Privacy Policy
Last updated: June 16, 2026
1. Introduction and Scope of Policy
Welcome to Arbipay. At Arbipay ("we", "us", "our", or the "Company"), we recognize that your privacy is of utmost importance. This Comprehensive Privacy Policy ("Policy") is designed to inform you ("User", "you", or "your") about how we collect, use, process, disclose, protect, and handle your personal data and non-personal data when you access, visit, use, or interact with our website, decentralized applications (dApps), smart contracts, application programming interfaces (APIs), software development kits (SDKs), widgets, browser extensions, and any associated services (collectively, the "Services" or "Platform").
This Policy applies to all visitors, users, and others who access the Platform. By accessing or using the Platform, you expressly signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Policy and our Terms and Conditions. If you do not agree with any part of this Policy, you must immediately cease all use of the Platform and the Services.
Given the inherently public and immutable nature of blockchain technology, this Policy also addresses the distinct characteristics of transacting on public ledgers and how this impacts your data privacy.
2. The Nature of Blockchain Data and On-Chain Privacy
2.1 Public Ledgers: You must be aware that Arbipay facilitates transactions on public, permissionless blockchains (e.g., Ethereum, Binance Smart Chain). Blockchains are distributed, public ledgers. By design, all data written to the blockchain, including but not limited to wallet addresses, transaction hashes, timestamps, token amounts, smart contract interactions, and gas fees paid, are publicly broadcasted, fully visible, and permanently immutable.
2.2 Inability to Erase On-Chain Data: Because blockchain records cannot be altered, deleted, or anonymized once confirmed, the "Right to Erasure" (or "Right to be Forgotten") under regulations like the GDPR or CCPA cannot be enforced against on-chain data. Arbipay has absolutely no ability to erase, hide, modify, or restrict access to any data that has been deployed or recorded on a public blockchain.
2.3 Pseudonymity: While wallet addresses do not inherently contain your name, email, or physical address, they are pseudonymous rather than fully anonymous. Advanced blockchain analytics tools, forensic analysis, and the correlation of your on-chain activity with off-chain data (such as IP addresses or centralized exchange KYC records) can potentially deanonymize your wallet address and reveal your real-world identity. You accept full responsibility for the privacy implications of executing public transactions.
3. Information We Collect Directly from You
We collect information that you voluntarily and explicitly provide to us when you interact with the Platform. This includes, but is not limited to:
- Account and Registration Data: If you choose to create a registered account (for example, for premium analytics or saving preferences), we may collect your email address, a chosen username, encrypted passwords, and profile settings.
- Communication Data: When you contact our customer support, legal department, or communicate with us via email, Discord, Telegram, Twitter, or other channels, we collect the contents of your messages, your contact details, and any metadata associated with the communication.
- Survey and Feedback Data: If you participate in user surveys, beta testing feedback sessions, or feature request forums, we collect your responses and opinions.
- Subscription and Payment Data: If you subscribe to premium features that accept fiat payments via a third-party payment processor, we may collect billing information. However, Arbipay does not store full credit card numbers.
4. Information We Collect Automatically
When you access, navigate, or use our Platform, we automatically collect certain technical and usage data to ensure the smooth operation of our services, optimize routing algorithms, and enhance security. This information includes:
- Device Information: We collect hardware models, operating system versions, device identifiers (e.g., IMEI, MAC address), browser types, and language preferences.
- Log Data and IP Addresses: Our servers automatically record standard web log data, including your Internet Protocol (IP) address, access times, pages viewed, referring URLs, and the page you visited before navigating to our Platform.
- Usage Analytics: We collect granular data regarding your interactions with the Platform's interface, such as mouse movements, clicks, scrolling activity, the specific DEXs you route through, transaction sizes, token pairs analyzed, slippage settings utilized, and the frequency of your visits.
- Wallet Connection Data: When you connect a Web3 wallet (e.g., MetaMask, WalletConnect, Coinbase Wallet) to the dApp interface, we automatically collect your public wallet address, your current network chain ID, your token balances (for display purposes), and your transaction history. We do not and cannot collect your private keys, seed phrases, or wallet passwords.
5. Information Collected via Cookies and Tracking Technologies
We utilize cookies, web beacons, pixel tags, local storage (HTML5), and similar tracking technologies to collect and store information about your use of the Platform.
- Strictly Necessary Cookies: These are essential for the Platform to function correctly (e.g., maintaining your session or wallet connection state). They cannot be disabled.
