Legal
Privacy Policy
Data handling disclosures for MoonSwap accounts, wallets, trading records, and notifications. Last updated August 30, 2026.
Scope and Controller
This Policy applies to personal data processed by the operator of MoonSwap through moonswap.trade, MoonSwap APIs, and related support or administrative services. Public blockchain activity and independent wallet, RPC, routing, exchange, hosting, notification, and analytics providers process information under their own policies.
Data MoonSwap May Process
MoonSwap may process wallet addresses and signatures used to prove wallet control; account identifiers and verified administrative identifiers; IP address, device, browser, security, and request metadata; watchlists, alerts, notifications, settings, subscriptions, and automation rules; trade, quote, order, execution, fee, cancellation, expiry, and reconciliation records; holder-verification results; support and privacy requests; and operational audit logs. MoonSwap does not request or need a wallet seed phrase or private key.
Sources and Purposes
Data comes from you, your wallet, public blockchains, service providers, and product interactions. It is used to authenticate wallet control, provide and secure the service, build and reconcile transactions, enforce order policies, maintain history and preferences, calculate holder benefits and fees, send requested notifications, prevent abuse, investigate incidents, satisfy legal obligations, and improve reliability.
Legal Bases
Where applicable law requires a legal basis, MoonSwap processes data as needed to provide requested wallet, account, routing, order, notification, and support services; to comply with legal obligations; and for legitimate interests in security, abuse prevention, reliability, accounting, and dispute handling, balanced against user rights. Optional analytics and push notifications rely on consent where required, and that consent may be withdrawn. A different jurisdiction-specific basis or notice applies where local law requires it.
Local Storage
MoonSwap may cache settings, watchlists, alerts, notifications, orders, and trade history locally so the app remains usable when persistence is unavailable.
Service Providers and Disclosures
MoonSwap may disclose the minimum necessary data to hosting, database, RPC, routing, liquidity, blockchain-data, notification, security, observability, and support providers, including Vercel, Supabase, Sentry, and the enabled Solana data and routing providers; professional advisers; authorities responding to valid legal process; and a successor in a corporate transaction. Public transaction data is broadcast to Solana and becomes publicly observable. MoonSwap does not sell personal data or use it for cross-context behavioral advertising.
Error Monitoring
When production error monitoring is enabled, Sentry may receive error messages, stack traces, release and runtime identifiers, page or request context, device and browser details, and network metadata needed to diagnose failures. MoonSwap configures error reporting to avoid wallet seed phrases, private keys, bearer tokens, service-role keys, and transaction-signing material. Do not include secrets or sensitive personal information in support descriptions or free-form fields.
Analytics and Cookies
Optional product analytics remain disabled unless deliberately enabled with an applicable legal basis and any required consent. If enabled, analytics may include coarse feature, token-symbol, route, amount, score, device, performance, and error events, but must not include wallet addresses, transaction signatures, emails, seed phrases, private keys, bearer tokens, or service-role keys. Essential local storage and security records may operate without optional analytics.
Retention
Wallet-auth and replay-prevention records are deleted after expiry when operationally feasible. General provider logs are targeted for 30 days; notifications, holder-verification metrics, optional analytics, failed quotes, and unexecuted route records for 90 days; and security or administrative audit logs for one year. Profiles, watchlists, alerts, subscriptions, and rules remain while active. Confirmed trade, order, execution, and fee records may be retained for up to seven years when reasonably necessary for accounting, disputes, security, or law. Legal holds and provider backup cycles can extend these periods.
Exports, Deletion, and Immutable Data
Connected-wallet users can download or delete wallet-linked MoonSwap records from Settings. MoonSwap may retain the minimum evidence required for security, disputes, accounting, legal holds, or compliance. Public blockchain records cannot be changed, and provider backup copies expire on their normal schedule.
Your Choices and Rights
You may clear browser-local data, revoke push permission, disconnect a wallet, and use authenticated export or deletion controls. Depending on your location, you may also have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal data, and to appeal or complain to a regulator. MoonSwap may verify wallet or account control before acting and may deny requests where an exception applies.
Security and International Processing
MoonSwap uses access controls, encryption provided by its infrastructure, secret separation, and audit logging intended to protect stored data. No system is perfectly secure. Providers may process data in the United States and other countries whose laws differ from your own.
Children
MoonSwap is not directed to children. You must be at least 18 and at least the age of majority in your jurisdiction. MoonSwap does not knowingly collect personal data from children through the service.
Policy Changes
MoonSwap may update this Policy by posting a new effective date. Material changes may be presented through the service or require renewed acknowledgement where applicable.
