> For the complete documentation index, see [llms.txt](https://help.getlfg.app/p/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.getlfg.app/p/agreements/privacy-policy.md).

# Privacy policy

**Effective date: 12th Septemnber 2026**

## 1. Controller and scope

**Layer Flow Gateway, Inc.**, Delaware File No. 10054149, is the controller for the personal data it processes to operate LFG accounts, its own onboarding, billing, security and support. Address: **131 Continental Dr, Suite 305, Newark, DE 19713, United States**. Contact: **<legal@getlfg.app>**; support: **<support@getlfg.app>**.

This Policy covers applicants, users, business representatives and beneficial owners, website visitors, support contacts and other people whose information we receive in connection with LFG. Privacy rights do not depend on successful onboarding or residence in an approved service country. Business records can contain personal data about individuals.

**EEA representative:** \[\[EEA REPRESENTATIVE — NAME, POSTAL ADDRESS AND EMAIL]].

**UK representative:** \[\[UK REPRESENTATIVE — NAME, POSTAL ADDRESS AND EMAIL, IF REQUIRED]].

The representatives are privacy contacts; they are not LFG’s contracting company, a recovery custodian or a financial-services authorisation. You can contact LFG directly regardless of where you live.

## 2. Information we process and where it comes from

| Information                          | Sources and use                                                                                                                                                                                                                                                                                              |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Account and contact details          | Information you provide, including name, contact details, age or date of birth, account settings and eligibility details. Used to set up and administer accounts and communicate with you.                                                                                                                   |
| Verification information             | Information submitted for Didit checks, including identity documents, relevant photographs or liveness material, business registration, representatives, beneficial ownership and screening results. We receive verification decisions and associated information through provider responses and dashboards. |
| Verification and integration records | Provider session references, decision payloads, review outcomes, status changes and raw event notifications. Full responses can contain more than an approval status, including identity details or links to verification evidence. Access is restricted and the retention schedule below applies.           |
| Wallet and transaction information   | Public addresses, network and token identifiers, amounts, transaction hashes, timestamps, payment requests and associated account labels or counterpart information. Obtained from you, your use of the interface, public networks and enabled providers.                                                    |
| Encrypted wallet backup              | Device-encrypted recovery material associated with the account. LFG cannot decrypt it independently. The active copy is deleted on account closure and cannot then be used by LFG to recover the wallet.                                                                                                     |
| Subscription information             | Plan, invoices, payment and cancellation records, the LFG Vault address and signed EIP-3009 authorisations for LFG’s own fees. Signed payment authorisations are sensitive even though they are not the LFG Vault’s private key.                                                                             |
| Technical and security information   | IP addresses, authentication and security events, app/device information, error reports and necessary service logs. Used for access, geographic controls, security and troubleshooting.                                                                                                                      |
| Notification information             | Push tokens, device/app identifiers, notification preferences and delivery or interaction information processed through the enabled OneSignal configuration.                                                                                                                                                 |
| Telephone and messaging information  | If SMS is enabled, telephone number, opt-in or opt-out record, message type, delivery status and interaction information. Used for requested authentication, account/security communications and separately authorised marketing where offered.                                                              |
| Support and business contacts        | Messages, attachments, complaint records and information needed to respond. Do not send wallet secrets or unnecessary identity evidence to support.                                                                                                                                                          |

We do not require you to send a usable private key or recovery phrase to LFG support. The encrypted server backup must not be confused with readable key material. Device biometrics used locally by an operating system to unlock a device are also distinct from photographs, liveness checks or facial verification used in onboarding.

Payment-card information entered in a provider’s own checkout is handled by that provider. LFG receives relevant status and transaction references; do not send full card information to LFG support. The exact information supplied to a provider is explained in that provider’s journey and privacy notice.

