zttldas in: settled.

Legal

Privacy Policy

Effective Date: April 2026 · Zttld Labs LLC, a Delaware Limited Liability Company

This Privacy Policy describes how Zttld Labs LLC ("Zttld," "we," "us," or "our") collects, uses, and discloses personal data when you access or use the Zttld platform at zttld.com and zttld.io. It includes additional disclosures required by the EU General Data Protection Regulation ("GDPR") and the UK GDPR for residents of the European Economic Area, the United Kingdom, and Switzerland.

1. Introduction

Zttld is a non-custodial freelance marketplace that uses public blockchain infrastructure (Base Layer 2, USDC) to coordinate milestone-based payments between Clients and Freelancers. Because some data we process is recorded on a public blockchain, certain disclosures in this policy differ from a typical SaaS privacy notice. Please read this policy carefully, particularly Section 5 (Blockchain Data).

For the purposes of the GDPR and UK GDPR, Zttld Labs LLC is the "data controller" for personal data processed in connection with your use of the Platform.

2. Information We Collect

2.1 Information You Provide

  • Account data: name, email address, password, profile photo, professional bio, skills, and time zone.
  • Verification data: government-issued ID, proof of address, date of birth, and tax identification numbers (W-9 / W-8BEN).
  • Financial data: wallet addresses, tax forms, and payout preferences.
  • Contract data: job descriptions, milestone definitions, deliverable submissions, messages, dispute filings, and review content.
  • Support data: any information you share when contacting us.

2.2 Information Collected Automatically

  • Device and log data: IP address, browser type, operating system, device identifiers, referral URLs, pages viewed, and timestamps.
  • Cookies and similar tracking technologies — see Section 4.
  • Wallet connection metadata when you connect a self-custodial wallet (address, chain ID, connection time).

2.3 Information From Third Parties

  • Identity verification partners (e.g., Persona).
  • Blockchain analytics providers (Chainalysis, TRM Labs): wallet screening results, transaction risk scores, and sanctions-related flags for OFAC compliance.
  • Sanctions list providers (OFAC SDN, EU Consolidated, UK OFSI).
  • Fraud-prevention services and communications platforms integrated with Zttld.

2.4 Sensitive Data

Government-issued ID images and biometric templates derived from ID verification may constitute "special category" data under the GDPR. We process such data only where it is strictly necessary for identity verification and anti-money laundering compliance, on the legal bases set out in Section 2.5.

2.5 Legal Bases for Processing (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 (and, where applicable, Article 9) of the GDPR:

  • Performance of a contract (Art. 6(1)(b)): processing required to create your account, match you with counterparties, coordinate escrow milestones, process payouts, and provide support.
  • Compliance with a legal obligation (Art. 6(1)(c)): KYC/AML screening, OFAC and UK OFSI sanctions compliance, tax reporting (1099-K), record retention, and responding to lawful requests from authorities.
  • Legitimate interests (Art. 6(1)(f)): securing the Platform against fraud and abuse, debugging, improving our services, and defending legal claims. Our legitimate interests are balanced against your rights and freedoms; you may object at any time as described in Section 7.
  • Consent (Art. 6(1)(a)): where we ask for it, including for non-essential cookies, optional marketing communications, and processing of sensitive data under Article 9(2)(a). Consent may be withdrawn at any time.
  • Substantial public interest / AML (Art. 9(2)(g)): where sensitive data is processed for sanctions screening or anti-money-laundering compliance.

3. How We Use Your Information

  • Create and operate your account, verify your identity, and maintain platform security.
  • Match Clients and Freelancers, display profiles, and facilitate contracts and messaging.
  • Coordinate milestone funding, payouts, and refunds via the Commerce Payments Protocol.
  • Screen wallet addresses and user identities against sanctions and PEP lists on an ongoing basis.
  • Generate tax forms (1099-K) and file required reports with tax authorities.
  • Prevent fraud, abuse, and violations of our Terms of Service.
  • Respond to disputes, legal process, and support requests.
  • Improve the Platform through analytics and product research.
  • Send transactional and, where permitted, marketing communications.

3.6 Automated Decision-Making (Article 22 GDPR)

Some aspects of our service involve automated processing that may produce legal or similarly significant effects — in particular:

  • Automated sanctions screening of user identities and wallet addresses, which may result in account suspension or declined onboarding.
  • Automated risk scoring of transactions for fraud and AML purposes, which may result in additional verification requests or blocked transactions.
  • Smart-contract auto-release of milestone payments after the 5-business-day approval window described in the Terms of Service.

These automated decisions are necessary for entering into or performing our contract with you and for compliance with our legal obligations (Article 22(2)(a) and 22(2)(b) GDPR). Where applicable, we apply suitable measures to safeguard your rights, including the right to obtain human intervention, express your point of view, and contest the decision by contacting privacy@zttld.com. A Zttld team member will review the automated outcome and respond to you within a reasonable time.

4. Cookies and Similar Technologies

We use cookies, local storage, and similar technologies to authenticate sessions, remember preferences, measure usage, and improve security. You can manage non-essential cookies through your browser settings or through the cookie banner shown on your first visit. Blocking essential cookies may break core Platform functionality.

