Locus endpoints are now live on MPP โ try them at Endpoints live on MPP โ mpp.sh/services
Privacy Policy
Last Updated: April 10, 2026
This Privacy Policy (the "Policy") explains how Locus Technologies Inc., a Delaware corporation, and its affiliates (collectively, "Locus," "we," "us," or "our") collect, use, disclose, store, and otherwise process information when you ( "you" or "your") use our services, including our websites: https://paywithlocus.com, https://beta.paywithlocus.com, https://app.paywithlocus.com, and https://buildwithlocus.com as well as any other websites associated with Locus from time to time (collectively, the "Site"), our applications, dashboards, software development kits, including the Locus Agent SDK ("SDKs"), and application programming interfaces ("APIs") (together the "Platform"), and related technologies (collectively, the "Service"). By using the Service, you agree to the practices described here. If you do not agree, do not use the Service. The Service is intended for business and developer users only. You may not use the Service for personal, family, or household purposes.
Summary at a Glance
(not a substitute for the full policy)
- We collect information you provide, information collected automatically, and information from third parties (e.g., OFAC sanctions screening providers, transaction partners, blockchain infrastructure providers).
- We use data to operate the Service, enable payments through our partners, conduct OFAC sanctions screening, manage risk and fraud, comply with law, provide support, and improve our products (including via deidentified/aggregated data).
- We share data with service providers (e.g., blockchain infrastructure providers, cloud hosting, communications providers), with your direction, to comply with law, and in business transfers. We do not sell personal information.
- You may have rights to access, correct, delete, or opt out of certain processing depending on where you live. See Your Rights & Choices.
1. Scope & Relationship with Other Terms
This Policy applies to information processed in connection with your access to and use of the Service. It should be read with our Terms of Service and, where applicable, any product-specific Additional Terms or disclosures (together, the "Terms"). Capitalized terms not defined here have the meanings given in the Terms.
Geographic Scope (Current): North America (U.S. & Canada). Locus currently offers and supports the Service only in the United States and Canada. Jurisdiction-specific disclosures below focus on applicable U.S. federal and state laws and Canadian federal and provincial laws. If Locus expands to additional regions, we will update this Policy and provide any required regional notices.
Non-Custodial by Default; Custodial Features via Partners. Locus is a non-custodial platform for its core products. To the extent custodial functionality is offered through the Service (e.g., stored balances, accounts, or investment features), that Service is provided solely by regulated third-party custodial partners, and your assets and related records are held by those partners pursuant to their terms of service and privacy policies. Locus does not take possession of, custody, or control over customer assets. Where custodial functionality is used, custody is provided solely by regulated third-party custodial partners pursuant to their terms. Locus is not the custodian.
2. Information We Collect
We collect information to provide, secure, and improve the Service.
2.1 Information You Provide
- Account & Profile: Email address (required), password hash, full name (optional), public wallet address, signup IP address, AWS Cognito User ID, account role (user, admin, superadmin), authentication credentials, last login timestamp, dashboard widget configurations, escrow expiry preferences, and onboarding completion status.
- Compliance: OFAC sanctions screening results. Note: Locus is a non-custodial platform and does not collect KYC information such as date of birth, government-issued IDs, SSN/ITIN, or nationality.
- Financial & Transactional: Transaction amounts (in USDC), wallet IDs and addresses, blockchain transaction hashes, counterparty addresses, memos, transaction status, and ledger entries. For Bring Your Own Card ( "BYOC") functionality, tokenized card references are stored by our third-party PCI-DSS Level 1 certified vault provider, Basis Theory. Locus never stores, processes, or has access to raw card numbers.
- Contacts & Counterparties: Contact names, wallet addresses, email addresses, phone numbers, descriptions, and whitelist relationships you create for approved recipients.
- Support & Communications: Messages to us (including recordings you share with support), bug reports, satisfaction surveys, and any files you upload.
- Developer & API Use: Agent IDs, agent names and descriptions, API key hashes and prefixes, API key creation timestamps, Model Context Protocol ( "MCP") OAuth credentials and scopes, usage logs, request/response metadata, webhook endpoints, IPs, event payloads, and error diagnostics.
- Wrapped API Proxy Data: When you use our pay-per-use API proxy service, we store the provider name, endpoint called, full request body, full response body, USDC price charged, and status/error details for each API call. This may include any personal information, prompts, queries, images, documents, or other content you include in your API requests. Your request data is forwarded to third-party API providers (see Section 4), and both request and response payloads are retained in our database. We provide access to over 40 third-party API providers and approximately 55 API endpoints. You should assume that any data you submit through the Wrapped API proxy may be stored by Locus and processed by the applicable upstream provider.
