Skip to content
Back to Legal

Privacy Policy

Last Updated: 12 March 2026

This Privacy Policy explains how Web3Settle Ltd (“Web3Settle”, “we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you use our services through our website, web3settle.com, or interact with our non-custodial blockchain payment gateway. We are committed to safeguarding your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

1.1. Web3Settle Ltd is the data controller responsible for your personal data. We are a limited company registered in England and Wales, with our registered office in London, England.

1.2. We are registered with the Information Commissioner’s Office (ICO).

1.3. If you have any questions or concerns about this Privacy Policy or how we process your data, please contact our Data Protection Officer (DPO) at legal@web3settle.com.

2. Data We Collect

2.1. We collect the following categories of personal data:

  • Merchant account information: name, email address, and business name.
  • Technical data: API keys, public blockchain wallet addresses, IP addresses, browser information, and device information.
  • Transaction metadata: transaction hashes, amounts, timestamps, and blockchain network details.
  • Usage and analytics data: information about how you use our services, collected via cookies or similar technologies (subject to consent where required).

2.2. We do not collect or store private keys, plaintext passwords, or payment card details.

2.3. Blockchain transaction data is inherently public due to the nature of blockchain technology and is not considered personal data under our control once recorded on-chain.

3. How We Use Your Data

3.1. We use your personal data for the following purposes:

  • To provide and maintain our non-custodial blockchain payment gateway services, including deploying per-merchant smart contracts.
  • To manage merchant accounts and facilitate transactions.
  • To monitor and improve our services through usage and analytics data.
  • To comply with legal and regulatory obligations, including tax and audit requirements.
  • To communicate with you, including responding to enquiries and, where consent is provided, sending marketing communications.
  • To protect the security and integrity of our systems and services.

4. Lawful Basis for Processing

4.1. We process your personal data on the following lawful bases under the UK GDPR:

  • Performance of a contract: to provide our services to you as a merchant or user.
  • Legitimate interests: to improve our services, ensure security, and manage our operations, provided your rights and freedoms are not overridden.
  • Legal obligation: to comply with applicable laws, such as tax or anti-money laundering regulations.
  • Consent: for non-essential cookies and marketing communications, where applicable.

4.2. You may withdraw consent at any time by contacting us, though this will not affect the lawfulness of processing prior to withdrawal.

5. Data Sharing

5.1. We share your personal data only with essential third-party service providers, such as cloud hosting and analytics providers, who process data on our behalf under strict data processing agreements.

5.2. We do not sell or otherwise disclose your personal data to third parties for their own purposes.

5.3. Blockchain transaction data, including public wallet addresses and transaction metadata, is inherently visible on public blockchains and outside our control once recorded.

6. International Transfers

6.1. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK government or reliance on UK adequacy decisions.

6.2. For further details on international transfers, please contact us at legal@web3settle.com.

7. Data Retention

7.1. We retain personal data for the following periods:

  • Merchant account data: for the duration of an active account and for 6 years thereafter, in line with UK limitation periods.
  • Transaction metadata: for 7 years to comply with tax and audit requirements.
  • Usage logs and technical data: for 90 days.

7.2. Data recorded on blockchains is immutable and cannot be deleted due to the nature of the technology.

8. Your Rights

8.1. Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access: to request a copy of your personal data.
  • Right to rectification: to correct inaccurate or incomplete data.
  • Right to erasure: to request deletion of your data, where applicable (note that blockchain data cannot be erased).
  • Right to restriction: to limit processing of your data in certain circumstances.
  • Right to data portability: to receive your data in a structured, commonly used, and machine-readable format.
  • Right to object: to object to processing based on legitimate interests or for direct marketing.

8.2. To exercise any of these rights, please contact us at legal@web3settle.com. We may require verification of your identity before processing requests.

8.3. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your data appropriately.

9. Cookies and Similar Technologies

9.1. We use essential cookies to operate our website and services. These do not require consent.

9.2. We use non-essential cookies for analytics and performance monitoring only with your consent. You can manage your cookie preferences through our website settings.

10. Security

10.1. We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security audits.

10.2. While we take all reasonable steps to secure your data, no system is completely immune to risks, and we cannot guarantee absolute security, especially for data transmitted over public networks or recorded on blockchains.

11. Children

11.1. Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

11.2. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such data.

12. Changes to This Privacy Policy

12.1. We may update this Privacy Policy from time to time to reflect changes in legal requirements or our practices.

12.2. Any updates will be posted on our website, and significant changes will be communicated to you via email or through our services.

12.3. Your continued use of our services after such changes constitutes acceptance of the updated Privacy Policy.

13. Governing Law

13.1. This Privacy Policy is governed by and construed in accordance with the laws of England and Wales.

13.2. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Contact Us

For any questions, concerns, or to exercise your data protection rights, please contact our Data Protection Officer at: legal@web3settle.com

Web3Settle Ltd, London, United Kingdom

We aim to respond to all enquiries within 30 days.