App data safety summary

This page gives you a concise, structured summary of what data the mintus Wallet and the mintus Cashier apps collect, why they collect it, and whether it is shared. It is consistent with our Privacy Policy, which contains the legally authoritative details.

1. Data the app collects

Data typeCollected?PurposeRequired or optional
Name (display name)OptionalAccount function, personalisationOptional
Email addressYesAccount function, recovery, security notificationsRequired
User ID (mintus username)YesAccount functionRequired
Other user-generated contentOptionalVoucher artwork uploaded by Merchants, support messagesOptional
App interactionsYesAnalytics, product improvementRequired
Crash logsYesApp stability and bug-fixingRequired
DiagnosticsYesPerformance monitoringRequired
Device identifiersYesSecurity, fraud prevention, analyticsRequired
Push notification tokenOnly when grantedDeliver notifications about wallet activity, inbound messages, and account-security events; routed via Firebase Cloud Messaging (Android) / Apple Push Notification service (iOS)Optional — controlled by the system notification permission and revocable at any time in device settings
IP addressYesSecurity, fraud prevention, abuse detectionRequired
Approximate location (derived from IP)YesLocalisation, fraud preventionRequired
Precise locationNo
Photos / cameraOnly when invokedTo scan QR codes for voucher actions; processed on-device, not uploadedOptional
ContactsNo
Messages / SMSNo
Health / fitnessNo
Financial info (Merchants only)YesBilling for paid tiersRequired for paid tiers
Sensitive personal data (race, religion, sexual orientation, etc.)No

2. Data sharing

We share personal data only with service providers acting on our behalf (hosting, communications, security, analytics), with merchants you transact with (only the minimum needed to fulfil your request), and with regulators or law enforcement when legally compelled. We do not sell or rent personal data.

We do not share data with third-party advertising networks, and we do not embed any third-party ad SDK in the apps.

3. Encryption

All data transmitted between the apps and our servers is encrypted in transit using TLS. Personal data is encrypted at rest in our backend stores. Wallet signing keys are protected by hardware-backed secure storage on the device (iOS Secure Enclave / Android Keystore) and supplemented by threshold cryptography for recovery.

4. Your controls

5. Third-party services we use

We currently use the following processor categories. Specific vendor names change over time; the current list is available on request.

6. Children

The mintus apps are not directed to and are not intended for use by children under 13 (or the higher local minimum age). We do not knowingly collect data from such users.

7. Changes

This disclosure is updated whenever our app data practices change in a way that affects you, alongside the corresponding update of our Privacy Policy.

8. Contact

Email privacy@mintus.world.