Legal
Privacy policy
Last updated: [PLACEHOLDER: date set at launch]
Who we are
Suward processes business payments in cryptocurrencies. The controller of the data described here is the operator of the Suward service; for all privacy matters, contact payments@suward.com. This policy describes what we collect from merchants, their team members, and payers, and why.
What we collect
Account data: email, name, business information you provide. Payment data: on-chain transaction data (addresses, amounts, assets, transaction identifiers), payment metadata you attach (order identifiers), and screening results. Technical data: logs, device and usage data, cookies (see the Cookie Policy).
Why we process it
To provide the service (creating payments, crediting balances, executing withdrawals); to meet compliance obligations (AML and sanctions screening of every incoming transaction, pattern monitoring, record-keeping); to secure the service (fraud and abuse prevention, access control); to communicate with you (service messages, replies to your requests).
Screening providers
For Extended screening, transaction data is processed by independent blockchain-analytics providers under contractual safeguards. On-chain data is, by its nature, public.
Retention
Payment and screening records are retained as long as required by financial-compliance law; account data — for the life of the account and any legally required period after.
Your rights
Depending on the law that applies to you, you may have the right to access the personal data we hold about you, to correct or delete it, to restrict or object to its processing, and to receive a portable copy. Send requests to payments@suward.com; we answer within the time applicable law sets. One limit is technical rather than legal: data recorded on public blockchains is public by nature and cannot be erased from them — where erasure applies, we stop associating that data with your account instead.
Security
We secure account access with password hashing, optional two-factor authentication, and role-based permissions for team members you invite. API keys are shown once at creation, can be rotated or revoked instantly, and are scoped to a single project, so a leaked key's blast radius stays contained. Webhook payloads we send you are signed with Ed25519 so you can verify they came from Suward before acting on them. [TO CONFIRM: any third-party security audits or certifications to disclose here — not stated in current source material]
Changes
Material changes are announced on this page and, for account holders, by email or dashboard notice.
Questions about this policy: payments@suward.com