Privacy Policy

Last updated: February 2026

Thingdom ("we", "us", "our") operates the Thingdom Wallet mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information.

1. Information We Collect

Information You Provide

  • Account information: Email address, display name, password
  • Profile data: Style preferences, brand preferences, clothing sizes, budget preferences
  • Shipping addresses: Name, street address, city, postcode, country
  • Payment information: Processed by Stripe; we do not store full card numbers
  • Photos: Images of items you photograph for product identification
  • Communications: Chat messages with the AI shopping agent

Information Collected Automatically

  • Device information: Device type, operating system, unique device identifiers
  • Usage data: Features used, pages viewed, actions taken
  • Transaction data: Purchase history, marketplace activity, wallet transactions
  • Push notification tokens: Apple Push Notification Service device tokens

Financial and Cryptocurrency Data

  • Wallet balances: Cash, USDC, and credit balances
  • Transaction records: Purchases, sales, transfers, and payment history
  • Agent wallet: USDC wallet address and spending rules

Vault encryption keys and recovery phrases are stored locally on your device in the iOS Keychain and are never transmitted to our servers.

2. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process marketplace transactions and payments
  • Power AI product identification and valuation
  • Personalise shopping recommendations via the AI agent
  • Send transaction confirmations and purchase approval requests
  • Detect and prevent fraud and unauthorised transactions
  • Comply with legal obligations and regulatory requirements

3. Third-Party Services

We share data with the following third-party services as necessary to operate the Service:

  • Stripe: Payment processing, seller payouts (Stripe Connect), and crypto onramp. Subject to Stripe's Privacy Policy.
  • MoonPay: USDC purchase and withdrawal services. Subject to MoonPay's Privacy Policy.
  • Apple: Push notifications via APNs, biometric authentication via LocalAuthentication framework.
  • Cloudflare: Hosting and content delivery. Subject to Cloudflare's Privacy Policy.

We do not sell your personal information to third parties.

4. Data Security

  • All data in transit is encrypted using TLS 1.2+
  • Vault data is encrypted with AES-256-GCM on your device
  • Sensitive credentials are stored in the iOS Keychain
  • Recovery phrases use BIP39 standard and never leave your device
  • Purchase approvals require PIN or biometric authentication
  • Session tokens expire and can be revoked remotely

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Transaction records may be retained longer to comply with financial regulations. When you delete your account, we permanently delete your personal data within 30 days, except where retention is required by law.

6. Your Rights

You have the right to:

  • Access: Request a copy of your personal data (available via Settings > Privacy > Export Data)
  • Correction: Update inaccurate information via your profile settings
  • Deletion: Delete your account and all associated data (Settings > Privacy > Delete Account)
  • Portability: Export your data in a machine-readable format
  • Withdraw consent: Disable push notifications, revoke camera/photo access via iOS Settings

7. Children's Privacy

The Service is not directed to individuals under 17. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.

8. Cryptocurrency Disclaimer

USDC balances within the Service are not deposits and are not insured by the FDIC, FSCS, or any government agency. Cryptocurrency values may fluctuate. We do not provide investment, financial, or tax advice.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. Continued use of the Service after changes constitutes acceptance.

10. Contact

For privacy inquiries: [email protected]

Pentatonic Ltd
London, United Kingdom