Privacy Policy
This policy explains what happens to your data when you use ord20.io or the ORD20 Wallet apps. The short version: there is no account, your keys never leave your device, and we do not log the IP addresses of requests to our API.
Last updated: 29 September 2026Who is responsible
The controller for the processing described here is Mister HHC B.V., Van IJsendijkstraat 203, 1442 CL Purmerend, Noord-Holland, the Netherlands, registered with the Dutch Chamber of Commerce under number 89626222, VAT number NL896262222B01. The company trades under the names ORDnet and ORD20 and is the publisher of the apps in the App Store and on Google Play.
You can reach us at hello@ord20.io or on +31 20 210 1940. Full company details are on the legal page.
What this policy covers
This policy covers the website at ord20.io, the read API at api.ord20.io, and ORD20 Wallet for iOS, ORD20 Wallet for Android and the ORD20 Wallet browser extension for Chrome. It does not cover the Bitcoin SV network itself, which nobody owns or operates.
What we process, and what we do not
Data on the blockchain
A transaction you sign and broadcast becomes part of the Bitcoin SV blockchain. That is the point of it, and it has a consequence worth stating plainly: it is public and permanent. Anyone can read it, it cannot be edited, and it cannot be deleted — not by us, not by you, not by anyone. Addresses are pseudonymous rather than anonymous: they are not your name, but anything you link to an address stays linked in public.
Our indexer reads that public data. It does not add anything about you to it, because it has nothing about you to add.
Why we may process personal data
Where we do process personal data — in practice, only email correspondence — the legal basis under the GDPR is the performance of a contract or the steps before it (Article 6(1)(b)) when you ask us about the apps, and our legitimate interest in answering questions and keeping our services secure (Article 6(1)(f)).
Who else sees it
We do not sell personal data and we do not share it with third parties for their own purposes. The website and the API run on servers we operate ourselves. Email is handled by our mail provider, acting on our instructions. Apple and Google operate the stores you download the apps from and handle that relationship under their own privacy policies, which we do not control.
How long we keep things
There are no request logs to keep, because IP logging is off. Email correspondence is kept for as long as it is useful to answer you and to keep a record of what was asked, and is removed when it no longer serves that purpose or when you ask us to remove it.
Your rights
Under the GDPR you can ask for access to your personal data, correction, erasure, restriction of processing, portability, and you can object to processing. Because we hold so little, most of these will be answered quickly — often with the observation that we have nothing on file.
Write to hello@ord20.io. We answer without undue delay and in any case within one month, as Article 12(3) of the GDPR requires. The data deletion page explains exactly what can and cannot be deleted.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
Children
The apps are financial tools and are not directed at children. We do not knowingly process personal data of children.
Security
Traffic to ord20.io and api.ord20.io is encrypted in transit. Keys stay on your device, protected by the security features of your operating system or browser. That design means there is no central store of user funds or credentials to breach — and also that the safety of your recovery phrase is entirely in your hands. The risks page is blunt about what that means.
Changes
If this policy changes, the date at the top changes with it and the new version replaces this one on this page. Material changes will also be reflected in the app store listings.