Lightning Swap — Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains what personal data Lightning Swap collects when you visit the Website or use the Service, how we use it, and the choices you have. It should be read with our Terms of Service.
1. Definitions
In this Privacy Policy:
- Cookies means small data files placed on your device that may identify a session, store preferences, or support security features (such as CSRF protection).
- Lightning Swap, Website, and Service mean the website and services at lightning-swap.com (and related API, Order pages, and infrastructure we operate to provide coin→Lightning swaps).
- Log Files means server and application records of requests and events, which may include IP address, browser type, request path, referring URL, and date/time.
- Personal Data means information that identifies or can reasonably identify an individual, and for this Policy also includes device and usage data we associate with a visit or account (including Cookies and Log Files where applicable).
-
Order means a swap created through the Website or API, identified by a
public_token(and related on-chain / Lightning identifiers).
2. General
2.1. This Privacy Policy covers Personal Data we collect when you visit the Website or use the Service (including guest swaps, optional accounts, and API access).
2.2. Where the EU General Data Protection Regulation (GDPR) or similar laws apply, we process Personal Data in line with those requirements and the principles below.
2.3. We are committed to the following:
- collecting only what we need to operate, secure, and improve the Service;
- not renting or selling your Personal Data;
- using commercially reasonable safeguards to protect Personal Data; and
- providing a way to contact us about this Policy or your data (Section 10).
2.4. By using the Service or visiting the Website you acknowledge this Privacy Policy. If you do not agree, do not use the Service.
2.5. Creating a swap does not require an account or an email address. Holding
an Order’s public_token is the credential to view and manage that Order. Treat it
like a secret. Optional accounts add email login, API keys, and swap history.
3. Personal Data we collect
3.1. Account data (optional). If you create an account: email address and a hashed password. If you use Google sign-in: the OAuth provider identifier we need to authenticate you (we do not receive your Google password). Account email is used for authentication, verification, password reset, and security notices — not for marketing newsletters unless we clearly offer that and you opt in.
3.2. Swap and Order data. Amounts, asset pair, deposit address and memo/tag
if any, deposit and refund transaction identifiers, confirmations, BOLT11 invoice and
related Lightning payment metadata, refund address you submit, Order phase and emergency
status, API request metadata tied to an Order or API key, and the Order
public_token / provider identifiers needed to operate the swap.
3.3. API credentials. HMAC public keys and usage weights. API secrets are shown once at creation; we store only a digest, not the raw secret.
3.4. Automatically collected data. When you visit the Website or call the API we may collect Log Files and similar technical data (IP address, user agent, paths, timestamps). Real-time Order pages may use a WebSocket/ActionCable connection tied to the Order token you present.
3.5. Blockchain and Lightning data. Deposit addresses, transaction ids, amounts, and invoice payment proofs exist on public ledgers or Lightning infrastructure. We do not control the public nature of on-chain data once broadcast.
3.6. We do not knowingly collect sensitive categories of Personal Data such as racial or ethnic origin, political opinions, religious beliefs, or health data. We do not ask for government ID as a condition of ordinary self-serve swaps.
4. How we process Personal Data
4.1. Legal bases (where GDPR or similar law applies) include: performance of a contract / steps to provide the Service you request; legitimate interests in securing and operating the Service, preventing fraud and abuse, and improving reliability; consent where you provide optional account or contact information; and compliance with legal obligations.
4.2. We may collect, store, use, retrieve, disclose (as described in Section 6), and delete Personal Data as needed to run the Service. Processing may involve our infrastructure and authorised processors who help us host, monitor, or deliver the Service.
4.3. Purposes include:
- creating and fulfilling Orders (quotes, deposits, Lightning payouts, refunds);
- showing Order status on the Website and via API / real-time updates;
- authenticating accounts and API keys;
- rate limiting, fraud prevention, abuse detection, and security;
- customer support when you contact us with an Order token or account email;
- error monitoring and reliability (see Section 5);
- complying with law and responding to lawful requests; and
- improving the Service (product and operational metrics).
4.4. We do not use Personal Data for cross-site advertising networks, and we do not sell Personal Data.
5. Cookies, analytics, and monitoring
5.1. Essential cookies. We use session and CSRF cookies required for the Website to function securely. If you sign in, we may use a remember/session cookie for authentication. These are not advertising cookies.
5.2. Analytics. We use Plausible Analytics on marketing / Rails pages to understand aggregate traffic (e.g. page views). Plausible is designed to be privacy-friendly and does not use advertising cookies or build cross-site profiles for ads. See Plausible’s privacy policy. You can block the script with a browser content blocker if you prefer.
5.3. We do not use Google Analytics, Google Ads remarketing, Facebook Pixel, or similar advertising trackers.
5.4. Error monitoring. In production we may use Sentry (or a similar error service) to capture application exceptions. We configure it not to send default PII such as request bodies, cookies, or IP addresses in events. Sensitive parameters are filtered in our application logs.
6. Sharing
6.1. We may share limited data with:
- infrastructure and service providers (hosting, databases, email delivery for account messages, analytics, error monitoring) under arrangements that limit use to providing their service to us;
- blockchain networks and Lightning routing peers as an inherent part of sending or receiving cryptocurrency / Lightning payments; and
- competent authorities or other parties when required by law, or when reasonably necessary to protect users, the Service, or investigate prohibited or illegal activity (consistent with our Terms).
6.2. We do not share Order public_token values or API secrets for marketing.
Anyone who obtains your public_token can act on that Order — keep it private.
7. Retention and security
7.1. Swap and Order records are retained for operations, dispute handling, fraud prevention, security, and legal / regulatory compliance for as long as reasonably necessary or required by applicable law.
7.2. If you close an account, we scramble the account email so the address can be reused; Order audit rows and related operational records may remain.
7.3. We use commercially reasonable technical and organisational measures to protect Personal Data against unauthorised access, loss, or disclosure. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
8. Children
8.1. The Service is not directed to children. We do not knowingly collect Personal Data from anyone under the age required to use the Service under applicable law. If we learn that we have collected such data, we will take steps to delete it and may refuse further use of the Service.
9. Changes
9.1. We may update this Privacy Policy from time to time. The “Last updated” date at the top shows when it changed. Material updates may also be noted on the Website. Continued use of the Service after an update constitutes acceptance of the revised Policy. If you do not agree, stop using the Service.
10. Contact and your rights
10.1. Depending on where you live, you may have rights to access, correct, delete, or restrict processing of Personal Data we hold about you, to withdraw consent where processing is based on consent, and to lodge a complaint with a supervisory authority.
10.2. To exercise these rights or ask about this Policy, email
[email protected]. For Order-specific
requests, include the Order public_token and relevant transaction ids. We may
need to verify your request before acting (for guest Orders, possession of the
public_token is typically required).
10.3. We will respond within a reasonable time after reviewing the request. Some records (especially completed swaps) may need to be retained for legal, security, or dispute reasons even when an account email is removed.