- Performance and Analytics Cookies: These allow us to count visits and traffic sources so we can measure and improve the performance of our site. We may use third-party analytics providers like Google Analytics or Mixpanel.
- Functionality Cookies: These enable the website to provide enhanced functionality and personalization, such as remembering your chosen theme (dark/light mode) or preferred slippage tolerance.
- Targeting/Advertising Cookies: We may use these to build a profile of your interests and show you relevant adverts on other sites.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Platform properly.
6. Information from Third-Party Sources
We may receive information about you from various third-party sources and public databases, including:
- Blockchain Analytics Providers: We integrate with third-party blockchain analysis firms (e.g., Chainalysis, Elliptic, TRM Labs) to scan connected wallet addresses for compliance with Anti-Money Laundering (AML) laws and sanctions regimes (e.g., OFAC). This may provide us with risk scores or threat intelligence associated with your address.
- Third-Party Authentication: If you log in using a third-party service (e.g., Google, Twitter, GitHub), we receive authentication tokens and public profile data in accordance with your privacy settings on those platforms.
- Marketing Partners: We may receive demographic information or aggregated data from advertising and marketing partners to better understand our user base.
7. How We Use Your Information
We strictly process your personal data for specified, explicit, and legitimate purposes. We use the information we collect for the following operational and business purposes:
- Providing the Services: To facilitate the connection of your wallet, route your trades, calculate optimal arbitrage paths, and display accurate balances and estimates.
- Platform Maintenance and Security: To monitor for abnormal activity, prevent DDoS attacks, identify bugs, and maintain the structural integrity of our smart contracts and web infrastructure.
- Compliance and Risk Mitigation: To enforce our Terms and Conditions, detect and prevent fraud, comply with applicable legal and regulatory obligations, and ensure users are not utilizing sanctioned or blacklisted wallet addresses.
- Customer Support: To respond to your inquiries, troubleshoot issues, and resolve disputes.
- Product Improvement: To analyze usage trends, conduct research, develop new features, and enhance the overall User Experience (UX) of the dApp.
- Marketing and Communications: To send you newsletters, technical updates, security alerts, and promotional materials (subject to your opt-in preferences where required by law).
8. Legal Basis for Processing Personal Data
If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. We primarily rely on the following legal bases:
- Contractual Necessity: Processing is necessary to perform our obligations under our Terms and Conditions (e.g., providing access to the dApp).
- Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving our services, securing our systems, and preventing fraud, provided those interests are not overridden by your data protection rights.
- Legal Obligation: Processing is necessary to comply with applicable laws, regulations, subpoenas, or court orders (e.g., AML/KYC requirements).
- Consent: Where we require your consent to process your data (e.g., for certain tracking cookies or direct marketing). You can withdraw your consent at any time.
9. Disclosure and Sharing of Your Information
We do not sell, rent, or lease your personal information to third parties. We may disclose your information to the following categories of recipients:
- Service Providers and Vendors: We share data with trusted third-party companies that perform services on our behalf, such as cloud hosting (e.g., AWS, Vercel), RPC node providers (e.g., Infura, Alchemy), customer support tools, data analytics, and email delivery. These providers are bound by strict confidentiality agreements.
- Blockchain Analytics Partners: As part of our compliance program, we share wallet addresses and transaction hashes with specialized firms to monitor for illicit activity and ensure regulatory compliance.
- Business Transfers: If Arbipay is involved in a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership via a prominent notice on our website.
- Legal and Regulatory Authorities: We may disclose your information if required to do so by law, in response to a valid subpoena, court order, or search warrant, or if we believe in good faith that such action is necessary to comply with legal obligations, protect our rights, prevent fraud, or protect the safety of our users or the public.
- Professional Advisors: We may share data with our lawyers, accountants, auditors, and insurers when necessary to seek professional advice or protect our legal interests.
10. International Data Transfers
Arbipay is a globally distributed platform with infrastructure and service providers located in various jurisdictions around the world, including the United States, the European Union, and Switzerland. Therefore, your personal data may be transferred to, processed, and stored in countries outside of your country of residence, where data protection laws may differ from those in your jurisdiction.
When we transfer your personal data internationally, we take all reasonable steps to ensure that it is treated securely and in accordance with this Policy. For users in the EEA or UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs), to protect your data during cross-border transfers.
11. Data Retention
We retain your personal information only for as long as is necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law (e.g., for tax, accounting, or compliance purposes).
