Legal

Privacy Policy

Last updated: October 2, 2026

Last updated: October 2, 2026

This Policy describes how Nodo AI, Inc. (“Nodo”, “we”) handles information when you use Nodo on the web, iPhone, iPad, or desktop, or when you visit nodoia.app.

By using the Platform you accept this handling. Account, shop, Protecta, business, plan, wallet, and P2P details are also in the Terms of Use, Wallet and custody, and AML, KYC, and verification. To decide whether a use fits, see when Nodo fits.

1. Who is responsible

Nodo AI, Inc. operates the Platform. Legal address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Branch (correspondence): 2261 Market Street, San Francisco, CA 94114, United States. EIN: 37-2193232.

For your account data (email, sign-in identifiers, preferences), Nodo decides the processing.

For shop data — products, prices, the page, and the WhatsApp number for orders — the person who opens the shop introduces it and must have a basis to do so. Nodo processes it to provide the service. On a Protecta order, Nodo processes the order data in order to hold the money, pay it out, or refund it.

2. What we process

2.1 Account

  • Name or alias, email, profile photo if you upload one
  • Identifiers from the sign-in provider (Apple, Google, or another we enable)
  • Language, theme, notification preferences
  • Device identifiers for alerts, if you turn them on

2.2 Shop

  • Name, country, a tax id when it applies (for example RNC)
  • The WhatsApp number where orders arrive
  • Products, photos, and prices
  • The page, standard or designed for the shop
  • The account where you get paid, if the flow asks for it

2.4 Fiscal invoicing

If you connect e-CF: provider, certification status, tax id, and the metadata the flow asks for. The contents of a receipt follow the provider and the tax authority.

2.5 Plan payments

The plan is charged by a third party (Stripe). Nodo keeps subscription status and payment-customer references, not the full card number.

2.6 Wallet and on-chain activity

If you use the wallet:

  • The wallet address we bind to your account (Privy smart wallet or an address you connected)
  • Activity we index on Base (USDC and, for history, USDT transfers involving that address)
  • Send/receive actions you start in the app (destination address, amount, transaction hash once it exists)

We do not store your private keys or a seed phrase. Amounts and addresses on Base are already public on the chain.

2.7 P2P trading

If you post or take a trade:

  • Ad side, price, limits, and the payment methods you configure
  • Bank or remittance details you enter so the other party can pay you (holder name, account number, cédula or IBAN where the rail asks, and similar fields)
  • Order state, escrow address, and transaction hashes
  • Trade chat (text and images, including payment proofs)

Payout details stay hidden from the buyer until the escrow is linked, then they are shown to complete the off-chain payment. They are sensitive; we keep them to run the trade and to handle disputes.

2.8 USDC

A shop order is not a USDC charge at a register. USDC sits in the wallet and, on a P2P trade, in that trade’s escrow. See the wallet and P2P sections.

2.9 Merchant cash-out requests

If you submit a business-wallet cash-out request we process (or store, while the rail is still being finalized):

  • Bank, account type, holder name, account number
  • Amount in DOP and the fact that you requested a payout

That request is not an automated off-ramp today. See Wallet and custody.

2.10 Public shop

If you publish a shop:

  • Shop name, products, photos, prices, and the public URL
  • What a visitor puts in the cart to build the message

The page is visible to anyone who opens it. Publishing is the owner’s decision.

2.11 WhatsApp order

Nodo builds the order text and opens WhatsApp to the shop’s number, on the sender’s device. We do not receive or store the WhatsApp conversation. Payment on that path happens outside Nodo.

2.12 Protecta

If an order enters Protecta, we process:

  • Who buys and who sells (account and alias)
  • Title, description, terms, products, amount, and currency
  • That order’s fees, fixed when it was quoted
  • Status (accepted, paid, in custody, delivered, disputed, released, refunded, closed)
  • The order thread: messages and proofs the parties upload
  • Whether the payment was confirmed, rejected, or refunded

We do not store the full card number. The processor connected to that charge does. Nodo holds the order’s money; that custody is described in the terms, section 10.

