Loading

Loading

Privacy
Policy

Last Updated: 20 June 2026Legal Entity: BayLeaf OÜTrading As: Tomorrow's Wallet
Registered Address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Republic of Estonia
Contact: hello@tomorrowswallet.com

1. Introduction

BayLeaf OÜ, a private limited company incorporated in the Republic of Estonia, operating under the trading name Tomorrow's Wallet ("we", "us", or "our"), is committed to protecting your personal information and being transparent about how we collect, use, and share it.

This Privacy Policy applies to the Tomorrow's Wallet platform, website at tomorrowswallet.com, mobile application, and all related services (collectively, the "Service"). As an Estonian-registered entity, BayLeaf OÜ is subject to the General Data Protection Regulation (EU) 2016/679 (GDPR) as the primary applicable data protection law.

Where our users are residents of India, we additionally comply with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable provisions of the Information Technology Act, 2000. This policy must be read together with our Cookie Policy for full information about tracking technologies.

2. Data Controller

The data controller for all personal information processed through the Service is:

BayLeaf OÜ (trading as Tomorrow's Wallet)
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Republic of Estonia
General enquiries: hello@tomorrowswallet.com

For users in India, BayLeaf OÜ also acts as the Data Fiduciary under the DPDPA 2023. The contact addresses above are the primary point of contact for all Indian data subject requests.

3. Information We Collect

We apply data minimisation (GDPR Article 5(1)(c)): we collect only what is strictly necessary for each stated purpose.

3.1 Information You Provide Directly

  • Account registration data: Full name, email address, mobile number, and date of birth.
  • KYC/AML identity documents: Government-issued identity documents (PAN card; Aadhaar Virtual ID or masked reference only. We do not collect or store raw Aadhaar numbers or biometric data). Processed exclusively through our authorised KYC partner, Etherfuse, under a Data Processing Agreement.
  • Communication data: Support messages, feedback, and correspondence you send us.
  • Yield preferences: Yield allocation settings you configure within the Service.

3.2 Information Collected Automatically

  • Device and technical data: IP address, device identifiers, operating system, browser type, and app version.
  • Usage data: Pages visited, features used, interaction timestamps, session duration, and navigation patterns.
  • Transaction data: Records of yield accruals, payment events, and balance changes.
  • Analytics data: Aggregate behavioural patterns, collected with your consent via Google Analytics. See Section 10 and our Cookie Policy.

3.3 Information from Third Parties

  • Email signal data: With your explicit, separately obtained consent, limited email OAuth metadata is processed to identify billing and subscription signals. We request the minimum OAuth scope necessary. We do not read, store, or index email body content. You can revoke access at any time via your email provider's account settings or our in-app settings.
  • Screen Time / Device Activity data: With your explicit permission, app-usage duration data is accessed locally on supported devices. Processed on-device where possible; not transmitted to our servers unless strictly required for rule execution. Never used for advertising or profiling.
  • Blockchain and on-chain data: Public transaction data associated with connected wallets on the blockchains we support. This data is inherently public and is not subject to erasure rights under applicable law.
  • KYC verification data: Identity verification outcomes and risk scores from Etherfuse under our AML obligations.

4. Legal Basis for Processing (GDPR)

Every processing activity has a documented lawful basis under GDPR Article 6. Where we rely on Legitimate Interests (Art. 6(1)(f)), we have conducted a three-part Legitimate Interests Assessment (LIA).

Processing ActivityLegal BasisNotes
Account creation and service deliveryContract — Art. 6(1)(b)Necessary to provide the Service
KYC/AML identity verificationLegal Obligation — Art. 6(1)(c)AMLD6, Estonian and Indian AML law
Yield executionContract — Art. 6(1)(b)Core service functionality
Email signal / OAuth metadataConsent — Art. 6(1)(a)Granular, separately obtained, revocable
Screen Time / Device Activity dataConsent — Art. 6(1)(a)On-device preferred; separate consent flow
Analytics (Google Analytics)Consent — Art. 6(1)(a)Opt-in via Cookie Preference Centre only
Marketing communicationsConsent — Art. 6(1)(a)Opt-in; revocable via unsubscribe
Fraud detection and securityLegitimate Interests — Art. 6(1)(f)LIA on file; protects users and platform
Legal claimsLegitimate Interests — Art. 6(1)(f)LIA on file; proportionate retention

We do not sell, rent, or trade your personal data to any third party for commercial gain. We do not use your financial data, email signals, or usage patterns for targeted advertising.

