ResourcesLegalPrivacy Policy
Legal

Privacy Policy

How Dotva collects, uses, and protects your personal information, in compliance with New York State law.

Privacy Policy

Effective Date: June 18, 2026
Last Updated: June 18, 2026

Dotva Inc. ("Dotva", "we", "us", "our") is a company incorporated in the State of New York, United States. We are committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the Dotva platform, and explains your rights under applicable law.


1. Information We Collect

1.1 Account Information

  • Full name and email address
  • Password (stored as a bcrypt hash — never in plaintext)
  • Workspace name and slug

1.2 Identity Information

  • Cardholder names associated with virtual cards (first name and last name)
  • Billing address provided for card issuance

1.3 Financial Information

  • USDT wallet addresses used for deposits
  • Transaction amounts, merchant names, and transaction metadata
  • Ledger entries and wallet balance history
  • Subscription and fee records

1.4 Technical Information

  • IP address at login and during sensitive operations
  • Browser user agent
  • Session timestamps and duration
  • API request logs (used for rate limiting and security monitoring)

1.5 Communications

  • Support ticket messages and email correspondence with our team

We do not collect Social Security Numbers, government-issued ID numbers, or biometric data unless specifically required for a compliance verification process, in which case we will notify you separately.


2. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Dotva platform and services;
  • Process virtual card issuance and transactions;
  • Verify identity for account security and step-up authentication;
  • Detect, investigate, and prevent fraud, abuse, and suspicious activity;
  • Comply with legal, regulatory, and card network obligations (including AML, OFAC, BSA, and GLBA);
  • Send service notifications, security alerts, and billing communications;
  • Improve platform reliability, performance, and security.

We do not use your information for advertising or sell it to third parties.


3. Data Storage and Security

3.1 Encryption at Rest

All sensitive data is encrypted at rest using AES-256. Virtual card secrets (PAN, CVV, expiry) are protected using Envelope Encryption (KEK + DEK architecture) and are never stored in plaintext.

3.2 Encryption in Transit

All data in transit is protected by TLS 1.3. Connections using older or deprecated protocols are rejected.

3.3 Access Controls

  • Internal access to production data is role-restricted and audit-logged.
  • Administrative portal access is restricted to authorized personnel via IP allowlist.
  • Step-up authentication is required for all sensitive internal operations.

3.4 Cybersecurity Program

In compliance with the New York SHIELD Act (NY General Business Law § 899-bb), Dotva maintains a written cybersecurity program that includes reasonable administrative, technical, and physical safeguards appropriate to the size and complexity of our operations and the sensitivity of the personal information we hold.

3.5 Data Location

Your data is stored on servers located in the United States. We do not transfer personal data outside the United States without ensuring appropriate contractual or regulatory safeguards are in place.


4. Data Breach Notification

In the event of a security breach affecting "private information" as defined under the New York SHIELD Act, Dotva will:

  • Notify affected New York residents in the most expedient time possible and without unreasonable delay;
  • Notify the New York Attorney General, the Department of State, and the Division of State Police as required by law;
  • Provide notification to other affected users in accordance with the laws of their respective states or jurisdictions.

Notification will be delivered by email to the address on file, or by substitute notice if direct notification is not reasonably feasible.


5. Data Sharing

We do not sell your personal information. We share data only in the following circumstances:

RecipientPurpose
Card IssuerRequired to issue, manage, and process virtual card transactions
Payment Network (Visa)Card authorization and settlement
USDT Processing PartnerBlockchain deposit confirmation and USDT-to-USD conversion
Legal and regulatory authoritiesWhen required by applicable law, court order, or lawful government request

All third-party service providers are contractually required to handle personal information in a manner consistent with this policy.


6. Data Retention

Data TypeRetention Period
Account informationDuration of account + 7 years after closure
Transaction and financial records7 years (required by financial regulations including BSA)
Audit and security logs5 years
API request logs90 days
Support tickets3 years

We may be required to retain certain financial records beyond these periods pursuant to applicable law. Retention obligations will take precedence over any deletion requests.


7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Correction — request correction of inaccurate or incomplete information;
  • Deletion — request deletion of your account and associated personal data, subject to legal retention obligations;
  • Portability — receive your data in a structured, machine-readable format;
  • Objection — object to certain processing activities.

New York residents are entitled to the protections afforded by the NY SHIELD Act, including the right to be notified of data breaches affecting their private information.

To exercise any of these rights, contact us at support@dotva.io. We will respond within 30 days of receiving a verifiable request.


8. Cookies and Local Storage

Dotva uses minimal browser storage:

  • dotva_locale — stores your language preference (cookie, 1 year)
  • Authentication session token — stored in localStorage, not a cookie, expires with your session

We do not use third-party tracking cookies, advertising pixels, or behavioral analytics tools.


9. Children's Privacy

Dotva is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected information from a minor, we will delete it promptly.


10. California and Other State Residents

While Dotva is incorporated in New York, we respect the privacy rights of residents of other U.S. states. If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). Please contact us at support@dotva.io to submit a request.


11. Changes to This Policy

We will notify you of material changes to this Privacy Policy via email or in-app notice at least 14 days before the change takes effect. The "Last Updated" date at the top of this document will always reflect the most recent revision.


12. Contact

For privacy-related inquiries or to exercise your rights:

Email: support@dotva.io
Data Controller: Dotva Inc., New York, NY, United States