Legal

Privacy Policy & Data Safeguards

Last updated: July 18, 2026

This policy explains how Furlpay collects, uses and protects your data. It is designed to meet the requirements of the GDPR, the CCPA and the Gramm-Leach-Bliley Act (GLBA).

Data minimization

Furlpay does not store raw KYC documents. All identity checks are processed directly by our secure verification partners (Sumsub / Persona) via tokenized APIs. We retain only the verification result and the minimal metadata required to meet our regulatory obligations.

On-chain privacy

Public wallet addresses are indexed to build your transaction history. Private transaction details — such as recipient identities and notes — are stored encrypted off-chain and are never written to a public ledger.

Hardware authentication data

Biometrics never leave your device

Biometric data (Face ID, Touch ID) used for WebAuthn passkeys never leaves your local device and is never transmitted to or stored on Furlpay’s servers. Furlpay only ever sees the public key of your passkey credential.

Browser extension

The FurlPay browser extension (Chrome, Edge and Firefox) is a companion to your furlpay.com account. Its data handling is deliberately minimal and is disclosed here in full, consistent with the Chrome Web Store and Firefox Add-ons requirements:

What it accesses. The extension sends your existing furlpay.com session cookie with API requests to furlpay.com (first-party) so it can show your balance, approvals and activity. On web pages you visit it detects HTTP 402 “Payment Required” responses and shared FurlPay payment links, and announces a wallet provider to sites that request one (EIP-6963 / CAIP-294) — releasing your public smart-account address only after you approve that site in an explicit consent prompt.

What it never does. It does not collect or transmit your browsing history, the content of pages you visit, keystrokes, form inputs or your location. It stores no seed phrases, private keys or session tokens; passkey signatures happen only on furlpay.com, the origin they are bound to. On-page UI is rendered inside an isolated (closed) shadow root so a page cannot read or interfere with it. All extension code is bundled and served locally — no remote code is loaded or executed. Locally cached data (UI preferences, the x402 detection log, approved-site list) stays on your device and is size-bounded.

This data is used only to provide the extension’s single purpose above. It is not sold, not shared with third parties, and not used for advertising or any unrelated purpose.

Your rights

Depending on your jurisdiction, you may have rights to access, correct, port or delete your personal data, and to object to certain processing. Requests are handled subject to the record-keeping obligations imposed on regulated financial services.