SubScript Logo
SubScript
Sign InGet Started
Back to HomeData Protection & Global Privacy

Privacy Policy

Last Updated: September 4th, 2026 · Version 2.4 (GDPR & CCPA Compliant)

Data Minimization & Sovereign Privacy Standard

SubScript enforces strict data minimization. We collect only the data necessary to execute payments, deliver receipts, enforce security, and fulfill legal requirements. On-chain transaction records are permanent by blockchain design; all off-chain data is protected under modern GDPR/CCPA standards with automated 30-day statutory purge lifecycles.

1. Core Privacy Architecture & Data Minimization

SubScript Protocol ('SubScript', 'we', 'us', or 'our') is architected upon principles of privacy-by-design and rigorous data minimization. We collect only the off-chain information strictly required to authenticate accounts, coordinate smart contract subscription allowances, deliver verifiable receipts, route signed webhooks, and satisfy statutory anti-financial crime obligations.

We never sell, rent, or monetize your personal information. We never construct cross-context behavioral advertising profiles from your payment history, receipt data, or wallet transactions.

2. Lawful Bases for Processing (GDPR Article 6)

Under the European Union General Data Protection Regulation (Regulation (EU) 2016/679) and UK GDPR, SubScript processes off-chain personal data pursuant to the following lawful bases:

(a) Contractual Necessity (Art. 6(1)(b)): Processing wallet addresses, Checkout Intent IDs, and subscription states necessary to execute transactions you authorize under our Terms of Service;

(b) Legal Obligation (Art. 6(1)(c)): Retaining transaction audit logs, sanctions screening records, and tax-relevant payment references to comply with anti-money laundering (AML), counter-terrorist financing (CFT), and financial reporting statutes;

(c) Legitimate Interests (Art. 6(1)(f)): Processing technical telemetry, IP address lookups, rate-limiting counters, and anomaly logs to secure infrastructure, mitigate fraud, and prevent distributed denial-of-service (DDoS) attacks;

(d) Consent (Art. 6(1)(a)): Where you explicitly opt in to optional marketing communications or submit voluntary feedback.

3. Account and Cryptographic Wallet Information

External Self-Custodial Wallets: When connecting an external Web3 wallet (MetaMask, Rabby, Phantom, OKX Wallet, Coinbase Wallet), we record your public Ethereum address, role selection (USER or ENTERPRISE), account preferences, and optional notification email. We never access, handle, or store your private keys, seed phrases, or external passwords.

Embedded MPC Operating Accounts: When onboarding via email or social authentication, an embedded multi-party computation (MPC) wallet is provisioned via Circle developer-controlled wallet infrastructure. SubScript stores the resulting public address, linked email address, and opaque Circle wallet identifiers. Key material is mathematically distributed between Circle's hardware security modules (HSMs) and browser-scoped session storage. SubScript cannot access plaintext private keys.

Sign-In with Ethereum (SIWE): Authenticated sessions are established via cryptographically signed EIP-4361 statements. Nonces expire after 10 minutes and session tokens are stored in secure, HTTP-only, SameSite cookies.

4. Public Blockchain Immutability vs. Data Privacy (GDPR Article 17)

Crucial Notice on Blockchain Permanence: SubScript is built natively upon the Arc Network, Ethereum, and Solana. When you broadcast a transaction or authorize a subscription, certain metadata—including your public wallet address, transaction hash, token amount, timestamp, smart contract interaction, and Arc transaction memo—is permanently etched into decentralized public ledgers.

Public blockchain records are decentralized, mathematically immutable, and distributed across global independent validator nodes. SubScript possesses no technical or administrative capacity to alter, erase, overwrite, or delete records on the blockchain.

By interacting with SubScript, you expressly acknowledge and agree that your statutory 'Right to Erasure' (GDPR Art. 17 / CCPA) applies exclusively to mutable off-chain databases managed by SubScript, and cannot extend to immutable public blockchain ledgers.

5. KYC & Business Verification Privacy Guardrails

Zero Raw PII Storage Policy: SubScript intentionally does NOT store government IDs, passport photos, driver's licenses, biometric selfies, national identification numbers, full legal names, or raw credit scores on our servers.

When identity verification (KYC/KYB) is required for enterprise merchants or elevated tiers, applicants submit documents directly through our licensed, SOC2-compliant verification partner's hosted portal.

