Skip to content

Legal

Privacy Policy

How DDPay Wallet, LLC collects, uses, shares, and protects personal data across the DDPAY Network, including identity verification, transactions, and the Andina USD and Inca Coin stablecoins.

Effective dateJuly 15, 2026
Applies toDDPay Wallet, LLC — the DDPAY Network, Andina USD, and Inca Coin
StatusIn effect
Contactcompliance@ddpay.io
01

Introduction and scope

DDPay Wallet, LLC ("DDPAY," "the Company," "we," "us," or "our") is a Wyoming, USA limited liability company that operates the DDPAY Network, a cross-border payments and interoperability platform serving individuals and businesses across the United States, Peru, and other Latin American markets. Our principal operating office is located in Lima, Peru, from which our Latin American operations, customer support, and compliance functions for the region are directed.

This Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and protect personal data when you access or use our website, mobile application, wallet infrastructure, and related services (collectively, the "Services"), including services involving Andina USD and Inca Coin (together, the "DDPAY Stablecoins").

This Policy applies to consumers, merchants, and business users ("Users," "you") who register for or interact with the Services, wherever located. By using the Services, you acknowledge the data practices described in this Policy.

02

Information we collect

2.1

Identity and account information

When you register for the Services, we collect information necessary to verify your identity and comply with Know Your Customer ("KYC") and Anti-Money Laundering ("AML") obligations, including:

  • Full legal name, date of birth, nationality, and government-issued identification numbers (e.g., DNI, RUC, passport, U.S. Social Security Number or ITIN, as applicable).
  • Residential and business addresses, phone numbers, and email addresses.
  • For business and merchant accounts: entity formation documents, beneficial ownership information, and authorized-signer identification.
  • Copies of government-issued identity documents and, where applicable, selfie or liveness-check images used to confirm that the identity document belongs to you (see Section 2.4, Biometric information).
2.2

Financial and transaction information

  • Wallet addresses, transaction history, transfer amounts, currency pairs (including USD, PEN, supported cryptocurrencies, Andina USD, and Inca Coin), timestamps, and counterparties.
  • Linked bank account, debit/credit card, or local payment-rail information used to fund or withdraw from your wallet.
  • Source-of-funds and source-of-wealth information where required by our AML/CFT program or by SBS/UIF-Perú, FinCEN, or OFAC obligations.
  • Merchant settlement data, invoicing records, and payout history for business accounts.
2.3

Device, usage, and technical information

  • IP address, device identifiers, browser type, operating system, and mobile network information.
  • App usage data, log files, crash reports, and approximate geolocation derived from IP address or device settings.
  • Cookies and similar tracking technologies, as described in our separate Cookie Policy.
2.4

Biometric information

Where the Services use selfie capture or liveness detection to confirm you are a real person and to match your face against your identification document (a process sometimes performed through our identity-verification vendor), we or our vendor process biometric identifiers derived from that image. We collect biometric information only for identity verification and fraud-prevention purposes, retain it only as long as necessary for those purposes and applicable recordkeeping law, and do not sell biometric information. Where required by applicable law (including U.S. state biometric privacy statutes), we will obtain your prior consent before collecting biometric identifiers and will provide any additional disclosures required by such law.

2.5

Information from third parties

  • Identity-verification, sanctions-screening, and fraud-detection vendors (e.g., document- and biometric-verification providers, watchlist and OFAC/UIF screening providers).
  • Banking, payment-rail, and stablecoin-issuance partners involved in processing your transactions.
  • Publicly available sources used for sanctions, politically-exposed-person ("PEP"), and adverse-media screening.
03

How we use your information

We use personal data for the following purposes:

  • To create and administer your account and provide the Services, including wallet custody, cross-border transfers, merchant payments, and stablecoin issuance/redemption.
  • To perform identity verification, KYC/CDD, sanctions screening (including OFAC and Peru's UIF lists), PEP screening, and ongoing transaction monitoring required by our AML/CFT program.
  • To comply with recordkeeping, reporting, and Travel Rule obligations applicable to virtual-asset and payment service providers in the United States and Peru.
  • To detect, investigate, and prevent fraud, unauthorized access, and other illicit activity.
  • To communicate with you about transactions, security alerts, and changes to the Services or our policies.
  • To improve, personalize, and secure the Services, including through analytics and product development.
  • To respond to lawful requests from regulators, courts, or law-enforcement authorities, including SBS, UIF-Perú, FinCEN, and OFAC.
  • To market our products to you where permitted by law and, where required, with your consent.
05

How we share information

We do not sell your personal data. We share personal data only as follows:

