HedgePay App Privacy Policy
Version 0.0.1 · Updated 3 September 2026
1. Controller
Nabla Finance OÜ, registry code 17287187, VAT EE103017547, Pikk 7, Tallinn 10123, Estonia, is the controller of personal data processed through the HedgePay mobile application (the “App”). Contact for all privacy matters: contact+privacy@hedgepay.app.
Because the controller is established in the European Union, the General Data Protection Regulation (GDPR) applies to all personal data we process through the App, wherever you are located. Where the law of your country gives you additional rights, section 11 explains how to use them.
This policy covers the App. The hedgepay.app website has its own privacy policy.
2. What we collect and why
2.1 Account and sign-in. When you sign in, our authentication and wallet infrastructure provider verifies your email address with a one-time code and confirms it to us. We store: your email address, a user identifier from that provider, an internal account identifier we generate, the username you choose, the purpose of use you select, a display name and profile picture if you add them, and sign-in timestamps. We do not receive or store your one-time codes. Legal basis: performance of this contract with you (GDPR art. 6(1)(b)).
2.2 Wallet. We store the public address of your Stellar wallet. The address identifies your transactions on the public Stellar network. We never hold the signing key (see the User Agreement, section 6). Legal basis: art. 6(1)(b).
2.3 Transactions and activity. To show your history and send you notifications, we store records of your activity: amounts, currency, transaction hashes, memos, and the counterparty’s username, identifier, address and, where you saved one, the name label you gave them. Blockchain transactions themselves are public on the Stellar network and are outside our control. Legal basis: art. 6(1)(b).
2.4 Contacts. When you save a recipient, we store the name you typed for them and whether it matched their verified name. Legal basis: art. 6(1)(b).
2.5 Recipient confirmation. When you pay a username, our server compares the recipient’s verified name against the name you saved and returns only a match verdict. The verified name is not shown to you.
2.6 Identity verification (KYC). Verification for currency conversion is performed by Bridge, which acts as an independent controller for it (section 3). Our part: when you start verification we send your name and email address to Bridge to open the process; when you complete the in-App questionnaire we forward your answers to Bridge (purpose of the account, employment status, source of funds, occupation, expected monthly volumes, whether you act for someone else, nationality, place of birth). We store the verification status, the capabilities Bridge has approved, and, once verified, the name Bridge verified. Legal basis: art. 6(1)(b) (steps necessary to give you the conversion features you request).
2.7 Deposits and withdrawals. To let you receive and withdraw local currency we store: the deposit coordinates issued for you (such as a Pix code, an IBAN, or a US account and routing number pointing to the conversion provider), and the withdrawal destinations you save — your Pix key, your IBAN, or your US bank account and routing number, with the account holder’s name and, where required, address. We store these because the provider masks them on later reads and the App needs to display them to you. Legal basis: art. 6(1)(b).
2.8 Notifications. If you allow notifications, we store your device’s push token and the content of the notifications sent to you (for the in-App notification centre). Legal basis: consent, given through the operating-system permission and withdrawable in your device settings (art. 6(1)(a)); storing the notification centre content, art. 6(1)(b).
2.9 Profile picture. If you add one, it is stored with our hosting provider and shown only to signed-in users of the App through short-lived links. Your username and profile picture are visible to other signed-in users who search for your username. Legal basis: art. 6(1)(b).
2.10 Technical data. Our servers keep operational logs of API requests (method, path, timestamps, status). The hosting platform records standard access logs, which include IP addresses, under its own settings. We use logs for security and to keep the service running. Legal basis: legitimate interest in security and operation (art. 6(1)(f)).
2.11 No tracking. The App contains no analytics and no crash-reporting SDKs. We do not profile you and we do not use your data for advertising.
3. Data Bridge collects as its own controller
The identity documents, photo or liveness capture, date of birth, residential address, phone number and tax identification number required for verification are provided by you directly to Bridge inside its hosted verification flow. That data goes to Bridge, not to us; we never receive or store it. For this data Bridge is a separate, independent controller under its own privacy policy — Bridge’s EEA policy states: “We are the controller of the Personal Data obtained via the Services”. Depending on your residence, the responsible Bridge entity is Bridge Building Inc (United States), Bridge Building S.A. (European Economic Area, Luxembourg), or Bridge Building Limited (elsewhere). Bridge’s privacy policies are published at https://www.bridge.xyz/legal/overview. Exercise rights over that data with Bridge; we will help you route a request.
