DCB V1 pilot

Privacy notice

V1 pilot update · October 6, 2026

This notice describes the information used to run and protect DCB's invited pilot accounts and test transactions.

Information we collect

How we use information

We use this information to create and manage accounts, check access permissions, process pilot DCB activity, display balances and receipts, review merchant activity, investigate errors or abuse, deliver account-recovery messages, and support pilot users.

Browser and camera

Account workspaces use session cookies for sign-in. Browser storage can hold a pending transfer operation key so an uncertain payment can be checked before another attempt, and a local sign-out lock flag. The merchant terminal keeps its lock flag across app restarts until server sign-out is confirmed. Installed app files may be cached by the browser. With your permission, the Wallet can use the camera to scan a payment QR code; you can enter the reference instead.

Service providers

The V1 pilot uses application hosting, a PostgreSQL database, a public web gateway, and configured email delivery for account recovery. V1 application infrastructure runs on DigitalOcean. The Merchant Terminal also uses a Render web gateway. Other provider details can change as the pilot is deployed.

Storage and security

Passwords are stored as salted Argon2id hashes, rather than reversible encrypted passwords. Session tokens and password-reset codes are stored as hashes. KALE receipts are signed with a server-managed key. No online service can promise perfect security; protect your password, reset codes, and devices.

Your choices

You may contact DCB to request access to, correction of, or deletion of account information. Some transaction and security records may need to be retained for dispute, security, or legal reasons.

Contact

Email security@dcbsend.com with privacy questions. Do not email your password or reset code.