- Wallet & Blockchain Data: Wallet IDs, smart contract addresses, wallet types (proprietary smart wallets and Tempo passkey smart wallets), wallet versions, blockchain chain identifiers, deployment transaction hashes, session key references (KMS ARN, addresses, expiration), permissioned key data, wallet budget settings (limits, periods, current and lifetime spend), and soft-delete status.
- Embedded Wallet Platform Data: If you access Locus wallet functionality through a third-party platform that has integrated our embedded wallet infrastructure, we collect: embedded provider name, API credentials, external user identifiers from the provider's system, and embedded user metadata. The third-party platform that embeds our Service may have its own privacy policy governing its collection of your data. We receive data from that platform necessary to provide wallet functionality. Your relationship with the embedding platform is governed by their terms and privacy policy.
- Escrow/Subwallet Data: For email or phone-based payments, we collect subwallet addresses, recipient email and/or phone number, amount in USDC, passcode hashes, access tokens, status (pending, claimed, expired, etc.), expiration timestamps, and claim/withdrawal timestamps.
- AgentMail Data: If you use AgentMail integration (provided by agentmail.to, a separate third-party company), we process agent email addresses, email messages sent and received, email threads, attachments, and HTML/text email bodies. This data is transmitted to and stored on AgentMail's infrastructure. This data flows to AgentMail's infrastructure pursuant to their privacy policy. Locus does not control how AgentMail processes your data after transmission.
- Checkout & Merchant Data: Checkout instance IDs, domains, session amounts, currencies, descriptions, checkout types, account references, payment methods, success/cancel URLs, webhook URLs and HMAC secrets, payer addresses and emails, transaction hashes, receipt configurations, idempotency keys, and merchant-defined metadata.
- Policy & Spending Control Data: Policy group names and spend limits, budget period configurations, scopes/permissions, token allowlists, contract registry data (addresses, ABIs, verification status), and contract policies.
- Promotional and Gift Code Data: If you use or request redemption codes or gift codes, we collect: the code string, your associated email address, the USDC amount, code status (active, redeemed, expired, cancelled), and for gift code requests, your reason for requesting credits (which may include detailed explanatory text), requested amount, and any administrative notes.
2.2 Information Collected Automatically
- Device & Network: IP address, device identifiers, operating system, browser, language, mobile carrier, app version.
- Usage & Log Data: Access times, pages/screens viewed, product features used, clicks, referring pages/UTM parameters, diagnostic events, performance metrics.
- Cookies & Similar Technologies: Authentication tokens, identity tokens, refresh tokens, and user preferences stored in browser local Storage. We use Google Analytics 4 for page views, button clicks, external link clicks, and scroll depth. We do not currently use advertising pixels, session replay tools, or device fingerprinting.
- Location: Approximate location inferred from IP; precise geolocation only with your consent via device settings.
- Public Blockchain Data: Wallet addresses and on-chain transaction metadata that are publicly available.
2.3 Information from Third Parties
- Sanctions Screening: OFAC sanctions screening results via our compliance API integration.
- Payments & Blockchain Partners: Data from Coinbase Developer Platform ("CDP") (our crypto on/off-ramp provider), Pimlico (ERC-4337 transaction bundler), Tempo (passkey smart wallet provider), and the Base blockchain (Layer 2 on Ethereum) related to funding sources, transactions, wallet creation, and on-chain activity.
- Risk Partners: Risk scores and screening results as permitted by law.
- Card Tokenization: If you use Bring Your Own Card ("BYOC") functionality, tokenized card data is stored and processed by Basis Theory, a third-party PCI-DSS Level 1 certified vault provider. Your raw card numbers, expiration dates, and CVV codes are transmitted directly to Basis Theory and stored in their secure vault. Locus never receives, stores, or has access to your raw card numbers, only tokenized references provided by Basis Theory.
- Merchants/Platform Customers: If you transact with or through a merchant or platform, we may receive information about you from that merchant or platform.
3. How We Use Information
We use information for the following purposes:
- Provide the Service: Create and manage accounts, enable payments and transfers, initiate refunds, provide receipts, and operate dashboards/APIs.
- Risk & Security: Conduct OFAC sanctions screening, authenticate users, detect and prevent fraud, abuse, and unauthorized access, enforce spending policies and transaction limits, and manage disputes.