4. Who processes data for us
We share personal data with providers that process it to run the App:
- Our authentication and wallet infrastructure provider — processes your email address for sign-in and operates the wallet service through which you sign transactions.
- Bridge (entities in section 3) — currency conversion. Receives the data in sections 2.6 and 2.7. For verification data it is an independent controller (section 3); for executing your transfers it acts under its own terms.
- DeFindex (api.defindex.io) — Earn vault operations and rates. Receives your wallet’s public address.
- Expo (Expo push service, USA) — delivery of push notifications. Receives push tokens and notification content.
- Google Cloud (Google Ireland Limited / Google LLC) — application hosting in the European Union (region europe-west4) and file storage, including profile pictures.
- MongoDB Atlas (MongoDB, Inc.) — database hosting.
- Mailgun Technologies, Inc. (a Sinch company; EU data region) — delivery of service emails.
We may also disclose data where the law requires it, or to protect our rights or the safety of others. We do not sell personal data and we do not share it with advertisers.
5. Data on your device
The App stores on your device: your sign-in session and its keys, in the operating system’s secure storage (Keychain on iOS, Keystore on Android); a local copy of your activity and transaction history, including counterparty names and memos, in a local database; cached balances, contacts and interface preferences. This data stays on the device. On a device where you are signed in, the App reopens without asking for a code. Anyone who can unlock your device can open the App. Signing out removes the session and clears cached account data; deleting the App removes the rest. The App does not read your contacts book, location, photos or files, except the photo you choose for your profile picture and camera access when you scan a code or complete verification.
6. Retention
We keep your data while your Account is open. When your Account is closed, or when you ask us to delete your data, we delete or anonymise it without undue delay, except what we must keep to comply with law, to resolve disputes or to enforce agreements — and we tell you what we are keeping and why. An in-App account deletion control is a beta capability and will be added; until then, deletion requests are handled through contact+privacy@hedgepay.app. Server logs are short-lived operational records. Records held by Bridge follow Bridge’s own retention obligations.
7. International transfers
We host the App’s backend and database in the European Union. Some providers process data in the United States (Expo; Google LLC; Mailgun; MongoDB, Inc. depending on cluster region; Bridge Building Inc for US users). Where data leaves the European Economic Area, we rely on the EU–US Data Privacy Framework for certified providers and otherwise on the European Commission’s Standard Contractual Clauses. Copies of the safeguards are available on request.
8. Security
Data in transit is encrypted (TLS). Sessions are held in the device’s secure storage. Access to production systems is limited to people who need it. We never hold the signing keys for your wallet. No system is completely secure; if we become aware of a breach affecting your data we will notify you and the supervisory authority as the law requires.
9. Your rights (GDPR)
You have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting processing done before withdrawal. To exercise any of these, email contact+privacy@hedgepay.app. We may ask you to confirm your identity. We respond within one month.
You can complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee). You may also complain to the authority in your own EU country.
Data recorded on the Stellar network (addresses, transactions) is public and permanent by design; we cannot erase it.
10. Children
The App is not directed at people under 18 and we do not knowingly process their data. If you believe we have, contact us and we will delete it.
11. Country-specific information
Brazil. If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) also applies. You have the rights listed in article 18 of the LGPD, including confirmation of processing, access, correction, anonymisation, deletion, portability, and information about sharing. Our contact person for LGPD matters (encarregado) can be reached at contact+privacy@hedgepay.app. The supervisory authority is the ANPD.
Argentina. If you are in Argentina, Law 25.326 also applies. You have the rights of access, rectification, updating and deletion of your data, exercisable free of charge at intervals of not less than six months unless a legitimate interest is shown. The Agencia de Acceso a la Información Pública (AAIP) is the authority responsible for enforcing Law 25.326 and receives complaints about non-compliance.
Colombia. If you are in Colombia, Law 1581 of 2012 also applies. By accepting this policy in the App you give your prior, express and informed authorisation to the processing described here. You may know, update, correct and delete your data and revoke your authorisation at any time by emailing us. The Superintendencia de Industria y Comercio (SIC) is the supervisory authority.
Other countries. If the law of your country gives you rights beyond those listed here, you can exercise them by contacting us and we will honour them where the law applies to us.
12. Changes
We may update this policy. The version and date at the top identify the current text. Material changes are shown in the App and, where we hold your email address, announced by email.
13. Contact
Nabla Finance OÜ, registry code 17287187, VAT EE103017547, Pikk 7, Tallinn 10123, Estonia. contact+privacy@hedgepay.app.