PRIVACY POLICY

Last Updated: February 13, 2026

INTRODUCTION

Klydo, Inc., a Delaware corporation (d/b/a VaultLeap) ("Klydo," "VaultLeap," "we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy, together with our Terms of Service, explains how we collect, use, and safeguard your information when you use our website, vaultleap.com, and related services, including the VaultLeap Platform (collectively, the "Services").

By using the Services, you agree to this Privacy Policy. If you do not agree, you must not use the Services.

1. INFORMATION WE COLLECT

1.1 Banking and Financial Services Data

We collect limited financial and identity information necessary to provide regulated financial services:

  • Account Establishment Data: legal name, address, date of birth, nationality, tax identification numbers, and government-issued identification
  • Transaction Data: payment amounts, timestamps, counterparties, routing information, settlement data, and transaction purpose
  • Compliance Documentation: data required to satisfy AML, KYC, KYB, sanctions screening, and fraud-prevention obligations
  • Banking Details: account numbers, routing numbers, IBANs, and related information required for ACH, Fedwire, and SEPA processing

1.2 Stablecoin & Blockchain Interaction Data

To facilitate fiat-to-stablecoin and blockchain-based operations:

  • Public wallet addresses
  • Transaction hashes, network identifiers, and timestamps
  • Conversion records, settlement confirmations, and fees

VaultLeap never collects or stores private keys, seed phrases, or credentials that grant access to your digital assets. We cannot recover wallet credentials if lost.

1.3 Communications & Support Data

When you contact us or interact with support:

  • Message content and metadata
  • Attachments (screenshots, logs, documents)
  • Support ticket history, internal case notes, and resolution records

1.4 Phone Number & Identity Verification

We collect phone numbers for identity verification, fraud prevention, and account security, including:

  • One-time passcodes (OTP)
  • Login and security alerts
  • Transaction confirmations

We do not use phone numbers for marketing, promotional messaging, or non-transactional communications. You will only receive messages related to account security and verification via phone number.

1.5 Device and Usage Data

We automatically collect limited technical information:

  • Device type, OS, browser, language
  • IP address and approximate location (city or regional level)
  • Login timestamps, activity logs, feature usage, reward activity, tier changes, and subscription events

1.6 Cookies and Similar Technologies

We use cookies and similar technologies to operate and improve the Services.

What are cookies? Cookies are small text files stored on your device that help us recognize you, maintain your session, and analyze usage patterns.

Types of cookies we use:

  • Essential Cookies: Required for core platform functionality (login, session management, security). These cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with the Services to improve performance and user experience.
  • Preference Cookies: Remember your settings and preferences.

Your choices: Most browsers allow you to control cookies through settings. Note that disabling essential cookies may prevent you from using certain features of the Services.

Where required by law, non-essential cookies are disabled until you provide explicit consent through our cookie banner.

For more information, see our Cookie Policy at https://vaultleap.com/cookies or contact us at support@vaultleap.com.

1.7 Referral Program Data

If you participate in referral programs, we collect:

  • Referral identifiers
  • Referral link usage
  • Referral activation and eligibility status
  • Referred user transaction volume (for calculating referrer rewards)

Referral rewards (Tier Points) are a non-monetary platform feature used solely to determine tiers and benefits. They are not stored value, currency, or financial assets.

This data is used to calculate Tier Points, determine referral eligibility, prevent fraud and abuse, and ensure compliance with program rules.

1.8 Sources of Information

We collect personal data from:

  • You directly (when you create an account, use features, or contact support)
  • Your device and browser (automatically)
  • Regulated financial and compliance partners
  • Identity verification and fraud-prevention vendors
  • Public blockchain networks

2. HOW WE USE INFORMATION AND LEGAL BASES

We process personal data for the purposes described below. For users in the EEA, UK, and other jurisdictions that require a legal basis for processing, we have identified the applicable legal basis for each purpose.

PurposeLegal Basis (GDPR)
Provide and operate banking, payment, card, and account servicesContract performance
Facilitate fiat-to-stablecoin and stablecoin-to-fiat conversionsContract performance
Meet regulatory, compliance, audit, AML, KYC, tax, and reporting obligationsLegal obligation (EU Anti-Money Laundering Directives, Bank Secrecy Act, applicable tax laws)
Prevent fraud, abuse, money laundering, and unauthorized activity through manual review and partner-provided screening servicesLegal obligation (AML regulations); Legitimate interest (platform security and integrity)
Improve platform performance, security, and user experienceLegitimate interest (service improvement and security)
Respond to support inquiries and resolve disputesContract performance; Legitimate interest (customer service)
Communicate account updates, security alerts, and compliance noticesContract performance; Legal obligation
Calculate rewards points, tier status, referral rewards, subscription eligibility, and applicable platform feesContract performance
Enforce our Terms of Service and other policiesLegitimate interest (enforcement of legal rights)
Analytics and usage tracking (non-essential cookies)Consent
Marketing communications (where applicable)Consent; Legitimate interest (direct marketing to existing customers, with opt-out)

Legitimate Interest Assessments: Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting support@vaultleap.com.