- Compliance & Reporting: Comply with legal and regulatory obligations, respond to lawful requests, maintain records, and satisfy audit and tax requirements.
- Customer Support & Communications: Respond to requests, send service/transactional messages, and communicate changes to terms, features, or security notices.
- Product Improvement & Research: Monitor usage, fix bugs, develop new features, and perform analytics. We may use deidentified or aggregated data to develop and improve machine-learning models that support fraud detection, risk scoring, and product features. When we use aggregator-derived financial data, we limit such use to the requested features, compliance, and security as stated above.
- Personalization & Marketing: With your consent or as permitted by law, personalize content, measure campaigns, and send promotional communications.
- Developer & API Operations: Provide API functionality, usage analytics, rate-limiting, abuse prevention, and webhook/event delivery.
Agent Delegation & Pay-Per-Use Service. If you create Agent Access Keys to delegate spending authority to AI agents or third-party applications:
- We process and store API key hashes, agent configurations, MCP OAuth credentials, usage logs, and all transactions initiated by your agents;
- When your agent uses our pay-per-use Wrapped API proxy, we forward your request data to the upstream third-party API provider and store both the complete request and response payloads in our database;
- You acknowledge that AI agents may operate autonomously within the permissions you grant, and may initiate transactions, make API calls, send communications, or take other actions without your real-time supervision;
- You bear full responsibility for all transactions executed by agents you have authorized, including any errors, unauthorized actions within granted permissions, or unintended consequences;
- Locus does not monitor, supervise, or control the behavior of AI agents you authorize, and Locus is not liable for any losses, damages, or harms arising from agent actions;
- We process this data to provide the Service, enforce spending policies, maintain audit trails, and support dispute resolution.
x402 Machine-to-Machine Payment Protocol: We support the x402 HTTP 402 protocol, which enables automated machine-to-machine payments for API access. When you or your agents use x402-enabled Services, we process payment authorization, quoted prices, transaction amounts, and payment status. x402 transactions are processed automatically without manual intervention and are subject to the same spending controls and audit logging as other transactions.
Automated Decision-Making and AI Systems: Locus uses automated systems and artificial intelligence to operate the Service. These systems may make decisions that affect your ability to complete transactions or use certain features. Our automated systems include:
- Spending Policy Engine: A three-layer automated system that evaluates transactions against (i) user-defined global limits, (ii) per-wallet budget settings, and (iii) policy group controls. Transactions exceeding these limits are automatically rejected without human review.
- OFAC Sanctions Screening: Automated screening against U.S. Treasury Department sanctions lists before certain transactions. Positive matches may result in transaction blocks or account restrictions.
- Budget Enforcement: Automatic enforcement of a rolling 30-day spending limit for non-verified users.
- Transaction Screening: Pre-execution screening with results stored for audit purposes. Transactions may be flagged, held, or declined based on automated risk assessment.
- Session Key Rotation: Periodic automatic rotation of cryptographic session keys for security purposes.
Your Rights Regarding Automated Decisions: Where automated decisions produce legal or similarly significant effects on you (such as account suspension or transaction blocks), you have the right to: (i) receive an explanation of the decision logic; (ii) express your viewpoint; and (iii) request human review. To exercise these rights, contact legal@paywithlocus.com.
No Automated Profiling for Marketing: We do not use automated systems to build profiles about you for marketing, advertising, or content personalization purposes without your consent.
4. When & With Whom We Share Information
We may share information as follows:
Service Providers / Sub-Processors: Vendors who host, process, or support the Service, including: AWS (cloud infrastructure, authentication via Cognito, key management via KMS, job scheduling), Cloudflare (CDN and file proxy), SendGrid (transactional email), Twilio (SMS notifications), Google Analytics (analytics), and Basis Theory (PCI-DSS Level 1 card tokenization vault). These parties are bound by contractual obligations to protect your data.
Pay-Per-Use API Providers: When you use our Wrapped API proxy service, we forward your request data to third-party API providers and store both request and response payloads in our database. We provide access to over 40 third-party APIs across categories including providers such as OpenAI, Anthropic, Google Gemini, Mistral AI, Perplexity, Brave Search, Firecrawl, Deepgram, Stability AI, DeepL and others for AI, search, data enrichment, and productivity Services. The ownership of prompts you submit and outputs generated is governed by the applicable upstream provider's terms of service. Locus does not claim ownership of your prompts or AI-generated outputs. However, our storage of request and response payloads is subject to this Privacy Policy. Each upstream provider has its own privacy policy and terms governing how they process the data we send them on your behalf, intellectual property rights, training data usage and content policies. By using the Wrapped API proxy, you consent to your request data being transmitted to these providers and stored by Locus.
