Privacy Policy
What we collect, why we collect it, and your rights.
Who we are
This policy explains how AINA Technologies LLC, a Colorado limited liability company of 1500 N Grant St, Ste 45878, Denver, CO 80203, United States (“AINA”, “we”, “us”), handles personal data when you use shft.money and the Shft Money app. AINA is the controller of the personal data described here: we decide why and how it is used. Contact us at privacy@shft.money.
Whop provides payments, balances, withdrawals, identity verification, conversions and cards. Whop is a separate, independent controller of the payment, identity and payout data it collects and uses for those services, and handles it under its own Privacy Policy. This policy covers what we do.
Whose data this covers
- Account holders: people who open a Shft Money account, and the team members they invite.
- Buyers and tippers: people who pay a business through a Shft Money page, link or checkout.
- Visitors to our website and to businesses' public pages.
- Anyone who contacts us.
What we collect
From account holders
- Login: your email address and password, whether you have confirmed your email, and when you agreed to our terms and which version. We store the password only as a one-way hash, so we can't read it.
- Business and page: business name, handle, country, bio, profile image link and social links. These appear on your public page.
- Team: the email address and role of each person you invite, who invited them and when.
- Products: names, descriptions, prices, thank-you notes and delivery links.
- Stream settings: whether alerts and messages are on, and how long alerts show.
- Money records: payments you receive, with fees, refunds and disputes; withdrawals, with amount, fee, status and the name of the payout method or institution (never account numbers); business payments, with the recipient's Whop business ID and name, the purpose, the reference and the amount; your card's status and last four digits.
- From Whop, about your account: your Whop account ID, whether you are verified and what Whop still needs, which features are active, your account's country, and your balance. We also check that the owner email Whop holds matches your login email.
- Messages you send us, for example to support.
From buyers and tippers
- The amount, the currency and what you paid for.
- Your name and message, if you add them to a tip. The business sees them, and they can appear on the business's live stream. Your name also appears on the business's public support wall unless you choose to hide it. Please don't include sensitive information in a message.
- Your email address, if you give it at checkout for a receipt or access.
- The status of your payment, Whop's reference numbers for it, and the payment notices Whop sends us. These notices can include details Whop holds about the payment, such as your name or email address. We don't receive full card numbers.
Whop collects your card and billing details directly in its checkout. You pay under Whop's Buyer Terms, and Whop handles those details under its own Privacy Policy.
From everyone who visits
- Technical data: when your browser connects, our hosting provider receives your IP address, browser details and the page you asked for, and keeps them in server logs. Our own logs leave out email addresses, messages and card or bank details.
- Abuse protection: to limit repeated sign-in, sign-up and other attempts, we use your IP address and, where relevant, the email address entered. We store these only as one-way hashes, with a count and a time window.
- Usage counts: we count events such as “page viewed” or “checkout opened” per day. The counts have no IP address, cookie or other identifier attached. If your browser sends a Do Not Track signal, we don't count your page views. For some payment events we store a one-way hash of the payment's reference, so that one payment is not counted twice.
- Cookies and browser storage: see our Cookie Notice.
What we don't collect
Identity documents, selfies, full card numbers, card security codes and bank account numbers. Whop collects these directly, in its own secure frames and checkout. Your card number is shown only to you, inside Whop's card frame. We don't ask for sensitive data such as health, religion or political views.
How we use it, and our legal bases
Where laws such as the EU or UK General Data Protection Regulation apply, we rely on these legal bases. “Contract” means we need the data to provide Shft Money to you. “Legitimate interests” means we have a real reason that we have weighed against your rights, and you can object.
| Why we use it | Data | Legal basis |
|---|---|---|
| Open and run your account, confirm your email address, sign you in and keep you signed in | Login, business and team details | Contract |
| Create and connect your Whop account, take payments, show your balance, and carry out withdrawals, conversions and other money actions you ask for | Login email, business details, money records, data from Whop | Contract |
| Show your public page, tips on your support wall and alerts on your stream | Page details; tippers' names and messages | Contract (account holders); legitimate interests in showing the support a tipper chose to send, which the tipper controls (tippers) |
| Process payments and tips for the business you pay, and give you your receipt or access | Payment details, optional email address, name and message | Legitimate interests in delivering what you paid for, for you and the business |
| Let your team work in your business with the access their role allows, and send invitations | Invitee email address, role, who invited them | Contract (account holders); legitimate interests (invitees) |
| Send service emails and notices about your account, our terms and security | Email address | Contract; legal obligation where the law requires a notice |
| Keep Shft Money secure: prevent fraud and abuse, limit repeated attempts, and check our records against Whop's every hour | Hashed IP addresses and emails, logs, money records | Legitimate interests in keeping accounts and money safe and records correct |
| Understand how Shft Money is used | Daily counts with no identifiers; hashed payment references | Legitimate interests in improving the service |
| Keep financial and tax records, record your agreement to our terms, answer lawful requests, and deal with disputes and legal claims | Money records, agreement records, messages | Legal obligation; legitimate interests in defending legal claims |
| Answer your messages and give support | Your messages and contact details | Contract (account holders); legitimate interests (everyone else) |
We don't rely on consent for any of these. If we ever ask for your consent, you can withdraw it at any time.
We don't sell personal data, we don't share it for cross-context behavioural advertising, and we don't show ads. We don't make decisions with legal or similarly significant effects about you based only on automated processing. Whop makes its own verification and risk decisions under its privacy policy.
International transfers
AINA is based in the United States. Our servers and database are in Singapore, and our providers operate in the United States and other countries. So your data is processed outside your country, where data protection laws can be different.
