Privacy Policy

Last updated: August 2026

1. Overview

Avocado Fund ("we", "our", "the Protocol") is committed to protecting your privacy. This policy describes how we collect, use, and handle information when you use our interface at avocado.fund.

As a decentralized protocol, all transactions occur on public blockchains and are inherently transparent and immutable. Wallet addresses, transaction amounts, and timestamps are visible to anyone.

2. Information We Collect

Automatically collected:

  • IP address (anonymized after 24 hours)
  • Browser type and version
  • Pages visited and time on site
  • Referring URL
  • Device type (desktop, mobile)

On-chain data (public):

  • Wallet addresses you connect
  • Transaction hashes and amounts
  • Smart contract interactions

3. Analytics

We use Plausible Analytics to understand aggregate interface usage. When enabled for a campaign, we also use Addressable to attribute visits and wallet interactions to campaign sources. Addressable may process device, browser, referral, wallet-connection, and on-chain interaction data and may use third-party cookie-sync or similar attribution technologies. We do not sell this data. You can block non-essential tracking scripts with browser privacy controls or a content blocker.

4. Cookies

The interface uses local storage and may use cookies or similar technologies for:

  • Theme preference (light/dark mode)
  • Wallet connection state
  • Local analytics session ID
  • Campaign attribution when the Addressable integration is enabled

Campaign attribution is non-essential to the lending contracts. Blocking it does not prevent direct smart-contract use, though some interface analytics may not function.

5. Identity Verification & KYC Data

When you apply to borrow from the protocol, identity information is processed to verify eligibility, assess creditworthiness, and prevent fraud. Verification is currently performed through a manually-reviewed form (ID + selfie), with review completed by our team within 2-24 hours. The active verification screen identifies the process in use before you submit information.

Identity data collected:

  • Full legal name, date of birth, residential address
  • Government-issued ID (passport, driver's license) - front and back photos
  • Selfie photo for liveness verification
  • Credit bureau data (via Creditsafe or similar providers)
  • Bank account connection data (via TrueLayer or similar providers)

How we use this data:

  • Verify your identity and comply with KYC/AML requirements
  • Assess creditworthiness and assign credit tiers
  • Prevent fraud and protect the protocol
  • Maintain regulatory compliance

Data storage & retention:

  • Avocado receives the submitted identity documents for manual review
  • Manual reviews are conducted within 2-24 hours of submission
  • Identity data is retained only as long as needed for verification, fraud prevention, legal obligations, dispute handling, and enforcement, then securely deleted or anonymized
  • Processors may include identity verification, credit check (Creditsafe), and bank verification (TrueLayer) providers, depending on the feature in use

Your rights:

  • Request access to your identity data at any time
  • Request data correction if information is inaccurate
  • Request data deletion (subject to regulatory retention requirements)
  • Withdraw consent for future borrowing (existing loans remain valid)

We do not sell your identity data to third parties. Data is used solely for creditworthiness assessment, fraud prevention, and regulatory compliance. To exercise your rights or for questions about identity data, contact [email protected].

6. Data Retention

Server logs are retained for up to 90 days and then deleted. Analytics data is aggregated or minimized where practical. Identity data is handled under Section 5 and is not covered by the general server-log retention period.

7. Third-Party Services

The interface may interact with third-party RPC providers (e.g. Alchemy, Infura) to read blockchain state. Other providers may include Plausible, Addressable, identity verification, Creditsafe, and TrueLayer, depending on the feature and configuration in use. These providers have their own privacy policies. You may configure a custom RPC endpoint in your wallet settings.

8. Your Rights

If you are located in the EU or UK, you have rights under GDPR including the right to access, rectify, erase, and port your data. To exercise these rights, contact us at [email protected]. Note that on-chain data cannot be erased due to the immutable nature of blockchain technology.

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Your continued use of the interface after changes constitutes acceptance of the updated policy.

10. Contact

For privacy-related questions, contact us at [email protected]