Third-Party Integrations: We integrate with the following third-party services: (a) AgentMail (agentmail.to) a separate third-party company that provides email inboxes for AI agents; email addresses, message content, attachments, and email metadata flow to their infrastructure; (b) Laso Finance, prepaid virtual debit card ordering (US only); we share authentication tokens, card order details, payment amounts, and your IP address; (c) Fiverr, freelancer marketplace integration with escrow-backed payments; we share order requests, category selections, timelines, deliverable specifications, and gig links; and (d) Billboard (@MPPBillboard), a paid posting service to X/Twitter; we share the content you wish to post with this service. Each third-party service has its own terms and privacy policy which govern their use of your data.
Payments & Blockchain Ecosystem: CDP (crypto on/off-ramp), Pimlico (ERC-4337 bundler for transaction submission), Tempo (passkey smart wallet infrastructure), Base blockchain (Layer 2 on Ethereum where all on-chain transactions occur), and smart contract infrastructure providers as needed to route transactions and validate on-chain activity. All on-chain data (wallet addresses, transaction amounts, contract interactions) is public and immutable on the blockchain.
Merchants & Platform Customers: If you use Locus to pay a merchant or through a platform, we share necessary information with that merchant or platform to complete the transaction and for their records.
Embedded Wallet Platforms: Third-party platforms may embed Locus wallet infrastructure into their products. When you use Locus functionality through such platforms, we share transaction data, wallet information, and user identifiers with the embedding platform as necessary to provide the integrated service.
Affiliates: Within our corporate group for operations and support consistent with this Policy.
Legal, Safety & Compliance: To comply with law, regulation, legal process, or governmental request; to enforce our terms; to protect the rights, property, or safety of Locus, our Users, or the public.
Business Transfers: In connection with a merger, acquisition, financing, restructuring, or sale of assets; your data may be transferred as part of that transaction.
With Your Direction or Consent.
No Sale of Personal Information: We do not sell personal information. If we ever engage in activities that qualify as "sharing" for cross-context behavioral advertising under applicable law, we will provide a method to opt out (including honoring Global Privacy Control ( "GPC") signals where required).
5. Cookies & Similar Technologies
We use browser local storage (not traditional cookies) to maintain your authentication session, store tokens, and remember preferences such as theme settings. We use Google Analytics 4 ("GA4") to analyze page views, button clicks, external link clicks, and scroll depth. GA4 is disabled in non-production environments. We do not currently implement advertising or attribution cookies, session replay tools, or a cookie consent banner.
We honor GPC signals for applicable opt-outs where required by law. We do not respond to browser Do Not Track ("DNT") signals because there is no common industry standard for DNT implementation. Our practices remain consistent regardless of DNT signal status.
6. Data Retention
We retain information as long as necessary to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce agreements. Specific retention practices include: (a) blockchain transaction data is immutable and permanently public on-chain; (b) wallets, agents, policy groups, and contacts are soft-deleted (data retained with deletion flag); (c) escrow wallets expire after a configurable period (default 30 days) and are auto-reclaimed; (d) file tokens expire after 48 hours; (e) Wrapped API call request/response payloads are retained indefinitely and are not subject to automatic deletion to support audit trails, dispute resolution, and service improvement; (f) queue jobs are retained indefinitely for audit purposes. Locus has implemented formal data deletion procedures, data de-identification processes, and provides Users with the right to request deletion or access to their data, except where retention is required by law or for compliance purposes. Retention periods for all data types are defined and documented, and secure disposal of data is performed in accordance with SOC-2 requirements. Actions taken regarding retention and deletion are documented for audit purposes.
7. Your Rights & Choices
Depending on your location, you may have rights to:
- Access and port your information;
- Correct inaccurate information;
- Delete information;
- Restrict or object to certain processing (including automated decision-making);
- Withdraw consent where processing is based on consent;
- Opt-out of marketing communications and (where applicable) targeted advertising;
- Disconnect linked accounts connected via third-party integrations (e.g., AgentMail, external wallet connections).
