Legal
Privacy Policy
Effective
This Privacy Policy explains what personal information 3-102-942062 Sociedad de Responsabilidad Limitada, trading as Ktap (Ktap, we, us or our), collects when you visit ktap.io or use the Ktap app, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
The short version: the website collects nothing about you. The app collects what it needs to run your account, and — only if you apply for a card — the identity information that the card issuer is required by law to verify. We never see your wallet's private keys or Recovery Phrase, and we never store your full card number.
01Who is responsible for your data
The controller of the personal information described in this policy is:
- Legal name
- 3-102-942062 Sociedad de Responsabilidad Limitada
- Registration
- Cédula jurídica 3-102-942062, Republic of Costa Rica
- Registered office
- Forum Uno, Building G, First Floor, Office 101, Offices of NCC Law, Pozos, Santa Ana, San José, Costa Rica
- Privacy contact
- dev@ktap.io
For the identity verification and card services described below, the card programme partner and the licensed card issuer we work with (together, the Card Partners) are also controllers of the information they receive, and process it under their own privacy notices, which are shown to you when you apply for a card.
02What this policy covers
This policy applies to:
- the website at ktap.io, including this page and the Terms of Service;
- the Ktap mobile app and the account you create in it; and
- email and other communications between you and us about the Services.
It does not cover the card-issuing interface we provide to business partners under separate written agreements, nor the services of third parties that have their own privacy notices — the Card Partners, the identity-verification provider, Apple, and the public blockchains the wallet connects to.
03The website
ktap.io is a static website. It sets no cookies, runs no analytics or advertising scripts, embeds no third-party trackers and has no forms. We do not collect any personal information from you when you read it.
Like any website, it is delivered by a hosting and content-delivery provider whose servers may record standard technical logs of each request — the requesting IP address, the page requested, the time, and the browser and operating system reported by your device — for security and operational purposes. We do not use those logs to identify or profile visitors.
04Information we collect in the app
When you create an account
- Email address, which is your account identifier, and the one-time codes we send to it to sign you in. We store codes only in hashed form and they expire.
- Your name (first and last), if you provide it.
- Device Keys — when you enrol a passkey or similar credential we store its public key, an identifier for the device and a label so you can recognise it. The private half never leaves your device. Face ID or fingerprint data is used by your device to unlock the key and is never sent to us.
- Push-notification tokens for the devices where you enable notifications, and the device platform.
When you use the wallet
- The public blockchain addresses of the wallet on your device, which the app registers with us so we can show your balances and history, and the public on-chain data for those addresses (balances, transfers, transaction hashes), which we read from the blockchains and from blockchain-data services.
- What we never collect: your private keys and your Recovery Phrase. They are generated and stored only on your device, and no part of the Services transmits them to us. We could not recover them for you even if you asked.
When you apply for a card
The card issuer is required by anti-money-laundering law to verify who its cardholders are. To apply, you give us, and we pass to the Card Partners:
- Identity details — first and last name, date of birth, gender, nationality, and the number, issue date and expiry date of your identity document;
- Contact details — residential address, city, postal code, country, email address and phone number;
- Profile details the issuer requires — your occupation, the purpose of the account, your expected monthly volume and your annual income range;
- Identity document and likeness — the document check itself is carried out by an identity-verification provider through a screen or link presented in the app. The images of your document and of your face are collected by that provider and the Card Partners under their own notices; we receive the outcome (approved, pending or rejected, and the reason for a rejection), not the images.
When you use the card
- Card records from the Card Partners — a reference for your card, its status, the last four digits and expiry, your Card Balance, your card transactions (amount, currency, merchant and time) and your deposit orders (token, amount, rate, fee, the deposit address and the on-chain transaction).
- Event notifications the Card Partners send us about your verification, card and deposits, which we keep briefly to process them.
- What we never store: your full card number, security code and expiry as a set. When you reveal them in the app they are fetched from the Card Partners for that request only, after you approve with a Device Key, and are neither logged nor saved by us.
Automatically, when the app talks to our servers
- Request logs — the IP address, time, request identifier, the endpoint called and the result, and the app and operating-system version your device reports. We keep these to operate the service, detect abuse and investigate problems.
When you contact us
- The contents of your message and the address you write from, so we can reply and keep a record of the correspondence.
05Why we use it, and on what legal basis
We use personal information only for the purposes below. For each purpose we state the legal basis we rely on where the law of your country requires one, such as the EU and UK General Data Protection Regulation. Where the law of your country — including Costa Rica's Law No. 8968 on the Protection of Individuals regarding the Processing of their Personal Data — requires your consent for a particular use, we ask for it in the app and you can withdraw it at any time.
- To create and run your account — signing you in, keeping your profile, remembering your devices, sending you security and service messages. Basis: performance of our contract with you.
- To show your wallet — reading public chain data for the addresses you register. Basis: performance of our contract with you.
- To apply for, issue and operate your card — passing your verification details to the Card Partners, keeping your card and deposit records in sync, delivering one-time codes for online purchases. Basis: performance of our contract with you.
