BAGHOLDER
  • Home
  • Terms
  • How BAGHOLDER Works
  • Support

Privacy Policy

Version 1.6 — Last updated: August 12, 2026

This Privacy Policy describes how BAGHOLDER ("we," "us," or "our") collects, uses, and protects your information when you use our mobile application.


Information Stored on Your Device

BAGHOLDER stores the following data locally on your device using encrypted storage (iOS Keychain / Android Keystore for secrets, an encrypted local database for structured data):

  • Your bags and token lists
  • Purchase history and pending orders
  • Blocked-attempt audit log (kept for 365 days for support purposes; a structured mirror is also stored on our server — see below)
  • Portfolio snapshots
  • Diagnostic logs
  • State of residence
  • Date of birth verification status
  • Wallet address
  • App settings and preferences
  • Disclosure and terms acceptance records

Other than the blocked-attempt mirror noted above, this data is NOT transmitted to our servers and remains exclusively on your device.

Encrypted Cloud Backup

To protect against data loss (device replacement, app reinstallation, or accidental storage clearing), BAGHOLDER automatically creates an encrypted backup of your on-device data. This backup is encrypted on your device using a key derived from your wallet before transmission. We store the encrypted data on our server but cannot decrypt, read, or access its contents. Only your wallet can unlock the backup.

The backup includes: purchase history, bag configurations, app settings, and portfolio snapshots. On reinstall or device change, signing in recovers your wallet, which automatically decrypts and restores your data.

You can delete your backup at any time by deleting your account in Settings.


Information Stored on Our Server

Our server stores the following data in a secured database:

  • Payment profile (wallet address, transaction volume)
  • Payment charge records (payment provider session ID, charge amount, fee amount, wallet address, chain, status, timestamp)
  • Gas funding records (wallet address, transaction hash, native-token gas amount, chain, timestamp)
  • Fee sweep records (chain, amount, transaction hash, fee type, timestamp) retained for 7 years for tax purposes
  • Per-token swap outcomes (chain, symbol, amount, DEX used, success/failure reason, transaction hash)
  • Cached wallet token balances (so we do not pay third-party RPC providers for repeat reads of the same on-chain data)
  • Solana ATA membership cache (which token accounts your Solana wallet has, so we charge the correct account-creation rent)
  • Per-state activity aggregates and snapshots: rolling-12-month totals of purchase volume, platform fees, purchase count, and active-user count, broken out by the state code recorded on each purchase. Used to monitor compliance with state-level thresholds such as California Financial Code §3103(b)(9). A snapshot of these aggregates is persisted to a separate table approximately once per calendar quarter, to provide a historical record of what we knew when. The aggregates and snapshots do not contain wallet addresses or individual purchase records — only state-level totals.
  • Verified wallet binding pair if you bind a Solana wallet (EVM address ↔ Solana address, signed proof)
  • Wallet-to-account binding (a record linking each wallet address you sign in with to the account identifier issued by our wallet provider, Privy). Used to enforce the gas- funding Sybil cap and suspension provisions described in the Terms of Service — not a per-account limit on how much you may purchase. No additional personal information is collected through this binding.
  • Suspended-wallet list (wallet addresses we have refused service to, with a short text reason and timestamp). Used to enforce the suspension provisions in the Terms of Service. Suspension blocks new purchases through the App only; suspended accounts retain the ability to export their private keys through the wallet provider's hosted page.
  • Anonymized usage events (e.g., app opens, feature usage, purchase outcomes) associated with your wallet address only and automatically deleted after 1 year
  • Blocked-attempt audit log mirror (chain, amount requested, token symbols, block reason, timestamp) — required to demonstrate compliance with state eligibility, age, and limit rules. Retained for the regulatory window (no automatic deletion).
  • Token registry liquidity events (token de-list/re-list history with reason — used to power the "this token was removed" message in the app)
  • Shared bag configurations (token lists only, no personal data) if you choose to share a bag via the sharing feature. Unused shared bags are automatically deleted after 1 year
  • Optional username + the encrypted cloud backup of your local app data if you opt in — encryption key is derived from your wallet signature and the server cannot decrypt it
  • Onboarding attestation records (see below) — the pass/fail outcome recorded at each signup gate (age, state, and legal-document review), keyed to a device identifier rather than your wallet, and retained for about 1 year. On a failed age check we record only an age band, never your date of birth.

Onboarding attestation records

During signup, before you have a wallet, the App records the pass/fail outcome at each eligibility gate (age verification, state selection, and legal-document review) so we can maintain a compliance audit trail and apply anti-abuse and rate-limiting safeguards against automated or repeated evasion. These records are keyed to a device identifier rather than your wallet, name, or email, and are retained for about one year. On a failed age check we record only an age band — never your date of birth. We also record the request IP at the moment of state attestation as a secondary cross-reference for the audit trail; your self-attested state of residence is the primary record. These records are never linked to your wallet, payment, or order records, and do not include your name, email, or any other personally identifiable information (PII).

Important: your email address may pass through our server when you make a buy — it is forwarded to our payment provider as required by their payment API. The transit is encrypted (HTTPS) and the value is discarded immediately after it's sent. No row of any database on our server contains your email at rest.


