Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how SettleBolt, operated by PROTASIS LTD, a software company registered in Bulgaria, VAT BG201136934, with registered address at Suha Reca Region Str., Sofia P.C. 1505, Bulgaria (“SettleBolt”, “we”, “us”), handles personal data when you use our website, dashboard, and services (the “Service”). We aim to collect only what we need to run, secure, bill, support, and improve the Service.
Blockchain notice. Cryptocurrency transactions are recorded on public, permanent blockchains that SettleBolt does not own or control. Wallet addresses and on-chain transaction data are public and cannot be changed, hidden, or deleted by us. Do not use SettleBolt if you do not want this information to be public on a blockchain.
1.Data we collect
- Account & business data — name, email, password (hashed), business name, plan, team members, and settings you provide.
- Wallet & transaction data — public wallet addresses you connect, signatures used to verify ownership, and metadata about payments (amounts, tokens, chains, transaction hashes, timestamps, status). Public blockchain data associated with your addresses is inherently public.
- Customer & invoice data — information you enter about your own customers or invoices (such as a customer name, email, or line items) so we can generate and deliver payment requests and receipts on your behalf.
- Billing data — subscription and billing details processed by our billing provider; we do not store full card numbers.
- Content — logos, brand assets, and other materials you upload.
- Technical & usage data — IP address, device/browser information, log data, approximate location, session records, security events, and how you use the Service, collected for authentication, security, fraud prevention, support, and product operation.
2.How we use data
- Provide, operate, secure, and improve the Service, including detecting and recording on-chain payments.
- Authenticate you, manage your account, and process subscription billing.
- Prevent, detect, and investigate fraud, abuse, security incidents, and prohibited use, and enforce our Terms.
- Communicate with you about your account, transactions, service changes, and support.
- Comply with legal, regulatory, tax, and law-enforcement obligations, and establish, exercise, or defend legal claims.
- Analyse usage to develop and improve features. We may use aggregated or anonymised data for any purpose.
3.Legal bases (where applicable, e.g. under GDPR)
We process personal data where necessary to (a) perform our contract with you; (b) pursue our legitimate interests in running, securing, supporting, and improving the Service and preventing fraud, provided those interests are not overridden by your rights; (c) comply with a legal obligation; or (d) with your consent, where we ask for consent. You may withdraw consent at any time without affecting prior processing.
4.Merchants as data controllers
When you use the Service to collect and process personal data about your own customers, you are the data controller of that customer data and SettleBolt acts as your processor, handling it on your documented instructions to provide the Service. You are responsible for having a lawful basis and appropriate notices and consents for the customer data you put into the Service, and for responding to your customers’ rights requests. We will assist you with reasonable processor support requests sent through the dashboard privacy ticket flow or to [email protected]. A data-processing addendum is available on request.
5.How we share data
We do not sell your personal data. We share it only as needed:
- Service providers / sub-processors — infrastructure and hosting, database and storage, our billing processor, email delivery, blockchain node/RPC and block-explorer providers, price-data providers, and security providers, each processing data on our behalf.
- Public blockchains — transaction and address data is broadcast to and stored on public networks outside our control.
- Legal & safety — to comply with law, regulation, legal process, or government request, to enforce our Terms, or to protect the rights, safety, and property of SettleBolt, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy will continue to apply to the transferred data.
6.International transfers
We and our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers. By using the Service you understand your data may be processed in those locations.
7.Retention
We keep personal data for as long as your account is active and as needed to provide the Service. If you delete your account, we delete live service data such as customers, invoices, payment links, support tickets, feedback, wallets, webhooks, API keys, sessions, and settings, subject to legal exceptions. We may retain a limited archive for legal, tax, accounting, fraud-prevention, security, dispute-resolution, or chargeback purposes where required or permitted by law. We minimise that archive and do not retain API keys, webhook signing secrets, 2FA secrets, password hashes in exports, or avoidable customer-contact details in deleted-account dispute snapshots. We may retain aggregated or anonymised data indefinitely. On-chain data cannot be deleted by us.
8.Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to portability, and to withdraw consent, subject to legal exceptions. Account owners can download an account JSON export in Settings → Privacy & data. You can also submit a privacy ticket from the dashboard or contact [email protected]. We may need to verify your identity. We aim to respond within one month unless an extension is permitted by law. If you provided data as an end-customer of a merchant, please contact that merchant, who is the controller of your data. You may also complain to your local data-protection authority. We cannot remove data that is recorded on a public blockchain.
9.Security
We use reasonable technical and organisational measures designed to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials and wallet keys safe. Any transmission of data is at your own risk.
10.Cookies and browser storage
We use strictly necessary browser storage and security technologies to run the Service, keep you signed in for the current browser session, prevent abuse, and verify sign-up challenges. We also offer optional analytics to understand aggregate site traffic. Analytics is off by default, and the Google Analytics tag is not loaded unless you accept analytics cookies in the banner. You may clear or change that choice through your browser storage settings.
11.Children
The Service is for businesses and is not directed to children. We do not knowingly collect data from anyone under 18 (or the age of digital consent in your jurisdiction). If you believe a child has provided us data, contact us and we will delete it.
12.Changes
We may update this Policy at any time by posting the revised version with a new “last updated” date. Material changes take effect when posted (or on a stated later date). Your continued use of the Service constitutes acceptance.
13.Contact
Privacy questions or requests: [email protected].
Data controller: PROTASIS LTD, Software Company, Suha Reca Region Str., Sofia P.C. 1505, Bulgaria. VAT: BG201136934.