1. Platform Overview & Scope
StableBank Ltd. and its affiliated global operating entities (“StableBank”, “we”, “us”, or “our”) provide decentralized multi-currency stablecoin accounts, virtual Visa debit card issuing rails, and direct settlement infrastructure.
This Privacy Policy details how we collect, store, share, and protect information when you access our mobile applications, web portals, APIs, and associated products. By utilizing StableBank, you consent to the data collection and processing methods described herein.
2. Information We Collect
We gather only the minimum data required to facilitate regulatory compliance, prevent financial crimes, and deliver uninterrupted banking services:
- Account & Contact Data: Name, registered email address, country of residence, and optional StableTag identifier.
- Verification Data (Tiered KYC): Government-issued identification, proof of address, and liveness biometric telemetry provided strictly through our certified identity verification partners.
- Transactional & Device Telemetry: IP address, device fingerprints, card authorization logs, and settlement timestamps used for fraud monitoring.
3. On-Chain Ledger & Public Keys
Blockchain networks (including Ethereum, Arbitrum, Base, Polygon, and Avalanche) operate on publicly verifiable ledgers. When executing stablecoin transfers, deposits, or protocol interactions:
Public blockchain addresses, gas fees, transaction hashes, and timestamped smart contract calls are permanently recorded on decentralized ledgers. StableBank does not and cannot modify or erase public ledger state.
4. MPC Security & Self-Custody Architecture
StableBank uses Multi-Party Computation (MPC) cryptography. Private keys are never constructed or stored as single whole secrets on any server:
Key shards are segregated across client-side cryptographic secure enclaves and audited threshold networks. We have zero programmatic ability to execute asset transfers without your authenticated cryptographic consent.
5. How We Use Information
We strictly utilize gathered data to:
- Process card authorization requests and settle digital asset conversions in real time.
- Perform mandated Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), and OFAC sanctions screenings.
- Detect and prevent unauthorized account access, card cloning, and fraudulent activities.
- Transmit high-priority transaction confirmations, card freeze notifications, and security alerts.
6. Card Rails & Banking Partners
Virtual and physical debit card services are provided through licensed bank issuers and the Visa payment network. When performing card purchases, necessary settlement data is securely transmitted to:
- Payment network operators (Visa International) for clearing and chargeback adjudication.
- Licensed banking partners for processing ACH, FedWire, CHAPS, and SEPA fiat transfers.
- Regulated cloud infrastructure providers adhering to ISO 27001 and SOC 2 Type II audit standards.
7. Your Global Privacy Rights (GDPR & CCPA)
Regardless of geography, all verified StableBank users retain enforceable rights regarding personal data:
Right to Access & Export
Request a full machine-readable export of all off-chain personal data held by StableBank.
Right to Rectification
Correct inaccurate or outdated personal profile details through in-app settings or support.
Right to Erasure (“To Be Forgotten”)
Request deletion of off-chain records subject to statutory financial recordkeeping obligations.
Right to Restrict Processing
Opt-out of non-essential product telemetry, research communications, and marketing campaigns.
8. Data Retention & Security Measures
We implement AES-256 encryption at rest and TLS 1.3 encryption in transit across all systems. Audit logs, KYC records, and transaction logs are preserved for 5 to 7 years in compliance with international financial AML directives, after which they are securely purged.
9. Contact Our Privacy Office
To exercise your data protection rights or escalate an inquiry to our Data Protection Officer (DPO), please reach out via: