This Privacy Policy explains how LAR TECHNOLOGY JOINT STOCK COMPANY (CÔNG TY CỔ PHẦN CÔNG NGHỆ LAR), the operator of InfraIO Pay (“InfraIO Pay”, “we”, “us”), handles information when you visit infraio.xyz, use the InfraIO Pay mobile app (the “App”), use the InfraIO Pay merchant dashboard on the web (the “Dashboard”), or use the related InfraIO Pay services (together, the “Service”). The InfraIO Wallet app has its own Privacy Policy. For cookies and similar technologies on our website, see our Cookie Policy.

1. Information you give us

  • Account and sign-in. Your email address and/or phone number, a password if you set one, your name or display name, and a username. If you sign in with Apple or Google we receive the identifier, email address and name that provider shares with us. If you add a passkey, we store its public key and identifier (never the private key). We send one-time codes by email or SMS to verify you.
  • Profile picture. If you choose one, the photo you pick or take is uploaded to our servers and shown on your profile.
  • Business and workspace data. Business or workspace name, website, support email, time zone, settings, the payment methods and tokens you enable, API keys and webhook endpoints you create, and, where required for compliance, verification information such as business registration details.
  • Orders, payment links and customers. Orders and payment links you create, the payments received for them (order identifiers, amounts, token and network, on-chain transaction identifiers, deposit and payer wallet addresses, status) and any refund requests. If you enter or import customer details, such as a customer’s name, email address or phone number, we store them for you. See section 5 for who is responsible for that data.
  • Referral and credit. Referral codes, referral commissions and credit balances linked to your workspace.
  • Support messages. The Support screen opens a draft email in your own mail app, addressed to [email protected]. It may include your workspace name, workspace ID, account ID and app version. We receive it only if you send it. If you use the in-app problem report, the App builds a report file on your device and opens your device’s share sheet; nothing is uploaded unless you choose to send it to us.
  • Contact form. If you use the contact form on our website we receive the name, work email, company name, storefront URL, estimated monthly volume and message you enter, and use them only to respond to you.

2. Wallet features in the App

The App includes a passkey wallet. When you create, add or recover a wallet, the App registers it with our wallet service: the wallet address, the public key and identifier of each passkey or device key that can approve it (never the private key), the wallet name you choose, the networks you activate and the tokens and NFTs you add or hide. If you use the address book, each contact’s name, addresses and any note are stored on our servers so they stay the same across your devices. When you send or activate a network, the App sends the request to our service, which prepares the transaction for you to approve with your passkey and submits the signed transaction to the blockchain. Our service also reads the public blockchain to show your balances, history and NFTs, resolves names you look up, and checks recipients you enter to warn you about likely mistakes. Your passkey itself stays with your device and your platform provider (iCloud Keychain or Google Password Manager); we never receive it.

Wallet addresses, balances and transactions are public on the blockchain and cannot be deleted or altered by us. The App can also connect to decentralized applications through WalletConnect or its built-in browser; those sites receive what you approve, such as your public address, and handle it under their own policies. Bookmarks and recently visited pages in the built-in browser stay on your device.

3. Information collected automatically

  • Device and session data. When you sign in, we record your IP address, user agent, app type and an app-generated device identifier (on iPhone, the identifier for vendors; on Android, a random ID generated by the App). We use this to keep you signed in, list and revoke your sessions, and to ask for an extra one-time code when a sign-in comes from an IP address and device we have not seen on your account before. We do not use GPS or device location.
  • Genuine-app checks. To tell real App installs from bots, the App uses Apple App Attest on iPhone and Google Play Integrity on Android. These checks send a one-time challenge and the attestation result issued by Apple or Google to our servers; on our website and Dashboard we use Cloudflare Turnstile for the same purpose.
  • Push notifications. If you allow notifications, we store a push token for your device (from Apple Push Notification service or Firebase Cloud Messaging), the platform, the app and the device identifier, and the notifications we send you. You can turn notifications off in your device settings or in the App.
  • Crash reports. In production builds the App sends crash reports to Firebase Crashlytics (Google), which include device model, operating system version, app version and the technical state of the App when it failed. The Dashboard and our servers report errors to our own self-hosted Sentry, configured not to collect personal data by default.
  • Server logs. Our servers receive standard log information (IP address, user agent, referrer, request time) for security, debugging and abuse prevention.
  • Website analytics. On infraio.xyz, analytics cookies are used only if you accept them in the cookie banner; see the Cookie Policy. The App does not include advertising and does not track you across other companies’ apps or websites.

4. Permissions the App may ask for

  • Camera: to scan wallet-address and WalletConnect QR codes and to take a profile picture. Scanning happens on your device; a profile picture is uploaded only if you choose to save it.
  • Photo library: only when you pick an image, either a profile picture or a QR image to scan.
  • Face ID, Touch ID or fingerprint: to sign you in, unlock the App and confirm sensitive actions such as deleting your account. Your operating system handles biometric data; it is never available to us.
  • Notifications: to deliver the push notifications described above.

5. Your customers’ data

If you are a merchant, you decide which customer information you put into InfraIO Pay and why. For that information you are responsible for having a lawful basis, informing your customers and answering their requests; we process it on your behalf to provide the Service and follow your instructions. Do not put into the Service information you have no right to share. Customers who have questions about a specific purchase should contact the merchant they paid.

6. How we use information

  • To create and secure your account, sign you in and verify it is you.
  • To provide, maintain and improve the Service, including processing payments, refunds, wallets and notifications.
  • To send you service messages such as one-time codes, security alerts and receipts.
  • To respond to enquiries, support requests and problem reports.
  • To detect, prevent and respond to fraud, abuse or violations of our Terms of Service and Acceptable Use Policy.
  • To comply with applicable laws and lawful requests.

We do not sell personal data and we do not use it for advertising.

7. Legal bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on contract performance, legitimate interests (such as security and fraud prevention), legal obligation, or your consent (for example for analytics cookies or push notifications), whichever is appropriate to the processing activity.

8. Who we share information with

  • Service providers acting on our behalf, under confidentiality and security obligations: Twilio (SMS and verification codes), our email delivery provider (verification codes and notifications), Google Firebase (push notifications through Firebase Cloud Messaging and Crashlytics crash reports), Apple (push notifications, App Attest and Sign in with Apple), Google (Sign-In and Play Integrity), Cloudflare (Turnstile and network protection) and our hosting and infrastructure providers.
  • Blockchain networks and node providers. Transactions you approve are published on public blockchains. Blockchain RPC nodes and explorers we use may see the addresses and requests involved.
  • Merchants and customers. When a customer pays a merchant, the merchant sees the order and payment details, and the customer sees the merchant’s business name.
  • Authorities when required by law, subpoena, or to protect rights and safety.
  • Successors in connection with a merger, acquisition, or asset sale, subject to the protections of this policy.

9. Retention and account deletion

We keep information for as long as needed to provide the Service, meet legal and regulatory obligations (including accounting, tax and anti-money-laundering requirements), resolve disputes and enforce our agreements. Transaction and payment records, and any compliance documentation, may be kept for the period required by law in the relevant jurisdiction. Server logs, crash reports and correspondence are kept only as long as needed for security, troubleshooting and legal purposes. We cannot delete or change data on a public blockchain.

You can delete your account in the App (Delete account). When you do, we sign you out on every device, end all sessions, release your sign-in methods (email, phone, Google, Apple and passkeys) so they stop working for the account, and mark your user profile and settings as deleted. We keep a minimal account record as an audit trail, and we keep payment records and other data where the law requires or where needed to resolve disputes. Deleting your account does not by itself erase every record we hold about you; to request erasure of a specific record, contact us as described below.

10. Your rights

Depending on your jurisdiction you may have the right to access, correct, port, restrict or delete your personal data, and to object to processing or withdraw consent. We may need to verify your identity first. To exercise these rights, contact [email protected].

11. Security

We use safeguards that include TLS encryption in transit, access controls, passkeys and one-time-code verification, and logging of security-relevant events. No system is perfectly secure. Please use a strong password, keep your device and platform account secure, and protect any recovery phrase you create.

12. International transfers

We are based in Vietnam, and our providers and infrastructure may process data in other countries. Where required we put in place standard contractual clauses or equivalent safeguards.

13. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes

We will post material changes here and update the “Last updated” date. Continued use after changes means you accept the updated policy.

15. Contact

LAR TECHNOLOGY JOINT STOCK COMPANY (CÔNG TY CỔ PHẦN CÔNG NGHỆ LAR). Questions about this policy or data-subject requests: [email protected].