Privacy Policy
Last updated: August 4, 2026
This Privacy Policy explains how Asher Card (“Asher Card,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our website, applications, and related services (collectively, the “Services”). Asher Card is currently in early access / sandbox, and any statistics or balances shown in the product are illustrative. Card issuing and on-/off-ramp payment rails are powered by our partner, Rain.
1. Introduction & Scope
This Policy applies to personal information we process when you visit our website, create an account, join a waitlist, or otherwise interact with the Services. It does not apply to the independent privacy practices of third parties, including Rain and other payment, banking, or identity-verification partners, who process certain information under their own policies. Where a partner acts as an independent controller, their policy governs their handling of your data.
By using the Services, you acknowledge the practices described here. If you do not agree, please do not use the Services.
2. Information We Collect
We collect the following categories of information:
- Account & identity data. Name, email address, phone number, username, password credentials, and preferences you provide when creating or managing an account.
- KYC / verification data. When identity verification is required for card or ramp features, you (or our verification partners) may provide date of birth, residential address, government-issued identification documents, tax identifiers, and related information needed to satisfy Know-Your-Customer (KYC) and Anti-Money-Laundering (AML) obligations. This information is typically collected and held by our KYC/AML and card-issuing partners.
- Transaction data. Records of on-ramp, off-ramp, card, and bill-pay activity, including amounts, timestamps, counterparties, and status. In the sandbox, these are simulated and no real funds move.
- Wallet & blockchain data. Public wallet addresses you connect, on-chain transaction hashes, and related public ledger data. Note that blockchain transactions are public and permanent by design (see Section 5).
- Device & usage data. IP address, browser type, operating system, device identifiers, pages viewed, referring URLs, session activity, and approximate location derived from IP.
- Cookies & similar technologies. Information collected through cookies, local storage, and similar technologies (see Section 6).
- Communications. Information you provide when you contact us for support, feedback, or other inquiries.
3. How We Use Your Information
We use personal information to:
- Provide, operate, maintain, and improve the Services;
- Create and administer your account and authenticate you;
- Facilitate card issuance, on-/off-ramps, and bill pay through Rain and partners;
- Verify identity and comply with KYC, AML, sanctions, and other legal obligations;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Communicate with you about updates, security alerts, and support requests;
- Analyze usage to understand and improve product performance;
- Comply with applicable laws and enforce our Terms of Service.
4. Legal Bases for Processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or another region with similar laws, we process personal data on the following legal bases:
- Contract. Processing necessary to provide the Services you request.
- Legal obligation. Processing required to comply with KYC/AML, tax, and other laws.
- Legitimate interests. Processing to secure, improve, and market the Services, provided your rights do not override those interests.
- Consent. Where required (e.g., certain cookies or marketing), which you may withdraw at any time.
7. Data Retention
We retain personal information for as long as necessary to provide the Services, comply with our legal obligations (including recordkeeping under financial and AML laws), resolve disputes, and enforce our agreements. Retention periods vary by data type and legal requirement; KYC and transaction records are typically retained for a period mandated by applicable financial regulations. When information is no longer needed, we delete or anonymize it. Data recorded on public blockchains cannot be deleted.
8. Data Security
We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for securing any self-custodied wallets and private keys, which we never hold.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Access a copy of the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your personal information, subject to legal exceptions;
- Restrict or object to certain processing;
- Data portability — receive your data in a portable format;
- Withdraw consent where processing is based on consent.
California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use and disclose it, to request deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising in a manner that requires an opt-out beyond honoring GPC signals. We will not discriminate against you for exercising your rights.
To exercise any right, contact us at privacy@ashercard.com. We may need to verify your identity before responding, and you may use an authorized agent where permitted by law. EEA/UK users may also lodge a complaint with their local data-protection authority.
10. International Transfers
We and our service providers may process personal information in countries other than where you reside, including the United States. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses and equivalent mechanisms, to protect your information.
11. Children’s Privacy
The Services are not directed to, and are not intended for, anyone under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it. If you believe a minor has provided us information, please contact us.
12. Third-Party Links
The Services may contain links to third-party websites and services that we do not operate or control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party site you visit.
13. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
14. Contact Us
If you have questions or requests about this Policy or your personal information, contact us at:
Looking for our terms? Read the Terms of Service.
Launch app