Privacy Policy
Effective Date: 22 September 2026 · previous version
This policy explains what personal data we collect when you use SpendLayer.com and the SpendLayer wallet, why we collect it, and what rights you have. It should be read with our Terms and Conditions.
1. Who we are
The controller of your personal data is Circinus Finance Ltd., a non-resident domestic company incorporated in the Republic of the Marshall Islands with corporation number 133239, whose registered office is at Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, Republic of the Marshall Islands MH 96960 ("SpendLayer", "we", "our", "us").
You can contact us about anything in this policy at info@spendlayer.com.
If you are in the European Economic Area or the United Kingdom and wish to contact us about this policy or about your personal data, write to info@spendlayer.com and we will respond.
2. What we do not hold
SpendLayer is non-custodial. We hold your private key only in encrypted form, encrypted with your password. We do not hold your password and cannot decrypt your key, so we cannot use it, cannot recover it for you, and have no access to the assets in your wallet. We do not collect identity documents.
3. What we collect
3.1 Account data. When you create an account we collect your email address and a password, and we hold your private key in encrypted form. We do not keep your password itself and cannot read it: it is stored only as a cryptographic hash, which lets us check that a password is correct but not recover it, and it is your password that decrypts your key.
3.2 Technical data. Our servers record ordinary access information when you use the website or the wallet, including your IP address, browser and device type, the pages or screens requested, and the date and time.
3.3 Support correspondence. If you contact us we keep your message and our reply, together with the address you sent it from.
3.4 Blockchain data. To show you your balances, mandates and history, we read publicly available data associated with your wallet address from public blockchain networks. We do not add anything to those networks about you beyond the transactions you yourself authorise.
4. Why we use it, and our legal basis
- To create and operate your account and provide the wallet — because it is necessary to perform our contract with you.
- To keep the Service secure, to detect and prevent abuse, fraud and attacks, and to keep it working reliably — on the basis of our legitimate interests in protecting the Service and its users.
- To answer your support messages — to perform our contract with you, and on the basis of our legitimate interests in responding to enquiries.
- To comply with a legal obligation, or to establish, exercise or defend legal claims — where that applies.
We do not sell or rent your personal data, we do not use it for advertising, and we do not make any decision about you by automated means that produces a legal or similarly significant effect.
5. Blockchain data cannot be changed or deleted
Transactions and mandates you authorise are recorded on public blockchain networks. Those networks are operated by no one, are public to anyone, and are permanent. We cannot alter, hide or delete anything recorded on them, and neither can you. Your wallet address may be linked to you by anyone who can connect it to your identity. Please consider this before authorising any transaction — rights of correction and erasure under section 9 cannot apply to data on a public blockchain.
6. Who we share it with
- Service providers who host our infrastructure and send our emails, acting on our instructions and bound by written terms.
- Professional advisers, and any party to a merger, reorganisation or transfer of our business, where necessary and under a duty of confidence.
- Public authorities, where we are legally required to disclose, or to establish, exercise or defend legal claims.
We do not share your data with the merchants you pay. Where a merchant receives a payment from you, it sees the blockchain transaction, which is public, and whatever you give it directly.
7. On-ramps, swaps and other third-party services
The wallet lets you reach independent third-party providers, for example to buy or sell digital assets. You are redirected to the provider and contract with it directly. Each provider is a separate controller of the data you give it, applies its own privacy notice and its own identity checks, and we are not responsible for what it does with your data. We do not receive the identity documents you give them.
8. Where your data is held, and transfers
We are established in the Republic of the Marshall Islands. Where you give us data directly, that is not a restricted transfer under EU or UK data protection law, because you are disclosing it to us rather than someone transferring it on your behalf. Where we use service providers who process your data outside your country, we put in place an appropriate safeguard for that processing, such as the European Commission’s standard contractual clauses or the UK addendum to them. You can ask us for details.
9. Your rights
Depending on where you live, you may have the right to ask us to:
- confirm whether we hold personal data about you, and give you a copy;
- correct data that is inaccurate or incomplete;
- delete your data, where we have no continuing reason to keep it;
- restrict how we use it, or object to our use of it where we rely on legitimate interests;
- provide the data you gave us in a portable form, or send it to someone else; and
- withdraw any consent you have given, without affecting anything done before you withdrew it.
Write to info@spendlayer.com and we will respond within one month. We may ask you to confirm control of the email address on the account. These rights cannot apply to data recorded on a public blockchain — see section 5.
If you are unhappy with how we have handled your data you can complain to the data protection authority in the country where you live or work. We would rather you told us first, so we can try to put it right.
10. How long we keep it
- Account data: while your account is open, and for 12 months after you close it.
- Technical and server log data: 12 months.
- Support correspondence: 24 months from the last message.
- Anything we must keep by law, or need in order to establish, exercise or defend a legal claim: for as long as that applies.
11. Security
We use technical and organisational measures appropriate to the limited data we hold, including encryption in transit, encryption of private keys at rest, hashed passwords, access controls and logging. No system is completely secure. Your password, and any private key you export, are yours alone to protect — we cannot recover either.
12. Children
The Service is not offered to anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.
13. Cookies and similar technologies
We use only cookies and local storage that are strictly necessary to keep you signed in and to keep the Service secure. We do not use advertising cookies and we do not run third-party analytics or tracking on this website. If that changes we will ask for your consent first where the law requires it.
14. Changes to this policy
We may update this policy. Where we do, we publish the revised policy on this page with a new Effective Date, and that version takes effect on publication. Where a change is material we will also bring it to your attention within the Service. Superseded versions remain available on this page.
15. Contact
Circinus Finance Ltd., Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, Republic of the Marshall Islands MH 96960. Email info@spendlayer.com.