Launch app
◐ Early access · Sandbox

Privacy Policy

Last updated: August 4, 2026

This Privacy Policy explains how Asher Card (“Asher Card,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our website, applications, and related services (collectively, the “Services”). Asher Card is currently in early access / sandbox, and any statistics or balances shown in the product are illustrative. Card issuing and on-/off-ramp payment rails are powered by our partner, Rain.

1. Introduction & Scope

This Policy applies to personal information we process when you visit our website, create an account, join a waitlist, or otherwise interact with the Services. It does not apply to the independent privacy practices of third parties, including Rain and other payment, banking, or identity-verification partners, who process certain information under their own policies. Where a partner acts as an independent controller, their policy governs their handling of your data.

By using the Services, you acknowledge the practices described here. If you do not agree, please do not use the Services.

2. Information We Collect

We collect the following categories of information:

  • Account & identity data. Name, email address, phone number, username, password credentials, and preferences you provide when creating or managing an account.
  • KYC / verification data. When identity verification is required for card or ramp features, you (or our verification partners) may provide date of birth, residential address, government-issued identification documents, tax identifiers, and related information needed to satisfy Know-Your-Customer (KYC) and Anti-Money-Laundering (AML) obligations. This information is typically collected and held by our KYC/AML and card-issuing partners.
  • Transaction data. Records of on-ramp, off-ramp, card, and bill-pay activity, including amounts, timestamps, counterparties, and status. In the sandbox, these are simulated and no real funds move.
  • Wallet & blockchain data. Public wallet addresses you connect, on-chain transaction hashes, and related public ledger data. Note that blockchain transactions are public and permanent by design (see Section 5).
  • Device & usage data. IP address, browser type, operating system, device identifiers, pages viewed, referring URLs, session activity, and approximate location derived from IP.
  • Cookies & similar technologies. Information collected through cookies, local storage, and similar technologies (see Section 6).
  • Communications. Information you provide when you contact us for support, feedback, or other inquiries.

3. How We Use Your Information

We use personal information to:

  • Provide, operate, maintain, and improve the Services;
  • Create and administer your account and authenticate you;
  • Facilitate card issuance, on-/off-ramps, and bill pay through Rain and partners;
  • Verify identity and comply with KYC, AML, sanctions, and other legal obligations;
  • Detect, prevent, and investigate fraud, abuse, and security incidents;
  • Communicate with you about updates, security alerts, and support requests;
  • Analyze usage to understand and improve product performance;
  • Comply with applicable laws and enforce our Terms of Service.

4. Legal Bases for Processing (GDPR)

If you are in the European Economic Area, the United Kingdom, or another region with similar laws, we process personal data on the following legal bases:

  • Contract. Processing necessary to provide the Services you request.
  • Legal obligation. Processing required to comply with KYC/AML, tax, and other laws.
  • Legitimate interests. Processing to secure, improve, and market the Services, provided your rights do not override those interests.
  • Consent. Where required (e.g., certain cookies or marketing), which you may withdraw at any time.

5. How We Share Your Information

We do not sell your personal information. We share information only as described below:

  • Rain and payment / banking partners. To issue cards, process on-/off-ramps, settle transactions, and provide bill pay, we share necessary information with Rain and associated banking and payment providers.
  • KYC / AML providers. Identity-verification and compliance vendors receive verification data to confirm your identity and screen for prohibited activity.
  • Card networks. Visa and other card networks receive transaction information necessary to authorize, clear, and settle card payments.
  • Service providers. Cloud hosting, analytics, customer-support, and communications vendors that process data on our behalf under contract.
  • Legal & compliance. Regulators, law enforcement, or other parties when required by law, to respond to legal process, or to protect the rights, safety, and property of Asher Card, our users, or the public.
  • Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • Blockchain (public by design). When you transact on a public blockchain, wallet addresses and transaction details are recorded on a public, permanent ledger that we do not control and cannot alter or delete.

6. Cookies & Tracking

We use cookies, local storage, and similar technologies to keep you signed in, remember preferences (such as light/dark theme), measure and improve performance, and secure the Services. Some cookies are strictly necessary; others are used for analytics or, where applicable, marketing. You can control cookies through your browser settings and, where required, through our consent controls. Disabling some cookies may affect functionality. We honor Global Privacy Control (GPC) signals where legally required.

7. Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal obligations (including recordkeeping under financial and AML laws), resolve disputes, and enforce our agreements. Retention periods vary by data type and legal requirement; KYC and transaction records are typically retained for a period mandated by applicable financial regulations. When information is no longer needed, we delete or anonymize it. Data recorded on public blockchains cannot be deleted.

8. Data Security

We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for securing any self-custodied wallets and private keys, which we never hold.

9. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights regarding your personal information:

  • Access a copy of the personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Delete your personal information, subject to legal exceptions;
  • Restrict or object to certain processing;
  • Data portability — receive your data in a portable format;
  • Withdraw consent where processing is based on consent.

California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use and disclose it, to request deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising in a manner that requires an opt-out beyond honoring GPC signals. We will not discriminate against you for exercising your rights.

To exercise any right, contact us at privacy@ashercard.com. We may need to verify your identity before responding, and you may use an authorized agent where permitted by law. EEA/UK users may also lodge a complaint with their local data-protection authority.

10. International Transfers

We and our service providers may process personal information in countries other than where you reside, including the United States. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses and equivalent mechanisms, to protect your information.

11. Children’s Privacy

The Services are not directed to, and are not intended for, anyone under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it. If you believe a minor has provided us information, please contact us.

13. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

14. Contact Us

If you have questions or requests about this Policy or your personal information, contact us at:

Privacy inquiriesprivacy@ashercard.com

Looking for our terms? Read the Terms of Service.

Launch app