Skip to main content
MoonTap
Counsel-review draft — not a production merchant agreement or legal advice.

Privacy Notice

Counsel-review draft describing MoonTap's current and planned data practices.

Moonsters LLC is the proposed controller of MoonTap account and merchant data. MoonTap collects only information needed for accounts, merchant onboarding, verified public wallet addresses, quotes, payment and refund evidence, security, support, compliance, and service communications.

MoonTap uses information to provide and secure the service, perform requested transactions, communicate about accounts, prevent fraud and abuse, satisfy legal obligations, establish or defend claims, and—only with separate consent where required—send marketing. The final notice must identify the applicable legal basis for each purpose and whether Moonsters LLC acts as controller or processor.

MoonTap does not need wallet private keys or seed phrases. Never send them to MoonTap. Raw identity documents should remain with the selected verification provider whenever possible; MoonTap should retain decision status, reason codes, audit references, and legally required evidence instead of duplicating documents.

Current service providers include Vercel for hosting, Supabase for authentication and database services, Brevo for authentication, product, and separately consented marketing email, private Solana RPC providers, Upstash for distributed rate limiting, and Better Stack for uptime and scheduled-job monitoring. Cloudflare, error-monitoring, and KYB/AML vendors must be added to the public subprocessor register before their production use.

Primary application data is hosted in the United States, currently including Supabase in AWS us-east-1 and Vercel functions in iad1. Vendors may process support, security, email, or telemetry data in other locations under their contracts; MoonTap does not promise data will remain exclusively in one state or country.

The baseline schedule keeps short-lived security challenges only through expiry and cleanup; observability data for 30 to 90 days; support records for 24 months; and payment, refund, settlement, tax, compliance-decision, and audit evidence for up to seven years after the relationship or transaction. Legal holds, sanctions duties, disputes, and mandatory reporting can extend retention.

Subject to applicable law and verified identity, people may request access, correction, deletion, portability, or restriction, and may opt out of marketing without affecting service email. MoonTap targets a response within 30 days and will not exceed an applicable statutory deadline without notice. Required ledger, security, tax, legal-hold, and compliance evidence may be retained while unnecessary profile data is deleted or de-identified.

MoonTap does not sell personal information. Cross-context behavioral advertising is not part of the current product. Marketing subscriptions are separate, affirmative, double-opt-in choices with their own suppression records.

Where applicable, MoonTap will honor recognized opt-out preference signals such as Global Privacy Control. Product and Moonsters company communications are separate lists: withdrawing from one must not enroll a person in another, and suppression records are used only to honor the choice and demonstrate compliance.

MoonTap is intended for merchant representatives who are at least 18 and is not directed to children. If MoonTap learns that it collected a child's personal information without lawful authorization, it will restrict use, investigate, and delete the information unless retention is legally required.

Privacy and security requests should be sent through MoonTap Support. Before production launch, Moonsters LLC must publish the final request address, subprocessor list, effective date, state-specific disclosures, and any international transfer terms reviewed by counsel.