This Privacy Policy explains how Gutschow LLC (“Gutschow,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our corporate websites, operator consoles, API sandbox, and B2B clearing / treasury software (the “Services”).
Gutschow LLC · Princeton, New Jersey, United States · Privacy inquiries: info@gutschow.xyz.
We process information to: provide and secure the Services; authenticate API and operator access; enforce Travel Rule, velocity, and sanctions-related gates; reconcile ledgers; detect fraud and abuse; fulfill contractual support; comply with law; and, for site visitors, respond to partnership inquiries.
Depending on context: performance of a contract with Customer; legitimate interests in securing and improving B2B infrastructure; compliance with legal obligations; and consent where required for optional cookies or marketing emails.
We do not sell personal information. We share data with: (a) cloud and database providers hosting the Services; (b) licensed banking / stablecoin partners when required to execute Customer-instructed settlements; (c) security, observability, and email delivery vendors; and (d) professional advisers or authorities when legally required. Subprocessors are bound by confidentiality and data-protection terms appropriate to the service.
Infrastructure may be hosted in the United States and other jurisdictions. Where required, we use appropriate transfer mechanisms (e.g., standard contractual clauses) for cross-border transfers of personal data.
Transaction and audit records are retained for the period required by Customer contracts, internal security policy, and applicable recordkeeping laws (often multi-year for financial-crime auditability). Marketing contacts are retained until opt-out or inactivity purge. Sandbox data may be deleted on a shorter cycle.
We apply administrative, technical, and organizational controls including TLS in transit, role-scoped credentials, HMAC request signing, rate limiting, and immutable audit logs. No method of transmission or storage is perfectly secure; Customers must protect their own keys and operator accounts.
Depending on jurisdiction, individuals may request access, correction, deletion, restriction, portability, or objection. Enterprise users should typically route requests through their employer (our Customer). We will not discriminate for exercising privacy rights. California residents may have additional CCPA/CPRA rights; we do not sell or “share” personal information for cross-context behavioral advertising as those terms are defined under CCPA.
The Services are not directed to individuals under 18. We do not knowingly collect children’s personal information.
We may update this Policy by posting a revised version with an updated date. Material changes affecting Customers will be communicated through reasonable commercial channels.