Privacy Policy
Last updated: January 2025
1. Our Privacy Commitment
Trustfy is a non-custodial P2P marketplace. We collect the minimum data needed to operate the service, resolve disputes, and comply with applicable law. We never sell your data to third parties. We never use your data for targeted advertising. Your wallet address is your identity — we don't require email, phone, or government ID to start trading.
2. Data We Collect
- Wallet address — your primary identity, linked via SIWE (Sign-In with Ethereum) signature. We never see your private keys.
- Display name — 3–15 alphanumeric characters, shown publicly on offer cards.
- Country & preferred currency — used for marketplace filtering and regional compliance.
- Payment method details — encrypted at rest with AES-256-GCM. Only revealed to your trade counterparty after escrow is funded on-chain.
- Trade chat & evidence — private to trade participants. Visible to an assigned arbitrator only after a dispute is opened.
- Telegram handle (optional) — used solely for sending trade notifications.
3. Privacy Tiers — Who Sees What
| Data | Public | Participants | Arbitrator | Admin |
|---|---|---|---|---|
| Offer price & rails | ✓ | ✓ | ✓ | ✓ |
| Payment account details | ✗ | ✓ after FUNDED | ✓ after dispute | ✗ (default) |
| Trade chat | ✗ | ✓ | ✓ after dispute | ✗ |
| Evidence files | ✗ | ✓ | ✓ after dispute | ✗ |
Admins do not have standing access to evidence. Emergency access requires break-glass governance with a reason code, duration, and audit log entry.
4. Data Storage
- On-chain (BNB Smart Chain): escrow locks, dispute bonds, slashing outcomes — public and immutable by design.
- Off-chain (PostgreSQL): offer metadata, match coordination, payment method PII (encrypted), chat messages, and evidence file hashes.
- Evidence files: stored in encrypted object storage (MinIO, S3-compatible). SHA-256 hashes are anchored on-chain via
EvidenceSubmittedevents for tamper-proofing.
5. Data Retention
Trade data is retained for 7 years to support dispute audit and regulatory compliance. KYC documents (where applicable) are deleted 90 days after verification — only the verification status is retained. On-chain data is immutable and cannot be deleted.
6. Your Rights
You may request export or deletion of your off-chain data at any time via Telegram [@trustfy_bot](https://t.me/trustfy_bot). On-chain data (smart-contract state, transaction history) is immutable and cannot be modified or deleted by anyone — including Trustfy.
7. Cookies & Local Storage
Trustfy uses browser localStorage for: your SIWE session token (24-hour TTL), viewer preference, and UI state. We do not use third-party tracking cookies, analytics scripts, or advertising pixels.
8. Security Measures
All payment method PII is encrypted at rest using AES-256-GCM. Backend startup validation rejects insecure configurations. Role-based access control (RBAC) limits admin capabilities. Rate limiting is enforced on all endpoints. Replay protection is applied to all signed requests. The smart contract is protected by ReentrancyGuard and replay-protected via operationId.
9. Compliance & Law Enforcement
Trustfy may disclose data when required by law, court order, or legitimate government request, but only to the extent necessary. We do not proactively share user data with any government. We will publish a transparency report if we receive law-enforcement requests.
10. Contact
For privacy questions or data requests, contact us via Telegram at [@trustfy_bot](https://t.me/trustfy_bot) or email [email protected].