This policy explains what Fyer collects when you use the Fyer app, why we collect it, who else sees it, and how long we keep it. We have written it to describe what the service actually does rather than to cover every theoretical case.
- 01 Who we are
- 02 What we collect
- 03 How we handle your passport
- 04 Why we use it
- 05 Who we share it with
- 06 Blockchain data
- 07 How long we keep it
- 08 Your rights
- 09 How we protect it
- 10 Where your data goes
- 11 Children
- 12 Changes
- 13 Contact
01Who we are
Fyer is operated by New Frontier Labs LLC. We decide what personal data is collected through the service and why, which makes us the controller of that data.
| Company | New Frontier Labs LLC, a Delaware limited liability company |
|---|---|
| Formed | October 10, 2025 · Delaware State File Number 10363007 |
| Employer Identification Number | 39-4843593 |
| Registered office | 16192 Coastal Highway, Lewes, Delaware 19958, United States |
| Privacy Officer | Privacy Officer, New Frontier Labs LLC · contact@fypherusd.com |
Write to the Privacy Officer at the address above about anything in this policy, including the rights described in section 08. We answer within 30 days.
02What we collect
Everything below is collected because a specific part of the service needs it. We do not collect anything for advertising, and we do not track you across other apps or websites.
You give us
| Data | When |
|---|---|
| Full name, nationality, date of birth | Identity check at sign-up |
| A one-way fingerprint of your passport number — never the number itself | Identity check at sign-up |
| Wallet address you deposit from | When you link a wallet |
The service records as you use it
| Data | Why it exists |
|---|---|
| Deposits, conversions, voucher issuance, spending and refunds | Your balance and history |
| Voucher records and remaining balances | So the amount shown at the counter is correct |
| App install identifier, platform, app version | Binding a session to one device and detecting hijacking |
| Push notification token | Only if you allow notifications |
| Risk signals on transactions | Detecting fraud and misuse |
| Access and change logs | Audit trail |
What we do not collect
- Your contacts, photos, calendar or location
- Advertising identifiers, and no third-party analytics or ad SDKs
- Your card or bank account details — the service never asks for them
- The private keys to any wallet
03How we handle your passport
Confirming who you are is required before Fyer can issue vouchers to you. Your passport is read by a specialist identity provider inside the app. Here is exactly what happens to it.
- Your passport number passes through our servers. To confirm your identity, we send your country, passport number, name and date of birth to the identity provider, which compares them against the passport it scanned and answers only match or no match. The passport number is encrypted before it leaves us. It is held in memory for the length of that one check.
- We store your name, nationality and date of birth.
- We store a one-way cryptographic hash of your passport number. The number itself is never written to our database. A hash lets us tell two accounts apart and stop the same passport being used twice; it cannot be turned back into your passport number.
- We do not keep the passport photo page image or the chip data after the check completes.
The scan and chip read are performed by Lordsystem Co., Ltd. inside the app, under its own privacy terms. Ask us at the address in section 01 if you want to be pointed to them.
04Why we use it
| Purpose | What it covers |
|---|---|
| Running the service | Creating your account, issuing vouchers, showing balances, processing refunds |
| Confirming identity | Checking you are who you say you are before value is issued |
| Preventing fraud and misuse | Risk scoring, duplicate-account detection, investigating suspicious activity |
| Keeping records straight | Reconciling our ledger against the voucher issuer's |
| Meeting legal obligations | Anti-money-laundering record-keeping, sanctions screening, tax and accounting records, and responding to lawful requests |
| Support | Answering you when you contact us |
We do not sell personal data, and we do not use it to build advertising profiles.
05Who we share it with
We share only what each party needs to do its job.
| Who | What they receive | Why |
|---|---|---|
| Lordsystem Co., Ltd. — voucher issuer | Voucher identifiers, amounts and usage events | KR Tourism Vouchers are issued and settled on their system |
| Lordsystem Co., Ltd. — identity verification | Your passport scan and chip read at the moment of the check, and the four passport fields we send back to confirm a match | To confirm your identity |
| Cloud hosting (Amazon Web Services) | Stores the data on our behalf | Running the service |
| Apple and Google | Push notification tokens and message payloads | Delivering notifications you turned on |
| Authorities | Only what a valid legal request requires | Legal obligation |
Lordsystem Co., Ltd. (〈lordsystem.io〉) issues the KR Tourism Vouchers and runs the passport verification used at sign-up. It handles the scan and chip read under its own privacy terms. We are based in the United States and Lordsystem is in the Republic of Korea, so confirming your identity and issuing a voucher involves sending the data described above across borders. We send only what each step needs.
06Blockchain data
When you send stablecoins to Fyer, that transfer happens on a public blockchain. The deposit address, the amount and the time are public and permanent. Nobody — including us — can edit or delete them.
We do not publish your name or passport data on any blockchain. But be aware that if you tell someone your wallet address, they can look up its activity themselves.
07How long we keep it
| Data | Kept for |
|---|---|
| Identity check results and the passport hash | 5 years after your account closes |
| Transaction and voucher records | 5 years after the transaction |
| Access and audit logs | 1 year |
| Push tokens | Until you turn notifications off or the token stops working |
| Support messages | 3 years after the matter is closed |
The five-year periods exist because anti-money-laundering rules require us to be able to reconstruct who transacted and what moved. We cannot shorten them on request. When a period ends, the record is deleted or irreversibly anonymised.
Blockchain deposits are the exception described in section 06: those entries are on a public ledger we do not control and cannot delete.
When a period ends we delete the data or strip it of anything that identifies you.
08Your rights
You can ask us to:
- show you what we hold about you
- correct anything that is wrong
- delete your data, where we are not required to keep it — see Delete your account
- pause our use of it while a dispute is open
- send you a copy in a portable format
- stop sending notifications — you can also do this in your device settings
Write to the address in section 13. We will respond within the period the law allows. Two limits are worth stating plainly: we cannot remove anything already written to a public blockchain, and we cannot delete records we are legally required to keep until that period ends.
09How we protect it
- Traffic is encrypted in transit, and the connection to the voucher issuer runs over a dedicated tunnel rather than the open internet.
- Your passport number passes through our servers only to be checked, and is stored only as a one-way hash.
- Access to production systems is restricted and logged.
- Sensitive actions in the app require your PIN.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as the law requires.
10Where your data goes
Fyer's systems run in the Republic of Korea. If you use the service from outside Korea, your data is processed in Korea. Push notifications are delivered through Apple and Google, which operate internationally.
11Children
Fyer is not for children. You must be at least 19 to use it, and the identity check at sign-up confirms your date of birth. If we learn that we hold data from a child, we delete it.
12Changes
When this policy changes we update the effective date at the top and post the new version here. If a change materially affects you, we will tell you in the app before it takes effect.
13Contact
Privacy questions and rights requests: contact@fypherusd.com
If you are not satisfied with our answer, you may complain to the data protection authority where you live, or to the Personal Information Protection Commission in Korea.