Privacy & Public Ledger Policy
Last Updated: September 7, 2026 • Version 2.2
Important Notice on Public Blockchain Ledgers
Transactions dispatched via decentralized blockchain rails (such as the Solana network, XRP Ledger, and Base L2) are recorded to public, decentralized ledgers. While sensitive personal banking details (routing and account numbers) are encrypted off-chain, your public wallet addresses, transaction hashes, timestamps, token transfer amounts, and ledger sequence numbers are permanent, publicly viewable by anyone, and cannot be deleted, modified, or scrubbed.
1. Overview & Data Architecture
InstaPay IPX (“we”, “us”, or “our”) operates a multi-rail payout orchestration gateway. We believe in strict data minimization, zero-knowledge privacy architecture, and complete transparency regarding how data is handled across both off-chain systems and public decentralized blockchains.
2. What We Collect & How It Is Protected
Sensitive Banking Data (Off-Chain & Encrypted)
ABA routing transit numbers, bank account numbers, and worker identity details are encrypted at rest using industry-standard AES-256-GCM encryption. Bank details are transmitted solely across PCI-DSS compliant, TLS 1.3 secured channels directly to regulated banking partners. We never store unencrypted bank account numbers.
Public Blockchain Identifiers (On-Chain)
Public wallet addresses (e.g. Solana base58 keys, XRPL classic addresses, Base EVM hex addresses), smart contract interaction signatures, transaction amounts, and ledger block numbers are submitted to public networks to achieve settlement consensus. By using our multi-rail service, you acknowledge that on-chain data is inherently public.
Identity Verification & Screening Data
Government identifiers (SSN/EIN, driver's licenses, tax documentation) collected for KYC/KYB identity verification and OFAC sanctions screening are processed in partnership with certified identity providers and retained under strict regulatory isolation.
3. KYC/AML Regulatory Data Retention & PII Segregation Requirements
As a financial technology gateway routing through regulated banking and payment networks, InstaPay IPX is subject to federal and state compliance obligations, including:
- Seven (7) Year Statutory Recordkeeping: Under the Bank Secrecy Act (BSA, 31 CFR Chapter X), FinCEN guidelines, and Internal Revenue Code (26 U.S.C. § 6001 / § 6050W), all financial transaction audit trails, payout disbursements, on-chain ledger hashes, and sanctions screening logs must be securely retained for an immutable period of seven (7) years.
- Data Segregation Architecture: We segregate customer Personal Identifiable Information (PII) from the immutable financial ledger. When a user or merchant requests account deletion under GDPR Article 17 or CCPA § 1798.105, all personal marketing details, names, telephone numbers, push tokens, and passwords are permanently scrubbed and anonymized (
pii_anonymized = true). - Statutory Erasure Exemption: Pursuant to GDPR Article 17(3)(b) and CCPA § 1798.105(d), mandatory financial ledger transactions, anti-fraud velocity logs, and on-chain blockchain settlement records cannot be deleted and remain locked under the 7-year statutory hold.
4. Biometric & Passkey Privacy
When utilizing our Tier 1 Instant Smart Wallet powered by WebAuthn and Passkeys:
- Your biometric data (FaceID, TouchID, fingerprint) is processed strictly within your device's Secure Enclave.
- InstaPay IPX never sees, receives, transmits, or stores your biometric templates or raw biometric records.
- The gateway receives only a cryptographic proof (public key signature) confirming that local biometric authorization succeeded.
5. Third-Party Service Providers & Network Nodes
We share data only with essential infrastructure partners under strict confidentiality and security agreements:
- Regulated Banking & Clearing Partners: To initiate FedNow, RTP, and ACH credit transfers.
- Blockchain Validators & RPC Nodes: Public transaction payloads broadcast to decentralized RPC infrastructure.
- Identity Verification Partners: Automated sanction screening and document verification services.
- Zero Sale of Data: We do not sell, monetize, rent, or trade user personal or transactional data under any circumstances.
6. Security Measures
We implement comprehensive defense-in-depth measures, including SOC 2 Type II audit alignment, TLS 1.3 encryption for data in transit, AES-256-GCM encryption for data at rest, immutable SHA-256 signed audit logging, and automated threat monitoring. See our Security Architecture page for detailed specifications.
7. Contact the Privacy Officer
If you have inquiries regarding this policy or our data practices, please contact our Data Protection Officer at: privacy@instapayipx.com.