Privacy Policy
Last updated: August 2026
1. Overview
Avocado Fund ("we", "our", "the Protocol") is committed to protecting your privacy. This policy describes how we collect, use, and handle information when you use our interface at avocado.fund.
As a decentralized protocol, all transactions occur on public blockchains and are inherently transparent and immutable. Wallet addresses, transaction amounts, and timestamps are visible to anyone.
2. Information We Collect
Automatically collected:
- IP address (anonymized after 24 hours)
- Browser type and version
- Pages visited and time on site
- Referring URL
- Device type (desktop, mobile)
On-chain data (public):
- Wallet addresses you connect
- Transaction hashes and amounts
- Smart contract interactions
3. Analytics
We use Plausible Analytics to understand aggregate interface usage. When enabled for a campaign, we also use Addressable to attribute visits and wallet interactions to campaign sources. Addressable may process device, browser, referral, wallet-connection, and on-chain interaction data and may use third-party cookie-sync or similar attribution technologies. We do not sell this data. You can block non-essential tracking scripts with browser privacy controls or a content blocker.
4. Cookies
The interface uses local storage and may use cookies or similar technologies for:
- Theme preference (light/dark mode)
- Wallet connection state
- Local analytics session ID
- Campaign attribution when the Addressable integration is enabled
Campaign attribution is non-essential to the lending contracts. Blocking it does not prevent direct smart-contract use, though some interface analytics may not function.
5. Identity Verification & KYC Data
When you apply to borrow from the protocol, identity information is processed to verify eligibility, assess creditworthiness, and prevent fraud. Verification is currently performed through a manually-reviewed form (ID + selfie), with review completed by our team within 2-24 hours. The active verification screen identifies the process in use before you submit information.
Identity data collected:
- Full legal name, date of birth, residential address
- Government-issued ID (passport, driver's license) - front and back photos
- Selfie photo for liveness verification
- Credit bureau data (via Creditsafe or similar providers)
- Bank account connection data (via TrueLayer or similar providers)
How we use this data:
- Verify your identity and comply with KYC/AML requirements
- Assess creditworthiness and assign credit tiers
- Prevent fraud and protect the protocol
- Maintain regulatory compliance
Data storage & retention:
- Avocado receives the submitted identity documents for manual review
- Manual reviews are conducted within 2-24 hours of submission
- Identity data is retained only as long as needed for verification, fraud prevention, legal obligations, dispute handling, and enforcement, then securely deleted or anonymized
- Processors may include identity verification, credit check (Creditsafe), and bank verification (TrueLayer) providers, depending on the feature in use
Your rights:
- Request access to your identity data at any time
- Request data correction if information is inaccurate
- Request data deletion (subject to regulatory retention requirements)
- Withdraw consent for future borrowing (existing loans remain valid)
We do not sell your identity data to third parties. Data is used solely for creditworthiness assessment, fraud prevention, and regulatory compliance. To exercise your rights or for questions about identity data, contact [email protected].
6. Data Retention
Server logs are retained for up to 90 days and then deleted. Analytics data is aggregated or minimized where practical. Identity data is handled under Section 5 and is not covered by the general server-log retention period.
7. Third-Party Services
The interface may interact with third-party RPC providers (e.g. Alchemy, Infura) to read blockchain state. Other providers may include Plausible, Addressable, identity verification, Creditsafe, and TrueLayer, depending on the feature and configuration in use. These providers have their own privacy policies. You may configure a custom RPC endpoint in your wallet settings.
8. Your Rights
If you are located in the EU or UK, you have rights under GDPR including the right to access, rectify, erase, and port your data. To exercise these rights, contact us at [email protected]. Note that on-chain data cannot be erased due to the immutable nature of blockchain technology.
9. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. Your continued use of the interface after changes constitutes acceptance of the updated policy.
10. Contact
For privacy-related questions, contact us at [email protected]