Privacy Policy
Last updated 12 August 2026
Draft — not yet reviewed by counsel. This describes what WeOkay’s systems actually collect and store today, so that an accurate policy can be drafted. It is not a complete privacy notice and must be reviewed against GDPR, UK GDPR, CCPA and any other applicable regimes before launch.
What we actually store
Rather than describe categories in the abstract, here is what exists in our systems:
| Data | Why |
|---|---|
| Email address and/or phone number | Account identity, provided via Privy |
| Your Privy account identifier | Links your login to your WeOkay account |
| Wallet address | Paying you, and deriving your decentralised identifier |
| Identity documents you upload | Regulatory identity verification (KYC) |
| Verified country | Determining where regulated features may be offered |
| Who referred you, and who you referred | Calculating compensation |
| Commission, ledger and booking records | Paying you accurately and meeting record-keeping duties |
| Messages and posts you write | Delivering the community and support features |
What we deliberately do not store
- We never hold your wallet private keys. Wallets are self-custodial through Privy.
- We do not store card or bank details. Payment and on-ramp providers handle those directly.
- Your identity credential contains only your decentralised identifier, a verified flag and your country — deliberately no name, document number or date of birth, so that presenting it discloses the minimum necessary.
Identity documents
Documents you upload go directly to encrypted object storage using a short-lived, single-purpose link. They are never publicly readable, and are retrieved only through a freshly issued, expiring link for review.
What is published on a public blockchain
WeOkay publishes cryptographic hashes of financial events to a public blockchain so that records can be proven unaltered. A hash is one-way: it cannot be reversed to reveal the underlying data. However, blockchain records are permanent and cannot be deleted, including in response to an erasure request. Wallet addresses and transaction amounts are inherently public on any blockchain.
Who we share data with
- Privy — authentication and wallet infrastructure
- Travel providers — only what is needed to complete a booking you make
- Identity verification providers — for KYC checks
- Your upline — limited information so that compensation can be calculated and attributed
We do not sell personal data.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your data, and to object to certain processing. Note two real limits: financial records we are legally required to retain cannot be deleted on request, and blockchain entries are immutable.
Still required before launch: the identity of the data controller and any EU/UK representative, lawful bases for each processing purpose, concrete retention periods, international transfer mechanisms, cookie and analytics disclosures, a data-subject request process and contact point, and breach notification commitments.