Privacy Policy
Effective date: July 15, 2026 · Version 1.0
This Privacy Policy explains how the operator of stabledeliver.com ("StableDeliver", "we", "us") collects, uses, shares, stores, and protects personal data when people use the StableDeliver website, seller dashboard, hosted checkouts, plugins, APIs, webhooks, support, and related services.
Role distinction: StableDeliver acts as a controller for account, security, billing, and platform-operation data, and as a processor/service provider when handling buyer data solely on a seller's instructions. Sellers remain responsible for their own buyer privacy notices and lawful basis.
1. Who is responsible for your data
The operator of stabledeliver.com, operating from the United Arab Emirates, is the controller for personal data used to create and manage StableDeliver accounts, operate and secure the platform, administer subscriptions, prevent abuse, communicate with users, and comply with law.
For buyer contact or fulfilment data submitted by a seller, StableDeliver generally acts on behalf of that seller. The seller determines why the data is collected and must provide the buyer with an appropriate privacy notice. The Data Processing Addendum governs this processing where applicable.
2. Data we collect
- Account data: email address, authentication records, account status, preferences, and organisation information.
- Wallet data: public wallet addresses, supported networks, wallet-signature or connection metadata, and seller-configured receiving addresses. Public wallet addresses can be personal data when linked to an identifiable person.
- Seller Content: product names and descriptions, files, links, licence keys, access instructions, branding, pricing configuration, and related metadata.
- Buyer and fulfilment data: information required by the seller's chosen delivery method, which may include an email address, Telegram or Discord identifier, claim status, delivery token, licence-key assignment, or access record.
- Order and blockchain data: order identifier, product, quote, asset, chain, amount, destination address, transaction hash, confirmations, timestamps, and delivery outcome.
- Subscription and billing data: selected plan, amount, currency or token, invoice or order reference, payment transaction, subscription dates, and tax information where applicable.
- Device, log, and security data: browser and device type, timestamps, request metadata, authentication events, error data, API usage, abuse signals, and IP address where processed by servers, security systems, hosting, or network providers. We do not use this information for behavioural advertising.
- Support and communications: messages, attachments, feedback, complaint history, and records necessary to resolve requests.
- Analytics: privacy-focused, self-hosted event data about page, tool, checkout, and feature usage. We do not use behavioural advertising cookies, fingerprinting, or third-party ad trackers.
3. Data we do not need
StableDeliver does not need and will not ask you to provide a wallet seed phrase or private key. Never send either to StableDeliver or to any seller. If anyone claiming to represent StableDeliver asks for one, report it immediately to [email protected] (subject line: "Security").
StableDeliver does not collect payment-card credentials. If card or fiat payment products are added later, this policy will be updated before launch.
4. How we use personal data
- Provide, maintain, personalise, and support the Service.
- Authenticate accounts, maintain sessions, issue API credentials, and manage permissions.
- Create checkout quotes, observe on-chain payments, match orders, and release configured fulfilment.
- Deliver files, links, licence keys, access instructions, notices, and seller-requested messages.
- Administer subscriptions, plan allowances, invoices, and account status.
- Detect fraud, phishing, malware, abuse, sanctions risk, account compromise, service attacks, and policy violations.
- Measure performance and improve reliability, usability, documentation, and conversion.
- Respond to support, privacy, copyright, legal, and security requests.
- Comply with law, legal process, recordkeeping, tax, sanctions, and regulatory obligations.
- Establish, exercise, or defend legal claims.
5. Legal bases
Depending on location and context, we rely on performance of a contract, steps requested before entering a contract, legitimate interests, compliance with legal obligations, consent, and establishment or defence of legal claims. Where consent is required, it may be withdrawn without affecting earlier lawful processing.
Our legitimate interests include operating a secure non-custodial checkout and fulfilment service, preventing abuse, supporting users, improving the product, and maintaining business records. We balance these interests against individual rights.