When we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we use a lawful safeguard: an adequacy decision (including the EU-US Data Privacy Framework and its UK and Swiss extensions, where the recipient is certified), or the European Commission's Standard Contractual Clauses with the UK Addendum and Swiss changes where needed. Our providers' data processing terms include these safeguards. You can ask for a copy at privacy@shft.money.
How long we keep data
We keep personal data only as long as we need it for the purposes above, then delete or anonymise it.
| Data | How long |
|---|---|
| Account, business page, team, products and stream settings | While your account is open. Deleted or anonymised within 30 days after you close your account or ask us to delete your data, except the records below. |
| Payment, fee, refund, dispute, withdrawal, conversion, business payment and card records, the payment notices Whop sends us, and the buyer details attached to them | As long as financial record, tax and anti-money laundering laws require, usually up to 7 years after the transaction. Then deleted or anonymised. |
| When you agreed to our terms, and which version | While your account is open, and up to 7 years after it closes, to show what was agreed if there is a dispute |
| Sign-in sessions | 30 days, or until you log out. Expired records are deleted within 30 days. |
| Email confirmation, password reset and team invitation links | Email confirmation links expire after 24 hours, password reset links after 1 hour and team invitation links after 7 days. Expired links are deleted within 30 days. The record of who was invited, by whom and when stays in the team's history while the business exists. |
| Abuse-protection records (hashed IP addresses and emails) | Up to 30 days |
| Server logs | Up to 30 days |
| Messages to support, privacy and legal | Up to 3 years after the conversation ends |
| Daily usage counts | Kept, because they contain no personal data |
| Database backups | Deleted data can remain in backups for up to 30 days until they are replaced |
We may keep data longer if we need it for a legal claim, an investigation or a legal hold, and only for as long as that lasts. We delete personal data we received from Whop within 30 days of a verified request to delete it, or when we no longer need it to provide Shft Money, unless the law requires us to keep it.
Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy of it;
- correct it;
- delete it;
- object to, or restrict, how we use it, including where we rely on legitimate interests;
- receive it in a portable format;
- withdraw consent, where we rely on it;
- opt out of the sale or sharing of personal data, or of targeted advertising and profiling (we don't do any of these); and
- not be treated differently for using these rights.
How to use your rights
You can edit your page and business details in the app. For anything else, email privacy@shft.money from the email address on your login, or tell us which payment your request is about. We will confirm it's you before we act, and we will reply within 30 days. If a request is complex, or we receive many, we may take longer where the law allows, and we will tell you why within those 30 days. Where the law allows, you can use an authorised agent, who must show us your permission.
If we decline your request, we will tell you why. You can appeal by replying to our decision, and we will answer within 45 days. If you are still not satisfied, you can contact your state attorney general or your data protection authority.
Deleting your account and data
To delete your account and your data, email privacy@shft.money from the email address on your login. Withdraw your balance first. We will confirm it's you, close your account, and delete or anonymise your personal data within 30 days, except the records the law requires us to keep, as explained under How long we keep data. Deleting your Shft Money data doesn't delete data Whop holds, such as your Whop account and verification documents: ask Whop for that. If you are a buyer or tipper, tell us which payment your request is about, or ask the business you paid.
Complaints
You have the right to complain to a data protection supervisory authority, for example the one where you live or work. In the United Kingdom that is the Information Commissioner's Office. We would like the chance to help first, at privacy@shft.money.
Notice for US state privacy laws
This section adds detail that some US state laws, such as California's, ask for.
- Categories we collect: identifiers (such as name, email address, IP address and account IDs); commercial information (payments, products and money records); internet activity (logs and hashed IP addresses); professional information (your business details); approximate location (the country you give us); and sensitive personal information limited to your login (email and password), which we use only to sign you in.
- Sources: you, your team, the people who pay you, Whop, and your browser.
- Purposes: those in How we use it.
- Disclosures: for business purposes, to Whop, our service providers, and the business a buyer or tipper pays, as described in Who we share it with.
- No sale or sharing: we don't sell personal information or share it for cross-context behavioural advertising, and we haven't in the past 12 months. We don't knowingly sell or share the personal information of anyone under 16. We treat a Global Privacy Control signal as a request to opt out; since we don't sell or share, nothing changes.
- Retention: see How long we keep data.
Security
- Passwords are stored as one-way hashes. Sign-in, email confirmation, password reset and invitation tokens are stored as hashes too.
- Connections use HTTPS, and our sign-in cookie can't be read by scripts on the page.
- Our server logs leave out email addresses, messages, and card and bank details.
- Only a business's owner can move its money. Our support tools can't.
- Identity documents and card details stay with Whop.
No system is completely secure. If a personal data breach is likely to put your rights at risk, we will tell you without undue delay and notify the authorities where the law requires, which in the EU and UK is within 72 hours of becoming aware of it. If a security incident affects data we received from Whop, we will also tell Whop within 24 hours of becoming aware of it.
If you find a security problem, please email support@shft.money.
Children
Shft Money is not for children. You must be at least 18 to open an account or join a team. People under 18 may pay a business only where Whop's Buyer Terms allow it and with a parent's or guardian's permission. We don't knowingly collect personal data from children under 13, or under 16 in the EU and UK. If you think a child has given us personal data, email privacy@shft.money and we will delete it.
Changes to this policy
We will post updates on this page and change the date at the top. If a change is material, we will tell account holders by email or in the app at least 30 days before it takes effect, unless the law requires it sooner.
Contact
Email privacy@shft.money, or write to AINA Technologies LLC, 1500 N Grant St, Ste 45878, Denver, CO 80203, United States.