Aonax Wallet Privacy Policy
Effective Date: April 21, 2026
This Privacy Policy describes how Aonax Wallet ("we," "us," or "our") collects, uses, discloses, and safeguards your personal information when you use our mobile application ("App") and associated smartwatch features, including card enrollment, NFC payments, and smartwatch card provisioning. It applies to both Android and iOS versions of the App, noting that NFC functionality is currently only available on Android devices.
1. Information We Collect
We collect only the information necessary to provide our core payment and wallet services. This includes:
1.1 Information You Provide
- Payment Card Data: Encrypted card details (PAN, expiry, CVV, and related metadata) when you enroll cards for mobile and smartwatch payments. We do not store raw card data on our servers; all sensitive information is tokenized and processed in compliance with payment card industry standards.
- User Authentication Data: Biometric verification (fingerprint or face scan) handled by your device’s secure environment (e.g., Android BiometricPrompt, iOS Face ID/Touch ID) to authenticate payments and App access. We never access or store raw biometric data, which remains securely stored on your device.
- Account Information: Optional profile details (name, contact information) if you choose to create an account for syncing across devices.
1.2 Information Automatically Collected
- Device Information:
- Android: Device model, OS version, hardware identifiers, and NFC capability status (for enabling contactless payments).
- iOS: Device model, OS version, and Bluetooth capability (for smartwatch pairing and syncing).
- Network and Connection Data: Network status (Wi-Fi/cellular connectivity) and Bluetooth connection logs for pairing, card provisioning, and transaction processing.
- Transaction Data: Timestamps, merchant details (anonymized), and payment amounts for verification, fraud prevention, and service improvement.
2. Permissions We Request and Their Purposes
To deliver core functionality, the App requests the following permissions, which you can manage in your device settings at any time:
2.1 Android-Specific Permissions
| Permission |
Purpose |
| INTERNET |
Process payment transactions, sync card data, and provision cards to your smartwatch. |
| ACCESS_NETWORK_STATE |
Verify network connectivity for successful transactions. |
| NFC / android.hardware.nfc |
Enable contactless payments (Android only). |
| android.hardware.nfc.hce |
Support secure NFC-based payments. |
| USE_BIOMETRIC / USE_FINGERPRINT |
Authenticate App access and payment transactions. |
| BLUETOOTH / BLUETOOTH_CONNECT / BLUETOOTH_SCAN |
Pair with smartwatch, provision cards, and sync data. |
2.2 iOS-Specific Permissions
- Bluetooth: Required for smartwatch pairing and card/data syncing.
- Biometric Authentication (Face ID/Touch ID): Secure App access and payment verification. No biometric data is shared with our servers.
3. How We Use Your Information
We use your information exclusively for the following purposes:
- Process and verify payment transactions via mobile and smartwatch devices.
- Enroll and provision payment cards to your phone and paired smartwatch.
- Authenticate your identity and prevent unauthorized access.
- Troubleshoot issues, improve App performance, and enhance security.
- Comply with legal and regulatory requirements.
We do not sell, rent, or share your personal information with third parties for marketing purposes. We only share data with trusted service providers under strict data protection agreements.
4. Data Security
We implement industry-standard security measures:
- End-to-end encryption for all transactions and card provisioning.
- Tokenization of sensitive payment card data.
- Device-level secure storage for biometric data (never transmitted to our servers).
- PCI DSS compliance and regular security audits.
- Encrypted Bluetooth communication between phone and watch.
5. Data Retention
We retain your data only as long as necessary to provide our services:
- Transaction logs are retained as required by applicable laws.
- Card enrollment data is stored securely until you remove the card or delete your account.
- Biometric and raw payment data are never stored on our servers.
6. Your Rights
You have the right to:
- Access and update your account information.
- Remove payment cards or unlink your smartwatch at any time.
- Revoke device permissions (may limit certain features).
- Request account and data deletion by contacting our support team.
- Opt out of non-essential communications.
7. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes via the App. Your continued use of the App after updates constitutes acceptance of the revised policy.