5. How We Use Your Information

We process your personal data only for the following purposes, each tied to a legal basis in Section 4:

  • Provide, operate, and maintain the Service and your account
  • Execute your yield allocation instructions
  • Complete mandatory KYC/AML identity verification as required by law
  • Detect, investigate, and prevent fraud, abuse, and security threats
  • Send transactional and service-critical notifications (always permitted)
  • Send marketing communications and product updates — only with your separate, explicit consent
  • Comply with legal obligations under Estonian, EU, Indian, and other applicable laws
  • Analyse anonymised, aggregated data to improve product quality
  • Establish, exercise, or defend legal claims

6. Web3 & Blockchain Data

  • Public ledger permanence: All on-chain transactions executed through or connected to the Service are recorded permanently on public blockchains. This data is outside our control and cannot be deleted, rectified, or restricted. The right to erasure (GDPR Art. 17) does not apply to public on-chain records.
  • Wallet address association: When you connect a non-custodial wallet, your public address is visible on-chain. We associate it with your account for service functionality only.
  • No private key storage: We never store, access, request, or transmit your private keys, seed phrases, or recovery mnemonics. Any communication requesting this information is fraudulent.
  • Etherfuse / LiFi infrastructure: Yield execution uses Etherfuse / Stablebond infrastructure; cross-chain routing uses LiFi Protocol. Both process transaction data as sub-processors under Data Processing Agreements. See Section 7 for transfer details.

Because blockchain data is public and permanent, we recommend you fully understand the irreversible nature of on-chain activity before connecting a wallet or executing transactions. Our Terms of Service detail these risks.

7. How We Share Your Information

We share personal data only where necessary. All processors are bound by GDPR Article 28 Data Processing Agreements. Non-EU/EEA transfers rely on Standard Contractual Clauses (SCCs) supported by documented Transfer Impact Assessments (TIAs).

RecipientProcessorPurposeBasisLocation / Safeguard
KYC / AMLEtherfuseIdentity verification and KYC screeningLegal ObligationUS — SCC + TIA
Yield InfrastructureEtherfuse / StablebondYield instrument executionContractUS — SCC + TIA
Cross-chain RoutingLiFi ProtocolCross-chain liquidity routingContractEU — SCCs where applicable
Wallet InfrastructureTurnkeyNon-custodial wallet provisioningContractUS — SCC + TIA
Cloud / HostingAmazon Web Services (AWS)Hosting, storage, computeContractEU-West preferred; SCC for non-EU
AnalyticsGoogle AnalyticsProduct analytics (opt-in only)ConsentUS — SCC + TIA
Account Aggregator (India)Licensed RBI AA entitiesFinancial data retrievalYour consentIndia — DPDPA compliant
Regulatory AuthoritiesGovernment agenciesLawful compliance requestsLegal ObligationJurisdiction-specific

8. Data Retention

We retain personal data only as long as necessary for its stated purpose or as required by law (GDPR Art. 5(1)(e)). All extended retention has a documented legal basis.

