Privacy policy
This policy covers both the ShyPay mobile app and this website: what each collects, what we never collect, who else is involved, and why a public blockchain means some things can never be deleted.
What this policy covers
This policy explains how ShyPay handles personal information across everything ShyPay operates: this website at shypayments.com, the early access list, and the ShyPay mobile application (the "app").
The app is a self-custody USDC wallet on Solana, built with Expo and React Native. As shipped today, the app's code operates only on the Solana devnet test network — a mode called "mainnet" exists in the app's source so every build must name it, and building one is refused. Nothing described here changes if that changes; we will update this page first.
It does not cover the independent services ShyPay is designed to work with. Where wallet authentication, or (once integrated) funding, cash-out, or identity verification is carried out by another company, that company handles your information under its own policy and is responsible for it. See Third-party processors and public infrastructure below.
Who we are
ShyPay, LLC is the controller responsible for the personal information described in this policy, for both the website and the app. You can reach us about anything in this document at privacy@shypayments.com.
ShyPay, LLC, 8115 NW Eastside Dr, Weatherby Lake, MO 64152, United States.
What the app collects
The app is designed to hold as little about you as the features require. This is everything ShyPay's server receives or stores because of the app.
Signing in
- Your email address is handled by Dynamic (dynamic.xyz), not by ShyPay. Signing in sends a one-time code to the email you enter, and Dynamic — not ShyPay's server — verifies that code and manages the resulting session. ShyPay's server never receives your email address for an app account; it receives an authentication token from Dynamic and derives an opaque account identifier from it (a namespaced string, not your email).
- Your wallet's signing key never reaches ShyPay. Dynamic holds its share of the split signing key in secure hardware; the other share stays on your device. ShyPay's server has no share, cannot reconstruct one, and cannot sign, move, or freeze your funds.
Your profile and wallet
- A handle, a display name, and your Solana wallet address, so the app can show your balance and let other people find and pay you.
- Proof that you control your wallet address. When you link a wallet, the app signs a one-time message and ShyPay's server checks that signature before attaching the address to your profile. This only confirms a signature is valid — it never requires, receives, or produces a private key.
Contacts and payment requests you create
- Contacts you add by handle, so you can pay the same person again without retyping their details. ShyPay does not import, read, or ask for access to your device's contact book.
- Payment requests: the amount, the asset (USDC), a reference, and the request's status (open, declined, canceled, or expired), so both people can see it in the app. Once a matching transaction appears on the public Solana ledger, we may record that transaction's public signature so the request shows as paid. ShyPay's server never approves, holds, or moves the payment itself — the transaction is signed on your device and sent directly to the Solana network.
Scanning a code
- Camera access, only while you are on the scan screen. The app reads a QR code's contents on your device to route you to a payment or request screen. The camera image or video itself is never sent to or stored by ShyPay's server.
Notifications
- A device push token, if you allow notifications, so we can tell you about an incoming payment request. We use this token only to deliver that notification through Google's Firebase Cloud Messaging.
Diagnostics
- Server-side operational logs, used to keep the service running and to investigate abuse. Wallet addresses and handles are truncated before they are logged, and full addresses, tokens, or signatures are never written to a log.
What the website collects
We keep this deliberately short, because the website is deliberately plain.
Information you give us
- Your email address, if you ask to join early access or write to one of our mailboxes. We use it to reply to you and to tell you about ShyPay's progress and availability.
- Your name, and anything else you choose to put in a message. Both are optional. We would encourage you not to send us sensitive information we did not ask for.
- Whether you described yourself as an individual or a business, if you told us, so we can send you relevant news rather than all of it.
Information collected automatically
- Standard server records. Our hosting provider records requests made to the site, which includes an IP address, the page requested, a timestamp, and the browser's user-agent string. This is ordinary web-server logging, used to keep the site available and to investigate abuse.
- Nothing else. The website sets no cookies, runs no advertising or analytics scripts, embeds no third-party fonts, images, videos, or widgets, and contains no tracking pixels. See the cookie notice.
How the early access form works
When you submit the form on the early access page, your browser sends your email address, the option you chose, and your company name if you gave one, directly to a server we operate on Google Cloud. We store that record so we can write to you. The form also contains a hidden field used only to filter automated submissions.
Your details are not passed to any third-party form service, marketing platform, or customer-data tool. To be removed from the list, write to privacy@shypayments.com and we will delete the record.
Third-party processors and public infrastructure
We do not sell personal information, we do not share it with data brokers, and we do not use it for advertising or profiling. A small number of parties necessarily see information because the app and the website run on their infrastructure, or because a payment you approve is, by design, broadcast publicly.
- Dynamic (dynamic.xyz) authenticates you when you sign in to the app with an emailed one-time code, and holds its share of your wallet's split signing key in secure hardware. Dynamic handles your email address and session data under its own policy: dynamic.xyz privacy policy.
- Google Cloud and Firebase run ShyPay's server (Cloud Run), store app and website records (Firestore), and deliver push notifications (Firebase Cloud Messaging), on our instructions and under Google's own commitments: Google Privacy Policy and Google Cloud Privacy Notice.
- The public Solana network is where every payment you approve settles. The app submits your already-signed transaction to a public Solana RPC endpoint; from there it is confirmed and permanently recorded by a global, decentralized set of independent validators that ShyPay does not operate, contract with, or control. Solana is not a company processing data on our behalf — it is a public ledger. The Solana Foundation publishes its own privacy policy for its websites at solana.com/privacy-policy, but no one, including ShyPay or the Foundation, can edit or remove what is written to the ledger itself. See Blockchain data is public and permanent, and our fuller privacy approach page, which walks through who sees what, party by party.
