FurlPay Docs
Open App
  • Introduction
  • Quickstart
  • For AI Agents
  • Monorepo
  • API Routes
  • Authenticationnew
  • Webhook Eventsnew
  • Error Codesnew
  • Rate Limitsnew
  • Agentic Payments (x402)
  • Agent Trust & Mandates (TAP)
  • CCTP Cross-Chainnew
  • LI.FI Swapsnew
  • FurlPay Travels (Travel MCP)
  • Solana Actions & Blinks
  • Claude Connectornew
  • AI Assistants
  • Stripe Crypto
  • Persona KYC
  • MiCA Roadmap
  • Security Posturenew
  • MPC & WebAuthn
  • Help Centernew
  • Getting Started
  • KYC Verification
  • Passkeys & Biometrics
  • Privacy & Data Protection
  • Transaction Statuses
  • Gasless Transfers
  • Deposits & Withdrawals
  • Managing Virtual Cards
  • Freezing & Unfreezing Cards
  • Declined Transactions
  • SDK & API Support
  • x402 Monetization Basics
  • Booking Travel
  • Travel Refunds & Cancellations

Resources

  • Changelog
  • System Status
  • OpenAPI Spec
  • Community
  • GitHub
Docs/Help Center/Privacy & Data Protection

Help Center

Privacy, Data Protection & GDPR

Plain-language answers to what FurlPay stores, what it deliberately does not, and how to exercise your data rights.

What we store

  • Account data: email, verification tier, region, security settings.
  • Financial records: your transactions and balances — retained as required by financial regulation, which overrides deletion for these records.
  • Support tickets: what you write to support, kept per-account with a bounded history.

What we deliberately do not store

  • Passwords — none exist. Sign-in is one-time codes and passkeys.
  • Your private keys or recovery phrases — FurlPay is non-custodial for on-chain assets; keys stay on your device.
  • Secrets pasted into support tickets — card numbers, recovery phrases, and API keys are stripped automatically before a ticket is stored or emailed, keeping only safe fragments like a card's last four digits.

Secrets never come back out

API responses never include authenticator secrets, session tokens, private keys, or full card numbers — responses are stripped server-side as a hard rule, not a UI choice.

Your GDPR rights

  • Access / export: request a copy of your data via a Support Center ticket in the KYC category.
  • Rectification: profile fields are self-service; verified-identity fields change via a KYC re-submission.
  • Deletion: self-service, in Profile → Delete account (in the Android app or on the web — no app install required). You re-authenticate, confirm, and the account is erased immediately: profile and contact details, passkeys and linked sign-ins, balances, cards, bills, transaction history, trips, support conversations, agent keys and push registrations. Two categories survive, and the confirmation screen says so before you confirm: settled on-chain deposit records (kept as the permanent record of funds that moved, with your account detached from them) and the security/compliance audit trail (kept for fraud prevention, dispute resolution and auditing — it records that actions happened, not who you are). Where financial record-keeping obligations apply, they override deletion for the records they cover. Full detail: Delete your FurlPay account. If you cannot sign in, open a ticket and we will verify ownership before acting.

KYC-category tickets are mirrored into an internal compliance feed on creation, so a data request is visible to the compliance team immediately, not whenever a mailbox gets read.

Formal policies

The binding documents are the Privacy Policy and Terms of Use. This article is a summary and the policies win where they differ.
Did this page help?
Edit this page on GitHub

← Previous

Passkeys & Biometrics

Next →

Transaction Statuses