Privacy Policy
Last updated: October 10, 2026
This policy covers the current Allot test website. Allot creates USDC payment splits on Solana Devnet. It does not support real-money payments.
Information used by the demo
You enter a payment title, recipient names, wallet addresses, percentages, and optionally an amount. The app encodes this information in the payment link in your browser. Encoding does not encrypt it: anyone with the link can read and copy it. Shared links can also appear in browser history and hosting request logs.
When you connect a wallet, the app uses its public address and wallet connection to display balances and request transaction approval. Allot does not ask for your seed phrase or private key. Your wallet controls signing.
When you view a receipt, the app uses the transaction signature to retrieve public transaction data. New team-backed links identify approved requests stored in our database. Older links still contain request data directly.
Accounts and teams
Supabase Auth processes your email, password, email confirmation, and password recovery. Allot forwards credentials to Supabase and does not store passwords in its application tables. Session cookies keep you signed in.
Supabase Postgres stores team names, membership, display names, invitation hashes and expiry, split versions, wallet addresses, decisions, and requested percentages. Active members can see the workspace and negotiations. We use this information to provide accounts, team access, and approval workflows.
Anyone possessing an invitation code/link can join after confirming an account. Codes expire after seven days and the owner can replace them. Share invitations only with intended members. Published payment details are public to link holders; account emails and internal negotiations are excluded.
Public blockchain records
Submitted transactions expose wallet addresses, token amounts, transaction signatures, and a memo containing the payment title on Solana Devnet. Blockchain records can be copied and indexed by others. Allot cannot edit or delete those records. Avoid personal, confidential, or sensitive information in payment titles and recipient labels.
Why information is processed
The app uses payment details to prepare a split, wallet information to request your approval, and blockchain data to display balances and receipts. Hosting infrastructure processes technical request data to deliver and protect the website. These technical records may include IP addresses, requested URLs, timestamps, and browser information.
Service providers and external services
Vercel hosts the website. Supabase provides authentication and database storage. Solana RPC services receive requests for balances, transactions, and receipts; the default endpoint is api.devnet.solana.com. Your wallet provider and any explorer you open handle information under their own policies. These services may process data outside your country.
See Vercel’s Privacy Notice and Supabase’s Privacy Policy for their data practices. We have not added advertising trackers or analytics tools to this version.
Cookies and browser storage
The app uses essential account-session cookies to keep you signed in and complete email confirmation or password recovery. It does not set advertising or analytics cookies. Your browser stores whether you dismissed the cookie notice; this does not alter session cookies. Wallet software and hosting infrastructure may use their own storage or security mechanisms. Your browser may retain payment and invitation URLs. You can manage cookies, storage, and history in browser settings; removing session cookies logs you out.
Retention and security
Account, team, approval, and payment records are retained to operate the workspace. Team owners can permanently delete their workspace and its related records from the live database. Account deletion, data export, a fixed retention period, and tested backup restoration are not yet available. Hosting logs follow the provider’s configured retention. Public blockchain records and independent copies remain outside Allot’s control.
No website, wallet, or network is risk-free. Share links only with intended recipients and review addresses before signing. Never send a password, private key, or seed phrase in a support request.
Your privacy rights
Depending on applicable law, you may request information about processing, access, correction, or deletion of personal data under our control, and object to processing where available. These requests cannot remove public blockchain records or copies held independently by others.
For users in Brazil, the ANPD explains data-subject rights and complaint channels.
Contact
A dedicated public privacy contact has not yet been designated for this test demo. Do not submit sensitive personal information through payment links.
Changes
We will update this page when data practices change. The date above identifies this version. See also our Terms of Use.