Legal
Privacy Policy
Effective date: June 1, 2026 · Last updated: June 1, 2026
Loofta ("we," "us," "our") respects your privacy. This Privacy Policy explains what information we collect when you use Loofta Pay, how we use it, and your rights regarding that information. We are a non-custodial service — we never hold your funds — and we aim to collect only the minimum data necessary to operate the Service.
Contents
1. Overview
Loofta Pay is a non-custodial Solana-based payment platform. Authentication is handled by Privy, Inc.; transaction data and user profiles are stored in our own database (Supabase); and certain features rely on third-party services described in Section 4. This policy applies to the Loofta Pay web application and all associated services.
2. Information We Collect
a) Information you provide directly
- Email address — when you sign up or log in using email-based authentication via Privy.
- X (Twitter) account details — if you choose to log in using your X account via Privy (username and profile identifier).
- Username — if you set a custom Loofta username in settings.
- Wallet addresses — Solana wallet addresses associated with your account, including addresses of embedded wallets created by Privy on your behalf.
b) Information generated by your use of the Service
- Transaction records — sender/recipient identifiers, amount, timestamp, transaction hash, and status for all payments you send or receive through the Service.
- Payment links — metadata associated with payment links you create, including any message or emoji attached.
- Deposit and withdrawal records — including third-party protocol identifiers and transaction hashes.
- Rewards and referral activity.
c) Technical information collected automatically
- Browser and device type, operating system, and language preference.
- IP address and approximate geographic location (country/region level).
- Pages visited, features used, and interaction events — collected via Vercel Analytics in an aggregated, privacy-preserving manner.
- Cloudflare Turnstile signals — behavioral signals used to distinguish human users from bots. No personal data is sold or shared from this process.
d) Information from third parties
- Privy user identifier — a unique identifier assigned by Privy that we use to link your identity to your Loofta account.
- Compliance signals — wallet address risk signals from Range Protocol used to screen withdrawal addresses.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your Loofta account.
- Authenticate you via Privy when you log in.
- Process, record, and display payment transactions you initiate or receive.
- Enable you to find other users by email or username to send payments.
- Screen wallet addresses against sanctions lists and risk databases as required by law.
- Provide customer support and respond to your inquiries.
- Detect and prevent fraud, abuse, and unauthorized use of the Service.
- Send transactional notifications related to your account or payments (we do not send marketing emails without your consent).
- Analyze aggregated, anonymized usage patterns to improve the Service.
- Comply with applicable legal obligations.
4. Third-Party Services
We share limited data with the following third-party service providers, strictly to the extent necessary to operate the Service:
| Third Party | Purpose |
|---|---|
| Privy, Inc. | Identity management and embedded Solana wallet creation. Privy stores your email or social login credentials and manages your embedded wallet keys. See Privy's Privacy Policy at privy.io. |
| Supabase | Database storage for user profiles, payment history, and app state. Data is stored in a managed PostgreSQL instance. |
| Vercel | Frontend hosting (pay.loofta.xyz) and privacy-preserving usage analytics. Vercel Analytics does not use cookies or fingerprinting. |
| Railway | Backend hosting and server-side processing. |
| Helius | Solana RPC infrastructure. Transaction data is broadcast to the Solana network via Helius. |
| Range Protocol | Wallet address compliance and sanctions screening for withdrawals. |
| Defuse Protocol / Near Intents | Cross-chain deposit and withdrawal routing. Your wallet address and intended transaction are shared to facilitate cross-chain operations. |
| Cloudflare | Bot and spam protection (Turnstile). Cloudflare may process IP address and behavioral signals. |
| X (Twitter) | Optional social login. If you log in with X, Privy processes your X account identifier. |
We do not sell your personal information to any third party. We do not share your data with advertisers. We may disclose information to law enforcement or regulators if required by applicable law, court order, or to protect the safety of users or the public.
5. Blockchain & Public Data
All transactions processed through the Service are recorded on the Solana blockchain, which is a public, immutable ledger. This means:
- Transaction details including wallet addresses, amounts, and timestamps are permanently and publicly visible to anyone who queries the Solana blockchain.
- We cannot delete, modify, or obscure blockchain records.
- Payment links contain a short identifier that may be shared publicly; the link itself reveals only the payee's identifier and requested amount, not their full wallet address unless the payer views the chain.
You should be aware of the public nature of blockchain transactions before using the Service. Our non-custodial architecture means your wallet address is the primary identifier for your funds on-chain.
7. Data Retention
We retain your account information and transaction history for as long as your account is active, plus a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
If you request deletion of your account, we will delete or anonymize your personal information within 30 days, subject to our obligation to retain certain records under applicable law (e.g., AML regulations may require us to retain transaction records for up to 5 years).
Blockchain transaction data is permanent and cannot be deleted, as described in Section 5.
8. Security
We implement industry-standard technical and organizational security measures to protect your information, including:
- Encryption of sensitive keys at rest using Google Cloud KMS (Key Management Service).
- HTTPS encryption for all data in transit.
- Access controls limiting internal access to personal data.
- Supabase row-level security policies to ensure users can only access their own data.
- Cloudflare Turnstile to prevent bot abuse and unauthorized automated access.
No security system is impenetrable. We cannot guarantee the security of your information, and you use the Service at your own risk. You are responsible for securing your own wallet credentials and login methods.
10. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) or equivalent laws:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data, subject to legal retention obligations.
- Right to restriction — request that we restrict processing of your data in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on your consent, withdraw it at any time.
To exercise any of these rights, email us at privacy@loofta.xyz or contact@loofta.xyz. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Our legal bases for processing include: performance of a contract (operating the Service for you), compliance with legal obligations, and our legitimate interests in fraud prevention and service improvement.
11. Your Rights (CCPA / California)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
- Right to know — request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete — request deletion of your personal information, subject to certain exceptions.
- Right to opt out of sale — we do not sell your personal information.
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights.
To make a CCPA request, contact us at contact@loofta.xyz. We will verify your identity before processing the request.
12. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child under 18, please contact us immediately at contact@loofta.xyz and we will delete such information promptly.
13. International Data Transfers
Loofta operates globally and your information may be transferred to, stored in, and processed in the United States and other countries where our service providers maintain infrastructure. By using the Service, you consent to such transfers.
Where we transfer personal data from the EEA or UK to countries not deemed to provide an adequate level of data protection, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and, where required, notify you through the application or by email. We encourage you to review this policy periodically.
15. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: