:收集關於訪客如何使用網站的匿名彙總資料(如瀏覽頁面、停留時間)。
  • 偏好 Cookies:記住您的語言及顯示設置。

首次訪問時,Cookie 同意提示允許您接受、拒絕或自定義非必要 Cookies。您也可以通過瀏覽器設置管理 Cookies。

11. 未成年人隱私

服務不面向 18 歲以下人士。我們不會故意收集未成年人的個人資料。若我們發現收集了 18 歲以下人士的資料,將立即予以刪除。如您認為我們在無意中收集了此類資料,請聯絡 contact@invisipay.fi。

12. 政策變更

我們可能不時更新本隱私政策,以反映我們的做法、技術或法律要求的變化。我們將在網站上發佈更新後的政策,如屬重大變更,將通過電子郵件或應用程式內通知告知您。本頁頂部的日期顯示政策的最後修訂時間。

13. 聯絡我們及資料保護負責人

如有隱私相關問題、請求或投訴,請聯絡我們的資料保護負責人:

InvisiPay, Inc. — 隱私事務團隊
電子郵件:contact@invisipay.fi
主旨欄:「PRIVACY ENQUIRY」

如您對我們的回覆不滿意,您有權向您所在司法管轄區的相關資料保護監管機構提出投訴。

InvisiPay

Crypto payments, simple and private.

Product
U-Card Privacy Pay For Merchants API Docs
Company
About Blog Careers Press
Connect
Twitter / X Discord Telegram GitHub
© 2026 InvisiPay, Inc. All rights reserved.
Privacy Terms