How we collect, use, store and protect your personal data, and what rights you have over it.
In effect from 10 August 2026
Personal data is processed by the operator of the Walletbridge service (wallet-bridge.com); details of the legal entity are available on request via support. No separate data protection officer has been appointed — requests are handled by the service team at help@wallet-bridge.com. This Policy covers the website, your personal account, the B2B cabinet and the notifications sent from them.
We collect only the categories of data the service needs:
We do not collect card details and have no access to them: payment takes place on the payment provider's side.
Most of it you give us yourself — when registering, placing an Order and contacting support. Some is generated automatically as you use the service (logs, technical request parameters). A limited set comes from partners: the payment provider reports payment status, the supplier reports delivery status, and the verification service reports the outcome of a check.
We process data for the following purposes and on the following bases:
We use only strictly necessary cookies and browser local storage: signing in, form protection, cart contents, chosen language and theme. There are no analytics or advertising cookies on the site. The full list with purposes and lifetimes is in the Cookie Policy.
We keep our own visit statistics and connect no third-party analytics platforms. It works without tracking cookies: a visit is tagged with a daily pseudonym derived by a one-way function from the IP address and user agent, so visits by the same person cannot be linked across days through that identifier. The country is resolved from the IP address on our side and stored in aggregate form.
To protect users and the service we apply automated rules: device fingerprinting, operation scoring, limits and risk flags. These rules may lead to an extra check, a paused operation or a verification request. Decisions that significantly affect you — blocking an account or declining a payout — are reviewed by a human on request; you may ask for an explanation and contest the outcome.
To reply faster we use a third-party language model: it helps the operator summarise a request and draft a reply. The text of your request and the related Order context are sent to the model; passwords and verification documents are not. The provider processes this data on our instructions and does not use it to train its models. Every access by the AI to a user's financial data is recorded in the audit log.
We do not sell personal data. Sharing is limited to processors that keep the service running — code suppliers, the payment provider, notification delivery, hosting, monitoring — and to cases required by law. The full list of recipient categories, the data shared with each and the safeguards applied are on the Data Sharing page.
Account data is kept while the account exists and is deleted or anonymised after it is closed. Records and documents relating to operations are retained for the period the law prescribes for settlement records, even if the account has been deleted. Technical logs and security-check records are kept no longer than needed to investigate incidents and prevent repeat abuse. Support correspondence is kept while it is needed to resolve the request and evidence the actions taken.
You can delete your account yourself in your profile. Deletion takes effect after 30 days; three days beforehand we send a reminder, and until the deadline the request can be cancelled and any remaining Balance withdrawn. After deletion your email, phone and credentials are anonymised, while records of operations are retained to the extent required by law without being linkable to you through that data.
We apply traffic encryption, encryption of secrets and backups, role-based access control for staff, an audit log of administrative actions and regular infrastructure updates. Staff access to user data is limited to what their work requires and is logged. No system can be fully secure; where an incident materially affects you we notify you in the manner and within the timeframe the law requires.
The service is not intended for people below the age of majority in their jurisdiction, and we do not knowingly collect their data. If you believe an account was created by a minor, tell us — we will check and delete the data.
Some processors are located outside your country of residence, so data may be transferred across borders. Where that happens we apply the safeguards the law provides — standard contractual clauses or an equivalent — and transfer only the minimum data required.
You may request access to your data, its correction, deletion or restriction of processing, receive it in a machine-readable format, object to processing based on legitimate interests and withdraw consent to newsletters. Send requests to the contacts below; the procedure, timelines and specifics for users in the EEA and the UK are described on the GDPR page.
We update this Policy when our processing changes — for example when a new processor is engaged. The version in force is always published on this page and its date is shown at the top of the document; material changes are announced on the site and, where appropriate, by email.
For any privacy question and to exercise your rights, write to help@wallet-bridge.com or call the number below. We reply within one business day, and to formal rights requests within the timelines set out on the GDPR page.