- To meet legal obligations — identity verification, anti-money-laundering and sanctions screening, record-keeping, responding to lawful requests from authorities. Basis: compliance with a legal obligation.
- To keep the Services secure — detecting fraud, abuse and unauthorised access, rate-limiting, investigating incidents. Basis: our legitimate interest in protecting the Services and our users.
- To improve the Services — understanding, from request logs and support messages, where the app fails or confuses people. Basis: our legitimate interest in running a reliable product. We do not build advertising profiles.
- To answer you when you contact us. Basis: our legitimate interest in responding, or our contract.
- To send push notifications — only where you have enabled them on your device. Basis: your consent, which you withdraw in your device settings.
We do not sell personal information, and we do not use it for third-party advertising. We currently send only service messages — sign-in codes, security alerts and transaction notifications. If we introduce marketing messages we will ask for your consent where the law requires it, and every such message will include a way to opt out.
Decisions about whether to register you as a cardholder are made by the Card Partners under their procedures, which may include automated checks of your documents and screening against sanctions and watch lists. If you believe a decision is wrong, contact us and we will ask the Card Partners to review it.
07Where it is processed
We are a Costa Rican company and our providers operate from other countries. Your information may therefore be stored and processed outside the country where you live, including outside Costa Rica, the European Economic Area and the United Kingdom. Where the law of your country requires it, we transfer information only to countries with an adequate level of protection or under appropriate safeguards such as standard contractual clauses, and you can ask us at dev@ktap.io for details of the safeguards that apply to you.
08Public blockchains
Your wallet operates on public blockchains that we do not control. Every transaction you sign — including a deposit to your card — is recorded permanently and publicly on that blockchain, together with the addresses involved. Anyone can read it, it cannot be edited or deleted by us or by anyone else, and public analysis of a blockchain can sometimes link an address to a person. Your rights to rectification and erasure under this policy cannot be applied to data already written to a blockchain.
09How long we keep it
- Account, device and wallet-address records — for as long as your account is open, and then for as long as we need them to resolve disputes, enforce our Terms or meet legal obligations.
- Verification, card and deposit records — for as long as your card is open and then for the period that anti-money-laundering and tax law requires after the relationship ends. The Card Partners keep their own records for the same reasons, and closing your Ktap account does not shorten that period.
- One-time codes and card-detail requests — codes expire within minutes; revealed card details are never stored.
- Event notifications from the Card Partners — for a short period to process and reconcile them.
- Request logs — for a limited period sufficient to investigate security incidents and operational problems.
- Correspondence — for as long as needed to deal with your query and any follow-up.
When information is no longer needed we delete it or make it anonymous.
10How we protect it
We design the Services so that the most sensitive things are never in our hands: wallet keys stay on your device, and card details are fetched on demand and never stored. For everything else we use measures including encryption of all traffic between the app and our servers, hashed storage of sign-in codes, cryptographic Device Keys instead of passwords, a separate approval step before card details are revealed, secrets kept in managed secret stores rather than in code, and access to production systems limited to the people who need it.
No system is perfectly secure. If we learn of a breach that affects your information we will tell you and any authority we are required to notify without undue delay. You can help by keeping your device updated, protecting it with a passcode and biometrics, and never sharing a one-time code or your Recovery Phrase with anyone — we will never ask for them.
11Your rights
Subject to the law that applies to you, you have the right to:
- access the personal information we hold about you and receive a copy;
- correct information that is inaccurate or incomplete — you can change your name in the app, and your verification details through the app or by contacting us;
- delete your information — you can close your account in the app at any time, which deletes our account, device and wallet-address records. Verification, card and deposit records that we or the Card Partners must keep by law are retained for the period described above and deleted after it;
- object to processing based on our legitimate interests, and to any direct marketing;
- restrict processing while a dispute about it is resolved;
- receive the information you gave us in a portable, machine-readable form;
- withdraw consent where we rely on it, without affecting processing that already took place; and
- complain to a supervisory authority. In Costa Rica that is the Agencia de Protección de Datos de los Habitantes (PRODHAB). If you live in the European Economic Area or the United Kingdom you may complain to the data-protection authority where you live.
To exercise any of these rights, email dev@ktap.io from the address on your account. We may ask you to confirm your identity first, and we will respond within the time the law allows — normally within one month. We will not charge you unless a request is clearly unfounded or excessive.
12Children
The Services are for adults. We do not knowingly collect personal information from anyone under 18, and an account opened by a minor will be closed. If you believe a child has given us information, contact us and we will delete it.
13Changes to this policy
We may change this policy at any time — for example when a new provider is added, a new feature collects something new, or the law changes. The current version is always at ktap.io/privacy with its effective date at the top, and it applies from that date. If a change is material we will tell you in the app or by email before it takes effect; otherwise, please review this page from time to time.
14Contact
Questions, requests and complaints about privacy should be sent to dev@ktap.io or by post to:
3-102-942062 Sociedad de Responsabilidad Limitada
Forum Uno, Building G, First Floor, Office 101
Offices of NCC Law, Pozos
Santa Ana, San José
Costa Rica