## 3. Purposes and lawful bases

Where EU or UK GDPR applies, we use the following bases as appropriate to the particular information and purpose:

| Purpose                                                                                          | Basis and explanation                                                                                                                                                                                                                            |
| ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Provide an individual’s requested account and service; support and administer their subscription | Performance of, or steps requested before, the contract, but only for processing objectively necessary for it.                                                                                                                                   |
| Administer a company’s account and communicate with its representatives                          | Legitimate interests in providing and administering the company’s requested service; contract where the individual is personally the contracting party.                                                                                          |
| Verify eligibility and prevent fraud, account misuse and sanctions exposure                      | Legitimate interests following an assessment of necessity and the person’s rights; an applicable legal obligation only where a relevant law actually imposes it on LFG. Biometric identification requires the additional condition in section 4. |
| Keep billing, tax and legally required records                                                   | The applicable legal obligation, or another valid basis where that obligation is not itself a GDPR legal-obligation basis, including assessed legitimate interests in accounting and legal compliance.                                           |
| Maintain necessary security and resolve incidents                                                | Legitimate interests in protecting users and the service; a legal obligation where applicable.                                                                                                                                                   |
| Optional diagnostic collection, notification uses or marketing requiring consent                 | Consent, requested separately with a way to refuse or withdraw. Necessary service communications and the assessment of device-storage consent are treated separately.                                                                            |
| Send requested SMS authentication and necessary account or security communications               | Performance of the requested service or legitimate interests in account security, as applicable. Electronic-marketing rules and consent apply separately to marketing messages.                                                                  |
| Establish, exercise or defend legal claims; respond to lawful demands                            | Applicable legal obligations or assessed legitimate interests, with any additional condition required for sensitive information.                                                                                                                 |

We do not assume that all customers’ identity files must be held under an AML law merely because LFG chooses to verify users. A third-party provider’s legal duty is not automatically LFG’s duty. Where a law requires particular information, or a service cannot be provided without necessary information, we explain that requirement and the consequence of not providing it.

We do not sell personal data or share it for cross-context behavioural advertising. We do not use identity evidence or biometric material to train general models or enable optional provider training for LFG verification. We do not treat accepting the Terms as consent to an unrelated data use.

## 4. Identity checks, biometrics and review

All LFG applicants must complete the relevant identity or business verification before activation. **Didit performs LFG’s verification checks. LFG determines whether the resulting eligibility requirements for its account have been met.** Authorised LFG administrators can view verification information, and LFG retains relevant provider responses. Read-only access is still access to personal data.

Where facial matching or another biometric-identification method is offered on an explicit-consent basis, we request that consent separately before the check. You can choose the available non-biometric verification review through <support@getlfg.app> instead and can withdraw biometric consent. Identity verification remains necessary, but refusing optional biometric processing is not itself a reason to deny a suitable alternative. A different legal basis for biometric processing will be identified in a specific notice before that processing begins; ordinary contract wording or a generic fraud-prevention interest is not, by itself, a special-category condition.

Verification uses checks on document validity, matching identity information, liveness where selected, and relevant fraud, eligibility or screening indicators. The result can determine whether activation or a feature is allowed. Automated checks can produce mistakes. Contact <legal@getlfg.app> to contest a result, give additional information and request meaningful human review. Where the issue is a Didit result, we arrange review using its human-review process and reconsider LFG’s corresponding decision. We do not use a solely automated decision with a legal or similarly significant effect unless permitted by applicable law and with the required safeguards.

Owl’s separate off-ramp onboarding, including its Sumsub verification, is governed by Owl’s privacy arrangements. LFG verification does not replace it. LFG account closure does not direct Owl to erase information it must independently retain.

## 5. Sharing and international processing

We disclose information to providers as needed for the particular service: hosting and security providers; verification and screening providers; enabled wallet or blockchain infrastructure; notification and diagnostic providers; and a conversion provider you choose to use. We may also disclose relevant information to professional advisers, a lawful business successor, or authorities where lawfully required or justified. We assess the scope and legal basis of a request; this Policy is not blanket consent to release customer files to anyone claiming to be an authority.

The [Integrated Service Providers](https://help.getlfg.app/p/agreements/integrated-service-providers) document explains the current integrations. Service processors act under applicable data-processing arrangements. Independent financial-service providers determine their own compliance processing under their notices. Calling a company a partner or sub-processor does not determine its legal role for every purpose.

