1Shot Privacy Policy
Effective Date: August 7, 2026
This Privacy Policy explains how 1Shot API, Inc. (“1Shot,” “we,” “us,” or “our”) handles personal information across one ecosystem: websites, including any 1ShotPay-branded pages still operated during product wind-down; hosted public infrastructure; registered Developer Services; and 1Shot wallet interfaces and relayer-assisted transactions (collectively, the “Services”).
The architecture and data relationship differ by service. The non-custodial 1Shot wallet interface is designed so that neither 1Shot nor a cloud service acting for 1Shot can generate, possess, reconstruct, decrypt, or independently use that wallet's private signing key. Certain Developer Services separately use managed or server-side key-management and signing systems under a developer customer's authenticated instructions.
1. Information We Handle
1.1 Developer accounts and billing
For registered Developer Services, we may collect a name, organization, email address, account and authentication information, team roles, plan and checkout records, subscription and payment status, and support communications. A payment processor may collect payment credentials directly; 1Shot ordinarily receives a payment token, status, and limited billing records.
1.2 Developer instructions and configurations
We process data submitted through Developer Services, such as API-key identifiers, contract addresses and ABIs, workflows, webhooks, labels, instructions, transaction parameters, outputs, managed-wallet or key-management references, signing requests and results, access policies, and end-user data a customer directs us to process.
1.3 Wallet, passkey, and encrypted records
The Wallet Services may process a passkey credential identifier and public key; public wallet addresses and keys; wallet settings; delegation identifiers, scopes, limits, counterparties, and revocation status; credential issuer or verifier origins; and encrypted credential or delegation records.
We do not receive a device biometric template or the passkey's private key. Supported credential and delegation records may be encrypted on the user's device and stored as ciphertext in the relayer. 1Shot cannot decrypt those records. We may process non-content metadata needed to authenticate, store, retrieve, or delete them.
1.4 Transactions and product events
We process public wallet and contract addresses, chain identifiers, transaction hashes and status, method identifiers, duration, destination, error codes, and related fee or quote information. Wallet product events may also identify the embedding host domain and a credential issuer or verifier origin.
Wallet addresses, transaction hashes, host domains, and combined event fields are pseudonymous and may be linked to public blockchain activity. We do not describe them as anonymous merely because they are not attached to a name.
1.5 Technical and infrastructure data
1Shot and infrastructure providers may process IP address, request time, browser or client type, operating system, requested page or endpoint, response code, performance information, request or session identifiers, security signals, and approximate region inferred from IP address. Cloudflare processes requests as 1Shot's CDN and security provider. Google Cloud hosts infrastructure and required audit logs.
Infrastructure providers retain logs according to the applicable service configuration, provider terms, security requirements, and legal obligations. 1Shot does not intentionally maintain a separate long-term Cloudflare HTTP request-log export. Provider defaults and required audit-log periods may change.
1.6 Public blockchain and third-party information
We read public blockchain information such as addresses, balances, token transfers, transaction hashes, receipts, contract events, and network status. We may receive or transmit information through RPC or indexing services, embedding hosts, passkey providers, credential issuers or verifiers, and services selected by the user.
1.7 Cookies and device storage
Websites and Developer Services may use essential cookies or similar technologies for authentication, security, and preferences. 1Shot does not currently use the Services for cross-context behavioral advertising. Nonessential cookies will not be added without any legally required consent mechanism.
Wallet interfaces may use browser local storage or IndexedDB for wallet state, preferences, credentials, delegations, and activity. Device-stored information remains until the user or browser clears it and is not centrally controlled by 1Shot. Because no uniform browser signal is an accepted legal opt-out mechanism for all processing, the Services do not presently respond to browser “Do Not Track” signals; legally required preference signals will be honored where applicable.
2. How We Use Information
We use information to provide and authenticate the Services; operate accounts, APIs, workflows, wallets, credentials, relayers, quotes, and transactions; store and retrieve client-encrypted records; provide support; calculate and reconcile fees; secure services and prevent abuse; enforce permissions and ecosystem terms; improve performance and user experience; communicate about services and legal changes; comply with law; and establish or defend claims.
We do not sell personal information, share it for cross-context behavioral advertising, or use client-encrypted content because we cannot decrypt it.