  • Service providers and vendors who perform functions on our behalf, including identity verification (e.g., Persona), wallet infrastructure and on/off-ramp providers (e.g., Crossmint), stablecoin issuance and reserve management (e.g., Brale), cross-border USD orchestration (e.g., Bridge.xyz), blockchain infrastructure providers, cloud hosting, and customer-support tooling — each bound by contractual confidentiality and data-protection obligations.
  • Banking and payment-rail partners necessary to execute your transfers.
  • Regulators and government authorities, including SBS, UIF-Perú, FinCEN, OFAC, and other competent authorities, where required by law, regulation, sandbox supervision, or lawful request.
  • Counterparties to a transaction, to the extent necessary to complete a transfer or payment (e.g., recipient name and wallet or account identifier).
  • Professional advisors (legal, audit, compliance) under confidentiality obligations.
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to comparable privacy protections.
  • Any other party where you have provided explicit consent.
06

International data transfers

Because DDPAY operates across the United States and Peru, personal data may be transferred between, processed in, and stored in both countries, as well as in jurisdictions where our infrastructure and service providers operate (which may include other Latin American and cloud-hosting jurisdictions).

Where we transfer personal data originating in Peru outside of Peru, we will do so on the basis of your consent, contractual necessity, or another basis recognized under Ley N.° 29733 and its regulations, and we will require recipients to maintain a comparable level of protection. Where we transfer personal data originating in the United States internationally (including to our Lima, Peru office or vendors), we apply contractual and technical safeguards designed to protect that data consistent with this Policy.

07

Data retention

We retain personal data for as long as necessary to provide the Services and to satisfy the purposes described in this Policy, including:

  • KYC, transaction, and AML/CFT records: generally a minimum of five (5) years following account closure or the date of the relevant transaction, consistent with SBS/UIF-Perú recordkeeping requirements and comparable U.S. Bank Secrecy Act-derived standards, or longer where required by applicable law or an active legal, audit, or regulatory matter.
  • Biometric identifiers: retained only as long as necessary for identity verification and fraud-prevention purposes and applicable recordkeeping law, then deleted or de-identified.
  • Marketing and analytics data: retained until you opt out or for a period consistent with our data-minimization practices.
08

Data security

We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including encryption in transit and at rest, access controls, multisignature custody controls (via Squads Protocol) for on-chain assets, redundant infrastructure, and vendor due diligence.

No system is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify you and applicable regulators as required by law.

09

Your privacy rights

9.1

Peru — Ley N.° 29733 ("ARCO" rights)

Peru

If you are located in Peru, you have the right to access, rectify, cancel, and object ("derechos ARCO") to the processing of your personal data, as well as the right to withdraw consent, subject to statutory exceptions (including our AML/CFT and regulatory recordkeeping obligations). Requests may be submitted to the contact channel identified in Section 14.

9.2

United States — state privacy laws

United States

Depending on your state of residence, you may have rights to know, access, correct, delete, or opt out of certain processing of your personal data, and to be free from discrimination for exercising these rights. We will honor verifiable requests to the extent required by applicable state law and subject to exceptions for information we must retain for legal, security, or regulatory-compliance purposes.

9.3

Verification and response

We will take reasonable steps to verify your identity before fulfilling a rights request and will respond within the timeframe required by applicable law. We may decline or limit a request where an exception applies, including where fulfilling the request would conflict with our AML/CFT, sanctions, or recordkeeping obligations.

10

Cookies and tracking technologies

Our website and app use cookies and similar technologies for authentication, security, analytics, and (where applicable) marketing. Details on the categories of cookies we use, their purposes, and how to manage your preferences are set out in our separate Cookie Policy, which forms part of this Policy by reference.

11

Automated decision-making

We use automated and algorithmic tools, including transaction-monitoring and sanctions-screening systems, to detect potentially suspicious or prohibited activity. These automated tools may result in a transaction being delayed, held, or declined, or an account being restricted, pending manual review.

You may contact us using the details in Section 14 to request human review of an automated decision that materially affects your access to the Services, subject to our overriding legal and regulatory obligations.

12

Children's privacy

The Services are not directed to, and may not be used by, individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child without appropriate consent, we will delete it.

14

Contact us

Questions, requests, or complaints regarding this Policy or our data practices may be directed to:

  • DDPay Wallet, LLC
  • Principal Office: Lima, Peru
  • Email: compliance@ddpay.io
15

Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. We will post the revised Policy with an updated "Last Updated" date and, where required by law, provide additional notice or obtain renewed consent before a material change takes effect.

Questions about your privacy

Reach out to our compliance team and we'll get back to you.

Email us