6. Public blockchains
Blockchain transactions are public and may be permanent. StableDeliver cannot delete or alter data written to a public blockchain. Even if we delete account information, transaction hashes and wallet activity may remain publicly visible and may be copied or analysed by third parties.
Do not use a wallet address for StableDeliver if you do not want that address associated with your business activity or orders.
7. Cookies and local storage
StableDeliver uses strictly necessary cookies and local storage for authentication, CSRF protection, security, preferences, and checkout state, plus one first-party attribution cookie that remembers your first-touch source for signup. We do not use advertising cookies. See the Cookie and Local Storage Notice for the technologies in use.
8. How we share data
- Sellers and buyers: information necessary to create, verify, deliver, support, or evidence an order.
- Service providers: hosting, CDN/DNS, email, and blockchain infrastructure providers listed on the Subprocessor page.
- Wallets, blockchains, and infrastructure: public transaction requests or blockchain queries necessary to support the chosen network.
- Professional advisers: lawyers, auditors, accountants, insurers, and compliance advisers under confidentiality duties.
- Authorities and rights protection: where required by law, legal process, regulatory request, protection of users, security investigation, sanctions compliance, or enforcement of policies.
- Corporate transactions: financing, merger, sale, reorganisation, or transfer, subject to appropriate confidentiality and legal safeguards.
9. International transfers
StableDeliver and its providers may process data in countries other than your country, including Germany (hosting) and the United States (email delivery, CDN). Where required, we use recognised transfer mechanisms, contractual safeguards, adequacy decisions, or other lawful bases. Business customers may request applicable transfer terms through [email protected].
10. Data retention
We retain personal data only for as long as necessary for the purposes described, including account operation, security, legal compliance, dispute resolution, backup integrity, and enforcement. The published Data Retention Schedule states the normal periods.
11. Security
We use administrative, technical, and organisational safeguards appropriate to the nature and risk of processing, including access control, tenant isolation, encryption where appropriate, audit logging, secure authentication, backups, and security monitoring. No system is completely secure, and we cannot guarantee that unauthorised access or loss will never occur.
If a security incident affects personal data, we will investigate and provide notices required by applicable law.
12. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive a portable copy, complain to a regulator, or obtain information about transfers and automated decisions.
Submit requests to [email protected] with the subject line "Privacy request". We may verify identity and authority before responding. If StableDeliver processes buyer data solely for a seller, we may refer the request to that seller and assist as required.
Rights are subject to legal exceptions, public-blockchain limitations, recordkeeping obligations, security, and the rights of others.
13. Seller responsibilities for buyer data
Sellers must collect only data reasonably required for fulfilment, provide buyers with a lawful privacy notice, establish a valid legal basis, honour buyer rights, secure exported data, and avoid uploading sensitive data unless expressly supported and legally justified.
Sellers must not use StableDeliver to collect passwords, private keys, seed phrases, government identifiers, health data, biometric data, children's data, or other high-risk data unless StableDeliver has expressly approved the use in writing and appropriate safeguards are in place.
14. Children
The Service is intended for adults and businesses and is not directed to children. Sellers may not knowingly use StableDeliver to sell to, profile, or collect personal data from children in violation of applicable law. If we learn that prohibited children's data has been collected, we may restrict the account and delete or preserve information as legally required.
15. Automated processing
We may use automated systems to match transactions, detect abuse, identify risk, prioritise alerts, or enforce technical limits. We do not intend to make solely automated decisions that produce significant legal effects about individuals unless permitted by law and accompanied by required safeguards.
16. Changes and contact
We may update this policy. The current version and effective date will be posted on the website, with additional notice for material changes where appropriate.
Controller: StableDeliver (operator of stabledeliver.com, United Arab Emirates) Registered entity details are available on request to parties with a legitimate need. Privacy contact and general support: [email protected] (subject line "Privacy request" for data-rights matters)