To exercise your rights, use in-product settings where available or contact us at privacy@paywithlocus.com. We may verify your request and may deny or limit requests as permitted by law. If we deny your request, you may appeal by contacting us using the subject line "Privacy Request Appeal." We will inform you in writing of any action taken or not taken in response to the appeal and the reasons, and how you may contact your state Attorney General if you disagree. Where permitted, you may designate an authorized agent to submit a request on your behalf. We may require proof of authorization (e.g., power of attorney or signed permission) and seek to verify your identity directly. In addition to email, we will provide a web form within account settings to submit and track requests.
8. Jurisdiction-Specific Disclosures
8.1 United States (Federal & State)
- Categories Collected: Identifiers; commercial information; internet/network activity; geolocation (approximate, inferred from IP); inferences (e.g., risk scores).
- Sources & Uses: As described above.
- Disclosures for Business Purposes: To service providers, transaction counterparties and affiliates.
- Sale/Sharing: We do not sell personal information. We do not engage in "sharing" for cross-context behavioral advertising or "targeted advertising" unless expressly stated in the Service. If we introduce such activities, we will provide a clear in-product method to opt out (including GPC signal recognition).
- Retention: See Section 6.
- Non-Discrimination: We will not discriminate against you for exercising your rights.
Your State Privacy Rights
Depending on your state of residency, you may have certain rights related to your personal information, including:
- Access and Data Portability. You may confirm whether we process your personal information and access a copy of the personal information we process. To the extent feasible, information will be provided in a portable format. Depending on your state, you may have the right to receive additional information and it will be included in the response to your access request.
- Correction. You may request that we correct inaccuracies in your personal information that we maintain, taking into account the information's nature and processing purpose.
- Deletion. You may request that we delete personal information about you that we maintain, subject to certain exceptions under applicable law.
- Opt-Out of Using Personal Information for Targeted Advertising, Profiling, and Sales. You may request that we do not use your personal information for these purposes.
Important: The exact scope of these rights vary by state. There are also several exceptions where we may not have an obligation to fulfill your request.
To exercise any of these rights, please contact us at privacy@paywithlocus.com or use the web form available in your account settings. To appeal a decision regarding a consumer rights request, contact us at privacy@paywithlocus.com with the subject line "Privacy Request Appeal."
We honor GPC signals for applicable opt-outs where required by law.
8.2 Canada (PIPEDA & Provincial Laws)
- Applicability: We comply with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and, where applicable, substantially similar provincial laws such as Alberta PIPA, British Columbia PIPA, and Quebec Law 25.
- Collection & Consent: We collect, use, and disclose personal information with your knowledge and consent, except where otherwise permitted or required by law. Consent may be express or implied depending on sensitivity and context. You may withdraw consent at any time; doing so may affect our ability to provide certain features or Service.
- Access & Correction: You may request access to your personal information and correction of inaccuracies.
- Safeguards & Location: Personal information may be stored and processed in the U.S. and Canada (see Section 11). We use contractual and organizational safeguards appropriate to the sensitivity of the information.
- Quebec (Law 25): Where applicable, we conduct privacy impact assessments for projects involving cross-border transfers or use of sensitive personal information and honor rights to de-indexation/portability in line with Law 25 requirements.
- Contact (Canada-specific): privacy@paywithlocus.com (Attention: Privacy Officer - Canada). You may also file a complaint with the Office of the Privacy Commissioner of Canada or your provincial regulator.
8.3 European Economic Area, United Kingdom, and Switzerland (Reserved)
Locus does not currently offer or market the Service to users in the European Economic Area, United Kingdom, or Switzerland. If you access the Service from these jurisdictions, you do so at your own risk and acknowledge that Locus has not implemented the specific safeguards required by the General Data Protection Regulation ("GDPR") or UK GDPR for data transfers to the United States.
If Locus expands to these regions, we will update this Policy to include: (a) our legal bases for processing personal data; (b) appropriate transfer mechanisms (such as Standard Contractual Clauses); (c) data protection officer contact information; and (d) information about your rights under GDPR including the right to lodge a complaint with a supervisory authority.
8.4 California Residents
If you are a California resident, the California Consumer Privacy Act ( "CCPA"), as amended by the California Privacy Rights Act ("CPRA"), provides you with additional rights regarding your personal information. This section describes those rights and how to exercise them.
Personal Information We Collect
We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household ( "personal information"). Personal information does not include:
- Publicly available information, including from government records, through widely distributed media, or that the consumer made publicly available without restricting it to a specific audience.
- Lawfully obtained, truthful information that is a matter of public concern.
