NexusPay
  • What it costs
  • Gas
  • How it works
  • Safety
  • Questions
Get a card

Legal

Privacy Policy

A wallet address is not anonymous. It is a permanent public identifier, and once it is linked to you it stays linked. This policy is written on that basis rather than around it.

Effective [EFFECTIVE DATE].

1. Who is responsible for your data

[LEGAL ENTITY NAME], of [REGISTERED ADDRESS], decides how and why your personal data is used, and is the controller of it. Questions, requests and complaints go to [PRIVACY EMAIL].

2. What we collect

From your wallet

  • Your TRON wallet address. We receive it when you connect, and it is the identifier your card and your activity are tied to.
  • The spending allowance you granted to our treasury address, and its remaining amount.
  • Your USDT balance and transaction history on TRON, which we read from the public chain in order to tell you whether a purchase can go through.

From using the card

  • Card transactions — amount, currency, date, merchant name and category, and whether the authorisation was approved or declined. We receive these from [ISSUING PARTNER].
  • Identity documents, but only if you spend above US$1,000 in a day and the check in section 6 of the Terms is triggered. Typically a government-issued identity document, a selfie and your date of birth, collected through [KYC PROVIDER].

From your browser

  • Server logs when this site talks to our backend: IP address, the time, the request, and the browser's user-agent string.
  • Anything you send us, such as the content of a support message and the address you send it from.

What we never collect

  • Your private keys or seed phrase. They never leave your wallet, and there is no field in our software that could receive them. Anyone asking you for them — including someone claiming to be us — is stealing from you.
  • Your full card number. Card credentials are held by [ISSUING PARTNER] under the card scheme's security rules, and are shown to you rather than stored by us.

3. Cookies and what is stored in your browser

This site sets no cookies and runs no analytics or advertising trackers. There is no consent banner because there is nothing to consent to.

It does keep four values in your own browser's storage, which stay on your device, are readable only by this site, and are cleared when you clear site data:

Key What it holds Why
cryptocard.session_v1 A session token and your wallet address So you are not asked to sign in again on every visit
cryptocard.onboarding_v1 Which setup steps you have finished So the site does not restart you at step one
cryptocard.pending_wallet_connect The wallet app you were sent to, and when To resume the connection when your wallet app returns you here
cryptocard.auto_open_attempted A flag, for this browser tab only So your wallet app is not opened twice in one session

4. Why we use it, and on what legal basis

  • To run the card you asked for — reading your balance and allowance, authorising purchases, taking the 4.5% commission, showing you your transactions. Basis: performance of our contract with you.
  • To meet legal obligations — identity checks above the daily threshold, sanctions screening, anti-money-laundering record keeping, tax and accounting. Basis: legal obligation.
  • To prevent fraud and abuse — spotting stolen cards, and use patterns designed to split spending across wallets to stay under the threshold. Basis: our legitimate interest in a service that is not used for crime, weighed against your interest in not being profiled; we use the minimum needed to spot it.
  • To keep the service working — diagnosing errors from logs. Basis: our legitimate interest in a service that functions.

We do not sell your data, and we do not use it to advertise to you anywhere.

5. Who else sees it

  • [ISSUING PARTNER] — issues the card and processes every transaction on it. They necessarily see your card activity, and your identity where a check was required. They act as a controller in their own right for that, under their own privacy notice.
  • TronSave — the service we rent TRON energy from and delegate to your wallet so you do not need TRX. To delegate energy to your wallet we must give them your wallet address. There is no way to sponsor your gas without doing this, and you should know it rather than discover it.
  • [KYC PROVIDER] — verifies identity documents when the daily threshold is exceeded.
  • [HOSTING PROVIDER] — runs the servers our backend and its database sit on.
  • Authorities — where we are legally required to disclose, and only what is required.

6. The part we cannot control

TRON is a public blockchain. Your wallet address, its USDT balance, the allowance you granted us, and every transfer made under it are published, permanent, and readable by anyone in the world, forever. We do not put them there in the sense of choosing to publish them — that is simply what using a blockchain is — but the effect on you is the same.

This has two consequences worth stating plainly:

  • Anyone who learns that this address is yours can see everything that address has ever done, and everything it does afterwards.
  • A deletion request cannot reach on-chain data. When we delete your data, we delete it from our systems. The chain is beyond our reach and beyond anyone else's. No provider who tells you otherwise is being straight with you.

7. How long we keep it

  • Identity documents and transaction records: [RETENTION PERIOD] after your last activity, because anti-money-laundering law requires us to keep them for a fixed period whether or not you are still a user.
  • Server logs: [LOG RETENTION PERIOD].
  • Support messages: [SUPPORT RETENTION PERIOD].

After those periods we delete the data or irreversibly anonymise it.

8. Where it goes

Our providers may process your data outside [JURISDICTION OF INCORPORATION]. Where they do, the transfer is covered by [INTERNATIONAL TRANSFER MECHANISM].

9. Your rights

You can ask us to:

  • give you a copy of the data we hold about you;
  • correct it if it is wrong;
  • delete it — which we will do except where AML law requires us to keep it for the period in section 7, and which cannot extend to the chain, as explained in section 6;
  • restrict or object to our using it where we rely on legitimate interests;
  • send it to another provider in a portable format.

Write to [PRIVACY EMAIL]. We will respond within [RESPONSE PERIOD] and will not charge you for it. If you are unhappy with how we handled it you can complain to [SUPERVISORY AUTHORITY].

10. How it is protected

Data is encrypted in transit. Access to systems holding personal data is restricted to the people who need it. The chain read key that would otherwise sit in this page's JavaScript is deliberately kept on the backend instead, because every value compiled into a browser bundle is readable by anyone who loads the page.

No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will tell you and the relevant authority within the time the law requires.

11. Children

NexusPay is not for anyone under [MINIMUM AGE]. We do not knowingly collect their data, and will delete it if we learn we have.

12. Changes to this policy

If we change how we use your data in a way that affects you, we will tell you by [NOTICE METHOD] before the change takes effect. The effective date above always reflects the current version.

NexusPay

A Visa card that spends the USDT in your own TRON wallet. We take 4.5% of what you spend and nothing else.

The card

What it costs How it works Supported wallets Spending limits

Safety

Cancel an approval What we can and cannot do Report a problem

Company

Terms Privacy Cardholder agreement Contact

NexusPay is a technology provider, not a bank. Cards are issued by our card issuing partner, and holding or spending stablecoins carries risk including the loss of your funds. Nothing here is financial advice.

© 2026 NexusPay