2.13 Merchant marketplace application

If you use Verify: brand name, category, phone, catalog questions, and notes. A cédula image is optional and not required in the current wizard. Admin review produces verified / rejected status. That is not document KYC for wallet or P2P.

2.14 Technical

  • Device type, OS, language, time zone
  • IP address and error or performance logs
  • Cookies or local storage to keep you signed in

We do not ask for the phone’s location to “match” people. If a future flow uses location (for example a floor map), we will ask then.

3. Why we use it

  • Create and keep your account and your shop
  • Publish the page — the standard one or one designed for the shop — and build the WhatsApp message that leaves from the sender’s device
  • Hold, pay out, or refund a Protecta order, and review its thread if there is a dispute
  • Bind a wallet and show balances and history
  • Run P2P ads, orders, chat, and disputes
  • Receive and review a merchant cash-out request
  • Detect abuse, failures, or fraud
  • Improve the product
  • Meet the law and answer an authority when we must

We do not sell your personal information.

4. Who we share with

Only what is needed:

  • Infrastructure (hosting, transactional email, technical logs)
  • Payments (the processor connected when a Protecta order is charged to a card, and Stripe if there is an account plan). Nodo does not store the full card number
  • Sign-in and wallet (Apple, Google, Privy, or the provider you use)
  • Fiscal invoicing, if the owner connects a provider or starts certification
  • The other party to a P2P trade, for the payout details and chat needed to complete that trade
  • The other party to a Protecta order, for the thread, the status, and what is needed to deliver, dispute, pay, or refund
  • WhatsApp, only because the sender opens the conversation on their device. Nodo does not operate that chat
  • The public Base chain, when you or the escrow contract publish a transaction (that is not a “share” we control; it is how the network works)
  • Authorities, when the law requires it

A page designed for the shop uses the shop’s catalog. That engagement, if it is signed, follows these rules or the ones in that contract.

5. Retention

We keep the account and business while the service is active, plus whatever extra time the law requires (for example sales, payment, or trade records).

P2P orders, escrow addresses, chat, cash-out requests, and Protecta orders (including the thread) may be kept longer than a closed ad if we need them for a dispute, a claim, or the law.

If you delete the account or the business, we delete or anonymize what we no longer need, except what we must keep by law or to close a claim. Deleting the account does not erase public chain history.

6. Security

We encrypt traffic, restrict internal access, and host on managed infrastructure. Private keys are not on our servers. No system is perfect. If an incident materially affects you, we will notify you as required.

On-chain escrow and payments follow the contracts on Base. That is a different trust model than a deposit account; see Wallet and custody. Money on a Protecta order is Nodo’s fiat custody, not a bank deposit in your name; see the terms, section 10.

7. Your rights

Depending on your jurisdiction you may ask for access, correction, deletion, objection, or to withdraw consent. Write to info@nodoia.app. The owner manages staff data in the business; if an employee wants a name or shift fixed, the natural path is the owner, and we help if needed.

We cannot “delete” a confirmed Base transaction.

8. Children

The Platform is not directed at children under 13. A business must not load a minor as floor staff. If we find that case, we delete it. P2P, wallet, and Protecta are not for children.

9. Transfers

We use providers that may process data outside your country (including Privy and infrastructure in the United States). We take reasonable steps so the level of protection still holds.

10. Cookies

On the web we use the minimum for session, language, and security. Clearing the browser store signs you out.

11. Changes

We will publish the updated policy on docs.nodoia.app, with a date. Use after a reasonable change means you accept it.

12. Contact

Nodo AI, Inc.
131 Continental Dr, Suite 305, Newark, DE 19713, United States
2261 Market Street, San Francisco, CA 94114, United States (branch)
EIN: 37-2193232

info@nodoia.app · nodoia.app