Privacy Policy

Last updated: August 2026

This Privacy Policy explains what personal data World Space ID collects, why, and how it's protected.

1. What we collect

DataWhy
Name, email, password (hashed)Account creation and login
Phone, shipping address, pin codePhysical card orders and delivery
Login IP, approximate location, device/browserYour own account security — shown to you under Activity → Login history
Wallet and miles transaction historyDisplaying your balance and activity accurately
Support ticket messagesResolving issues you raise

2. How location is determined

The approximate city/region shown in your login history is derived from your IP address at the time of login using a third-party IP-geolocation lookup. We do not use device GPS, and the lookup fails silently (leaving location blank) rather than blocking your login.

3. How we use your data

To operate your account, calculate your miles and tier, fulfill physical card orders, respond to support tickets, and detect fraudulent use of referral/offer codes.

4. Who can see your data

Platform administrators can see account, wallet, card, and ticket data necessary to operate the Service. Payment details (card, UPI, bank) are never seen or stored by us at all — they go directly to Cashfree Payments, our payment processor, over their own secure, PCI-DSS-compliant systems. We only receive confirmation that a payment succeeded or failed, plus a Payment ID for your records. We do not sell personal data to third parties. Aggregate, de-identified data (e.g. Anthropic-style analytics of usage patterns) may be used internally to improve the Service.

5. Data retention

We retain account data for as long as your account is active, and transaction/ledger records for as long as necessary for accurate balance history. You may request deletion of your account by contacting support, subject to records we're required to keep.

6. Security

Passwords are stored using industry-standard hashing (never in plain text). Full card numbers are never stored in this system — only a masked display format, consistent with standard PCI practices. Sessions use secure, HTTP-only cookies.

7. Your choices

You can review your own login history, update your profile address, freeze your card, and raise a support ticket at any time from your dashboard.

8. Changes to this policy

We may update this Privacy Policy periodically. Material changes will be reflected here with an updated "Last updated" date.

9. Contact

Privacy questions can be raised through the "Raise a ticket" option in your dashboard.