1. Scope
This policy applies to Strawberry ID products and services, including account onboarding, wallet operations, identity verification, merchant integrations, Google Sign-In, and support interactions.
2. Data We Process
We process profile data, contact data, KYC/verification records, transaction metadata, security telemetry, and operational audit logs required to deliver regulated financial services safely. If you use Sign in with Google, we also process your Google account identifier, verified email, and basic profile fields needed to create or authenticate your Strawberry account.
3. Legal Basis
Processing is performed under contractual necessity, legal obligations (including KYC/AML), fraud and abuse prevention, security interests, and consent where required by applicable law.
4. Verification and communications
We may use specialized services to verify identity and deliver messages. Results are combined with our risk controls and manual review when mismatch, expiry, or fraud indicators are detected.
5. Retention
Data is retained only for as long as needed for service delivery, legal obligations, fraud prevention, dispute handling, and security operations. Records may then be archived or deleted in line with retention schedules.
6. Security
We apply access controls, encryption, strict role permissions, and auditable event logging to reduce unauthorized access, disclosure, or alteration of personal data.
7. User Rights
Subject to legal and regulatory limits, users may request access, correction, and lawful objection to processing. Requests can be submitted via official support channels.
8. International Transfers
Where processing involves cross-border transfer, Strawberry ID applies contractual and technical safeguards intended to protect user data.
9. Policy Updates
We may update this policy to reflect legal, operational, or product changes. Material updates are versioned and may require renewed acceptance in-app before continued use of regulated features.