1. Who we are and scope
This Privacy Policy explains how the OmniWallet operator (“we”, “us”, “our”) collects, uses, shares and protects personal data in connection with OmniWallet (the “Service”), including our website, the merchant console, hosted payment pages, the POS and merchant app, and our APIs. The operator’s full legal name and registered address will be specified here before this policy takes effect.
This policy applies to merchants’ representatives and staff (including directors, beneficial owners and authorized representatives whose data we receive during merchant verification), payers who pay merchants through the Service, and visitors to our website. Terms not defined here have the meanings given in our Terms of Service.
For most of the processing described in this policy, we decide why and how personal data is processed. When we process payer data to carry out payments for a merchant, we act on that merchant’s behalf (see section 12).
2. Personal data we collect
- Account data: names, email addresses, phone numbers (if provided), login credentials, 2FA settings, and the roles and permissions of merchant users.
- Verification (KYB) data: company registration details; information about, and identity documents of, directors, beneficial owners and authorized representatives; business description, website or app, expected volumes and source of funds; additional information in higher-risk cases; and the results of sanctions and politically exposed person (PEP) screening.
- Transaction data: payment amounts and assets, deposit and sending addresses, settlement wallet and whitelisted addresses, transaction hashes, timestamps and statuses, and records of settlements, payouts and conversions.
- Payer data: information that a merchant passes to us or that a payer enters on a hosted page, such as an email address, and the payer’s IP address.
- Technical data: IP addresses, browser and device information (user agent), system logs and audit logs, and, if you use the merchant app, the device and push-notification tokens needed to pair the app and deliver notifications.
- Cookies and preferences: session and security cookies, and preferences such as your language (see section 10).
- Communications: the content of messages you send us, for example to support@ewin888.com.
Blockchain transactions, including addresses, amounts and transaction hashes, are recorded on public blockchains. Anyone can see them, and neither we nor anyone else can alter or delete them.
If you do not provide the data required for registration or verification, we may be unable to open your account, enable live payments or continue to provide the Service.
3. Sources of personal data
We obtain personal data:
- directly from you, for example when you register, complete verification, use the console or contact us;
- from the merchant you are associated with, for example when a merchant names you as a director, beneficial owner, representative or user, or passes us your data as its payer or sub-account user;
- from payers, when they enter information on a hosted page;
- automatically, from your device and our systems, when you use our website, console, apps or APIs;
- from public blockchains and blockchain data providers; and
- from the sanctions lists and other screening sources we use (such as the OFAC, UN and EU sanctions lists, the ScamSniffer scam list and Tether freeze lists), and from sources used for PEP screening.
4. Purposes and legal bases
We use personal data for the following purposes:
- Providing the Service: opening and managing accounts; processing payments, settlements, payouts and conversions; sending service and security notifications, including push notifications; and providing support.
- Merchant verification and compliance: KYB, sanctions and PEP screening, transaction screening and monitoring, record keeping and reporting under our AML/KYC Policy.
- Security and fraud prevention: authentication, bot protection, access control, audit logs and the investigation of abuse.
- Operating and improving the Service: troubleshooting, maintenance and service statistics.
- Legal matters: complying with legal obligations and lawful requests, and establishing, exercising or defending legal claims.
Depending on the applicable law, we rely on: the performance of our contract with you or the merchant (or steps taken before entering into it); compliance with our legal obligations; our legitimate interests in operating a secure and lawful payment service, preventing financial crime and protecting our rights, where those interests are not overridden by yours; and your consent where the law requires it (for example, when you enable push notifications on your device). You may withdraw your consent at any time, without affecting processing carried out before the withdrawal.
We do not sell personal data and do not use advertising trackers. We do not use personal data for purposes incompatible with those described above unless the law permits it.
5. Sharing and service providers
We share personal data only as described in this policy. Our service providers process it on our instructions and are subject to appropriate confidentiality and security obligations. They include:
- Cloudflare: hosting of our website, APIs and databases (Cloudflare Pages and Workers, with databases located primarily in the Asia-Pacific region, delivered over Cloudflare’s global network) and bot protection (Cloudflare Turnstile);
- Email providers: Cloudflare Email Service or another email provider (for example, Resend), to send verification, security and service emails;
- Blockchain infrastructure providers: RPC/node and block-explorer API providers, which receive blockchain addresses and transaction hashes when we query blockchains;
- Google Fonts: our website loads fonts from Google, which receives your IP address and browser information when you visit; and
- Push-notification providers: such as Expo, Apple and Google, to deliver notifications to the merchant app.