- Our website hosting, domain, and certificate providers, and our email provider process the limited information described above so the site and our mailboxes function. They act on our instructions and may not use it for their own purposes.
We may disclose information where we are legally required to do so, or where it is necessary to establish, exercise, or defend legal claims. If we are ever permitted to tell you about such a request, we will.
What we never collect
This is as important as the lists above, so we state it directly. ShyPay does not collect, ask for, want, or have the ability to reconstruct:
- Your seed phrase, private key, or any wallet recovery material. Nobody at ShyPay will ever ask you for these, and any message that does is fraud.
- Custody of your funds. ShyPay is self-custody software. It cannot move, freeze, recover, or sign for your USDC. Every payment is signed on your own device.
- A password for the app. Signing in uses a one-time emailed code verified by Dynamic, not a ShyPay password.
- Camera images or video from scanning a code — the code's contents are read on your device and never uploaded.
- Your device's contact book, your location history, or advertising identifiers.
- Any information about what you buy. ShyPay receives no merchant line items, receipts, category codes, or loyalty identifiers.
- Identity documents, card numbers, or bank account details. Identity verification, if and when a regulated on/off-ramp provider is integrated, will be performed by that regulated provider at the point money enters or leaves the system, not by us.
Blockchain data is public and permanent
Every payment you approve in the app becomes part of the Solana ledger: the paying address, the receiving address, the amount, and the time are recorded publicly and permanently. Anyone can read this, anyone can graph the flow between addresses, and nobody — not ShyPay, not Dynamic, not you — can edit or delete an entry once it is confirmed. Today this happens on the public Solana devnet, a test network, but the same permanence and visibility apply to whichever Solana cluster the app is configured to use.
A wallet address by itself does not carry your name. But if that address is ever linked to you elsewhere — on an exchange, in a forum post, by a counterparty who knows you — that link can be traced back onto the public ledger by someone determined enough. We do not publish that link, and we do not build one for advertisers, but we would be misleading you if we described a public blockchain as private or anonymous. See our privacy approach page for a fuller, party-by-party comparison.
Why we are allowed to hold it
Where the law of your region requires us to identify a lawful basis for processing:
- Performance of a contract, for app account information — your profile, wallet-ownership proof, contacts, and payment requests are processed because they are what you asked the app to do.
- Your consent, for sending you early access email and for app notifications. You may withdraw either at any time — a single reply, or the device's own notification settings.
- Our legitimate interests, for answering correspondence, keeping the app and site running, and protecting them against abuse. We have considered your interests and use the minimum information that achieves this.
- Legal obligation, where we are required to retain or disclose something.
How long we keep it
- App profile, handle, and wallet address: for as long as your account exists, and for a reasonable period afterwards in case you return or dispute a deletion.
- Wallet-ownership challenges: the one-time message you sign expires and becomes unusable after five minutes. A record that a challenge was consumed is kept afterwards, without your signature or key material, to stop it being replayed.
- Contacts and payment requests you create in the app: until you remove them, or until you ask us to delete your account.
- Device push tokens: until you sign out, uninstall the app, or ask us to remove them.
- Early access addresses: until ShyPay launches or the list is retired, or until you ask us to remove yours, whichever comes first.
- Correspondence: for as long as needed to deal with the matter and a reasonable period afterwards in case it comes back.
- Server records and diagnostic logs: for a short operational period consistent with our hosting provider's standard retention, after which they are deleted or aggregated.
- The Solana ledger itself is never something we delete from — it is public, permanent infrastructure that no party to a transaction controls. See Blockchain data is public and permanent.
Your rights
Depending on where you live, you may have the right to ask us for a copy of the information we hold about you, to have it corrected, to have it deleted, to object to or restrict how we use it, to receive it in a portable form, and to withdraw consent you previously gave. This applies to what ShyPay's server holds about your app account as much as to the website.
Write to privacy@shypayments.com and we will respond within the period required by the law that applies to you. Deleting your ShyPay account removes what our server holds about you; it cannot remove a transaction already confirmed on the Solana ledger, and it does not reach information Dynamic or Google hold under their own policies — you can ask them directly using the links in Third-party processors and public infrastructure.
If you are unhappy with how we have handled a request, you may complain to the data protection authority in your country. We would ask you to raise it with us first, because we would rather fix it.
Children
The website and the app are not directed at children, and ShyPay is not intended for use by anyone under the age required to use financial services where they live. We do not knowingly collect information from children. If you believe a child has sent us information or created an account, tell us and we will delete it.
Where your information is held
Our hosting, email, and infrastructure providers — including Google Cloud, Firebase, and Dynamic — operate in more than one country, so your information may be processed outside the country you live in. Where the law requires a safeguard for such a transfer, we rely on the mechanisms our providers make available, such as standard contractual clauses. A confirmed Solana transaction is, by its public nature, visible everywhere at once.
How we protect it
The website is served over HTTPS with strict transport security and a content security policy that does not permit third-party scripts to load, and there is no analytics or advertising code anywhere on it. In the app, signing in uses a one-time emailed code rather than a ShyPay password, and every payment requires a fresh, on-device confirmation before it is signed. Access to the mailboxes named on this site is limited to the people who need it.
We do not claim to be unbreakable, and we hold no security certification. What we can tell you is that the amount of personal information available to lose here is deliberately very small, and that ShyPay never holds the keys that would let anyone move your funds. If you find a weakness, please tell us through our responsible disclosure policy.
Changes to this policy
We will update this policy as the product develops. The date at the top of this page shows when it was last changed, and material changes affecting people on the early access list or with an app account will be notified to them by email or by an in-app notice.
Contact
Privacy questions and requests, for the website or the app: privacy@shypayments.com.
Anything else: see the contact page.
This document is current as of the date shown above. ShyPay may update it as the product develops, and the updated version will be published on this page.