Back to Home
Protocol Privacy

Privacy policy

Last Updated: July 8th, 2026

1. Privacy Principles

SubScript is built to reduce Web3 friction while keeping payment state transparent enough to verify. We collect the minimum off-chain data needed to operate accounts, receipts, webhooks, support, and notifications.

Some payment data is written to public blockchains. Public blockchain data is permanent, globally visible, and not fully controlled by SubScript.

2. Account and Wallet Information

If you sign up with an external wallet, we may store your wallet address, selected role, account settings, alias, linked email, and notification preferences.

If you sign up with email onboarding, SubScript provisions an embedded wallet through Circle developer-controlled MPC wallet infrastructure; key material for these embedded wallets is managed by SubScript's custody provider so the platform can execute the payment actions you request. SubScript may store the resulting wallet address, login email, Circle wallet references, and account role. We do not store seed phrases.

If you link an email to a wallet account, that email is used for notifications and account communication. Linking email to a wallet does not by itself mean SubScript can recover an external self-custody wallet.

3. Payment, Receipt, and Memo Data

SubScript may store Checkout Intent IDs, payment link IDs, receipt IDs, merchant references, payer references, transaction hashes, memo payloads, payment status, amount, token, timestamp, and webhook delivery status.

Receipt pages are designed to be human-readable. By default, receipt visibility is intended for the payer, merchant, and SubScript. Future invite flows may allow a payer or merchant to share a receipt with selected viewers.

Arc Network memo data and transaction hashes may be public or indexable depending on how the payment is executed.

4. Merchant Data and Webhooks

For merchants, we may store API key metadata, webhook endpoints, webhook secrets, DNS aliases, branding, payment links, pricing configuration, and integration settings.

Webhook payloads may include intent IDs, payment IDs, receipt IDs, amount paid, status, and transaction references so merchants can fulfill purchases in their own systems.

5. Identity Verification

If you start KYC or business verification, SubScript stores your wallet address, account type, country code, consent record, an opaque provider case reference, review status, controlled reason code, and lifecycle timestamps.

Identity documents, selfies, biometric data, full government identifiers, legal names, dates of birth, and provider screening evidence must be submitted directly to the configured verification provider. SubScript does not accept those materials through its KYC API.

The verification provider processes identity evidence under its own privacy and retention terms. SubScript retains its minimal case and audit records as needed for security, fraud prevention, compliance, and financial audit obligations. Approval can expire or be revoked.

6. Cookies and Session Data

SubScript uses cookies or similar storage to keep users signed in, preserve dashboard sessions, support embedded wallet login flows, and protect API requests.

Circle wallet session material generated by the frontend SDK is browser-scoped session material. It must not be treated as a global deployment secret and must not be shared across users.

7. Emails and Notifications

If you provide an email, we may use it for account notifications, sign-up messages, payment receipts, failed payment alerts, subscription notices, product updates, security messages, and support.

We may use email delivery providers to send these messages. Those providers process message metadata needed to deliver email.

8. Analytics, Security, and Logs

We may process limited technical data such as IP-derived region, device/browser information, request timestamps, rate-limit events, errors, and security logs to protect the service and improve reliability.

We do not sell personal information. We do not use private payment receipt data for advertising profiles.

9. Your Choices and Deletion Limits

You may request access, correction, export, or deletion of off-chain account data by contacting SubScript. We may retain records needed for security, legal, fraud prevention, or financial audit purposes.

We cannot delete or alter public blockchain records, third-party explorer records, or transaction data already propagated across decentralized networks.

10. Contact

For privacy requests, email compliance@subscriptonarc.com. Include the email or wallet address connected to the request so we can locate the relevant account records.

Privacy Policy | SubScript