Privacy Policy

Last Updated: July 2026

This Privacy Policy explains how Floe Labs, Inc. (“Floe,” “we,” “us”) collects, uses, discloses, and protects personal information in connection with the Services described in our Terms of Use. It applies to individuals and to representatives of businesses that use the Services, and it covers both our website and our financial-operations platform.

  1. Scope and Roles
    This Policy applies to personal information Floe processes as a controller (or “business”) — for example, information about account holders and their representatives. Where you provide us with personal information about your own end users, you are the controller/business for that information and Floe processes it as your service provider/processor under our agreement with you; you are responsible for providing notice to and obtaining any consent from your end users.
    Blockchain transactions are public and immutable. Floe cannot modify or delete data recorded on a public blockchain. Where the Services rely on self-hosted wallets, Floe does not collect personal information from on-chain activity beyond what is publicly available and what you associate with your account.

  2. Information We Collect
    We collect the following categories of information, directly from you, automatically through your use of the Services, and from third parties such as verification, banking, ramp, and analytics providers:
    Category Examples
    Identifiers & account data Name, email, business name, account and login identifiers, API keys.
    Business / KYB data Business registration details, beneficial-ownership and representative information, and verification results, collected directly or via providers such as Plaid.
    Financial & transaction data Balances, credits, transactions, spend and settlement records, vendor usage, card and payment metadata, and, where applicable, bank-connection and ramp data via third-party providers.
    Wallet & blockchain data Wallet addresses (including non-custodial wallets provisioned through our wallet-infrastructure provider, Privy) and on-chain transactions associated with your use of the Interface.
    Technical & usage data IP address (may be truncated), device and browser information, cookies and similar technologies, and interaction/log data.
    Communications Messages you send via email, support, or other channels.

We do not intentionally collect special categories of data (such as health or biometric data) and ask that you not submit them through the Services.
3. How We Use Information
We use personal information to:
• Provide, operate, maintain, and improve the Services, including account setup, balances, spend controls, settlement, and reporting;
• Verify identity and business status (KYB), and prevent, detect, and investigate fraud, abuse, and security incidents;
• Build and maintain reputation, cost-optimization, and underwriting analytics (the “Reputation Graph”), and, where offered, assess eligibility for working-capital or deferred-payment features;
• Process payments and facilitate third-party ramp, card, and vendor transactions;
• Communicate with you, respond to inquiries, and send service and, where permitted, marketing messages;
• Comply with legal, regulatory, sanctions, anti-money-laundering, tax, and recordkeeping obligations; and
• Establish, exercise, or defend legal claims, and enforce our Terms.
Where required by law, we rely on the following legal bases (GDPR/UK GDPR): performance of a contract; compliance with a legal obligation; our legitimate interests in operating, securing, and improving the Services and preventing fraud; and, where applicable, your consent (which you may withdraw).
Automated processing. The Reputation Graph and any eligibility assessments may involve automated processing of transaction data. Where any such processing produces legal or similarly significant effects about you and is solely automated, we will provide the rights and safeguards required by applicable law, including, where applicable, the ability to obtain human review.
4. Cookies and Similar Technologies
We and our providers use cookies and similar technologies to operate the Site, remember preferences, measure usage, and secure the Services. You can control cookies through your browser settings and, where offered, our cookie controls. Some features may not function without certain cookies.
5. How We Share Information
We share personal information with:
• Service providers and sub-processors that perform services on our behalf (hosting, analytics, security, KYB/identity verification, banking, card issuance, and ramp providers), under contractual confidentiality and data-protection obligations;
• Financial-services partners and vendors as necessary to process transactions you initiate;
• Professional advisors (legal, accounting, insurance);
• Authorities, regulators, and parties to legal process where we believe disclosure is required by law or necessary to protect rights, safety, or the integrity of the Services; and
• A successor entity in connection with a merger, acquisition, financing, or sale of assets.
We do not sell personal information for money. We do not use or disclose sensitive personal information for purposes that require a right to limit under applicable U.S. state law. To the extent any sharing for cross-context behavioral advertising is treated as a “sale” or “share” under laws such as the CCPA/CPRA, we honor opt-out preference signals (including Global Privacy Control) and provide the opt-out mechanisms described in Section 8.
6. International Transfers
Floe is based in the United States, and we and our providers may process information in the United States and other countries whose data-protection laws may differ from yours. Where we transfer personal information from the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.
7. Data Retention and Security
We retain personal information only as long as necessary for the purposes described in this Policy, including to provide the Services, comply with legal, tax, anti-money-laundering, and recordkeeping obligations (which may require multi-year retention of transaction and verification records), resolve disputes, and enforce our agreements. We implement reasonable technical and organizational safeguards designed to protect personal information, but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to opt out of certain sharing or targeted advertising. Subject to legal limits (for example, information we must retain for compliance, and immutable on-chain data we cannot alter), we will honor valid requests.
To exercise your rights, contact us at legal@floelabs.xyz. We will verify your request as required by law and will not discriminate against you for exercising your rights. You may use an authorized agent where permitted. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.
U.S. state privacy rights (e.g., California/CPRA and similar laws). California and certain other state residents have the rights described above, including to know the categories of information collected and disclosed, to request deletion and correction, and to opt out of any “sale” or “share.” We honor recognized opt-out preference signals such as Global Privacy Control.
9. Children’s Privacy
The Services are not directed to children, and account holders must be at least 18. We do not knowingly collect personal information from children under 13 (or the applicable age in your jurisdiction). If you believe a child has provided us information, contact legal@floelabs.xyz and we will take appropriate steps.
10. Third-Party Services and Links
The Services integrate with and link to third parties (wallet-infrastructure providers such as Privy, ramp providers such as Coinbase, card issuers, verification providers such as Plaid, vendors, and analytics providers) that have their own privacy practices. This Policy does not cover those third parties, and we encourage you to review their privacy notices.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last Updated” date and, where appropriate, by additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
12. Contact Us
Floe Labs, Inc. · Delaware, USA · Privacy requests and questions: legal@floelabs.xyz
If you are in the EEA/UK and we are required to designate a representative or data protection officer, their contact details will be provided here.