VaultLeap does not sell personal data and does not use personal data for cross-context behavioral advertising.

3. INFORMATION SHARING

VaultLeap shares data only as required to operate the platform securely and lawfully.

3.1 Regulated Financial Partners

We share data with regulated financial institutions and payment partners, including:

  • Bridge Ventures LLC
  • Lead Bank, Member FDIC

to enable compliant banking, payments, card issuance, and regulatory reporting.

3.2 Card Program Partners

If you use the VaultLeap Visa® Debit Card, we share necessary data with:

  • Bridge Ventures LLC (Program Manager)
  • Lead Bank, Member FDIC (Issuing Bank)

VaultLeap does not store full card numbers or CVV codes.

3.3 Service Providers (Sub-Processors)

We engage vetted service providers who process personal data on our behalf. All sub-processors operate under strict confidentiality and data-processing agreements that require them to process data only on our instructions and implement appropriate security measures.

Current sub-processors:

ProviderPurposeData ProcessedLocation
Bridge Ventures LLCBanking, payments, card program managementFinancial, identity, transaction dataUnited States
Lead BankCard issuance, banking servicesFinancial, identity dataUnited States
PrivyAuthentication and wallet infrastructureAuthentication credentials, wallet addressesUnited States
Google LLCAnalytics (Google Analytics)Anonymized usage data, device infoUnited States
Microsoft CorporationAnalytics (Microsoft Clarity)Session replay data, usage patternsUnited States
Cloud hosting providerInfrastructure and data storageAll data categoriesUnited States

Sub-processor changes: We will update this list when we engage new sub-processors. If you are located in the EEA or UK, you may subscribe to sub-processor change notifications by emailing support@vaultleap.com with the subject line "Sub-Processor Notifications." We will provide at least thirty (30) days' notice before engaging a new sub-processor that processes EEA or UK personal data. If you have a reasonable objection to a new sub-processor, you may contact us to discuss your concerns, and if we cannot resolve the objection, you may terminate your account.

3.4 Legal Obligations

We may disclose data when required by law, regulation, court order, subpoena, or lawful government request.

3.5 Corporate Transactions

If VaultLeap is involved in a merger, acquisition, financing, restructuring, or asset sale, personal data may be transferred subject to applicable legal protections. We will notify you of any such transfer and any choices you may have regarding your data.

3.6 No Sale or Advertising Use

VaultLeap does not sell or rent personal information and does not share personal information for cross-context behavioral advertising or marketing purposes.

4. INTERNATIONAL DATA TRANSFERS

VaultLeap is based in the United States and serves users globally. Your personal data may be transferred to, stored in, and processed in the United States and other countries where our service providers operate.

Data transferred outside your home country is protected by:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA
  • UK International Data Transfer Agreement (UK IDTA) for transfers from the UK
  • Other appropriate safeguards as required by applicable law

We conduct transfer impact assessments for international data transfers to ensure adequate protection of your personal data.

By using the Services, you consent to the transfer of your information to the United States and other jurisdictions that may have different data protection laws than your country of residence.

5. SECURITY

We employ enterprise-grade technical and organizational safeguards:

  • Encryption: in transit (TLS 1.2+) and at rest (AES-256)
  • Access Controls: role-based least-privilege permissions
  • Infrastructure Segregation: banking and blockchain systems operate independently
  • Continuous Monitoring: intrusion detection and anomaly monitoring
  • Vendor Management: all third-party providers undergo security assessments
  • Data Protection Impact Assessments: we conduct DPIAs for high-risk processing activities, including large-scale processing of financial data, cross-border transfers, and new technology implementations

User Responsibilities:

Users remain responsible for safeguarding their login credentials, wallet private keys, and account security. VaultLeap cannot reverse or recover blockchain transactions or restore lost wallet credentials.

Data Breach Notification:

In the event of a personal data breach:

  • EEA/UK users: We will notify the applicable supervisory authority within 72 hours of becoming aware of a breach that poses a risk to your rights and freedoms, and will notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms.
  • U.S. users: We will notify you and applicable state authorities as required by applicable state breach notification laws.
  • All users: Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach.

6. YOUR RIGHTS

6.1 U.S. State Privacy Rights

Depending on your state of residence, you may have rights to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your personal data (subject to legal retention requirements)
  • Receive disclosures about our data practices
  • Opt out of the sale or sharing of personal information (though we do not sell or share data)

States with Comprehensive Privacy Laws:

These rights currently apply to residents of California, Virginia, Colorado, Connecticut, Utah, and other states with applicable privacy legislation.

