Last updated: April 8, 2026
This Privacy Policy explains how Authbound ("we", "us") processes personal data for authbound.io, our business communications, and the Authbound Wallet closed alpha distributed through Google Play. We apply GDPR data-minimisation principles and process data only for legitimate, documented purposes.
The controller for the processing described here is Authbound, Finnish Business ID 3413139-1, Salomaantie 48 I 23, 37630 Valkeakoski, Finland. Privacy questions can be sent to [email protected].
This policy applies to:
Credentials and wallet material are designed to remain primarily under your control on your device. Some flows require data to be sent to issuers, verifiers, or other parties you intentionally interact with. Those parties act under their own notices and agreements.
The Authbound Age Gate app asks a shopper to prove they are over 18 with an EU Digital Identity Wallet before a merchant's storefront can be used. It is deliberately built to hold as little data as possible.
From the merchant.The app requests no Shopify access scopes and reads nothing from the Shopify Admin API. It stores only the store's domain and the authentication session Shopify issues at install, which is what keeps the merchant signed in to the app. That record is deleted when the app is uninstalled, and on receipt of Shopify's shop-redaction request.
From the shopper.The app asks the shopper's wallet for a single attribute: whether the holder is over 18. The wallet returns a yes or no. Name, date of birth, document number, and every other attribute stay in the wallet and are never sent to the merchant or to us. The answer itself is not stored. Instead, a signed token that proves only "this browser passed the check on this store" is placed in a cookie in the shopper's browser, so they are not asked again for a period the merchant sets. The token carries no identifying information and expires on its own.
The wallet exchange is carried out by Authbound's verification service, which creates a short-lived verification session for the duration of the check. IP addresses are processed transiently, and not written to storage, to rate-limit abuse of the verification endpoints.
Merchants remain responsible for their own privacy notice and for deciding whether an age check is required for their goods.
We share data only where necessary with infrastructure and service providers that help us operate the product, such as hosting, authentication, database, notification, and support tooling providers. We also share data with counterparties involved in wallet flows that you initiate, for example credential issuers, relying parties, or signature counterparts.
Some providers may process data outside the EEA. Where required, we use appropriate transfer safeguards such as the European Commission Standard Contractual Clauses and supplementary measures.
We keep personal data only as long as needed for the purposes above. Closed-alpha account data is retained while your account remains active and for a limited period afterwards for security, support, dispute handling, and legal compliance.
If you request account deletion through the app or through our public deletion page, we schedule deletion with a 30-day grace period. During that period we lock normal app access and allow cancellation. If you cancel during the grace period, normal access can be restored after sign-in. Once the grace period ends, the request enters processing and can no longer be canceled. We then delete or irreversibly remove your account profile, wallet activation state, linked devices, wallet-encryption data, signing documents and related storage objects, credits, user actions, identifiers, legal-acceptance event records, and other user-owned operational records used by the mobile wallet service.
Some narrowly scoped records may be retained for longer where necessary for security, fraud-prevention, legal defence, financial record-keeping, or compliance. These retained records are limited to what is reasonably necessary for those purposes.
We use layered technical and organisational safeguards, including access controls, encrypted transport, production access restrictions, and device-security checks for wallet flows. No service can guarantee absolute security, but we continuously improve our controls and monitor for misuse.
Depending on applicable law, you may have the right to access, correct, erase, restrict, object, or request portability of your data, and to withdraw consent where processing is consent-based.
To exercise your rights, contact [email protected]. You may also lodge a complaint with the Finnish Data Protection Ombudsman or your local supervisory authority.
We may update this policy when our services, practices, or legal requirements change. The "Last updated" date identifies the current version. The wallet closed alpha is also governed by the Authbound Wallet Alpha Terms. Website-only use remains subject to our Terms of Service.