1. Information We Collect
Account data: When you contact us or register, we may collect your name, email address, company name, role, and other information you provide. KYC/KYB data is processed only where verification is required for a specific service and defined by its terms or provider.
Usage data: We automatically collect information about how you interact with our platform, including API call logs, wallet activity, transaction metadata, IP addresses, device identifiers, and timestamps.
Cookies: We use third-party cookies and similar technologies for analytics and marketing measurement. See Section 7 for details.
2. How We Use Information
Service provision: We use your data to operate, maintain, and improve services that are currently available, to fulfill applicable contractual obligations, and to develop and prepare pre-launch products such as BroWallet and BroCard.
Security: Where configured for a specific service and agreed with the client, transaction data may be used for risk review, unauthorized-access prevention, or checks against relevant sanctions sources. These checks do not automatically apply to every service.
Analytics: Aggregated, anonymized usage data helps us understand platform performance and prioritize product improvements.
3. Data Sharing
No sale of data: We do not sell, rent, or trade your personal data to third parties for marketing purposes. Your data is not a product.
Service providers: Depending on the service configuration, we may engage sub-processors for cloud infrastructure, KYC, AML screening, or blockchain analytics. Applicable data-processing terms govern each such engagement.
Legal requirements: We may disclose data when required by applicable law, court order, regulatory authority, or to protect the rights and safety of BroLabel and its users.
4. Data Security
We apply technical and organizational measures intended to protect personal data against unauthorized access, alteration, disclosure, or loss. The measures used depend on the relevant service, data, and infrastructure configuration.
Access controls: Role-based access control (RBAC) with least-privilege principles. All administrative access is logged, monitored, and subject to multi-factor authentication.
MPC infrastructure: BroSettlement uses distributed key generation (DKG) and a 2-of-3 MPC threshold model. Signing authority is distributed across three key shares, and two shares are required to produce a signature.
5. Data Retention
Account data: Account data is retained while the relevant account or service relationship is active and afterward only for as long as reasonably needed for service delivery, contractual matters, security, dispute handling, or applicable legal requirements.
Retention of transaction records and any KYC/KYB or screening data depends on the relevant service configuration, client agreement, security needs, and legal requirements that actually apply. BroLabel does not apply a universal five- or seven-year AML retention period.
6. Your Rights (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):
Right of access: Request a copy of the personal data we hold about you.
Right to rectification: Request correction of inaccurate or incomplete data.
Right to erasure: Request deletion of your personal data, subject to legal retention obligations.
Right to data portability: Receive your personal data in a structured, machine-readable format.
To exercise any of these rights, contact us at privacy@brolabel.io.
7. Analytics and Marketing Technologies
Analytics cookies: We use Google Analytics (GA4) according to your analytics consent choice. When storage consent is denied, Google tags may send limited cookieless signals for measurement and modeling.
Meta Pixel: On most website pages, Meta Pixel loads only after you grant marketing consent and then sends a PageView event to Meta Platforms. Meta may receive the page URL, referrer, IP address, and browser or device information and may set or read its own cookies. Payment and BroPay verification pages are excluded from this integration.
8. BroPay Chrome Extension
Local data: BroPay stores saved recipient addresses, payment-link history, observed statuses, settings, and private revocation tokens in Chrome local storage. BroLabel does not receive this local history or the plaintext revocation tokens. Data leaves the browser only when you explicitly create, check, revoke, or export a payment request.
Payment-link service: When you create a link, the extension sends the selected network, token, amount, recipient address, optional merchant name, and an anonymous installation identifier to brolabel.io over HTTPS. The request is intentionally public to anyone who has its opaque URL. Vercel and Upstash provide hosting and temporary resolver storage. BroPay also caches the observed payment status and public blockchain evidence such as received amount, confirmation count, check time, and transaction hash to reduce repeated RPC requests; security logs may include the request IP address and timestamp.
Blockchain checks: BroPay sends the recipient address, allowlisted token contract, and bounded time or block range to public Ethereum RPC, TronGrid, or TRONSCAN services solely to identify matching public transfers. Payment and verification pages are excluded from BroLabel analytics. We do not sell this data, use it for advertising, request wallet credentials, or move funds.
Retention and control: A payment link is active for 24 hours and its public instructions remain available for 30 additional days. Mutable server-side status results expire after 30 seconds; a final Paid status and its public transaction hash remain until the payment-link record expires. Revocation removes its payment details and cached status from the resolver. Local records remain until you delete them, clean old records, remove the extension, or replace them through import. JSON exports contain sensitive revocation tokens and are created only at your request.
BroPay's use and transfer of user data is limited to providing, securing, and improving its single purpose: creating and monitoring non-custodial stablecoin payment links. BroPay complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
9. Contact
For privacy-related inquiries or data subject requests, contact us at privacy@brolabel.io.