Privacy Policy
Effective date: July 23, 2026 · Last updated: July 23, 2026
This Privacy Policy explains how NETTEN LLC, a Wyoming limited liability company ("NETTEN," "we," "us"), collects, uses, and shares personal information when you use our website and Services. We act as a data controller for the personal information described here.
1. Scope
This Policy covers information we handle as a controller — for example, when you visit netten.app, create a Merchant account, or contact us. It does not cover the independent processing carried out by third-party on/off-ramp and conversion providers (such as Transak, Guardarian, and ChangeNOW), who act as separate controllers for the identity and payment information you provide to them directly. Please review each provider's own privacy policy.
2. Information we collect
You provide to us
- Account & business details — name, email, business or trading name (if you have one), country, and similar details used to create and operate a Merchant account.
- Communications — messages you send us (e.g., support requests).
- Public blockchain identifiers — the XRP Ledger wallet address you designate to receive settlement.
Collected automatically
- Usage & device data — pages viewed, actions taken, IP address, browser/device type, and similar analytics data.
- Cookies and similar technologies — used for authentication, preferences, and product analytics (see Section 7).
We do not collect
Because NETTEN is non-custodial and does not perform the fiat leg, we do not collect or store your card numbers, bank account details, or the identity-verification (KYC) documents you submit to a Provider. That information is collected directly by the applicable Provider.
3. How we use information
- To provide, operate, secure, and improve the Services.
- To authenticate you (we use magic-link email sign-in) and manage your account.
- To communicate with you about the Services, including service and transaction notifications.
- To monitor for fraud, abuse, and security threats, and to comply with legal obligations.
- To understand product usage through analytics.
4. Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Services you request); legitimate interests (to secure, analyze, and improve the Services, balanced against your rights); legal obligation (to meet compliance and record-keeping duties); and consent (for certain cookies/analytics and marketing, where required).
5. How we share information
We do not sell your personal information. We share it only as follows:
- Service providers (sub-processors) who process data on our behalf, under contract — see the table below.
- On/off-ramp & conversion providers — when you choose to use a fiat on/off-ramp or conversion, we pass the limited data needed to initiate the transaction (such as amount and the relevant wallet address). Those providers then collect any KYC and payment data directly from you as independent controllers.
- Legal & safety — where required by law, regulation, legal process, or to protect rights, safety, or the integrity of the Services.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Sub-processors & partners
| Party | Role | Data involved |
|---|---|---|
| Transak | Fiat on/off-ramp (independent controller) | Initiated directly with the user; NETTEN passes transaction amount & wallet address only |
| Guardarian | Fiat off-ramp (independent controller) | As above |
| ChangeNOW | Digital-asset conversion (independent controller) | As above |
| Squid Router | Cross-chain digital-asset routing/swaps (independent protocol/provider) | Wallet addresses & transaction amounts needed to route the swap |
| Ripple / XRP Ledger | Public blockchain settlement (RLUSD) | On-chain wallet addresses & transaction data (public by nature) |
| Neon | Database hosting (PostgreSQL) | Account & application data |
| Vercel / Railway | Application & API hosting | Usage, logs, application data |
| Resend | Transactional email (magic-link sign-in, notifications) | Email address, message content |
| PostHog | Product analytics | Usage & device data, identifiers |
| Sentry | Error monitoring & application diagnostics | Error/diagnostic data, IP address, device metadata |
6. International transfers
We are based in the United States, and our providers may process data in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.
7. Cookies & analytics
We use strictly necessary cookies for authentication and preferences, and analytics cookies/technologies (e.g., PostHog) to understand usage. Where required, we request consent for non-essential cookies. You can control cookies through your browser settings; disabling some may affect functionality.
8. Data retention
We retain personal information only for as long as we need it for the purposes described in this Policy.
- Merchant account records and transaction logs — including your name, email address, business details, the XRP Ledger address you designate for settlement, and records of transactions initiated through the Services — are retained for the life of your account and for up to ten (10) years after it is closed, in order to meet tax, accounting, anti-money-laundering, and record-keeping obligations, and to establish, exercise, or defend legal claims.
- Support and other communications are retained for up to three (3) years.
- Usage, device, and analytics data is retained for no longer than twenty-six (26) months, after which it is deleted or retained only in aggregated or de-identified form.
After the applicable period, we delete or anonymize the information. Note that public blockchain records are permanent and outside our control.
9. Your rights
EEA/UK (GDPR): subject to conditions, you may request access, rectification, erasure, restriction, portability, and object to certain processing, and withdraw consent. You may also complain to your local supervisory authority.
California (CCPA/CPRA): subject to conditions, you may request to know, access, delete, and correct personal information, and to opt out of "sale" or "sharing." We do not sell personal information. We will not discriminate against you for exercising your rights.
To exercise any right, contact [email protected]. We may need to verify your identity before responding.
10. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and magic-link authentication (no stored passwords). No method of transmission or storage is completely secure, and you are responsible for safeguarding your own wallet keys and account credentials.
11. Children
The Services are not directed to individuals under 18, and we do not knowingly collect personal information from them.
12. Changes to this Policy
We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice where appropriate.
13. Contact
Privacy questions or requests: [email protected]
NETTEN LLC, 30 North Gould Street, Ste R, Sheridan, WY 82801, USA
© 2026 NETTEN LLC. Providers named above are independent controllers for the data you provide to them directly; please review their privacy policies. This Policy governs NETTEN's own processing only.