1. Overview & Developer Entity
LetsEscrow ("we", "our", or "the Platform", Android Package: org.letsescrow.app) operates a peer-to-peer (P2P) financial escrow exchange network. This Privacy Policy governs your use of our website (letsescrow.xyz), mobile web applications, and installed Android application. We adhere to strict data minimization: we only collect the minimum telemetry and identity details necessary to prevent financial fraud, arbitrate trade disputes, and secure financial custody.
2. Android Device Permissions & Data Usage
In compliance with Google Play Store User Data and Device Permissions policies, our Android app explicitly requests only essential hardware permissions:
Used exclusively to deliver instant background lockscreen alerts for trade status changes, counterparty chat replies, escrow releases, wallet deposits, and system security announcements via Google Firebase Cloud Messaging (FCM).
Used solely when you choose to take a photo of a physical gift card receipt or capture a verification document. Images are never recorded or transmitted in the background without explicit user action.
Allows users to select and attach payment proof screenshots and gift card image files from device storage within encrypted trade chat rooms.
Required for TLS 1.3 encrypted communication between your device and our financial escrow servers.
3. Information We Collect & Third-Party SDKs
Email address, chosen display name, avatar, preferred currency, and cryptographic password hash (stored using salted bcrypt).
Government ID images provided for KYC verification are stored in private encrypted object storage and accessed solely by authorized compliance officers.
Chat transcripts, card redemption proofs, receipt screenshots, and transaction references exchanged within encrypted trade rooms.
We integrate with trusted service partners strictly for app infrastructure: Google Firebase Cloud Messaging (FCM push delivery), Cloudflare (DDoS & bot mitigation), and PostgreSQL (encrypted database custody). We do not sell data to data brokers or ad networks.
4. Account Deletion & Data Erasure (Google Play Compliant)
You have the full right to permanently delete your account, authentication tokens, KYC documents, and personal details at any time without needing to keep the app installed.
6. Data Controller & Inquiries
For data access requests, deletion verifications, or regulatory inquiries, contact:
Email:
privacy@letsescrow.xyz / support@letsescrow.xyzWebsite:
https://letsescrow.xyz6. Blockchain Ledger & Public Addresses
Cryptocurrency transactions (USDT on TRC20/BEP20 and Bitcoin on Mainnet/Lightning) are processed on public decentralized ledgers. Deposit transaction hashes (TxHash) and destination payout addresses are published to the blockchain as an inherent function of distributed ledger technology and cannot be altered or deleted.
5. Security Safeguards & Encryption
All HTTP traffic is secured via modern TLS 1.3 encryption. We support hardware/app-based Two-Factor Authentication (TOTP Google Authenticator) and mandatory release security challenges. Database backups are encrypted at rest with AES-256 standards.
6. Cookies & Client Storage
We utilize essential HTTP-only session cookies and local storage tokens for user authentication, language preferences, and audio chimes. We do not sell user data to advertising brokers or track visitors across third-party websites.
7. Privacy Inquiries & Data Rights
Users can export their profile data or request account termination at any time by contacting our 24/7 support desk or opening a support ticket in the Support Center.