← Back to WeOkay

Privacy Policy

Last updated 12 August 2026
Draft — not yet reviewed by counsel. This describes what WeOkay’s systems actually collect and store today, so that an accurate policy can be drafted. It is not a complete privacy notice and must be reviewed against GDPR, UK GDPR, CCPA and any other applicable regimes before launch.

What we actually store

Rather than describe categories in the abstract, here is what exists in our systems:

DataWhy
Email address and/or phone numberAccount identity, provided via Privy
Your Privy account identifierLinks your login to your WeOkay account
Wallet addressPaying you, and deriving your decentralised identifier
Identity documents you uploadRegulatory identity verification (KYC)
Verified countryDetermining where regulated features may be offered
Who referred you, and who you referredCalculating compensation
Commission, ledger and booking recordsPaying you accurately and meeting record-keeping duties
Messages and posts you writeDelivering the community and support features

What we deliberately do not store

Identity documents

Documents you upload go directly to encrypted object storage using a short-lived, single-purpose link. They are never publicly readable, and are retrieved only through a freshly issued, expiring link for review.

What is published on a public blockchain

WeOkay publishes cryptographic hashes of financial events to a public blockchain so that records can be proven unaltered. A hash is one-way: it cannot be reversed to reveal the underlying data. However, blockchain records are permanent and cannot be deleted, including in response to an erasure request. Wallet addresses and transaction amounts are inherently public on any blockchain.

Who we share data with

We do not sell personal data.

Your rights

Depending on where you live, you may have rights to access, correct, export or delete your data, and to object to certain processing. Note two real limits: financial records we are legally required to retain cannot be deleted on request, and blockchain entries are immutable.

Still required before launch: the identity of the data controller and any EU/UK representative, lawful bases for each processing purpose, concrete retention periods, international transfer mechanisms, cookie and analytics disclosures, a data-subject request process and contact point, and breach notification commitments.