Privacy Notice

Last updated: July 7, 2026

1. Who we are

Mertl Luxury GmbH, a company registered in Austria (VAT number ATU76373979), trading as WalletOrigin, is the data controller for the personal data described in this notice. For any privacy question, contact us via the support channel in your dashboard.

2. Personal data we collect

  • Account data: email address, login credentials (hashed), display name.
  • Verification data: domain names, wallet addresses, DNS TXT records, chains, and verification timestamps you submit.
  • Support messages: content of messages you send us.
  • Usage and telemetry: API request counts, feature usage, error logs.
  • Device / network: IP address, user agent, approximate location derived from IP.
  • Cookies: essential cookies for authentication and preferences.

3. How we use your data and legal basis

  • Account creation and providing the Service — legal basis: performance of contract.
  • Security, fraud prevention, abuse detection — legal basis: legitimate interests.
  • Customer support — legal basis: performance of contract / legitimate interests.
  • Product improvement and analytics — legal basis: legitimate interests.
  • Compliance with law — legal basis: legal obligation.
  • Marketing communications — legal basis: consent, where required.

4. Who we share data with

  • Paddle.com — our Merchant of Record. When you buy a subscription, Paddle collects and processes your billing information (name, billing address, payment method, tax data) for payment processing, subscription management, invoicing, and tax compliance. See Paddle's privacy notice.
  • Infrastructure providers — hosting, database, and analytics subprocessors that operate the Service on our behalf under confidentiality obligations.
  • Professional advisers — legal, accounting, and audit advisers where relevant.
  • Authorities — where required by law, court order, or legitimate legal process.

Verified domain-to-wallet mappings that you list in the public directory are intentionally public and are visible to anyone who queries the Service.

5. International transfers

Data may be transferred outside the UK / EEA to our subprocessors. Where such transfers occur, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an adequacy decision.

6. Data retention

We keep account and verification data for as long as your account exists plus a reasonable period afterwards for legal, audit, and dispute-resolution purposes. Data no longer needed is deleted or anonymised. You can delete your account and its associated data at any time from settings.

7. Your rights

You have the following rights, subject to legal exceptions: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. If you are in the UK / EEA you also have the right to lodge a complaint with your supervisory authority. We aim to respond to rights requests within one (1) month.

8. Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, secure credential storage, and audit logging. No system is perfectly secure; you are responsible for keeping your credentials confidential.

9. Cookies

We use essential cookies to authenticate signed-in users and remember preferences. We may use limited analytics cookies to understand aggregate usage. You can manage cookies via your browser settings.

10. Changes

We may update this notice from time to time. Material changes will be communicated by email or in-app notice.

11. Contact

To exercise your rights or for any privacy question, contact us via the support channel in your dashboard.