LegalHukuki
Privacy Policy
This policy explains what personal data Metaverse Trading Ltd collects, why we collect it, how long we keep it and what rights you have over it. It covers this website and the software products we provide to businesses. We have tried to write it plainly. If anything is unclear, write to us at the address in section 12 and we will answer.
1. Who we are
METAVERSE TRADING LTD is a software company registered in England and Wales under company number 16644748, with its registered office at 71 to 75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. In this policy we refer to ourselves as "the Company", "we" and "us". For the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018 we are the controller of the personal data described here, except where this policy says otherwise.
2. What we do, and what we do not do
We build non-custodial payment software. Our flagship product, Sardium, lets a merchant accept card payments that settle as stablecoins into the merchant's own wallet. We supply the software; we do not hold money, we do not operate a payment account for anyone, and we do not carry out identity verification ourselves. Those functions are performed by licensed third-party providers under their own terms and privacy policies. This matters for your privacy because it limits what data ever reaches us.
3. Personal data we collect
3.1 Visitors to this website
- Server logs. Our hosting provider records the IP address, browser type, requested page and time of each request. We use these logs only to keep the site secure and to diagnose faults.
- Language preference. When you choose English or Turkish, that choice is stored in your own browser's local storage. It never leaves your device and we cannot read it.
- No cookies, no trackers. This website sets no cookies and loads no analytics, advertising or social media scripts.
- Email you send us. If you write to us, we keep your email address, your name if you give it, and the content of the correspondence for as long as needed to deal with your enquiry and any follow-up.
3.2 Merchants using our products
When a business integrates Sardium or another of our products, we collect the information needed to run the service: business name and registration details, the names and contact details of the people we deal with, the wallet address payments settle to, a hashed copy of the merchant's API key, the merchant's webhook address, and operational logs of API calls and webhook deliveries. We also collect the know-your-business documentation that our own compliance obligations require before we onboard a merchant.
3.3 End users of a merchant's checkout
When a merchant's customer pays through a Sardium checkout, we process a limited set of data on the merchant's behalf: an email address where the merchant's integration provides one, the public blockchain address that receives the funds, the amount and currency of the payment, and the on-chain transaction record. For this data the merchant is the controller and we are the processor.
We do not collect identity documents, card numbers or bank details. Card payment and identity verification are carried out by the licensed on-ramp provider chosen for the transaction, which acts as an independent controller under its own privacy policy. We never collect or hold private keys; by design they are generated on the user's own device and cannot reach our systems.
4. Why we process data, and on what legal basis
- To provide the service to merchants under our contract with them (performance of a contract).
- To keep the service secure, detect fraud and abuse, and diagnose faults (our legitimate interests, and those of our merchants).
- To screen blockchain addresses against sanctions lists before a transaction is broadcast (compliance with legal obligations and our legitimate interest in not facilitating unlawful transfers).
- To keep financial and audit records for the periods the law requires (compliance with legal obligations).
- To answer your enquiries and manage our relationship with merchants (legitimate interests and, where relevant, performance of a contract).
We do not use personal data for advertising and we do not sell it.
5. Who we share data with
- Hosting and infrastructure providers that run our website and services, under contracts that restrict what they may do with the data.
- Licensed on-ramp providers, who receive the data they need to process a fiat payment and, where required, to verify identity. They act as independent controllers.
- Merchants, who receive the data relating to their own customers' payments.
- Professional advisers such as lawyers, accountants and auditors, under a duty of confidentiality.
- Public authorities where the law requires us to disclose, or to establish, exercise or defend legal claims.
6. International transfers
Our providers operate in the United Kingdom, the European Economic Area and the United States. Where personal data leaves the UK or the EEA, we rely on an adequacy decision where one exists and otherwise on the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses, together with any additional safeguards those instruments require.
7. How long we keep data
- Website server logs: 90 days.
- Correspondence: for as long as needed to handle the matter, and then for up to two years in case of follow-up.
- Merchant account data: for the duration of the relationship and for six years after it ends, to meet accounting and legal obligations.
- Transaction records and audit trails: for the period required by applicable financial-records legislation, typically between five and ten years.
When a retention period ends, we delete the data or anonymise it so that it no longer identifies anyone.
8. How we protect data
Data at rest is encrypted with AES-256-GCM under a key-management envelope. Webhooks are signed with HMAC-SHA256 so a merchant can verify they came from us. API keys are stored only as hashes. Any change that affects the flow of funds requires approval from two people. Access to production systems is limited to those who need it and is logged in an append-only audit trail.
9. Your rights
Under UK and EU data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased where we no longer have a reason to keep it;
- restrict or object to certain processing, including any based on our legitimate interests;
- receive the data you provided to us in a portable format;
- complain to a supervisory authority.
If you are in Türkiye, you have the corresponding rights under Article 11 of the Personal Data Protection Law No. 6698, including the right to learn whether your data is processed, to request correction or deletion, and to object to results produced by automated analysis.
Merchants can exercise access and erasure requests for their own end users directly through our API, using the export and delete endpoints described in the integration documentation. If you are the customer of a merchant, please contact that merchant first; they hold the relationship with you and can act on your request through us. In every other case, write to us using the details in section 12. We respond within one month.
You can complain to the Information Commissioner's Office in the United Kingdom at ico.org.uk, to the data protection authority of the EU country where you live, or to the Personal Data Protection Board in Türkiye.
10. Children
Our products are made for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided data to us, contact us and we will delete it.
11. Changes to this policy
We will update this page when our practices change. The effective date at the top shows the current version. Where a change materially affects merchants, we will also notify the contact address we hold for them.
12. Contact
Metaverse Trading Ltd, 71 to 75 Shelton Street, Covent Garden, London, WC2H 9JQ,
United Kingdom.
Email: kyb@metaversetradingltduk.com