Privacy and Customer Data in Wallets and Digital Asset Applications
A customer contacts your support team about a failed transfer and includes a wallet address, an email address, and a screenshot. Your application may require no registration, yet the support record now connects a person with financial activity. If your website says the product collects no personal information, that support process belongs in the analysis before the claim appears.
For businesses building wallets and digital asset applications, privacy obligations depend on the information processed and the service provided. Customer control of signing credentials answers a question about authority over assets. Your business also needs to account for the information collected when customers connect, request balances, contact support, or use an integrated provider.
Identify the Information Your Business Connects
Under Texas Business and Commerce Code § 541.001, personal data includes information linked or reasonably linkable to an identifiable individual. The definition includes certain data used with additional identifying information and excludes deidentified data and publicly available information. Applying those distinctions requires examining the records your business maintains.
A public transaction record and your confidential record identifying its customer warrant separate treatment. Public access to a transaction doesn’t establish that the customer’s email address, support history, or association with that transaction is publicly available. You should identify which connections your business records, why it records them, and who receives them.
An address also doesn’t become anonymous simply because a database omits the customer’s name. If you describe information as deidentified, § 541.106 requires a covered controller to take reasonable measures against association with an individual, publicly commit against reidentification, and impose contractual obligations on recipients. Before making that claim, you should examine the information that can be combined with the retained record.
Determine Which Privacy Laws Apply
The Texas Data Privacy and Security Act has a defined scope. Under § 541.002, it applies to persons conducting business in Texas or producing products or services consumed by Texas residents, processing or selling personal data, and falling outside the federal Small Business Administration’s definition of a small business, subject to statutory exemptions. Those exemptions include financial institutions or data subject to Title V of the federal financial privacy law, 15 U.S.C. § 6801 and following.
A small business classification leaves a specific obligation in place. Section 541.107 requires prior consumer consent before a qualifying small business sells sensitive personal data. The classification and the proposed disclosure both require analysis. The SBA’s size standards vary by industry and use employee or receipt measures, with affiliate rules also relevant.
Texas protects residents acting in an individual or household context, excluding commercial and employment contexts under § 541.001. A product serving businesses and individuals therefore calls for distinctions among its users. A business customer’s employee records may require analysis under other applicable laws even when that Texas definition excludes the individual’s commercial activity.
Customer location also affects the assessment. Under California Civil Code § 1798.140(d)(1), a business meeting the provision’s profit, collection, control, and California business conditions must also meet at least one threshold. Those thresholds are annual gross revenue exceeding $26,625,000 in the preceding calendar year, annually buying, selling, or sharing personal information of 100,000 or more California consumers or households, or deriving at least 50% of annual revenue from selling or sharing consumers’ personal information. The revenue amount reflects the adjustment effective January 1, 2025. Other provisions cover certain affiliated entities, joint ventures, and voluntary certifications, so these thresholds are only part of the applicability analysis.
Account for Providers That Receive Customer Information
A wallet can disclose information while retrieving a balance. Ethereum’s privacy documentation explains that standard requests to a node provider, a service that answers queries about blockchain data, can expose the requester’s IP address and the addresses queried. Whether a particular implementation discloses or retains those details depends on its design and the provider’s practices.
You should examine each provider’s role in the customer interaction. An identity verification company may receive identification documents, a support platform may store screenshots, and an analytics service may receive events associated with wallet addresses. The relevant records include information sent directly from the customer’s device, even if your company never stores a copy.
Contracts should reflect what each recipient does with the information. Under § 541.104, the distinction between a controller, which determines processing purposes and means, and a processor acting on its behalf depends on the facts. A vendor using information for independent purposes calls for a different analysis from one following your instructions.
For a covered controller and processor relationship, that section requires a contract addressing instructions, purposes, data types, duration, and the parties’ obligations. Required provisions include confidentiality, deletion or return after services end subject to legal retention requirements, compliance information, assessments, and subcontractor obligations. The statute permits a qualifying independent assessment as an alternative to assessments conducted by the controller. You should compare these requirements with the agreement for the particular service and account your business uses.
Draft the Policy Around Actual Collection and Use
A covered controller must provide the privacy notice described in § 541.102. It must identify the categories of personal data processed, the purposes, applicable disclosures to third parties, and how consumers exercise and appeal their rights. The content should correspond to the product’s collection and sharing practices.
For a wallet, that can mean distinguishing information needed to supply a requested function from information collected for diagnostics or advertising. A statement that your business collects “technical information” may obscure the connection between an address queried, an IP address, and a support account. You should describe those categories and uses in language a customer can understand without knowing how the application communicates with providers.