Our primary application storage is in **AWS eu-central-1, Frankfurt, Germany**, and Sentry uses an EU ingestion endpoint. That does not guarantee that every provider operation, support access or onward transfer occurs in the EEA. LFG is a US company and provider or personnel access can involve other countries.

Where restricted international transfers occur, we use a mechanism valid for the particular recipient and transfer: an applicable adequacy decision within its scope, appropriate contractual safeguards with the required assessment and supplementary measures, or an applicable limited statutory exception. For relevant UK transfers this may include the UK Addendum or International Data Transfer Agreement. Encryption alone is not a substitute for a required transfer mechanism. Contact <legal@getlfg.app> for information about the applicable safeguards and a copy subject to necessary redactions.

## 6. Retention and deletion

The following are our standard maximum operational periods, subject to earlier deletion where information is no longer needed and a lawful exception where retention is required. A justified archive contains only relevant information and is not used as an active marketing, verification-training or recovery database.

| Record category                                                                                       | Standard retention and starting point                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ----------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Active profile, preferences and ordinary account records                                              | While needed for the account; delete from active systems within 30 days after closure, except the limited records below.                                                                                                                                                                                                                                                                                                                                                                  |
| Encrypted wallet backup associated with the account                                                   | Remove the active copy when the account is closed. Residual disaster-recovery copies follow the backup rule below and are not an available wallet-recovery service.                                                                                                                                                                                                                                                                                                                       |
| Minimum verification and eligibility audit                                                            | While the account is active, then up to 12 months after closure. Keep only the identity link, provider reference, relevant result/date and review evidence needed for the stated purpose, except a subset required in a lawful longer archive.                                                                                                                                                                                                                                            |
| Ordinary identity-document copies and verification media                                              | Avoid unnecessary duplication; delete no later than 30 days after the final verification decision or completion of a timely review, unless specific evidence must lawfully be retained. Biometric samples/templates are deleted when their specific purpose ends; this may require earlier deletion.                                                                                                                                                                                      |
| Abandoned applications                                                                                | Delete unnecessary application information within 30 days of abandonment.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Refused applications                                                                                  | Retain the minimum decision and review record for up to 90 days after refusal for a review request; the shorter rules for biometric material and unnecessary media still apply. A live appeal or documented fraud matter is considered separately.                                                                                                                                                                                                                                        |
| Raw provider event notifications and duplicate webhook payloads                                       | Up to seven days after receipt for necessary troubleshooting; extract needed records into their appropriate category and remove the raw copy.                                                                                                                                                                                                                                                                                                                                             |
| Ordinary crash diagnostics                                                                            | Up to 30 days after the event.                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Necessary application security logs                                                                   | Up to 90 days after the event, unless relevant evidence is needed for a documented incident.                                                                                                                                                                                                                                                                                                                                                                                              |
| Push identifiers and notification profiles                                                            | While needed for the enabled notification service; stop sending promptly after opt-out or closure and remove unnecessary identifiers within 30 days. Keep only a minimal suppression record where needed to honour the choice.                                                                                                                                                                                                                                                            |
| SMS delivery and consent records, if SMS is enabled                                                   | Message content and ordinary delivery metadata are kept only as long as needed for the communication, security or support purpose. A minimal opt-in, opt-out or suppression record may be kept for as long as needed to demonstrate and honour the choice or comply with law.                                                                                                                                                                                                             |
| Routine support tickets                                                                               | Up to 12 months after resolution; relevant billing or formal dispute evidence follows its separate justified period.                                                                                                                                                                                                                                                                                                                                                                      |
| LFG invoices, fee calculations, receipts, refunds and necessary related transaction/identity evidence | Normally seven years after the relevant financial year ends for accounting and claims purposes, subject to the actual tax and other applicable recordkeeping rules. This is not a statement that every country requires seven years.                                                                                                                                                                                                                                                      |
| Other off-chain wallet/payment history                                                                | While needed to provide the account’s history, then delete within 30 days after closure, except identified records needed for accounting, a specific legal duty or a documented claim. Blockchain publication does not justify keeping every identity-linked copy indefinitely.                                                                                                                                                                                                           |
| Subscription authorisations                                                                           | On cancellation, immediately mark the subscription cancelled and block the active billing-submission service from accessing or submitting unused authorisations. Remove the executable signed payloads from active systems, or irreversibly render them inaccessible to the submission service, without undue delay after cancellation, use or expiry. Retain only non-executable evidence of consent, amounts, validity periods and outcomes where needed for billing, a dispute or law. |
| Disaster-recovery copies of deleted information                                                       | Put beyond ordinary use and purge or overwrite within 90 days of deletion. Reapply deletion if a backup is restored. These copies are not promised to be available for customer recovery.                                                                                                                                                                                                                                                                                                 |

