Privacy Policy
Last Updated: July 28, 2026
1. Introduction
This Privacy Policy explains how the Meridian Association, a blockchain-native Swiss Association created through smart contract multi-signature transaction with cryptographic birth certificate at smart contract address: 0x9F586C59EF32456Af313780C81380B9fC698f18F, collects, uses, and protects your information when you use our x402 payment verification and settlement services. We are committed to transparency about our data practices and protecting your privacy in accordance with Swiss data protection law.
2. Information We Collect
Authentication Data
- Ethereum wallet addresses (for SIWE authentication)
- Session IDs and authentication tokens
- Chain IDs for blockchain network identification
- Organization associations and memberships
Payment and Transaction Data
- Payment signatures and cryptographic proofs
- Transaction amounts, timestamps, and blockchain metadata
- Payment verification results and settlement status
- Blockchain transaction hashes and network information
- Asset types and contract addresses (USDC, etc.)
API and Usage Data
- API key usage and request logs
- Service endpoint interactions and response times
- Error logs and debugging information
- Organization and project configuration data
3. How We Use Your Information
We use your information to:
- Service Operation: Provide x402 payment verification and settlement services
- Authentication: Verify wallet ownership through SIWE (Sign-In with Ethereum)
- Transaction Processing: Verify payment signatures and process blockchain settlements
- API Management: Generate, manage, and track API key usage for developers
- Security: Prevent fraud, abuse, and unauthorized access to our services
- Service Improvement: Analyze usage patterns to improve platform performance and reliability
- Legal Compliance: Meet regulatory requirements and respond to lawful requests
4. Cookies and Local Storage
We use cookies and browser storage (localStorage and sessionStorage) on this website. Everything that is not strictly necessary to deliver the service you requested is disabled until you give explicit, opt-in consent through our cookie banner. We do not use pre-ticked boxes, and refusing is as easy as accepting.
Strictly Necessary (no consent required)
These are required to operate the site and are exempt from consent under Art. 5(3) of the ePrivacy Directive. They cannot be switched off.
- Wallet connection state: Cookies and localStorage entries set by Wagmi and Reown AppKit / WalletConnect so your wallet stays connected across page loads
- Authentication session: A SIWE session token stored in localStorage after you sign in, used to authorise API requests
- Consent record: A first-party cookie recording your cookie choices and the time you made them, so we do not ask again on every visit
- Interface state: Theme preference and dashboard sidebar state
Analytics (opt-in only)
Off by default. Loaded only after you opt in, and used solely to understand aggregate usage of the site.
- Vercel Analytics: Aggregate page view and performance measurement. The script is not loaded at all unless you consent
- Reown AppKit telemetry: Aggregate measurement of wallet connection flows. Disabled at initialisation unless you consent
Cached Information
When you are signed in to the developer dashboard, we temporarily cache your own analytics and transaction data in sessionStorage for up to five minutes to avoid repeated requests. This cache stays on your device, is never transmitted to third parties, and is cleared automatically when you close the browser tab or sign out.
Managing and Withdrawing Consent
You can change or withdraw your consent at any time, and withdrawing is as easy as giving it. There is no penalty for refusing: the site works fully without optional cookies.
- Select Cookie Preferences in the footer of any page to reopen the banner and update your choices
- Withdrawing analytics consent takes effect immediately and reloads the page to unload any third-party telemetry
- You can also delete cookies and site data directly in your browser settings at any time
- Your consent record expires after six months, after which we will ask you again
5. Data Security
We implement appropriate security measures to protect your information:
- Cryptographic Security: All payment data uses blockchain-grade cryptographic signatures
- No Private Key Storage: We never store or have access to your private keys or seed phrases
- Hashed API Secrets: API secret keys are cryptographically hashed and never stored in plaintext
- Database Security: Encrypted data storage with access controls and authentication
- Network Security: HTTPS/TLS encryption for all data transmission
- Regular Audits: Ongoing security assessments and monitoring
6. Data Sharing
We do not sell, rent, or trade your personal information. Due to the nature of blockchain technology, some information is inherently public:
- Public Blockchain Data: Transaction hashes, amounts, and wallet addresses are publicly visible on blockchain networks
- Service Providers: Trusted third-party services that help us operate our platform (with appropriate data protection agreements)
- Legal Requirements: When required by law, court order, or regulatory authority
- Business Transfers: In the event of a merger, acquisition, or sale of assets (with user notification)
- Consent: Other parties only with your explicit consent
Important: Blockchain transactions are permanent and publicly visible. This is inherent to blockchain technology and not specific to our service.
7. Your Rights
You have the right to:
- Access: Request access to your personal information we have collected
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your information (subject to legal and technical limitations)
- Portability: Receive a copy of your information in a structured, machine-readable format
- Objection: Object to processing of your information for certain purposes
- Restriction: Request restriction of processing under certain circumstances
- Withdraw Consent: Withdraw any consent you have given at any time, without affecting the lawfulness of processing carried out beforehand. Cookie consent can be withdrawn via Cookie Preferences in the footer
Blockchain Limitations: Please note that blockchain transactions cannot be deleted or modified once confirmed. This includes transaction hashes, amounts, and wallet addresses that are permanently recorded on public blockchains.
8. Changes to Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes through the Service, email, or other reasonable means. Your continued use of the Service after such modifications constitutes acceptance of the updated Privacy Policy.
9. Legal Basis and Swiss Law
As a Swiss Association, we process your personal data in accordance with Swiss Federal Act on Data Protection (FADP) and applicable European data protection regulations where relevant.
Our legal basis for processing includes:
- Contractual Performance: Processing necessary to provide our x402 services
- Legitimate Interests: Service improvement, security, and fraud prevention
- Legal Compliance: Meeting Swiss regulatory and legal requirements
- Consent: Where you have provided explicit consent for specific processing, including storing or reading any non-essential information on your device
10. Contact
Meridian Association
A blockchain-native Swiss Association
Registered Address:
Weinberghöhe 31
CH-6340 Baar
Switzerland
Smart Contract Address: 0x9F586C59EF32456Af313780C81380B9fC698f18F
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us through our support channels. As a Swiss entity, we are committed to handling your requests in accordance with Swiss data protection law.
