Privacy Policy
Last updated: July 11, 2026 · Effective: July 11, 2026
1. Introduction
This Privacy Policy explains how Pagga ("Pagga," "we," "us," or "our") collects, uses, discloses, and safeguards your information when you use our website, applications, and services (collectively, the "Service"). It applies to visitors, account holders, and authorized users of business accounts.
Pagga is an AI-powered financial operations platform providing software tools for payment processing, invoicing, treasury management, and business formation. Pagga is non-custodial and is not a bank, money transmitter, or financial institution. Your use of the Service is also governed by our Terms of Service.
2. Who We Are (Data Controller)
Pagga Inc. is the controller responsible for your personal data in connection with the Service. For privacy questions or to exercise your rights, contact privacy@pagga.io. Our full contact details are in Section 15.
3. Information We Collect
We collect the following categories of information, depending on how you use the Service:
- Account & identity data: name, email address, and authentication identifiers. We use Privy for authentication (wallet connect, email, and OAuth sign-in).
- Business & formation data: company name, entity type, jurisdiction, registered-agent details, beneficial-ownership information, and EIN/SS-4 application details you provide for formation and document-generation features.
- Verification & compliance data: identity-verification documents and information used for KYC/AML checks and sanctions screening (see Section 9).
- Financial & transaction data: invoices, payment records, treasury balances, wallet addresses, and on-chain transaction history associated with your account.
- Blockchain data: public wallet addresses and transactions recorded on public blockchains (e.g., Solana, Ethereum, Polygon, Avalanche). Note that on-chain data is public and not controlled by Pagga.
- Communications & support data: messages, inquiries, and content you submit to our AI agents or support team.
- Usage, device & cookie data: log data, IP address, device/browser information, and cookies or similar technologies (see Section 12).
Pagga does not custody your funds or hold your private keys. Self-custodied wallet seed phrases are controlled by you and are not accessible to Pagga.
4. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service, including payments, invoicing, treasury, and formation features;
- Authenticate you and secure your account;
- Power AI agents that read your data and generate invoices, documents, and financial insights on your instruction (see Section 6);
- Perform KYC/AML checks, sanctions screening, and fraud prevention;
- Communicate with you about the Service, including transactional and, where you have consented, marketing messages;
- Comply with legal, tax, and regulatory obligations; and
- Improve, analyze, and develop the Service.
5. Legal Bases for Processing
Where the EU/UK GDPR applies, we process personal data on the following legal bases: performance of a contract (to provide the Service you request); compliance with legal obligations (including AML/KYC and sanctions requirements); our legitimate interests (securing, improving, and marketing the Service, where not overridden by your rights); and your consent (e.g., for marketing emails and certain cookies), which you may withdraw at any time.
7. AI Processing
Pagga's AI agents use large language models provided by Anthropic to automate financial operations on your instruction. Content and data you submit to an agent (including financial queries and documents) may be transmitted to Anthropic's API for processing. We use these providers under agreements intended to protect your data, and we do not authorize them to train their public models on your business data except as permitted by their enterprise terms. Do not submit information to an agent that you do not wish to be processed for these purposes.
8. Data Retention
We retain personal data for as long as your account is active and as needed to provide the Service. After account termination, we may retain data for up to 90 days, and longer where required to comply with legal, tax, accounting, or regulatory obligations (including AML recordkeeping), to resolve disputes, and to enforce our agreements. On-chain transaction data recorded on public blockchains is permanent and cannot be deleted by Pagga.
9. Data Security & Compliance Screening
We implement administrative, technical, and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including encryption and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
As part of our legal obligations, we conduct identity verification and sanctions screening (including OFAC and other sanctions lists) using third-party providers, and we may report suspicious activity to FinCEN or other authorities. By using Pagga, you consent to sanctions screening and identity verification.
10. International Data Transfers
Pagga operates in the United States, and our service providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers of personal data.
11. Your Privacy Rights
Depending on your location, you may have the right to access, correct, delete, or port your personal data; to object to or restrict certain processing; and to withdraw consent. If you are in the EU/UK, these rights arise under the GDPR. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and correct personal information and to opt out of "sale" or "sharing" (note: we do not sell your personal information). We do not discriminate against you for exercising these rights.
To exercise any right, contact privacy@pagga.io. We will verify your request and respond within the timeframes required by applicable law. You may also lodge a complaint with your local data-protection authority.
13. Marketing Communications
Where you have consented, we may send you marketing emails about Pagga's products and services. You can opt out at any time using the unsubscribe link in any marketing email or by contacting us. Opting out of marketing does not affect transactional or service-related messages.
14. Children's Privacy
The Service is intended for users who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page, revise the "Last updated" date, and, for material changes, provide additional notice (such as email or in-app notification). Your continued use of the Service after an update constitutes acceptance of the revised policy.
16. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: privacy@pagga.io
Support: support@pagga.io
Pagga Inc., Wilmington, DE 19801, United States