Data CategoryRetention PeriodLegal Basis
Account registration dataActive + 30 days post-deletionContract; deleted on account closure
Financial / transaction records7 yearsEstonian Accounting Act; Indian PMLA 2002
KYC / AML identity documents5 years post-relationship endAMLD6; Estonian AML Act §44
Analytics / usage data (Google Analytics)26 months (default)Consent; anonymised thereafter
Device / technical log data90 daysSecurity and fraud detection (LIA)
Email signal / OAuth metadataConsent active + 30 days after revocationConsent
Screen Time / Device Activity dataOn-device only; not stored server-side except during active rule executionConsent; minimised
Support communications3 yearsLegitimate interest (dispute resolution)
Marketing consent recordsUntil withdrawn + 3 yearsLegal evidence of consent (GDPR Art. 7)
Blockchain / on-chain dataPermanent (immutable)Inherent blockchain architecture

On account deletion, personal data is anonymised or securely deleted within 30 days, except where a longer period is legally mandated as above.

9. Analytics & Cookies

We use cookies and similar technologies to operate and improve the Service. In compliance with the ePrivacy Directive (2002/58/EC) and CJEU rulings (Planet49, Orange Romania), we obtain your active, informed, prior consent before setting any non-essential cookies or activating non-essential tracking.

  • Strictly necessary cookies: Required for authentication and session management. No consent required; cannot be disabled without breaking core Service functionality.
  • Analytics cookies (Google Analytics): Opt-in only. Activated only after you click "Accept" in our Cookie Preference Centre. IP anonymisation is enabled. Google Analytics operates under SCCs with a completed TIA.
  • Functional cookies: Preferences such as language and display theme. Opt-in.
  • Marketing / advertising cookies: Not used. We do not run advertising cookie networks.

You can manage, update, or withdraw cookie consent at any time via our Cookie Preference Centre, accessible from the footer of every page. Withdrawing consent stops analytics immediately and does not affect core Service functionality.

For a complete list of every cookie type, its exact lifespan, and the processor involved, see our standalone Cookie Policy at tomorrowswallet.com/cookiepolicy.

10. Data Security

We implement appropriate technical and organisational measures (GDPR Article 32) proportionate to the risk, including:

  • Encryption: AES-256 at rest; TLS 1.3 in transit for all data communications
  • Access control: Role-based access controls (RBAC) with least-privilege principles and periodic access reviews
  • Authentication: Multi-factor authentication (MFA) enforced on all internal systems
  • Security testing: Regular penetration testing and vulnerability assessments by qualified third parties
  • Key management: Non-custodial wallet key management via Turnkey infrastructure — we hold no user private keys
  • Data isolation: Logical separation of development, staging, and production environments
  • Incident response: Documented breach response and escalation procedures

Breach Notification: In the event of a personal data breach, we will notify the Estonian Data Protection Inspectorate (AKI) within 72 hours of becoming aware (GDPR Art. 33). We will notify you directly without undue delay where the breach is likely to result in high risk to your rights and freedoms (GDPR Art. 34).

11. Children's Privacy

The Service is intended for users aged 16 and over. We do not knowingly collect personal data from individuals under 16. If you believe a minor under 16 has registered or provided personal data through the Service, please contact us immediately at privacy@tomorrowswallet.in. We will promptly investigate and delete any data collected from a minor.

12. International Data Transfers

BayLeaf OÜ is an Estonian entity and processes data primarily within the EU/EEA. Where sub-processors operate outside the EEA (principally the United States and India), we rely on Standard Contractual Clauses (SCCs) as our primary transfer mechanism, supplemented by documented Transfer Impact Assessments (TIAs) for each non-EEA transfer, in accordance with the principles established in Schrems II (C-311/18).

13. Changes to This Policy

We distinguish between two categories of update:

  • Material changes (new processing activities, new third-party processors, change in legal basis): Notified by email and in-app notification at least 14 days before taking effect. Where a change requires fresh consent, we will obtain it through a separate consent flow, continued use alone does not constitute acceptance of new processing.
  • Non-material changes (clarity improvements, corrected contact details, typographical fixes): Updated "Last Updated" date only. No advance notice required.

The current version of this policy is always authoritative at tomorrowswallet.com/privacy.

14. Contact & Grievances

We acknowledge all privacy requests within 5 business days and resolve within 30 days.

General Privacy Enquiries
hello@tomorrowswallet.com