- Deidentified or aggregated consumer information.
- Information excluded from the CCPA's scope, like health or medical information covered by the Health Insurance Portability and Accountability Act (HIPAA) and the California Confidentiality of Medical Information Act (CMIA), or personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA) and the Gramm-Leach-Bliley Act (GLBA).
The chart below identifies the categories of personal information we have collected from our consumers within the last 12 months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers. | A real name (optional), alias, unique personal identifier, online identifier, Internet Protocol address, email address, account name, wallet address, or other similar identifiers. | YES |
| B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code ยง 1798.80(e)). | A name, address, telephone number, email address, wallet address, transaction amounts, and tokenized card references (via third-party vault provider). Locus does not collect or store SSN, passport numbers, raw bank account numbers, or raw credit/debit card numbers. | YES |
| C. Protected classification characteristics under California or federal law. | Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, reproductive health decision-making, military and veteran status, or genetic information (including familial genetic information). | NO |
| D. Commercial information. | Records of personal property, products, or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | YES |
| E. Biometric information. | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | NO |
| F. Internet or other similar network activity. | Activity on our websites, mobile apps, or other digital systems, such as internet browsing history, search history, system usage, electronic communications with us. | YES |
| G. Geolocation data. | Physical location or movements. | YES |
| H. Sensory data. | Audio, electronic, visual, thermal, olfactory, or similar information. | NO |
| I. Professional or employment-related information. | Current or past job history. | NO |
| J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | NO |
| K. Inferences drawn from other personal information. | Profile reflecting a person's preferences, characteristics, spending patterns, AI agent usage patterns, API consumption history, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. Includes risk scores and transaction screening outcomes generated by automated systems. | YES |
| L. Sensitive personal information. | Further identified in the chart below. Note: As a non-custodial platform, Locus does not collect government identifiers, precise geolocation, or other categories of sensitive personal information. | NO |
Sensitive Personal Information
Sensitive personal information is a subtype of personal information consisting of the specific information categories listed in the chart below. The CCPA only treats this information as sensitive personal information when we collect or use it to infer characteristics about a consumer.
The chart below identifies which sensitive personal information categories, if any, we have collected from consumers to infer characteristics about them in the last 12 months:
| Sensitive Personal Information Category | Collected to Infer Characteristics? |
|---|---|
| L.1. Government identifiers, such as your Social Security number (SSN), driver's license, state identification card, or passport number. | NO |
| L.2. Complete account access credentials, such as usernames, account logins, account numbers, or card numbers combined with required access/security code or password. | NO |
| L.3. Precise geolocation. | NO |
| L.4. Racial or ethnic origin. | NO |
| L.5. Citizenship or immigration status. | NO |
| L.6. Religious or philosophical beliefs. | NO |
| L.7. Union membership. | NO |
| L.8. Mail, email, or text messages not directed to the Company. | NO |
| L.9. Genetic data. | NO |
| L.10. Neural Data. | NO |
| L.11. Unique identifying biometric information. | NO |
| L.12. Health information. | NO |
| L.13. Sex life or sexual orientation information. | NO |
| L.14. Children's personal information (under age 16). | NO |
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from you, such as from the forms or other information you provide to us.
- Indirectly from you, such as from your interactions with the Service, the Site, mobile applications, or customer service programs.
- From our service providers, such as OFAC sanctions screening providers, cloud hosting providers (AWS), communications providers (SendGrid, Twilio), and analytics providers (Google Analytics).
- From blockchain infrastructure providers (Base, Pimlico, Tempo) and crypto on/off-ramp providers (CDP).
- From third-party API providers when you use our Wrapped API proxy service (with your explicit direction).
How We Use Personal Information
We may use and disclose the personal information, including sensitive personal information, we collect to advance our business and commercial purposes, specifically to:
- Develop, offer, and provide you with our products and Service.
- Meet our obligations and enforce our rights arising from any contracts with you, including for billing or collections, or to comply with legal requirements.
- Fulfill the purposes for which you provided your personal information or that were described to you at collection, and as the CCPA otherwise permits.
- Conduct OFAC sanctions screening and manage risk and fraud.
- Comply with legal and regulatory obligations, respond to lawful requests, and maintain records.
- Respond to customer support requests and send service/transactional messages.
- Monitor usage, fix bugs, develop new features, and perform analytics.
- Administer and maintain our systems and operations, including for safety purposes.
- Engage in corporate transactions requiring review of consumer records.
