Trust Center
How WalletWallet handles security, data protection, and data residency. The Service is operated by Proof of Stake SRL, registered in Romania (J35/638/2018, VAT RO38943299).
- Data at rest
- Cloudflare's EU region
- Encryption
- In transit and at rest
- GDPR
- Signable Art. 28 DPA
- Sub-processor changes
- 30 days notice
Data Processing Agreement
Signable GDPR Article 28 terms: roles, instructions, breach notification, transfers, and technical measures. Print to PDF, sign, and email it to us to countersign.
Sub-processors
Every provider that touches personal data, with roles, locations, and transfer mechanisms, plus a dated changelog and 30 days notice of changes.
Security overview
Infrastructure, encryption in transit and at rest, API key and pass token handling, tenant separation, recovery, and how to report a vulnerability.
Security questionnaire
Pre-filled answers to the questions vendor security reviews ask most often, ready to paste into your portal.
Data residency
Customer and pass data is stored at rest in Cloudflare's European Union region: the primary database and the pass object store both run in Cloudflare's EU location, with no replicas outside it. Request processing runs on Cloudflare's global edge network, so compute is not EU only, and traffic is encrypted in transit throughout. For the transfers this involves, Cloudflare provides the EU Standard Contractual Clauses and holds an EU Cloud Code of Conduct verification.
Data we process
We store your account email, API usage counts, the pass content you submit, and the device data needed to deliver updates (Apple push tokens and Google install state). We never store passwords (sign-in is a one-time email code or Google sign-in) or card details (our payment provider Polar holds those), and passes must not contain special-category data, payment card numbers, or government ID numbers.
Subject rights and contact
Data-subject requests, DPA signatures, sub-processor notification sign-ups, and security reports all go to [email protected]. We acknowledge within 2 business days, complete data-subject requests within 30 days as the GDPR requires, and delete accounts within 30 days of a deletion request. Rights and legal bases are detailed in the Privacy Policy.