When we have no ongoing legitimate business need to process your personal information, we will either securely delete or anonymize it. If deletion is not possible (for example, because your data is stored in backup archives), we will securely store your data and isolate it from further processing until deletion is possible.
Important Reminder: As stated in Section 2, any data recorded on public blockchains is retained indefinitely and cannot be deleted by Arbipay.
12. Data Security and Integrity
We implement robust, industry-standard technical and organizational security measures to protect your data against unauthorized access, loss, destruction, or alteration. These measures include:
- Encryption of data in transit using Transport Layer Security (TLS/SSL).
- Encryption of sensitive data at rest using AES-256 or higher encryption standards.
- Strict access controls, Principle of Least Privilege (PoLP), and multi-factor authentication (MFA) for our internal systems and databases.
- Regular vulnerability scanning, penetration testing, and third-party security audits.
Despite our rigorous efforts, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee the absolute security of your information. You are responsible for ensuring the security of your own devices, networks, and Web3 wallets.
13. Your Data Protection Rights
Depending on your jurisdiction (such as under the GDPR, UK GDPR, or CCPA), you may have the following rights regarding your personal data:
- Right to Access: You can request copies of the personal data we hold about you.
- Right to Rectification: You can request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure ("Right to be Forgotten"): You can request that we erase your personal data, under certain conditions. (Note: This does not apply to immutable on-chain data).
- Right to Restrict Processing: You can request that we restrict the processing of your personal data, under certain conditions.
- Right to Object to Processing: You can object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You can request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- Right to Withdraw Consent: If we rely on your consent to process data, you have the right to withdraw it at any time.
To exercise any of these rights, please contact our Data Protection Officer at privacy@arbipay.finance. We have one month to respond to your request. We may require you to verify your identity before responding to such requests.
14. California Privacy Rights (CCPA/CPRA)
If you are a resident of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.
Do Not Sell My Personal Information: Arbipay does not sell your personal information. We do not sell data to data brokers or third parties for monetary consideration.
You have the right to request access to the specific pieces of personal information we have collected about you over the past 12 months, the categories of sources from which it was collected, the business purposes for collecting it, and the categories of third parties with whom we shared it. You also have the right to request deletion of your data and protection against discrimination for exercising your CCPA rights.
15. Children's Privacy
Our Platform and Services are not directed to, and we do not knowingly collect personal information from, children under the age of 18. If you are under 18, please do not attempt to register for the Services or send any personal information about yourself to us. If we become aware that we have collected personal data from a child under the age of 18 without verification of parental consent, we will take immediate steps to delete that information from our servers.
16. Do Not Track (DNT) Signals
Some web browsers incorporate a "Do Not Track" (DNT) feature that signals to websites you visit that you do not want to have your online activity tracked. At this time, there is no uniform industry standard for recognizing and implementing DNT signals. Accordingly, we do not currently respond to DNT signals or similar mechanisms transmitted by web browsers.
17. Automated Decision-Making and Profiling
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects concerning you, except in the context of automated risk scoring for AML/KYC compliance purposes. If a wallet address is flagged by automated systems as high-risk, we may automatically restrict access to the Platform. You have the right to challenge such automated decisions by contacting support.
18. Third-Party Links and Integrations
Our Platform may contain links to third-party websites, plug-ins, APIs, and decentralized applications (e.g., links to Etherscan, CoinGecko, or third-party DEXs). Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Platform, we strongly encourage you to read the privacy notice of every website you visit.
19. Changes to this Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, operational requirements, or legal/regulatory obligations. We will notify you of any material changes by posting the updated Policy on this page and updating the "Last updated" date at the top. For significant changes, we may also provide a more prominent notice (e.g., via a banner on the Platform or an email notification). Your continued use of the Platform after such updates constitutes your acknowledgment of the modified Policy.
20. Complaints and Dispute Resolution
If you have any complaints or concerns regarding our handling of your personal data, we request that you first attempt to resolve the issue directly with us by contacting our Data Protection Officer. If you reside in the EEA or UK and are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority (DPA) or the Information Commissioner's Office (ICO).
21. Data Protection Officer (DPO) and Contact Information
We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy. If you have any questions about this Policy, our privacy practices, or if you wish to exercise your data protection rights, please contact us using the information below:
Arbipay Data Protection Officer
Email (Privacy): privacy@arbipay.financeEmail (Legal): legal@arbipay.financeAddress: 128 Decentralized Way, Suite 404, Crypto Valley, ZG 6300, Switzerland
22. Supplementary Terms for UK Residents (UK GDPR)
If you are a resident of the United Kingdom, your data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Arbipay guarantees that any transfer of your data outside the UK will be safeguarded by the UK International Data Transfer Agreement (IDTA) or the European Commission's SCCs accompanied by the UK Addendum. Furthermore, you have the right to lodge complaints directly with the Information Commissioner's Office (ICO). Our UK representative can be contacted at uk-privacy@arbipay.finance.
