Landfall provides software and APIs that let online businesses accept digital assets inside their own products. This policy explains what personal information we handle, why we handle it, and the choices you have. It applies to our website, our operations console, our API and related support (together, the "Service").
We've tried to write it plainly. If anything is unclear, email privacy@landfallpay.com.
The short version
- Our customers are businesses. We handle a small amount of personal information about the people who work for them and about visitors to our website.
- When a customer's end users pay with digital assets, we process the related data on that customer's behalf and under its instructions. The customer decides what data is sent to us and how it is used.
- We don't hold our customers' funds or private keys. Wallets, keys and signing stay with the customer.
- We don't sell personal information, and our website uses only essential cookies.
Our role
How we treat personal information depends on whose information it is.
Where we decide how it's used. For website visitors, people who contact us, and customer staff who use the console, Landfall decides why and how the information is processed. In data protection terms, we are the controller, and this policy applies.
Where we act for our customers. When a customer uses the Service to accept payments, we process information about its end users (the people paying) only to provide the Service to that customer and only as it instructs. In data protection terms, the customer is the controller and we act as its processor. The customer's own privacy notice governs that data.
If you are an end user of one of our customers, please contact that business directly with questions about your data. If you contact us instead, we will pass your request to the customer and help it respond.
Information we collect
Website visitors
- Server logs: IP address, browser type and version, device and operating system details, referring page, pages requested and timestamps.
- Your language preference, stored in an essential cookie.
We don't use advertising or cross-site tracking cookies, and we don't build profiles of website visitors.
Console users (our customers' staff)
- Name, work email address, and assigned role and permissions.
- Two-factor authentication settings.
- Sign-in records and audit logs of actions taken in the console, including timestamps and IP addresses.
- Messages you send to our support team.
Business contacts
- Name, work email address and job title of people who handle contracts, billing or technical integration for a customer or prospective customer, and the content of our correspondence.
End-user data we process for customers
Depending on how a customer integrates the Service, this can include:
- Blockchain addresses, including the deposit addresses issued for the customer and the addresses that send or receive funds.
- Transaction hashes, amounts, assets, networks and confirmation status.
- The reference IDs the customer uses to identify its own users or orders.
- IP address and device information, only if the customer's checkout sends it to us.
We don't ask customers to send us end users' names, contact details or identity documents, and the Service doesn't need them to work.
A note on blockchain data. Transactions on public blockchains are visible to anyone and can't be altered or deleted by us or by anyone else. An address or transaction hash can become linked to a person when combined with other information. Whenever that's the case, we treat it as personal information.
How we use information
We use the information we control to:
- run, secure and support the website and the console;
- authenticate console users, enforce roles and permissions, and keep audit trails;
- detect and prevent fraud, abuse and security incidents;
- answer questions, provide support and send service notices such as incident updates, security alerts and changes to our terms;
- manage contracts and billing;
- understand, in aggregate, how the Service is used so we can improve it;
- comply with legal obligations and enforce our agreements.
We use end-user data only to provide the Service to the customer it belongs to: generating deposit addresses, detecting and confirming deposits, crediting them, sending webhooks, sweeping funds to the customer's wallets, preparing withdrawals and refunds, and keeping the records the customer sees in its console. We also use it to keep the Service secure and working. We don't use it for our own marketing, and we don't combine it across customers to profile individuals.
We don't make decisions with legal or similarly significant effects on people by automated means alone. Policy checks in the Service apply rules that each customer sets.
Legal bases
If you are in the European Economic Area, the United Kingdom or another place with similar rules, we rely on these legal bases for the processing we control:
- Contract: to provide the Service to our customers and their authorized users.
- Legitimate interests: to secure the Service, prevent abuse, keep records, improve our product and communicate with business contacts. We weigh these interests against your rights and don't rely on them where your rights prevail.
- Legal obligation: where the law requires us to keep or disclose information.
- Consent: where we ask for it. You can withdraw consent at any time.
How we share information
We share personal information only as described here:
- Service providers that help us run the Service, under written agreements that limit their use of the data to the work they do for us.
- Within a customer account. Console activity and audit logs are visible to authorized users of the same customer account. End-user data is available to the customer it belongs to.
- Integrations a customer connects. When a customer connects its own accounts at trading venues or liquidity providers, or points webhooks at its own systems, we send the data that function needs, at the customer's direction.
- Public blockchains. Transactions a customer signs and broadcasts become public on the relevant network.
- Legal and safety reasons. When we believe in good faith that disclosure is required by law or legal process, or is needed to protect the rights, property or safety of Landfall, our customers or others. Where we are allowed to, we tell the affected customer first.
- Business transfers. As part of a merger, acquisition or sale of assets, with this policy's protections continuing to apply.
We don't sell personal information, and we don't share it for cross-context behavioral advertising.
Service providers
We work with carefully selected vendors in these categories:
- cloud hosting, storage and database infrastructure;
- blockchain node and network data providers;
- email delivery;
- customer support and communication tools;
- error monitoring, logging and security tooling.
Customers can request our current list of sub-processors at privacy@landfallpay.com. We notify customers before adding a new sub-processor that handles end-user data.
International transfers
Our team and our service providers may be located in different countries, so your personal information may be processed outside the country where you live. When we transfer personal information across borders, we use the safeguards applicable law requires, such as standard contractual clauses, and we consider the protections available at the destination.
Retention
We keep personal information only as long as we need it for the purposes described above:
- Console accounts are kept while the user has access, then deleted or de-identified within a reasonable period after the account is removed. Audit log entries are kept as described below.
- Audit logs and transaction records are kept for the life of the customer's agreement and for any further period the agreement or the law requires, because customers rely on them for reconciliation and compliance.
- Server logs are kept for a limited period for security and troubleshooting, then deleted.
- Business correspondence is kept while the relationship lasts and afterwards for as long as needed to resolve questions or meet legal obligations.
When an agreement ends, we return or delete end-user data as the customer instructs, unless the law requires us to keep it. Information already recorded on a public blockchain can't be removed.
Security
We protect personal information with measures built for payments infrastructure, including:
- encryption in transit and at rest;
- role-based access, least-privilege permissions and two-factor authentication for our staff;
- signed webhooks and scoped, revocable API keys;
- logging and monitoring of access to production systems;
- separation of sandbox and live environments;
- vendor review and confidentiality obligations for everyone with access.
Signing happens in an environment each customer controls, so we don't store customers' private keys. No system is perfectly secure. If we become aware of a breach affecting personal information, we will notify affected customers and individuals as the law requires.
Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise a right, email privacy@landfallpay.com. We may need to verify your identity before acting, and we won't treat you differently for exercising your rights.
If your request concerns data we process for a customer, we will refer it to that customer and help it respond. You can also complain to your local data protection authority.
Cookies
Our website and console use only cookies they need to work:
- a language preference cookie, so pages load in the language you chose;
- a session cookie that keeps you signed in to the console.
We don't use advertising, social media or cross-site analytics cookies. You can block cookies in your browser settings, but signing in to the console won't work without the session cookie.
Children
The Service is built for businesses and is not directed to children. We don't knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the Service or the law changes. We will post the new version here with a new "Last updated" date. For material changes, we will also notify customers by email or in the console before the changes take effect.
Contact
- Privacy questions and requests: privacy@landfallpay.com
- Everything else: support@landfallpay.com