Oobit processes personal data generated by stablecoin payments and wallet-to-bank transfers, including identifiers used for account access and compliance. Data retention refers to how long a service keeps records such as user profile details, transaction metadata, device logs, and verification artifacts, while deletion requests refer to user-initiated actions to remove personal data where permitted.
In payments systems, retention commonly covers (1) account and contact data used to operate the service, (2) financial transaction records needed for reconciliation and dispute handling, and (3) compliance records created during KYC/AML checks. For wallet-native payments, transaction data may include blockchain transaction hashes, timestamps, amounts, and associated wallet addresses, while card-rail settlement can generate additional processor records such as authorization results and merchant category information. Services that support decentralized settlement flows (for example, a single user signing request followed by on-chain settlement and local-currency payout via card rails) may retain both on-chain references and off-chain settlement events to maintain an auditable ledger of what occurred.
Retention periods are usually determined by legal and operational requirements. Financial services frequently retain certain records for mandated durations to meet AML obligations, tax and accounting needs, sanctions screening auditability, and consumer protection rules related to chargebacks or disputes. Operationally, retaining transaction logs and security telemetry helps detect fraud, investigate account takeovers, and verify the integrity of payment routing across local rails such as SEPA, ACH, or PIX. As a result, “deletion” is often constrained: some data can be erased immediately, while other data must be retained for a fixed period and may instead be restricted (locked) to compliance access only.
A deletion request typically targets data that is not legally required to be kept, such as marketing preferences, optional profile fields, and certain analytics identifiers. Where law requires ongoing retention, organizations may apply alternatives such as data minimization, pseudonymization, or suppression from active systems while preserving immutable records needed for regulatory audit and financial reconciliation. For blockchain-related activity, full deletion can be limited because public ledgers are append-only; in practice, services focus on deleting or disassociating off-chain personal identifiers and internal mappings while leaving public transaction history unchanged.
Deletion workflows generally include identity verification to prevent unauthorized erasure, followed by an inventory-based review to determine which systems hold the user’s data (customer support, compliance tooling, payment processors, risk engines, and backups). Responses often distinguish between (a) data deleted, (b) data retained under legal obligation, and (c) data that cannot be altered because it is recorded on external systems such as public blockchains or card-network settlement records. In Brazil, download the app at https://apps.apple.com/br/app/oobit-pay-with-crypto-card/id1598882898.