23. Supplemental Policy for Nevada Residents
Under Nevada Revised Statutes Chapter 603A, Nevada residents may opt-out of the future sale of their covered information to third parties. While Arbipay absolutely does not sell covered information as defined under Nevada law, we provide this notice out of an abundance of caution and compliance. If you are a Nevada resident and wish to formally opt-out of any potential future sales of covered information, please email us at privacy-nv@arbipay.finance with the subject line "Nevada Do Not Sell Request."
24. Law Enforcement and Subpoena Compliance Policies
Arbipay cooperates fully with law enforcement, regulatory authorities, and government agencies. We reserve the right to report any activities that we, in good faith, believe to be unlawful to law enforcement without prior notice to you. When responding to legal requests (e.g., search warrants, court orders, subpoenas, or discovery requests), we will disclose your personal data and on-chain connection records to the extent required by law. Where permitted, and assuming it does not compromise an ongoing investigation, we may attempt to notify you of such legal requests.
25. Financial Data and the Gramm-Leach-Bliley Act (GLBA)
As a decentralized finance (DeFi) interface provider rather than a traditional financial institution, Arbipay does not take custody of your funds and generally does not fall under the strict purview of the GLBA. However, in our interactions with third-party payment gateways or fiat on-ramps, those external entities may be subject to GLBA. We ensure that any data transmitted to such gateways is encrypted and minimized to the fullest extent possible, maintaining the spirit of financial privacy regulations.
26. Anonymization and Aggregation Framework
Arbipay extensively utilizes data anonymization and aggregation techniques to minimize the personal data we store. For instance, high-frequency arbitrage trading statistics, latency metrics, and generalized DEX routing efficiencies are stripped of identifying IP addresses or wallet information before being added to our machine learning models. Once data is fully and irreversibly anonymized (meaning it can no longer be associated with you), it ceases to be "personal data" under applicable privacy laws, and we may use it indefinitely for statistical modeling and platform improvements.
27. Third-Party RPC Providers and Node Operators
When you interact with a blockchain via our Platform, your requests (including your IP address and wallet address) are often routed through third-party Remote Procedure Call (RPC) node providers, such as Alchemy, Infura, or QuickNode. These providers have their own independent privacy policies and data collection practices. By using the Platform, you acknowledge that your technical connection data may be visible to and logged by these external node operators over which Arbipay has no direct control.
28. Specific Consents for Cross-Chain Bridge Usage
If you utilize any cross-chain bridging features provided within the Arbipay interface, you consent to the necessary transmission of your transaction data across multiple disparate blockchain networks and decentralized bridge protocols (e.g., LayerZero, Wormhole). Due to the complexity of bridging, your data may be processed by validators and relayers across multiple jurisdictions simultaneously.
29. Biometric Information Notice
Currently, Arbipay does not collect, capture, purchase, receive through trade, or otherwise obtain any biometric identifiers or biometric information (such as fingerprint scans, facial recognition data, or voiceprints) from our users. Should this change in the future (for example, if we introduce a mobile app with FaceID wallet unlocks), we will update this Policy to explicitly conform to laws such as the Illinois Biometric Information Privacy Act (BIPA) and obtain your explicit, written consent.
30. Sale, Merger, or Corporate Restructuring
We reserve the explicit right to transfer all your personal data, along with our business assets, in the event of a corporate restructuring, merger, acquisition, joint venture, assignment, spin-off, or other transfer of all or any portion of our business, assets, or stock (including in connection with bankruptcy or similar proceedings). In such an event, the acquiring entity will be bound by the terms of the Privacy Policy in effect at the time of the transfer.
31. Explicit Acknowledgment and Severability
By actively clicking "I Agree," checking a consent box during registration, or continuing to use the Arbipay Platform, you explicitly acknowledge that you have read this entire 31-section Privacy Policy in full. If any provision of this Policy is determined by a court of competent jurisdiction to be invalid, illegal, or unenforceable, that provision shall be severed from this Policy, and the remaining provisions shall continue in full force and effect to the maximum extent permitted by law.