Privacy Policy
Last updated: 2026-06-09
1. Who we are
This Privacy Policy explains how the entity that operates the Stove websites, applications, and related services (the "Services") — referred to in this Policy as "the Company", "we", or "us" — collects, uses, and protects personal data. For the purposes of applicable data-protection laws, the Company is the data controller of the personal data described here.
For matters concerning the Stove tokens and onboarding, certain processing is also carried out by, or on behalf of, the token Issuer and its compliance providers; where they determine the purposes of that processing, they act as separate controllers under their own arrangements.
2. Scope
This Policy applies to personal data we process about visitors to our websites, users of our applications, and persons who apply for or complete onboarding. It does not apply to third-party services that have their own privacy policies.
3. Personal data we collect
- Identity and onboarding data — name, date of birth, nationality, country of residence, government identification, tax identification, entity details and beneficial-ownership information (for entities), and documents you provide during KYC/KYB and eligibility verification.
- Contact data — email address and other contact details you provide.
- Wallet and transaction data — blockchain wallet address(es), allowlisting status, and on-chain transaction records associated with your use of the Services.
- Usage and device data — IP address, device and browser information, log data, and analytics about how you interact with the Services (see Section 11, Cookies).
- Communications — records of your correspondence with us, including support requests.
We collect this data directly from you, automatically through your use of the Services, and from third parties such as identity-verification, compliance, and analytics providers.
4. How and why we use personal data
We use personal data to:
- provide, operate, and improve the Services;
- carry out onboarding, KYC/KYB, eligibility, sanctions, and anti-money-laundering / counter-terrorist-financing screening, and ongoing monitoring;
- determine and verify your eligibility to access the Services and the tokens;
- communicate with you, respond to requests, and provide support;
- maintain the security and integrity of the Services and prevent fraud and abuse;
- comply with our legal, regulatory, and contractual obligations and respond to lawful requests from authorities; and
- establish, exercise, or defend legal claims.
5. Legal bases for processing
Where data-protection laws such as the EU/UK GDPR require a legal basis, we rely on one or more of: performance of a contract with you; compliance with a legal obligation; our legitimate interests (including operating, securing, and improving the Services and preventing fraud), balanced against your rights; and, where applicable, your consent (for example, for certain cookies or communications), which you may withdraw at any time.
6. How we share personal data
We may share personal data with:
- Service providers and sub-processors acting on our behalf, including identity-verification and compliance providers, hosting and infrastructure providers, analytics providers, and communications tools;
- the token Issuer, custodians, and regulated brokers to the extent necessary for onboarding, issuance, custody, and settlement;
- professional advisers (such as legal, audit, and accounting firms);
- regulators, law-enforcement, and other authorities where required by law or to protect our rights; and
- affiliates and any successor in connection with a corporate transaction.
We do not sell your personal data.
7. International transfers
We may transfer personal data to recipients in countries other than your own, which may have different data-protection standards. Where required, we put in place appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for such transfers.
8. On-chain data
Please note that blockchain networks are public and, by design, immutable. Wallet addresses and transactions recorded on a public blockchain are visible to anyone and generally cannot be changed, deleted, or erased. Information that becomes part of the blockchain is therefore outside our control, and rights such as erasure cannot be exercised over on-chain data.
9. Data retention
We retain personal data for as long as necessary for the purposes described in this Policy, including to meet legal, regulatory, tax, accounting, and recordkeeping obligations (for example, AML recordkeeping requirements), and to establish or defend legal claims. When data is no longer needed, we delete or anonymize it.
10. Your rights
Subject to applicable law, you may have the right to: access your personal data; have it corrected; have it erased; restrict or object to certain processing; receive it in a portable format; and withdraw consent where processing is based on consent. Where processing is required for legal or compliance purposes, some of these rights may be limited. You may also have the right to lodge a complaint with your local data-protection authority.
To exercise any right, contact us at business@stove.finance. We may need to verify your identity before responding.
11. Cookies and similar technologies
We use cookies and similar technologies on our websites. For details and how to manage your preferences, see our Cookies Policy below.
12. Security
We maintain technical and organizational measures designed to protect personal data against unauthorized access, loss, or misuse. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children
The Services are not directed to, and are not intended for use by, children. We do not knowingly collect personal data from children.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by posting the updated Policy with a revised "Last updated" date.
15. Contact
For privacy questions or to exercise your rights, contact business@stove.finance.