3. Our Privacy Roles
1Shot generally determines the purposes of processing for its websites, direct wallet relationship, developer account administration, billing, security, analytics, and legal compliance.
When a business customer directs 1Shot to process personal data through the Developer Services, that customer may act as controller or business and 1Shot as processor or service provider. 1Shot will provide a DPA where required.
An embedding host independently determines its own collection and use. Its terms and privacy notice govern that separate processing. Public blockchains and some third-party services may independently determine their processing.
4. Legal Bases Outside the United States
Where required, we rely on performance of a contract; legitimate interests in operating, securing, supporting, and improving the Services; legal obligations; and consent for processing that requires it. Consent may be withdrawn without affecting prior lawful processing.
5. How We Disclose Information
We disclose information to infrastructure and service providers that support hosting, CDN and security, databases, logging, communications, support, and payment processing. Current core infrastructure includes Google Cloud and Cloudflare.
We disclose information to embedding hosts when necessary to operate the embedded experience; to public blockchains and RPC or index services to read state and submit transactions; and to key-management providers, issuers, verifiers, integrations, or other services used for the applicable service or selected interaction. Those parties may independently apply their own terms and privacy practices.
We may disclose information to comply with valid legal process; protect users, rights, assets, and service security; investigate fraud or abuse; or complete a merger, financing, acquisition, reorganization, or sale subject to appropriate protections.
6. Public Blockchain Records
Public blockchains are designed to preserve records. 1Shot cannot alter or erase an address, transaction, smart-contract event, or other record written to a public blockchain. A privacy request applies to eligible information in systems 1Shot controls, not the underlying blockchain or independent copies held by others.
7. Retention
We retain personal information only for as long as reasonably necessary to provide and secure the Services, maintain accounts and configurations, complete transactions and support requests, comply with legal, tax, accounting, and reporting obligations, enforce agreements, and establish or defend legal claims. The period depends on the type of information, the service and relationship, the sensitivity of the information, operational and security needs, and applicable law.
1Shot-controlled records are deleted, deidentified, or made inaccessible when they are no longer reasonably needed for these purposes, subject to legal exceptions and the time required for ordinary system and backup deletion processes. Contract-acceptance, billing, tax, security, dispute, and privacy-request records may be kept longer than ordinary product analytics because they support compliance and legal claims. Google Cloud, Cloudflare, and other infrastructure providers retain logs according to the configured service, provider requirements, security needs, and legal obligations. Backup copies expire through ordinary rotation, so deletion from backups may not be immediate.
Public blockchain records are outside 1Shot's deletion control. Device-stored wallet information remains until cleared by the user or browser.
8. Security
Relayer information is stored in a MySQL database with access limited to authorized personnel. We use administrative, technical, and organizational safeguards appropriate to the information, including access controls and encryption in transit. Client-encrypted records are encrypted before upload and are not decryptable by 1Shot.
No method is perfectly secure. Users must protect devices, browser profiles, passkeys, exports, and sessions and must not send a private key or recovery secret to support.
9. Rights and Requests
Depending on where a person lives, they may request access, correction, deletion, portability, restriction, objection, appeal, or withdrawal of consent and may complain to a regulator. 1Shot does not sell personal information or use it for targeted advertising.
Requests may be sent to info@1shotapi.com. We may verify control of the relevant account, wallet, passkey, or email without requesting unnecessary identity documents. Never send a private key or secret.
We may deny or limit a request where permitted, including where we cannot verify it, the information is exempt, retention is legally required, or fulfillment would affect others' rights. We cannot delete public blockchain records or information controlled solely by an embedding host.
10. International Transfers
1Shot operates from the United States and providers may process information in other countries. Where required, we use approved transfer mechanisms such as standard contractual clauses and supplementary safeguards.
11. Children
The Services are not intended for anyone under 18. Wallet users must also have reached the age of majority and have legal capacity where they live. If we learn that a child provided personal information, we will investigate and take appropriate deletion or restriction steps, recognizing that 1Shot cannot remove public blockchain records.
12. Changes
We will post an updated policy and effective date and provide additional notice of material changes where appropriate. The Privacy Policy is a notice; continued use does not replace fresh consent where consent is legally required for a changed processing activity.