California Residents:

VaultLeap does not sell or share personal information as defined by the California Consumer Privacy Rights Act (CPRA) and does not engage in cross-context behavioral advertising.

Exercising Your Rights:

To exercise any of these rights, please contact us at support@vaultleap.com with the subject line "Privacy Rights Request." We will verify your identity in accordance with applicable law before processing your request.

We will respond to verified requests within the timeframes required by applicable law (typically 45 days, with possible extension).

6.2 EEA & UK Residents (GDPR/UK GDPR Rights)

Under GDPR and UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten") in certain circumstances
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interests
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent for processing based on consent (e.g., non-essential cookies)
  • Lodge a complaint with your local data protection authority

Legal Bases for Processing:

See Section 2 above for a detailed mapping of processing purposes to legal bases.

Exercising Your Rights:

To exercise any of these rights, please contact us at support@vaultleap.com. We will respond within one month of receiving your request (with possible two-month extension for complex requests).

Supervisory Authority:

If you are located in the EEA or UK and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority.

EU/UK Representative:

To be appointed. VaultLeap is in the process of designating an EU representative under GDPR Article 27 and a UK representative under UK GDPR. This section will be updated once appointed. In the meantime, please direct all inquiries to support@vaultleap.com.

7. DATA RETENTION

We retain data only as long as necessary for:

Data CategoryRetention PeriodBasis
Regulatory compliance (AML/KYC)At least 5 years after account closureBank Secrecy Act, EU AML Directives
Transaction recordsAs required by banking partners and applicable regulationsLegal obligation
Support recordsUp to 3 yearsLegitimate interest
Security logsUp to 24 monthsLegitimate interest
Analytics and cookiesPer your consent preferences and applicable retention periodsConsent

After retention periods expire, data is securely deleted or anonymized in accordance with our data retention schedules and legal obligations.

Account Deletion:

If you close your account, we will delete or anonymize your personal data after applicable regulatory retention periods expire, except where retention is required by law, regulation, or to resolve disputes. You may request confirmation of deletion after retention periods have expired by contacting support@vaultleap.com.

8. MARKETING COMMUNICATIONS

Email Marketing:

You may receive occasional non-transactional communications about new features, platform updates, or promotions. You may opt out of these communications at any time using the unsubscribe link in the email or by contacting support@vaultleap.com with "Unsubscribe" in the subject line.

Transactional Messages:

You will continue to receive transactional, compliance, security-related, and account-related messages even after opting out of marketing, as these are necessary to provide the Services and meet our legal obligations. These include:

  • Security alerts and login notifications
  • Transaction confirmations
  • Compliance and verification requests
  • Changes to Terms of Service or Privacy Policy
  • Account status updates

Phone/SMS Communications:

As stated in Section 1.4, we do not use phone numbers for marketing purposes. You will only receive SMS messages related to account security, verification codes, and transaction confirmations.

9. CHILDREN'S PRIVACY

VaultLeap is not intended for individuals under 18. We do not knowingly collect data from minors. If we become aware that a user is under 18, we will terminate the account and delete associated data promptly.

If you believe we have inadvertently collected information from a minor, please contact us immediately at support@vaultleap.com.

10. THIRD-PARTY LINKS & SERVICES

Our Services may link to third-party platforms, websites, or services. VaultLeap is not responsible for the privacy practices of these third parties. Please review their privacy policies separately before providing them with personal information.

11. DO NOT SELL OR SHARE MY PERSONAL INFORMATION

California and Other U.S. State Residents:

VaultLeap does not sell or share your personal information as defined by the California Consumer Privacy Rights Act (CPRA) or other applicable state privacy laws. We do not use your personal information for cross-context behavioral advertising.

Because we do not sell or share personal information, there is no need to opt out. However, if you have questions about our data practices or wish to exercise your privacy rights, you may contact us at support@vaultleap.com with the subject line "Privacy Rights Request."

12. DISCLOSURE

VaultLeap is a financial technology platform, not a bank. Banking and payment services are provided by Bridge Ventures LLC and Lead Bank, Member FDIC. VaultLeap does not hold or custody user funds.

Card services are provided by Lead Bank, Member FDIC, pursuant to a license from Visa U.S.A. Inc., and managed by Bridge Ventures LLC.

13. CHANGES TO THIS POLICY

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or business operations. Updates will be posted at vaultleap.com/privacy with a revised "Last Updated" date.

Material changes will be communicated via email or prominent notice on the VaultLeap Platform at least seven (7) days before they take effect.

Continued use of the Services after the updated Privacy Policy is posted constitutes acceptance of the updated policy.

14. CONTACT

For privacy-related inquiries, questions, or to exercise your privacy rights:

Email: support@vaultleap.com

Address:

VaultLeap (Klydo, Inc.)
447 Sutter St, Suite 405, PMB 1066
San Francisco, CA 94108, USA

© 2023–2026 Klydo, Inc. All rights reserved.