SubScript stores only an opaque provider case reference, account role, country code, submission timestamp, consent version, and normalized review status (PENDING, APPROVED, REJECTED, EXPIRED). This prevents sensitive personal identification documents from being exposed in protocol databases.

6. Payment, Checkout Intent & Webhook Data

To coordinate commerce, SubScript processes Checkout Intent IDs, payment link IDs, receipt identifiers, merchant counterparty references, amounts, and settlement status.

Receipt Visibility: Human-readable receipt summaries are accessible to the paying wallet and the designated merchant. Receipts do not expose the payer's physical address, bank routing details, or private credentials.

Merchant Webhook Deliveries: Outbound webhooks sent to merchant endpoints carry transaction hashes, intent IDs, and payment status. Webhooks are signed with an HMAC SHA-256 signature to guarantee authenticity.

7. Cookies, Local Storage & Session Hygiene

Strictly Necessary Cookies: SubScript uses essential session cookies to maintain authenticated logins, verify CSRF tokens, and prevent session hijacking. These cannot be disabled.

Browser Local Storage: Scoped local storage keys are used to preserve UI theme preferences and temporary Circle MPC client execution tokens. We do not use third-party cross-site tracking cookies.

8. Subprocessors & Infrastructure Partners

SubScript engages trusted third-party cloud infrastructure providers bound by rigorous data protection agreements (DPAs):

(a) Circle Internet Financial: Embedded MPC custody and Cross-Chain Transfer Protocol (CCTP) infrastructure;

(b) Supabase Inc.: Encrypted PostgreSQL database hosting with Row-Level Security (RLS) and point-in-time recovery;

(c) Vercel Inc.: Serverless edge computing and web application hosting;

(d) Upstash Inc.: In-memory Redis caching for IP rate limiting and replay prevention;

(e) Resend Inc.: Transactional email delivery for receipts, billing notifications, and security alerts.

9. International Data Transfers & Standard Contractual Clauses

Your off-chain account information may be transferred to, stored, and processed in the United States and other jurisdictions where SubScript and our subprocessors maintain infrastructure.

For transfers of personal data outside the European Economic Area (EEA), United Kingdom, or Switzerland, SubScript relies on Standard Contractual Clauses (SCCs) adopted by the European Commission or adequacy decisions under the EU-U.S. Data Privacy Framework to safeguard your data.

10. Data Retention & Automated Statutory 30-Day Purge

We retain off-chain account data only for as long as your account remains active or as required to fulfill tax, legal, accounting, and anti-fraud statutory obligations.

Automated Statutory Deletion: When an account requests deletion via our settings portal or privacy desk, the account enters a 30-day soft-delete grace period. Following the expiration of 30 days, our automated daily sweeper (/api/cron/gdpr-hard-delete) executes a permanent, cryptographic purge of all off-chain profile data, linked emails, and session records.

11. Your Data Protection Rights (GDPR, UK GDPR & CCPA/CPRA)

Depending on your jurisdiction, you are entitled to exercise the following fundamental privacy rights:

(a) Right to Access & Portability: You may request a complete, machine-readable export of all off-chain data linked to your account via our automated endpoint (/api/user/account/gdpr-export);

(b) Right to Rectification: You may update or correct inaccurate account profile details or linked email addresses at any time in your dashboard;

(c) Right to Erasure ('Right to be Forgotten'): You may request full permanent deletion of your off-chain database records subject to the 30-day purge cycle;

(d) Right to Object & Restrict Processing: You have the right to object to or restrict certain non-essential data processing activities;

(e) California Rights (CCPA/CPRA): California residents have the right to know what personal information is collected, request deletion, and opt out of any sale or sharing of personal data (SubScript does not sell personal data).

12. Data Protection Officer (DPO) & Regulatory Contact

If you have inquiries regarding this Privacy Policy, wish to exercise statutory data rights, or suspect a data incident, contact our Data Protection and Compliance Desk at: compliance@subscriptonarc.com.

European Union residents also possess the right to file a complaint directly with their local Data Protection Authority (such as the Irish Data Protection Commission or CNIL) if they believe their personal data has been processed unlawfully.

Have questions about your data?

Our compliance team is ready to answer questions regarding account security, encryption, and GDPR rights.

Contact ComplianceCompliance Center
© 2026 SubScript Protocol. All rights reserved.
Terms of ServicePrivacy PolicyRefund PolicyFulfillment PolicyComplianceSupport