Settle legal
Privacy Policy
The short version: we collect the minimum needed to run the service, we never have access to your funds or keys, we run no advertising or third-party tracking, and we do not sell personal data.
Last updated: September 12, 2026
1. Who we are and what this covers
Settle operates a non-custodial stablecoin payment platform. This policy explains what data we handle when you use our website, the merchant dashboard, or a hosted checkout page, and the choices you have.
Where we decide why and how data is processed — for merchant accounts, platform security, and abuse prevention — we are the controller. Where we process data about a merchant’s customers on that merchant’s behalf, the merchant is the controller and we act as their processor under our Data Processing Addendum.
2. Data we collect
Merchant accounts: email address (for login and notifications), business name, and the settings you configure — payout wallet address and network, brand colour, webhook URLs, and API keys.
Payment sessions: when a customer opens a payment link or invoice we store the invoice details (amount, currency, chain, token), the email or name the customer chooses to provide (optional — merchants can enable anonymous checkout), and the on-chain transaction hash and payer address once payment settles. The latter come from public blockchains and are used to reconcile and prove payment.
Visit counts: a salted, irreversible hash of the visitor’s IP address — never the IP itself — plus referring page and browser user-agent, deduplicated per day so merchants can count payment-link visits. The hash cannot be reversed and is not used to profile anyone or to follow them across sites.
Dispute messages: the content of messages exchanged between a merchant and a customer in a dispute thread.
Operational logs: security and abuse-prevention records such as rate-limit events and webhook delivery results.
3. What we deliberately do not collect
We do not collect wallet private keys or seed phrases — we never see them and could not act on them if we did. We do not collect payment card or bank account details. We run no third-party advertising, no social pixels, no session-replay tooling, and no external analytics scripts, including on checkout pages. Customers can pay without creating an account, and merchants can switch off email collection entirely.
4. How we use data, and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Authenticating merchants and providing the dashboard | Performance of a contract |
| Creating, displaying, and reconciling invoices | Performance of a contract |
| Sending receipts, invoices, and renewal reminders | Performance of a contract |
| Securing the platform and preventing abuse | Legitimate interests |
| Counting payment-link visits for merchants | Legitimate interests |
| Meeting tax, accounting, and legal obligations | Legal obligation |
We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell personal data or share it for cross-context behavioural advertising.
5. Who we share data with
We rely on a small number of infrastructure providers — currently Supabase (accounts and database), Netlify (hosting), Alchemy and Helius (blockchain data and settlement detection), and Resend (transactional email). Each processes data only as needed to deliver its function, under contractual security obligations. The current list, with the data each one handles, is published at /legal/subprocessors.
We may also disclose data where required by valid legal process, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy.
6. Blockchain data is permanent
Payments settle on public blockchains, where transaction details — amounts, wallet addresses, timestamps, hashes — are permanently and publicly visible by design, replicated worldwide. Settle cannot delete, amend, or restrict on-chain data, and neither can anyone else. We associate on-chain transactions with invoices solely to reconcile payments. Please take this into account before paying: a wallet address may be linkable to other activity you have conducted with it.
7. International transfers
Our providers may process data outside your country, including in the United States. Where personal data originating in the EEA, the UK, or Switzerland is transferred to a country without an adequacy decision, the transfer is made under Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable.
8. Retention
Merchant account data is retained while your account is active and for up to ninety days after closure, except where longer retention is required for tax, accounting, or legal purposes. Invoice and settlement records are retained for the period required by applicable financial record-keeping rules. Visit-count hashes are retained in aggregated form only. Data already written to public blockchains cannot be deleted.
9. Your rights
Depending on where you live, you may have the right to access a copy of your personal data, to correct inaccurate data, to request erasure, to restrict or object to processing, to data portability, and to withdraw consent where processing relies on it. Where we rely on legitimate interests you may object at any time.
Exercise any of these by writing to [email protected]. We will respond within the period required by applicable law and will not discriminate against you for making a request. If you are a customer of a merchant rather than a merchant yourself, contact that merchant first — they control your data — and we will assist them. You also have the right to complain to your local data protection authority.
10. Security
We apply technical and organisational measures appropriate to the risk, including TLS in transit, encryption at rest, database-enforced tenant isolation via Row Level Security, HMAC verification of webhooks, and strict separation of privileged keys from anything shipped to a browser. Our Security Policy describes these in detail and explains how to report a vulnerability.
11. Children
The service is not directed to children and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact [email protected] and we will delete it.
12. Cookies
We set only strictly necessary cookies, all of which exist to keep a signed-in merchant session alive. There are no advertising or analytics cookies anywhere on the platform. See the Cookie Policy for the full list.
13. Changes and contact
If this policy changes materially we will announce the update on the site and, where we hold your email address, notify you. Continued use after changes take effect constitutes acceptance. Questions go to [email protected].