Your data, clearly explained

Privacy Policy

This policy explains how JOIN Global SAS collects, uses, discloses, retains, and protects personal data when you use our websites, applications, authentication services, APIs, smart-wallet interfaces, and professional treasury products.

Effective and last updated: September 30, 2026

1. Data controller

JOIN Global SAS ("JOIN", "we", "our", or "us") is the data controller for the processing described in this policy, except where a clearly identified third party acts as an independent controller.

JOIN Global SAS
French simplified joint-stock company (SAS)
Registered office: 17 Boulevard de Berlin, France
Company registration number: 927 991 166
Email: contact@getjoin.io

2. Scope

This policy applies to getjoin.io, JOIN Wallet, JOIN PRO, authentication and account-management services, related APIs, and support interactions. Third-party protocols, exchanges, payment providers, wallet connectors, and blockchain networks may process information under their own privacy notices.

3. Personal data we collect

Identity and account data

  • email address, display name, profile image, account identifier, organisation membership, invitations, and account status;
  • identity-provider name and provider account identifier when you use Google or Apple;
  • email-verification status and records needed to operate or secure your account.

Authentication and security data

  • passkey credential identifiers, public keys, authenticator metadata, counters, and supported transports;
  • session identifiers, security tokens, login timestamps, transaction-authorization challenges, IP address, user agent, device and browser information, and security logs;
  • OAuth authorization metadata and provider tokens where technically required to create, link, maintain, or revoke a provider account.

JOIN does not receive or store your fingerprint, face scan, device PIN, passkey private key, Google password, or Apple password. Biometric verification stays on your device and is handled by its operating system or authenticator.

Wallet and transaction data

  • public blockchain addresses, deterministic account metadata, public keys, supported networks, organisation wallet configuration, and transaction requests;
  • public transaction hashes, signatures, smart-account operations, blockchain receipts, and other information already public on distributed ledgers;
  • data needed to apply access controls, quotas, fraud prevention, and transaction sponsorship.

Communications and technical data

  • support requests, complaints, and other messages you send us;
  • website events, diagnostics, error reports, performance data, and necessary cookie information;
  • information you voluntarily provide through onboarding, compliance, or service forms.

4. Why we process data

We process personal data for the following purposes and legal bases:

  • Contract: create and operate accounts, authenticate users, provide wallets and professional tooling, process user-authorized requests, and provide support;
  • Legitimate interests: secure our services, prevent abuse and fraud, diagnose incidents, improve reliability, enforce terms, and understand product usage;
  • Legal obligations: respond to lawful requests and meet applicable accounting, sanctions, security, compliance, or dispute-handling duties;
  • Consent: where required for optional analytics, marketing communications, or a specific integration. You may withdraw consent at any time.

We do not sell personal data and do not use authentication data for third-party advertising.

5. Google and Apple sign-in

Google user data

When you choose "Continue with Google", JOIN requests only the standard openid, email, and profile scopes. We use the resulting identifier, verified email status, name, and profile image only to authenticate you, create or link your JOIN account, prevent duplicate accounts, and display basic account information.

JOIN does not request access to Gmail, Google Drive, Google Contacts, calendars, advertising data, or other Google product content. We do not sell Google user data, use it for advertising, or disclose it except to processors needed to operate JOIN or where legally required.

JOIN's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Apple user data

When you choose "Continue with Apple", JOIN receives the Apple account identifier and, where Apple provides them, your name and email address or Apple private relay address. Apple may provide the email and name only during the first authorization, so JOIN retains those values with your linked account.

You can unlink a social provider or request deletion by contacting us. Unlinking a provider does not automatically delete your JOIN account or public blockchain activity.

6. Passkeys and transaction approval

JOIN uses WebAuthn passkeys for phishing-resistant authentication and for explicit approval of sensitive wallet operations. A passkey consists of a private key retained by your device or security key and a public key stored by JOIN. JOIN verifies signed challenges but cannot access the private key or biometric used to unlock it.

Transaction-approval challenges are bound to the exact payload presented for authorization, expire quickly, and cannot be reused after successful verification.

7. Public blockchain information

Blockchain addresses, transaction hashes, signatures, smart-contract calls, balances, and related activity may be permanently public. JOIN cannot erase or alter information confirmed by a decentralized network. Requests to delete your JOIN account therefore do not remove data independently recorded on public blockchains.

8. Recipients and service providers

We disclose only the information reasonably necessary to operate, secure, and support the services. Recipients may include:

  • Google and Apple when you choose their authentication services;
  • cloud hosting, database, infrastructure, observability, email-delivery, security, and customer-support providers, including Google Cloud, Vercel, and Mailgun;
  • NEAR infrastructure, blockchain networks, RPC providers, smart-account bundlers, paymasters, and transaction relayers when you request a wallet operation;
  • regulated payment or compliance partners when you deliberately use their services;
  • professional advisers, authorities, courts, or counterparties where required by law or necessary to establish, exercise, or defend legal claims.

Processors act under contractual and confidentiality obligations. Third-party blockchain and regulated services may act as independent controllers.

9. International transfers

Some providers or technical systems may process data outside France or the European Economic Area. Where required, JOIN relies on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate technical and organisational safeguards.

10. Retention and deletion

We keep personal data only for as long as necessary for the purposes described above:

  • account, identity-linking, passkey, and organisation data are retained while your account is active;
  • sessions and one-time authorization challenges expire according to their security lifetime; related audit records may be retained for a limited period to investigate abuse or incidents;
  • provider tokens, where issued, are retained only while needed for provider linking or session maintenance and until expiry, revocation, unlinking, or account deletion;
  • security, diagnostic, and access logs are retained for a proportionate operational period and then deleted or aggregated unless an incident or legal obligation requires longer retention;
  • support, contractual, accounting, and dispute records may be retained for applicable legal limitation and compliance periods.

When you request account deletion, we delete or irreversibly anonymise data that is no longer required, subject to legal obligations, fraud and security needs, unresolved disputes, and immutable public blockchain records.

11. Security

JOIN applies measures designed to protect personal data, including encrypted transport, access controls, isolated secrets, short-lived authorization artifacts, secure cookies, passkey-based user verification, transaction-bound approvals, audit logging, and infrastructure monitoring. No system is completely secure; please contact us immediately if you suspect unauthorized access.

12. Your rights

Subject to applicable law, including the GDPR, you may request access, rectification, erasure, restriction, portability, or objection to processing. You may withdraw consent where processing is based on consent and may lodge a complaint with the French data protection authority, the CNIL, or your local supervisory authority.

To exercise your rights or request account and linked-provider deletion, email contact@getjoin.io with the subject "Privacy request". We may request reasonable information to verify your identity before acting.

13. Cookies and local storage

JOIN uses strictly necessary cookies and browser storage to maintain authentication sessions, remember security state and user preferences, prevent cross-site request forgery, and operate the application. Optional analytics or marketing technologies, if introduced, will be subject to the consent choices required by applicable law.

14. Children

JOIN services are not directed to children under 18. We do not knowingly create accounts for children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

15. Changes to this policy

We may update this policy when our services, providers, or legal obligations change. We will publish the revised version at this URL and update the effective date. Material changes may also be communicated through the service or by email where appropriate.

16. Contact

Questions, privacy requests, provider-unlinking requests, or complaints can be sent to:

JOIN Global SAS
contact@getjoin.io
17 Boulevard de Berlin, France