- Exercise or defend the legal rights of Locus and its employees, customers, Users and agents.
- Respond to law enforcement requests and as required by applicable law or court order.
Sensitive Personal Information Use and Disclosure Purposes
We use or disclose sensitive personal information for the following statutorily approved reasons ( "Permitted SPI Purposes"):
- Performing actions that are necessary for our consumer relationship and that an average consumer in a relationship with us would reasonably expect.
- Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information.
- Defending against and prosecuting those responsible for malicious, deceptive, fraudulent, or illegal actions directed at us.
- Ensuring physical safety.
- Short-term, transient use, such as non-personalized advertising shown as part of your current interactions with us, where we do not disclose the sensitive personal information to another third party or use it to build a profile about you or otherwise alter your experience outside your current interaction with us.
- Services performed for us, including maintaining or servicing accounts, processing or fulfilling transactions, verifying consumer information, processing payments, or providing financing, analytic services, storage, or similar services.
- Activities required to verify or maintain the quality or safety of a product, service, or device that we own, manufacture, had manufactured, or control; or improve, upgrade, or enhance the service or device that we own, manufacture, had manufactured, or controlled.
- Collecting or processing sensitive personal information that we do not use for the purpose of inferring characteristics about a consumer.
We do not use or disclose sensitive personal information for purposes other than the Permitted SPI Purposes.
Disclosing, Selling, or Sharing Personal Information
We have not disclosed consumers' personal information to third parties for a business purpose in the preceding 12 months beyond what is described in Section 4 of this Policy. We may disclose the personal information we collect to service providers and contractors for the business purposes described in the "How We Use Information" section, such as to support our business functions.
We do not sell your personal information to third parties and have not sold it in the preceding 12 months. We do not share your personal information with third parties for cross-context behavioral advertising purposes and have not shared your personal information in the preceding 12 months.
Your California Privacy Rights
If you are a California resident, the CCPA grants you the following rights regarding your personal information:
Right to Know and Data Portability
You have the right to request that we disclose certain information to you about our collection and use of your personal information (the "right to know"), including the specific pieces of personal information we have collected about you (a "data portability request"). You may exercise your right to know twice in any 12-month period.
Once we receive your request and confirm your identity, we will disclose to you:
- The categories of personal information we collected about you and sources from which we collected your personal information.
- The business or commercial purpose for collecting your personal information and, if applicable, selling or sharing your personal information.
- If applicable, the categories of persons, including third parties, to whom we disclosed your personal information, including separate disclosures identifying the categories of your personal information that we disclosed for a business purpose to each category of persons and sold or shared to each category of third parties.
- When your right to know submission includes a data portability request, a copy of your personal information, subject to any permitted redactions.
Right to Delete
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions and limitations (the "right to delete"). Once we receive your request and confirm your identity, we will delete your personal information from our systems unless an exception allows us to retain it. We will also notify our service providers, contractors, and other recipients to take appropriate action.
Right to Correct
You also have the right to request correction of personal information we maintain about you that you believe is inaccurate (the "right to correct"). We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct personal information that our review determines is inaccurate and notify our service providers, contractors, and other recipients to take appropriate action.
Right to Opt-Out of Personal Information Sales or Sharing
You have the right to request that businesses stop selling or sharing your personal information at any time (the "right to opt-out"), including through a user-enabled opt-out preference signal. As we do not sell or share consumers' personal information, we do not currently provide this consumer right.
Right to Limit Sensitive Personal Information Use
You have a right to ask businesses that use or disclose your sensitive personal information to limit those actions to just the CCPA's Permitted SPI Purposes (the "right to limit"). As we do not use or disclose sensitive personal information beyond the CCPA's Permitted SPI Purposes, we do not currently provide this consumer right.
Right to Non-Discrimination
You have the right not to be discriminated or retaliated against for exercising any of your privacy rights under the CCPA.
How to Exercise Your California Privacy Rights
To exercise your right to know (including data portability), delete, or correct described above, please submit a verifiable request to us by either:
- Emailing us at privacy@paywithlocus.com.
- Using the web form available in your account settings.
You or your authorized agent may only submit a request to know, including for data portability, twice in a 12-month period.
We cannot respond to your request to know, delete, or correct if we cannot verify your identity or authority to make the request and confirm the personal information relating to you. We will only use personal information provided in the request to verify the requestor's identity or authority to make the request.
We consider requests made through your password-protected account with us sufficiently verified when the request relates to personal information associated with that specific account. You do not need to create an account with us to submit a request to know, correct, or delete.
