Privacy Policy

Effective date: 15 July 2026

This is the Privacy Policy for the Peanut app, website (peanut.me), and related services (together, the "Service"), operated by Squirrel Labs Ltd, a company registered in England and Wales (company number 14558823, registered office Office One, 1 Coldbath Square, Farringdon, London EC1R 5HL) ("Peanut", "we", "us", "our").

Peanut is the controller of the personal data described in this Privacy Policy, and we process it in accordance with UK data protection law, including the UK GDPR and the Data Protection Act 2018.

This policy explains what personal data we collect, why and how we use it, who we share it with, and the rights you have. It supplements our Terms of Service and does not replace them. If you do not agree with this Privacy Policy, please do not use the Service.

The Peanut Card is covered by an additional notice. The Peanut Card is issued by Third National. When you apply for a card, the issuer's Account Opening Privacy Notice also applies to the data collected for the card program. This Privacy Policy does not repeat that notice — please read it before applying for a card.

1. What Peanut is (and why it matters for your data)

Peanut is a self-custodial smart wallet for instant global payments in digital dollars (USDC on the Arbitrum network), plus the Peanut Card. "Self-custodial" shapes how your data works here:

  • We never hold your passkey. Your account is secured by a passkey. The cryptographic key is generated and stored on your own device (in its secure hardware); it is never sent to our servers. Your biometric data (fingerprint or face) is used only by your device to unlock the passkey — Peanut never receives or stores it. Peanut cannot freeze your funds and cannot take or recover them for itself, and is never in the flow of funds. (If you activate the Peanut Card, you sign a scoped permission that allows Peanut to initiate transfers from your wallet only to your own card collateral account; withdrawals from collateral back to your wallet need your passkey signature plus the card issuer's co-signature, and the permission ends when you cancel the card — see the card terms.)
  • Your transactions are recorded on a public blockchain. Wallet addresses, transaction amounts, and transaction history on Arbitrum are public by nature. Anyone can view them, and neither we nor anyone else can edit or delete them.
  • We never see your identity documents. Identity verification is performed by specialist providers (see section 3). They hold the documents; Peanut receives only your verification status.

2. What information we collect

Information you give us:

  • Account data — your chosen username and contact email address, plus passkey credential identifiers (the public part of the credential, not the key itself).
  • Identity verification status — when you use features that legally require identity verification (bank transfers, QR payments, the Peanut Card), you complete verification directly with our verification provider, Sumsub. Your documents, photos, and verification data are collected and held by Sumsub — Peanut receives the outcome of the check (e.g. verified / not verified, and the reason category if a check fails), a reference to the verification, and the region it relates to — not the underlying documents or data.
  • Bank and payment details — when you deposit from or withdraw to a bank account, the details you enter (e.g. IBAN, account number, CLABE) are processed by us and the payment partner operating that rail (see section 4).
  • Communications — messages you send us through support chat, email, or social media, and feedback you provide.
  • Marketing preferences — whether you have opted in or out of marketing messages.

Information collected automatically:

  • Device and usage data — IP address, device and browser type, operating system, language and time zone settings, pages and screens viewed, taps and interactions, session length, referral source, and errors. We collect this through our analytics tooling (PostHog and Google Analytics — see section 6).
  • Notification data — device push tokens and email delivery/open events, processed through our notification provider (OneSignal).

On-chain data:

  • Your smart wallet address and the transactions associated with it exist on the public Arbitrum blockchain. We process this data to operate the Service, but we do not control the blockchain — it is public, permanent, and outside any one company's control.

What we do not collect:

  • Your private keys or seed phrases (passkey accounts have none to give).
  • Your biometric data.
  • Copies of your identity documents (held by the verification provider).

3. Identity verification

To offer bank transfers, QR payments, and the Peanut Card, we and our partners are required to verify who you are. Verification is run by Sumsub. You submit your documents and selfie directly to Sumsub; it performs the checks (including anti-fraud and sanctions screening) and stores the verification data under its own security and retention obligations. Peanut receives your verification status (the result of the check, a reference to it, and the region it relates to) — not your documents.

For the Peanut Card, Sumsub shares your verification data directly with the card program (Rain / Third National) via a secure share token, so you don't have to verify twice — Peanut passes the reference, not the data. The issuer's Account Opening Privacy Notice describes how it is used there.

4. Who we share your data with

We share personal data with the service providers and partners we need to run Peanut — no more than each one needs for its role. We do not sell your personal data.

PartnerRoleWhat data they process
SumsubIdentity verificationIdentity documents, selfie/liveness data, name, date of birth, address — submitted by you directly to Sumsub; Peanut receives status only
BridgeBank transfer rails (US, the SEPA zone, Mexico, UK)Name, verification data, bank account details, transfer amounts and references
MantecaLatin America on/off-ramps and QR payments (e.g. Argentina, Brazil)Name, verification data, bank/payment details, transaction amounts
Rhino.fiCross-chain crypto deposits and withdrawalsWallet addresses, deposit addresses, transaction data
Rain / Third NationalPeanut Card program manager and card issuerVerification data, card application and transaction data — see the Account Opening Privacy Notice
ZeroDevSmart wallet infrastructureWallet addresses, passkey credential identifiers (public), transaction (user operation) data
PostHogProduct analyticsDevice and usage data (section 2)
Google AnalyticsWeb analyticsDevice and usage data (section 2), including a pseudonymous account identifier
SentryError tracking and crash reporting (error diagnostics)Device and technical data, IP address, and error context when the app or website encounters a problem
OneSignalPush notifications and emailEmail address, device push tokens, delivery and engagement events
CrispCustomer support chatYour messages, email address, and basic device data when you contact support
VercelWeb hostingTechnical request data (e.g. IP address, request logs)
RenderAPI hostingTechnical request data and the account data our systems store

We may also share personal data:

  • With professional advisors (lawyers, auditors, insurers) where necessary for the services they provide to us.
  • With authorities — law enforcement, regulators, and other parties where we believe in good faith that disclosure is required by law or necessary to protect rights, safety, or property, or to prevent fraud or other illegal activity.
  • In a business transfer — if we sell, merge, or reorganise our business, personal data may be transferred as part of that transaction. We will require the recipient to respect this Privacy Policy.

