Privacy Policy
What we collect, why we collect it, and what we deliberately never receive.
Last updated
The short version. Unheld never receives your secret recovery phrase, private keys, or funds. Wallets are generated in your browser and the phrase never leaves it — we only receive the watch-only public key needed to recognise payments to your addresses. This is an architectural property, not a policy promise: there is no code path that transmits a recovery phrase to us.
1. Who we are
Unheld is operated by Ben Daamar Mohamed, based in Abu Dhabi Global Market (ADGM), Abu Dhabi, United Arab Emirates. Unheld Ltd is currently being incorporated with the Abu Dhabi Global Market (ADGM) Registration Authority; this page will be updated with the registered entity details once formation completes.
For questions about this policy or to exercise any right described below, contact support@unheld.io.
2. Which law applies
We process personal data in accordance with:
- the ADGM Data Protection Regulations 2021
- the UK and EU General Data Protection Regulation, where a merchant is established in those territories
Where both apply, we follow whichever gives you the stronger protection.
3. What we collect
Account data
| Data | Why |
|---|---|
| Email address | Login, password reset, service and security notices |
| Password (hashed with Argon2) | Authentication. We never store it in a readable form. |
| Two-factor secret, if you enable 2FA | Verifying login codes |
| Business name and country | Account identification and invoice display |
Access-application data
If registration asks you to apply for access, we collect your name and email address plus any company name and intended use case you choose to provide. We use it to assess the application, prevent duplicate entries, and contact selected applicants with a registration invitation.
Wallet data
| Data | Why |
|---|---|
| Extended public key (xpub) and derived receiving addresses | Watching the blockchain for payments to you. A public key can generate addresses and observe them; it cannot spend, sign, or move funds. |
| Secret recovery phrase / private keys | Never collected, never transmitted, never stored. |
Transaction data
Invoices you create (amount, asset, chain, status, expiry), payments detected against them, transaction hashes, and any customer reference or metadata you choose to attach. If you use customer records or subscriptions, we store the customer identifiers you supply.
Technical data
IP addresses, browser user-agent, and timestamps in server and security logs; API key usage; webhook delivery attempts and their outcomes. These exist for security, abuse prevention, rate limiting, and diagnosing failures.
On-chain data is public and permanent. Anything settled on a blockchain — addresses, amounts, timing — is published by that network, not by us. It is outside our control, cannot be deleted by us or by you, and will remain visible after you close your account. Please consider this before putting identifying information in an on-chain reference.
4. Why we process it
- To perform the contract — creating invoices, detecting payments, sending webhooks.
- Legitimate interests — securing the service, preventing abuse, debugging faults, and understanding aggregate usage.
- Legal obligation — where we are required to retain records or respond to a lawful request.
We do not sell personal data, and we do not use it for advertising or profiling.
5. Who else processes it
We use a small number of providers. Each receives only what its function needs.
| Provider | Function | Location |
|---|---|---|
| netcup GmbH | Server hosting and database | Germany |
| Cloudflare, Inc. | DNS, TLS termination, CDN, DDoS protection | Global |
| Alchemy, Moralis | Blockchain data and payment detection. Receives receiving addresses — which are public on-chain regardless — never personal account data. | United States |
| Google Analytics | Aggregate website usage on the public marketing site only | United States |
| Google reCAPTCHA | Spam and automated-submission protection on waitlist and registration forms | United States |
Email is sent from our own mail server; outbound messages are not handed to a third-party email provider.
Where a provider is outside your jurisdiction, transfers rely on standard contractual clauses or the provider's equivalent safeguards.
6. How long we keep it
- Access applications — until the admission process ends, you register, or you ask us to delete the application.
- Account data — for the life of the account, then deleted or anonymised within 90 days of closure, unless retention is legally required.
- Invoice and payment records — retained for accounting and dispute purposes; typically seven years.
- Security and access logs — up to 12 months.
- Webhook delivery records — 90 days.
7. Your rights
You may request access to your data, correction of inaccuracies, deletion, restriction of processing, a portable copy, or object to processing based on legitimate interests. You may also withdraw consent where processing relies on it.
Email support@unheld.io. We respond within 30 days. If you are unsatisfied, you may complain to the ADGM Office of Data Protection or to your local supervisory authority.
One limit we cannot work around: we cannot delete on-chain records. Deleting your account removes it from our systems; it does not and cannot remove transactions from a public blockchain.
8. Security
Passwords are hashed with Argon2. Webhook signing secrets are held in a secrets manager, not in the application database. All traffic is served over TLS. Two-factor authentication is available and recommended. Webhook payloads are signed with HMAC-SHA256 so you can verify they came from us.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to support@unheld.iorather than disclosing it publicly, and we will work with you.
9. Cookies
The dashboard uses strictly necessary cookies to keep you signed in. The public marketing site uses Google Analytics to measure aggregate traffic. Forms protected by Google reCAPTCHA may cause Google to read or set identifiers used for abuse prevention. Blocking reCAPTCHA can prevent a protected form from being submitted.
10. Children
Unheld is a business service and is not directed at anyone under 18. We do not knowingly collect data from children.
11. Changes
We will update this page when our processing changes and revise the date at the top. Material changes affecting your rights will be emailed to account holders.