We also share personal data with: the merchant concerned (for example, payment and payer information relating to payments made to that merchant); competent authorities, courts and law enforcement, where required by law or necessary to protect rights and safety, including for AML and sanctions reporting; professional advisers and auditors bound by confidentiality; and a successor if our business is reorganized, merged or sold, who will be bound by this policy.
6. International transfers
Our infrastructure runs on Cloudflare’s global network, and our databases are located primarily in the Asia-Pacific region. Our service providers may process personal data in other countries, whose data protection laws may differ from those where you live.
Where required by applicable law, we take appropriate steps (such as contractual safeguards) to protect personal data transferred internationally, and we comply with any restrictions on international transfers imposed by competent authorities.
7. Retention
We keep personal data only for as long as necessary for the purposes described in this policy, including legal, accounting and compliance requirements:
- verification (KYB) data, transaction records (including related payer data), and screening and compliance records: for the duration of the business relationship and at least five years after it ends, or longer where required by law;
- account data: while the account exists, and afterwards for as long as needed to keep the records above or to resolve disputes;
- technical logs and audit logs: for as long as needed for security, troubleshooting and audit purposes; and
- Test Environment data: it may be reset or deleted at any time.
When personal data is no longer needed, we delete or anonymize it. Data recorded on public blockchains cannot be deleted.
8. Security
We use technical and organizational measures designed to protect personal data and funds, including:
- role-based permissions, with 2FA mandatory for owners, administrators and roles that can send payouts or change whitelists;
- HttpOnly session cookies, and API keys stored only in hashed form and shown only once;
- IP allowlists for API keys with payout permissions;
- audit logs of significant account and security actions; and
- an isolated signing service that holds private keys and signs only transactions that it builds itself, in accordance with policy.
No system is completely secure. If a personal data breach occurs, we will notify affected individuals and authorities where required by applicable law. More information is available on our Security page.
9. Your rights
Subject to applicable law, you may exercise rights in respect of your personal data. Under Taiwan’s Personal Data Protection Act, you may:
- make an inquiry about, or request to review, your personal data;
- request a copy of it;
- request that it be supplemented or corrected;
- request that we stop collecting, processing or using it; and
- request that it be deleted.
Where the EU General Data Protection Regulation (GDPR) or similar laws apply, you may also have the right to restrict or object to processing, to data portability, to withdraw consent at any time, and to lodge a complaint with a data protection supervisory authority.
To exercise your rights, contact support@ewin888.com. We may need to verify your identity, and we will respond within the time required by law; where the law permits, we may charge a reasonable fee to cover our costs. We may refuse or limit a request where the law permits, for example where we must keep records under AML laws. If we process your data on behalf of a merchant, we may refer your request to that merchant.
10. Cookies and local storage
We use cookies and similar technologies only to run the Service: session cookies (set as HttpOnly) that keep you signed in, and security cookies that help protect against bots and abuse. Preferences such as your language are stored in your browser’s local storage.
We do not use advertising or cross-site tracking cookies. Our website loads fonts from Google Fonts, so Google receives your IP address (see section 5).
You can block or delete cookies in your browser settings, but some parts of the Service, such as signing in, will not work without them.
11. Children
The Service is intended for businesses and is not directed to children. Individuals who use the Service on behalf of a merchant must be of legal age. We do not knowingly collect children’s personal data; if you believe a child has provided us with personal data, contact support@ewin888.com and we will take appropriate steps, including deletion where the law permits.
12. Merchants’ responsibilities for payer data
When we process payer data to carry out payments for a merchant, we act on that merchant’s behalf and in accordance with its instructions. When we process payer data for our own AML, sanctions, security and legal obligations, we decide why and how it is processed and act as an independent controller.
Merchants are responsible for their customers’ privacy. They must give their customers an appropriate privacy notice that covers the use of OmniWallet, have a lawful basis for sharing payer data with us, share only the data needed for the payment, and handle their customers’ requests. The same applies to merchants that create sub-accounts for their own users.
If you are a payer, please contact the merchant you paid with any questions about how it uses your data. You can also contact us at support@ewin888.com.
13. Changes to this policy
We may update this policy from time to time. The “Last updated” date shows the current version. If we make material changes, we will notify merchants by email or in the console, or post a notice on our website, before the changes take effect.
14. Contact us
If you have questions about this policy or want to exercise your rights, contact us at support@ewin888.com. The operator’s full legal name and registered address will be specified here before this policy takes effect.