LEGAL

Privacy Policy

Effective July 2026 · rostopay, a DBA of Sieve Technologies, Inc. The short version: we are non-custodial — we never hold your biometrics, your money or your data, and every online cash payment moves directly between banks.

1. Who we are and scope

This Privacy Policy describes how Sieve Technologies, Inc., doing business as rostopay ("rostopay", "we", "us"), handles information in connection with the rostopay payment service, the facewallet, our websites and merchant tools (together, the "Service"). It applies to shoppers, merchants and visitors in the United States. For the Service, the user is the effective controller of their own vault; rostopay operates as non-custodial infrastructure.

2. The short version

We do not store photos or videos of your face. We do not hold your money. We do not keep your bank credentials. We do not sell or share personal information for advertising. Biometric processing happens on your device, payments settle bank to bank, and what we do not hold cannot be breached, sold or subpoenaed.

3. Information we process

Enrollment: name, email, phone, government ID (verified with AI OCR/MRZ parsing and then discarded — we keep a signed attestation, not the document), delivery addresses you choose to add, and the biovital token — an irreversible encrypted mathematical template derived from your face on your device.

Transactions: amount, merchant, timestamp, register and a cryptographic proof hash (Sieve ID). The financial message travels directly from your bank to the merchant’s bank; we never see or store account numbers.

Technical: device signals strictly needed for liveness, anti-deepfake and fraud prevention, processed transiently.

4. Biometric information policy

Written informed consent is collected before any biometric enrollment, as required by the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas CUBI Act, Washington law and similar statutes. Your face is converted on-device into an irreversible encrypted template split into cryptographic shards; no photograph, video or reversible representation is created or retained. We never sell, lease, trade or otherwise profit from biometric identifiers. Retention & destruction: your template exists only in your facewallet; deleting your facewallet at facewallet.rostopay.com destroys it immediately and permanently — in all cases no later than the earlier of the purpose being satisfied or 3 years after your last interaction, per BIPA’s schedule.

5. What merchants receive

When you authorize a payment, the merchant receives only what that transaction requires: payment confirmation, a verified-identity attestation, and — only if you approve — delivery details, transmitted as invisible, trackable codes so any leak is traceable to its source. Merchants never receive your bank information, biometric data or browsing history.

6. Service providers

Plaid provides open-finance bank connectivity for 11,000+ U.S. institutions under its own privacy policy — your bank credentials go to your bank via Plaid, never to rostopay. Licensed partner banks and money transmitters execute RTP, Fedwire and A2A transfers. Sieve provides the biometric verification infrastructure and KYC/AML screening (sanctions, watchlists, PEP) against 313 external verification connections worldwide. Each processor is bound by contract to use data only to provide its service.

7. What we never do

No sale of personal information. No sharing for cross-context behavioral advertising. No profiling for credit or insurance. No storage of biometric images. No data brokerage. If a category is not needed to move your payment, we do not touch it.

8. Security

End-to-end encryption in transit and at rest; templates and attestations sharded so no single party — including us — can reconstruct them; SOC 2 Type II audited infrastructure; NIST CSF-aligned operations; annual penetration testing; least-privilege access with hardware-key authentication for personnel.

9. Your rights

All users: access, correction, deletion and portability through facewallet.rostopay.com — no ticket, no waiting; deletion is immediate. California (CCPA/CPRA): right to know, delete, correct, opt out of sale/share (we do not sell or share) and to limit use of sensitive personal information. Other states (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA and equivalents): equivalent rights honored for all U.S. residents regardless of state. EU/Brazil visitors: GDPR and LGPD rights, including erasure and objection. To exercise any right: privacy@rostopay.com — answered within 30 days, never with a fee.

10. Data retention

Transaction proof hashes are retained as required by financial recordkeeping law (BSA: five years) — they contain no personal data. Attestations expire and are re-derived; your vault contents live with you and die with your deletion. We retain the minimum required by law and nothing more.

11. Children

The Service is for adults 18+. We do not knowingly process information of minors; suspected minor enrollment is terminated and erased.

12. Changes and contact

Material changes are notified in-product 30 days in advance. Questions and requests: Sieve Technologies, Inc. — privacy@rostopay.com.

Explore rostopay

Online cash payment, biometric checkout and pay-with-your-face resources.