Payment partners (such as Bridge, Manteca, and the card issuer) act under their own regulatory obligations and may be independent controllers of some data — their own privacy notices apply to that processing.

5. Why we use your data (purposes and lawful bases)

Under UK GDPR we need a lawful basis for each use of your personal data:

PurposeLawful basis
Creating and operating your account, executing payments and card transactions you requestPerformance of a contract
Identity verification, sanctions screening, fraud preventionLegal obligation (ours and our regulated partners'); legitimate interests in preventing fraud
Sending service messages (transaction confirmations, security alerts, changes to terms)Performance of a contract; legitimate interests
Sending marketing messages (email, push)Consent, or legitimate interests where permitted — you can opt out at any time (section 9)
Understanding how the app is used, fixing bugs, improving the productLegitimate interests in operating and improving the Service
Responding to support requestsPerformance of a contract; legitimate interests
Establishing, exercising, or defending legal claimsLegitimate interests
Complying with applicable law and lawful requests from authoritiesLegal obligation

Where we rely on legitimate interests, we balance them against your rights and freedoms, and you can object (section 10).

6. Cookies and analytics

We use a small number of cookies and similar technologies:

  • Essential — to keep you logged in and make the Service work (e.g. session state, security).
  • Analytics — we use PostHog and Google Analytics to understand how the app and website are used (screens viewed, interactions, device data). We use this to fix bugs and improve the product, not to serve third-party advertising. We do not use advertising networks or cross-site tracking cookies.

You can control cookies through your browser settings; blocking essential cookies may break parts of the Service. If you would like us to exclude your data from analytics, contact us (section 12).

7. International transfers

We are based in the United Kingdom, and some of our service providers (section 4) are based outside the UK and the European Economic Area, including in the United States. Where we transfer your personal data internationally, we use appropriate safeguards, such as:

  • transfers to countries covered by UK adequacy regulations; or
  • the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus additional measures where needed.

Contact us (section 12) for more information about the safeguards for a specific transfer.

8. How long we keep your data

We keep personal data only as long as needed for the purposes above, including satisfying legal, regulatory, tax, accounting, and reporting requirements. In outline:

  • Account data — kept while your account is active, and afterwards only for as long as required by law or needed to resolve disputes.
  • Verification status and payment records — retained in line with the financial-crime and record-keeping obligations that apply to us and our regulated partners, typically five to six years after the business relationship ends.
  • Analytics and support data — kept only as long as needed for the purposes described above, after which it is deleted or anonymised.
  • On-chain data — cannot be deleted by anyone; it is a permanent public record (see sections 1 and 10).

We may keep data longer if there is a complaint or a reasonable prospect of litigation, and we may anonymise data (so it can no longer identify you) and use it indefinitely for statistics and product research.

9. Marketing and notifications

We send two kinds of messages:

  • Service messages (transaction confirmations, security alerts, important changes) — these are part of running your account and you cannot opt out while you have an account.
  • Marketing messages (product news, features, offers) by email or push — you can opt out at any time via the unsubscribe link in any marketing email, your device's notification settings, or by contacting us.

10. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you (a "subject access request").
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data. We will comply unless we are legally required to keep it (e.g. financial-crime record-keeping) or it is technically impossible: data recorded on the blockchain — including your wallet address and transaction history — cannot be erased by us or anyone else.
  • Restriction — ask us to pause processing in certain circumstances.
  • Portability — receive data you provided to us in a machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing (we will always stop marketing on request).
  • Withdraw consent — where processing is based on consent, withdraw it at any time (this doesn't affect processing before withdrawal).

To exercise any right, contact us (section 12). We may ask you to verify your identity before acting on a request. If we refuse a request, we will tell you why.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator (ico.org.uk). We would appreciate the chance to address your concern first, so please contact us before going to the ICO.

11. Security

We protect personal data with technical and organisational measures, including encryption in transit, access controls limiting data to staff and contractors who need it, and contractual confidentiality and data protection obligations on our processors. The self-custodial design also limits what an attacker could gain from our systems: we hold no private keys and no identity documents.

No system is perfectly secure, and we cannot guarantee absolute security. We have procedures for handling suspected personal data breaches and will notify you and the ICO where legally required.

12. Contact

Questions, rights requests, or complaints about this Privacy Policy:

  • Email: support@peanut.me
  • Post: Squirrel Labs Ltd, Office One, 1 Coldbath Square, Farringdon, London EC1R 5HL

13. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data relating to children. If you believe we have collected personal data about your child, contact us (section 12) and we will delete it as required by law.

14. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to our business or the law. We will post the updated version on the Service with a new "last updated" date, and where changes are significant we will make reasonable efforts to notify registered users (for example by email or in-app notice) before they take effect.

15. Language

This Privacy Policy is drafted in English. If it is translated, the English version controls in the event of any inconsistency.