The business should also decide whether each collection serves a defensible purpose. Section 541.101 requires covered controllers to limit collection to information adequate, relevant, and reasonably necessary for the disclosed purposes. Except as otherwise provided by the chapter, processing for a purpose neither reasonably necessary to nor compatible with the disclosed purpose requires consent.
Consent has a defined meaning. Section 541.001 excludes acceptance of broad terms containing data processing descriptions alongside unrelated information. The definition also excludes actions such as closing content and agreement obtained through dark patterns, meaning interfaces that substantially undermine user autonomy or choice. Where a separate privacy consent is required, you should implement a specific affirmative choice and preserve its record. A wallet connection or agreement to customer terms cannot be treated as blanket permission for every subsequent use.
Texas classifies precise geolocation and biometric data used for unique identification as sensitive data under § 541.001. Subject to statutory exceptions, § 541.101(b)(4) requires consent before processing sensitive data, with a separate requirement for known children’s data tied to the Children’s Online Privacy Protection Act. A location or identity feature should be evaluated against those rules before collection begins.
Evaluate Analytics and Advertising Before Adding Them
An analytics integration can change the data recipients and purposes after your original privacy policy is drafted. You should establish whether the provider uses wallet activity only to report on your application or also combines it with information from other customers and services. The answer affects the policy, contract, and available privacy choices.
“No cash payment” doesn’t resolve whether a disclosure is a sale. The Texas definition includes monetary or other valuable consideration and contains exclusions for specified disclosures, including qualifying processing on a controller’s behalf. The exclusions also cover disclosures to a third party for a product or service the consumer requested. Each disclosure should be assessed against the applicable exclusion, including any additional use by the recipient. Exclusion from the sale definition leaves other applicable privacy duties for separate analysis.
If a covered controller sells sensitive or biometric personal data, § 541.102(b)–(c) requires the corresponding statutory sale notice in the same location and manner as the privacy notice. Posting that notice supplements any applicable consent requirement.
Covered consumers can opt out of processing for targeted advertising, data sales, and profiling supporting decisions with legal or similarly significant effects under § 541.051. Under § 541.055, consumers can also designate authorized agents through qualifying technology, subject to the section’s verification requirements and exceptions. Your procedures should account for applicable requests received through those mechanisms.
Some processing also requires a documented assessment. Section 541.105 covers targeted advertising, data sales, sensitive data, and other specified activities presenting risks to consumers. The assessment weighs benefits against risks and considers safeguards, customer expectations, and the processing context. Adding a feature that uses customer information can therefore require decisions beyond revising the policy.
Handle Requests Across Company and Provider Records
A privacy request can involve information spread across account records, support systems, and providers. Under § 541.052, a covered controller must respond without undue delay and within 45 days, with one additional 45 day extension when reasonably necessary and accompanied by timely notice and reasons. A refusal requires an explanation and appeal instructions.
You should assign responsibility for receiving requests, authenticating the requester, and obtaining any necessary provider assistance. Knowing a public wallet address alone doesn’t establish that someone is entitled to the associated support records. The verification method should account for the information requested and the risk of disclosing it to another person.
Deletion requires a distinction between company records and information recorded on a public network. Closing an account can remove an internal association while leaving the underlying transaction history visible. Your response should describe the records addressed and any applicable retention basis, without promising that your business can erase copies beyond its control.
Legal retention requirements and other statutory exceptions require separate consideration. Section 541.201 preserves specified activities, including compliance with law, handling legal claims, and responding to fraud and security incidents. You should identify the applicable basis for retaining particular records instead of relying on a general statement that all wallet information must be kept indefinitely.
Support Privacy Promises With Operating Procedures
Your retention schedule should identify the records kept, their purpose, and when they are deleted. The Federal Trade Commission’s business guidance recommends retaining sensitive information only while there is a business need and documenting retention, protection, and disposal. For a wallet business, support attachments and identity verification records warrant their own decisions alongside transaction records.
Security obligations also extend beyond statements in a policy. Section 541.101 requires covered controllers to maintain reasonable administrative, technical, and physical safeguards appropriate to the information. Provider agreements should address incident notification and cooperation, and your business should establish who evaluates an incident and coordinates any required notices.
The preparation for drafting should produce a record of what information each feature collects, where it goes, and what your business promises about it. From that record, counsel can draft the privacy policy, consent language, and provider terms while identifying procedures the business must implement. When a feature or provider changes, the business should update that record and assess the resulting obligations before offering the change to customers.
Related practice area: Digital Assets
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry