Privacy Policy
Last updated June 19, 2026
This Privacy Policy explains how Plinky Pay Inc. (“Plinky,” “we,” “us,” or “our”) collects, uses, and shares information when you use Plinky at plinky.to (the “Service”). Plinky is a non-custodial wallet: you control your own funds, and we never take custody of them.
The short version
- We collect the minimum needed to run your wallet: a username, optional profile details, your public wallet address, and transaction metadata.
- We never hold your funds, your wallet’s private keys, or your payment-card details.
- Buying funds with a card is handled by a third-party payment provider that performs its own identity checks; we don’t receive your card number or government ID.
- Blockchain transactions are public and permanent, which is outside our control.
Information we collect
Information you provide
- Account details: the username and display name you choose, and an optional profile image URL.
- Recovery email (optional): if you choose to add one as a backup way to access your account.
- Payment content: the amount and any optional message attached to a payment you send.
- Communications: anything you send us when you contact support.
Information collected automatically
- Wallet address: the public blockchain address of the embedded wallet created for your account.
- Transaction metadata: payment amounts, timestamps, and on-chain transaction hashes used to display your activity.
- Passkey identifiers: the public credential information needed to authenticate you. We never see or store the private key behind your passkey.
- Technical & usage data: IP address, browser/device type, and basic usage events, used for security and to keep the Service working.
What we do not collect
- We do not hold or have access to your funds or your wallet’s private keys.
- We do not collect or store your payment-card numbers. Those go directly to our payment provider.
- We do not collect government-issued identity documents. Where identity verification (KYC) is required to buy funds with fiat, the payment provider performs it directly with you.
How we use information
- To create and operate your wallet and show your balance and activity.
- To authenticate you and secure your account.
- To detect, prevent, and investigate fraud, abuse, and security issues.
- To comply with applicable legal obligations.
- To respond to your support requests and, where permitted, send you service-related messages.
Third-party service providers
We rely on a small number of trusted providers to deliver the Service. They process information only as needed to perform their function:
- Privy: authentication (passkeys) and non-custodial embedded wallet infrastructure.
- Supabase: database hosting for account profiles and payment metadata.
- Railway: application hosting.
- Fiat on-ramp provider(s) (such as MoonPay): they let you add funds to your own wallet with a card or local payment method. These providers are independent controllers of the information you give them, including any identity verification, and handle it under their own privacy policies.
- Public blockchains (Base / Ethereum): transactions you make are recorded on a public ledger that anyone can view. This data is permanent and cannot be edited or deleted by us or by you.
Cookies
We use essential cookies and similar technologies to keep you signed in and to operate core features. We do not use them to build advertising profiles.
When we share information
We do not sell your personal information. We share it only: (a) with the service providers above; (b) when required by law, legal process, or a valid government request; (c) to protect the rights, safety, and security of Plinky, our users, or the public; or (d) in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Data retention
We keep account and payment metadata for as long as your account is active and as needed to provide the Service and meet legal obligations. When you delete your account, we remove your profile and associated metadata from our systems, except where we must retain limited records for legal, security, or fraud-prevention purposes. Note that on-chain transaction data cannot be deleted.
Your choices and rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to or restrict certain processing. You can edit your profile or delete your account at any time in your settings, or contact us at ops@plinky.to. We will respond as required by applicable law. Because the Service is non-custodial, deleting your account does not move or recover funds in your wallet, and you remain responsible for your own wallet access.
Security
We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because your wallet is self-custodial, safeguarding your passkey and any recovery method is your responsibility.
Children
The Service is not directed to anyone under the age of majority in their jurisdiction, and we do not knowingly collect information from them. If you believe a minor has provided us information, contact us and we will delete it.
International users
We are based in Canada and our providers may process information in Canada, the United States, and other countries. By using the Service, you understand your information may be transferred to and processed in countries with different data-protection laws than your own.
Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above, and material changes may be highlighted in the Service. Your continued use after an update means you accept the revised Policy.
Contact us
Questions about this Policy or your information? Email us at ops@plinky.to. Plinky Pay Inc. is the entity responsible for your information and is incorporated under the laws of Canada, operating from the Province of Ontario, Canada.