5. Payment Network Data — Important Disclosure

5.1 Payment Network Transparency

The Zttld Platform coordinates payments on Base, a public blockchain. Information recorded on-chain — including wallet addresses, transaction amounts, timestamps, and smart-contract state — is permanently public, immutable, and outside our ability to delete or redact. You acknowledge and understand that:

  • On-chain records will persist even after you delete your Zttld account.
  • Blockchain analytics providers and third parties may associate wallet addresses with other publicly available information.
  • Zttld has no technical ability to modify or remove on-chain transaction records.

5.2 Your Payment Account Identifier

Off-chain, we store your wallet address and associate it with your account for operations, tax reporting, and compliance.

6. How We Share Your Information

We share personal data only with:

  • Service providers acting as processors on our behalf (hosting, email, identity verification, analytics, fraud prevention, customer support) under written agreements that restrict their use of data.
  • Blockchain analytics and sanctions-screening providers (Chainalysis, TRM Labs) to meet legal obligations.
  • Payment and tax-reporting partners (including the IRS and equivalent authorities where required).
  • Counterparties on the Platform, to the limited extent necessary to facilitate a contract (e.g., the Client sees the Freelancer's profile, deliverables, and wallet address).
  • Law enforcement, regulators, or courts in response to a lawful request, or where necessary to protect the rights, property, or safety of Zttld, our users, or the public.
  • Successors in the event of a merger, acquisition, reorganization, or sale of assets, subject to standard confidentiality protections.

We do not sell personal data for monetary consideration.

7. Your Rights and Choices

7.1 Account Controls

You can access and update much of your account information directly through your Zttld account settings, or by contacting privacy@zttld.com.

7.2 US Residents

Depending on your state (including California, Colorado, Connecticut, Virginia, Utah, and others), you may have the right to request access, deletion, correction, and portability of your personal data, and to opt out of targeted advertising or certain profiling. California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA.

7.3 EU, UK, and Swiss Residents (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights, subject to conditions and exemptions under applicable law:

  • Right of access (Art. 15): obtain confirmation of whether we process your personal data and receive a copy.
  • Right to rectification (Art. 16): have inaccurate or incomplete data corrected.
  • Right to erasure / "right to be forgotten" (Art. 17): request deletion of data we no longer need. Note that on-chain data cannot be deleted; we will delete off-chain records to the extent permitted by law.
  • Right to restrict processing (Art. 18).
  • Right to data portability (Art. 20): receive data in a structured, machine-readable format.
  • Right to object (Art. 21): object to processing based on our legitimate interests or for direct marketing.
  • Right not to be subject to solely automated decisions (Art. 22): as described in Section 3.6, including the right to obtain human review.
  • Right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint with your supervisory authority (for example, the UK's Information Commissioner's Office, Ireland's Data Protection Commission, or your local EU authority).

To exercise these rights, contact privacy@zttld.com. We will respond within one month, subject to extensions permitted by the GDPR.

8. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, including to provide the Platform, comply with legal obligations (tax, AML, sanctions), resolve disputes, and enforce our agreements.

  • Account and transactional data: at least 5 years after account closure, to satisfy tax and AML record-keeping obligations.
  • Dispute records: minimum 5 years from resolution.
  • KYC documents: retained for the duration of the account plus the statutory period required by AML law in the relevant jurisdiction.
  • On-chain data: permanent and cannot be deleted by Zttld.

9. International Data Transfers

Zttld is based in the United States. When you use the Platform from outside the United States, your personal data is transferred to, stored, and processed in the U.S. and in other countries where our service providers operate. Laws in those countries may differ from the laws of your country.

For transfers of personal data from the European Economic Area, the United Kingdom, and Switzerland to countries not deemed to provide an adequate level of protection, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and, where applicable, the Swiss addendum, as the legal mechanism for the transfer. We also apply supplementary technical and organizational measures (including encryption in transit and at rest, access controls, and vendor due diligence) consistent with the guidance of the European Data Protection Board.

A copy of the SCCs we use with a specific processor is available on request from privacy@zttld.com.

10. Security

We use administrative, technical, and physical safeguards — including TLS encryption in transit, encryption at rest for sensitive data, role-based access controls, audit logging, and independent security testing — to protect personal data. However, no system is impenetrable, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials and your self-custodial wallet's seed phrase or private keys.

11. Children's Privacy

The Platform is not directed to individuals under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will take appropriate steps to delete it.

12. Third-Party Services and Links

The Platform may link to or integrate third-party services (wallet providers, fiat on-ramps, decentralized arbitration services such as Kleros). Those services are governed by their own privacy policies. We are not responsible for the privacy practices of third parties and encourage you to review their policies before interacting with them.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the Platform, and we will update the "Effective Date" at the top of this page. Your continued use of the Platform after the effective date of any update constitutes your acceptance of the revised policy.

14. Data Breach Notification and Contact

14.1 Notification of a Personal Data Breach

If Zttld becomes aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will:

  • Notify the competent supervisory authority (for EU/UK residents, the relevant Data Protection Authority) without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, as required by Article 33 GDPR and the UK GDPR.
  • Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 GDPR.
  • Provide, in plain language, a description of the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
  • Comply with applicable U.S. state-level breach-notification laws (including California Civil Code §1798.82 and analogous statutes) on their required timelines.

If you believe an account or personal data has been compromised, please contact us immediately at security@zttld.com.

14.2 Contact the Data Protection Team

For any question about this Privacy Policy or to exercise your rights, contact:

Zttld Labs LLC · Privacy Policy · April 2026