Skip to content

Legal

Privacy policy

Last updated: [PLACEHOLDER: date set at launch]

01

Who we are

Suward processes business payments in cryptocurrencies. The controller of the data described here is the operator of the Suward service; for all privacy matters, contact payments@suward.com. This policy describes what we collect from merchants, their team members, and payers, and why.

02

What we collect

Account data: email, name, business information you provide. Payment data: on-chain transaction data (addresses, amounts, assets, transaction identifiers), payment metadata you attach (order identifiers), and screening results. Technical data: logs, device and usage data, cookies (see the Cookie Policy).

03

Why we process it

To provide the service (creating payments, crediting balances, executing withdrawals); to meet compliance obligations (AML and sanctions screening of every incoming transaction, pattern monitoring, record-keeping); to secure the service (fraud and abuse prevention, access control); to communicate with you (service messages, replies to your requests).

04

Screening providers

For Extended screening, transaction data is processed by independent blockchain-analytics providers under contractual safeguards. On-chain data is, by its nature, public.

05

Sharing

We share data with service providers under contract, with authorities where the law requires it, and in corporate transactions as permitted by law. We do not sell personal data.

06

Retention

Payment and screening records are retained as long as required by financial-compliance law; account data — for the life of the account and any legally required period after.

07

Your rights

Depending on the law that applies to you, you may have the right to access the personal data we hold about you, to correct or delete it, to restrict or object to its processing, and to receive a portable copy. Send requests to payments@suward.com; we answer within the time applicable law sets. One limit is technical rather than legal: data recorded on public blockchains is public by nature and cannot be erased from them — where erasure applies, we stop associating that data with your account instead.

08

Security

We secure account access with password hashing, optional two-factor authentication, and role-based permissions for team members you invite. API keys are shown once at creation, can be rotated or revoked instantly, and are scoped to a single project, so a leaked key's blast radius stays contained. Webhook payloads we send you are signed with Ed25519 so you can verify they came from Suward before acting on them. [TO CONFIRM: any third-party security audits or certifications to disclose here — not stated in current source material]

09

Changes

Material changes are announced on this page and, for account holders, by email or dashboard notice.

Questions about this policy: payments@suward.com