Where a specific AML recordkeeping obligation applies to LFG, the relevant evidence is kept for that obligation’s required period and starting event, which may be five years or another period. We do not apply a five-year blanket rule to every selfie, webhook or backup simply because a provider conducts KYC.

Records of transactions falling within applicable US sanctions recordkeeping rules may require at least ten years from the relevant transaction; records of blocked property have a separate retention trigger. These rules apply to the relevant records, not automatically to every data category. Other mandatory obligations can require different periods.

A specific legal hold, investigation or dispute may extend retention of relevant information. We restrict access, document the reason and review the hold, deleting information when the applicable purpose and obligations end. We do not keep everything indefinitely in case an authority might ask for it later.

We apply deletion instructions to processors where we control the processing. Independent providers may retain their own records under their notices and legal obligations. A request to close LFG does not automatically close every provider account. Public blockchain entries are not erased by deleting LFG’s off-chain records.

## 7. Security and recovery information

We use measures appropriate to the risks, including access controls, encryption where appropriate, restricted administration and incident procedures. No system can guarantee that a breach will never occur. Security incidents are assessed and notified where required by law.

You must secure your device and export and retain the recovery phrase or appropriate private key for every wallet before closing the account, deleting the app or deleting required device data. LFG cannot independently decrypt the server backup or recover a wallet afterwards. Identity verification, an email code or a new LFG account cannot recreate the missing keys. Planned social recovery is not part of the current service. If a new recovery feature is introduced, we will explain its separate processing and obtain any required consent before using it; it will not operate retrospectively to recover access already lost under the present system.

## 8. Your rights and choices

Depending on applicable law, you can request access, correction, erasure, restriction, portability and information about our processing; object to processing based on legitimate interests; withdraw consent; and contest relevant automated decisions. Direct-marketing objections are respected. Withdrawal does not invalidate processing lawfully carried out beforehand. Some records may need to be retained under a lawful exception, which we explain where permitted.

Send requests to **<legal@getlfg.app>**. We use proportionate verification and do not require a wallet secret to handle a privacy request. For GDPR requests, we respond without undue delay and ordinarily within one month. If the law permits an extension, we explain the reason within the initial period. Other applicable statutory deadlines and appeal rights apply where relevant.

US residents may have additional state-law rights, including rights concerning sensitive information, correction, deletion, portability, an authorised agent, appeals and freedom from unlawful discrimination. Applicable opt-out preference signals are respected where they apply. The categories, purposes and retention practices above also serve as our information about collection; any additional required notice is provided when relevant information is collected.

You can complain directly to your local data-protection authority. EEA residents may contact the authority where they live, work or consider an infringement occurred; UK residents may contact the ICO. You do not have to complain to LFG first. Other statutory remedies remain available.

## 9. Children and policy changes

LFG accounts are for adults aged 18 or older. If we learn that an ineligible child supplied information, we take appropriate steps to restrict the account and remove unnecessary information, subject to a lawful retention need. This does not remove that person’s privacy rights.

We publish material updates with a new effective date and notify affected users where appropriate. A new use requiring consent does not become authorised merely because we publish an updated policy or a user continues using the service.

***