Information We Do NOT Collect

BAGHOLDER does not store on any server:

  • Private keys or wallet seed phrases
  • Your name
  • Your email address (passes through in-transit on each buy only — see above)
  • Date of birth (only the age band on a rejected attempt — see "Onboarding attestation records" above)
  • Biometric data (device authentication returns a boolean only)
  • Bank account credentials or login information
  • Social Security numbers or government IDs
  • Location data (your IP address briefly touches our server during each buy and is forwarded to our payment provider for fraud-risk scoring — we do not log or store it; the single exception is the attestation-event audit trail described above, which is never linked to your wallet, payment, or order records)

Third-Party Services

BAGHOLDER integrates with third-party services that process your data under their own privacy policies:

Payment provider

Our licensed payment provider processes your fiat payment and delivers a USD stablecoin (currently USDC) directly to your wallet, and performs any identity checks under its own privacy policy. You can pay as a guest with Apple Pay, Google Pay, card, and more depending on your provider — no account needed to get started. On every buy we pass your wallet address, the amount, and the destination chain to the provider; the provider collects any payment or identity details directly from you on its own payment screen. We receive only confirmation of successful delivery of the stablecoin.

Tax reporting: BAGHOLDER is a non-custodial software tool and does not prepare or file tax forms on your behalf. Buying cryptocurrency through our integrated onramp is generally not itself a taxable event under current US tax law, but each subsequent token swap or sale can be a taxable event for which you are responsible. Any tax forms you receive related to your crypto activity will come from a third party (such as an exchange where you eventually sell), not from BAGHOLDER. Use the Activity CSV export in the app's Settings to keep a copy of your purchase history for your own records. Tax rules vary by jurisdiction and change over time — always consult a qualified tax advisor for your specific situation.

Privy (wallet creation)

Privy creates and manages your non-custodial embedded wallet using advanced cryptographic techniques. Privy may collect your email address or social login credentials for authentication. We do not receive or store these credentials.
See: privy.io/privacy

Firebase Crashlytics (crash reporting)

We use Google's Firebase Crashlytics for crash reporting. When the app crashes, Crashlytics sends Google a crash report that includes a Crashlytics Installation UUID (an anonymous identifier Google generates per app install — not linked to any account or wallet on our side), your IP address (used by Google for geographic crash distribution and discarded afterward), the stack trace and exception details, device model, and OS version. We strip wallet addresses and Solana addresses from error messages before sending. Crash reports do NOT contain your name, email, phone, or wallet address.
See: firebase.google.com/support/privacy

Blockchain infrastructure providers (RPC)

Third-party providers relay blockchain data between your wallet and the network. They may see your wallet address in transaction requests. No personal data is shared beyond the wallet address.

Jupiter (Solana DEX aggregator)

For purchases on Solana, our server sends your swap parameters (input token, output token, amount, your wallet address) to Jupiter's public aggregator API so it can return a routed swap transaction your wallet then signs. Jupiter sees only the wallet address and swap parameters.
See: jup.ag/legal/terms-of-use

CoinGecko (market data)

We fetch public cryptocurrency market data from CoinGecko. No user data is shared with CoinGecko.

DefiLlama (near-live prices)

We fetch public near-live token prices from DefiLlama, keyed only by the token identifier. No user data is shared with DefiLlama.


Data Retention

  • Local data: stored until you delete your account or uninstall the app.
  • Server payment records, gas funding records, and fee sweep records: retained for 7 years for tax and accounting purposes.
  • Payment profiles: retained while your wallet is active.
  • Anonymized usage events: retained for 1 year, then automatically deleted.
  • Shared bag configurations: automatically deleted after 1 year of inactivity.
  • Blocked-attempt audit log: retained on your device for 365 days, then automatically pruned.

Your Rights

You have the right to:

  • Export your data at any time from Settings.
  • Delete all local data by using the Delete Account feature in Settings. Upon deletion, all local data is permanently erased and your wallet session is disconnected.
  • View your transaction history at any time within the app.
  • Request deletion of server-stored data by contacting us at [email protected].

California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know what personal information we collect and how it is used.
  • Right to delete your personal information.
  • Right to opt out of the sale of your personal information. We do NOT sell your personal information.
  • Right to non-discrimination for exercising your rights.
  • Right to correct inaccurate personal information.
  • Right to limit use of sensitive personal information. We do not collect sensitive personal information.

To exercise these rights, contact us at [email protected].


Geographic Availability

BAGHOLDER is available in 43 U.S. states. BAGHOLDER is not available in New York, Connecticut, Louisiana, Vermont, Minnesota, New Mexico, the District of Columbia, or Pennsylvania.


Children's Privacy

BAGHOLDER is not intended for anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information.


Security

We use industry-standard security measures to protect your data, including:

  • Encrypted local storage (iOS Keychain / Android Keystore)
  • HTTPS for all server communication
  • Advanced cryptographic key management via our wallet provider
  • API keys stored server-side only, never on your device

No system is 100% secure. You are responsible for securing access to your device.


Changes to This Policy

We may update this privacy policy from time to time. The current version is always available in the app under Settings. If we make material changes, you will be asked to review and accept the updated policy.


Contact Us

If you have questions about this privacy policy, contact us at:
[email protected]
getbagholder.com

Home Privacy Policy Terms of Service How BAGHOLDER Works Support

© 2026 BAGHOLDER. All rights reserved.