Response Timing and Format
We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the ten-day timeframe, please contact privacy@paywithlocus.com.
We endeavor to substantively respond to a verifiable request within 45 days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing. We will deliver our written response to your verified email address or password-protected account.
Our substantive response will tell you whether or not we have complied with your request. If we cannot comply with your request in whole or in part, we will explain the reason, subject to any legal or regulatory restrictions. Applicable law may allow or require us to refuse to provide you with access to some or all of the personal information that we hold about you, or we may have destroyed, deleted, or made your personal information anonymous in compliance with our record retention policies and obligations.
Any disclosures we provide will cover information for the 12-month period preceding the request's receipt date. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
9. Security
We employ administrative, technical, and physical safeguards designed to protect information, including: (a) encryption in transit (HTTPS/TLS for all API communication); (b) encryption at rest (AES-256-GCM for private keys; all secrets in AWS Secrets Manager with KMS encryption); (c) private key management via AWS KMS (keys never leave KMS; signing via Lambda); (d) password hashing via Cognito-managed SRP protocol and bcrypt for escrow passcodes; (e) API key storage using SHA256 hashing (never stored in plain text); (f) rate limiting on API endpoints; (g) HTTP security headers (XSS protection, clickjacking prevention); (h) input validation via Zod schema validation; (i) three-layer spending policy engine with re-validation at execution time; and (j) non-root container execution. No system can be guaranteed 100% secure. Where a confirmed security incident materially impacts your personal information processed by Locus in connection with the Service, we will notify you without undue delay and in any event within the timeframes required by applicable law. For more information about our security measures, contact us at privacy@paywithlocus.com.
10. Smart Contracts and Blockchain Data
Locus uses smart contracts deployed on the Base blockchain (Layer 2 on Ethereum) to provide non-custodial wallet infrastructure. The following smart contracts are used:
- Locus SmartWallet: ERC-4337 account abstraction wallet with permissioned keys and subwallets.
- Locus Factory: Deterministic wallet deployment via CREATE2.
- Paymaster: Gas fee sponsorship for authorized wallets (Locus sponsors gas fees; users do not pay gas).
- Subwallet: Minimal proxy for temporary token holding used in email/phone-based escrow payments.
- Locus PaymentRouter: Stateless USDC routing for checkout payments (never holds funds).
Public and Immutable Nature of Blockchain Data. All on-chain data is public and immutable. This means: (a) your wallet addresses, transaction amounts, and smart contract interactions are permanently visible on the blockchain to anyone; (b) we cannot delete, modify, or redact on-chain transaction data once recorded; (c) while your Locus account information is private, the underlying blockchain transactions are not; and (d) third parties may be able to associate your wallet addresses with your identity through blockchain analysis or other means. By using the Service, you acknowledge and accept these inherent characteristics of blockchain technology.
11. Children's Privacy
The Service is intended for business and developer users only and is not directed to individuals under 18 years of age (or the age of majority in your jurisdiction, if greater). We do not knowingly collect personal information from children under 18 years of age.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact us at privacy@paywithlocus.com. If we learn we have collected personal information from a child without appropriate consent, we will take steps to delete such information and terminate the associated account.
12. International Data Transfers
We process and store information in the United States and we may transfer information globally to operate the Service. By using the Service, you understand your information may be transferred across borders. Specifically: (a) our primary infrastructure (RDS, S3, ElastiCache, KMS) is in the US; (b) CDN Service via AWS CloudFront and Cloudflare have global edge locations; (c) blockchain data on Base L2 is globally distributed, public, and immutable; and (d) third-party services (SendGrid, Twilio, Google Analytics, CDP, Wrapped API providers) may process data in various jurisdictions. We implement contractual, technical, and organizational safeguards appropriate to the sensitivity of the information and applicable law. If we later expand to additional regions, we will implement additional safeguards as required by the destination jurisdiction's laws and update this Policy.
13. Changes to This Policy
We may update this Policy from time to time. If changes are material, we will provide notice (e.g., via email, product banner, or dashboard notification). Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact Us
Locus Technologies Inc
1111B S Governors Ave STE 39737
Dover, DE 19904, USA
Email: For privacy inquiries, contact privacy@paywithlocus.com. For legal notices, contact legal@paywithlocus.com. For DMCA notices, contact DMCA@paywithlocus.com.
Security & Privacy Reports: privacy@paywithlocus.com