Maharaja Coin
Home Legacy Books Movies Wallet Terms Privacy

Legal · Maharaja Coin

Privacy Policy

Version 5.0 Effective 21 Jul 2026

In short: Malwa Brothers Limited (“Maharaja Coin”) collects only what we need to operate the app and website. We do not sell personal information. We never ask for private keys or seed phrases. When you use a fiat on-ramp partner such as MoonPay or another approved provider, that partner collects payment and KYC data under its own privacy policy — not ours. See also our Terms & Conditions.

1. Scope & data controller

This Privacy Policy explains how Malwa Brothers Limited, trading as Maharaja Coin (“we,” “us”), processes information when you use our iOS app, Android app, and website (the “Services”).

Contact: manager@maharajacoin.app
Location: Auckland, New Zealand

This Policy works together with our Terms & Conditions.

2. Information we collect

2.1 Information you provide

  • Support communications — email address and message content when you contact us
  • App preferences — settings you choose (e.g. currency display, notification opt-in)
  • Disclaimer acceptance — a local flag indicating you accepted in-app disclosures

2.2 Wallet & authentication data

  • Public wallet addresses — to display balances and transaction history from public blockchains
  • Privy identifiers — when you use embedded wallet features, Privy may process authentication data under its own policy
  • Local nicknames — optional labels stored on your device for addresses you save

2.3 Automatically collected information

  • Device type, operating system, app version, and language
  • Feature usage necessary to operate and improve the Services
  • Push notification tokens if you opt in (Apple APNs / Firebase Cloud Messaging)
  • Cached configuration, prices, and rates on device or via Firebase
  • Anonymous Firebase authentication on the website for live stats and social links
  • Diagnostic and crash information where enabled by platform policies

2.4 On-ramp partner data (MoonPay & others)

When you purchase crypto through Apple Pay, debit card, or other enabled methods, the transaction is processed by a regulated third party such as MoonPay or Stripe. Those providers may collect:

  • identity verification (KYC) documents and verification results;
  • payment card or bank details (processed directly by the provider);
  • billing address, phone number, and transaction history; and
  • wallet address, asset, amount, and currency for order fulfilment.

Maharaja Coin may receive limited transaction metadata (e.g. status callbacks, wallet address, order references) to update the app UI. We do not receive or store your full payment card number on our servers.

2.5 AI assistant interactions

If you use the in-app assistant, your questions and responses may be processed through configured backend services. Do not share seed phrases, passwords, government IDs, or payment details in chat.

3. What we do not collect

Maharaja Coin never requests, collects, or stores:

  • private keys, seed phrases, or recovery words;
  • full payment card numbers or CVV codes (handled by on-ramp partners); or
  • precise GPS location (unless a future feature explicitly requests it with consent).

We will never ask you to share wallet credentials by email, chat, social media, or website forms. Anyone making such a request is not affiliated with Maharaja Coin.

4. Local device storage

The app and website may store non-sensitive data locally on your device or in your browser, including:

  • display preferences (such as currency selection);
  • cached prices, configuration, or last-known stats;
  • optional wallet address labels or nicknames;
  • disclaimer or onboarding acceptance flags; and
  • browser localStorage entries on the website for public configuration caching.

You can clear much of this data through app settings, by clearing site data in your browser, or by uninstalling the app.

5. Anonymous authentication

The website and some app features may use Firebase Anonymous Authentication so clients can read public configuration (such as social links, prices, or stats) without creating a named account. Anonymous identifiers are assigned by Firebase and are not linked by us to your real-world identity unless you separately contact us (for example, by email for support).

6. Firebase & analytics services

We use Google Firebase and related Google Cloud services to operate the Services, including where applicable:

  • Cloud Firestore — app content, configuration, and legal documents;
  • Realtime Database — live metrics where enabled;
  • Authentication — including anonymous sign-in on the website;
  • Cloud Messaging — push notifications when you opt in;
  • Cloud Functions — server-side integrations such as assistant or on-ramp callbacks; and
  • Crashlytics / performance monitoring — only where enabled by platform policies and app configuration.

Crash reporting and performance analytics are collected only when enabled through platform SDKs and our configuration. We do not use Firebase for third-party advertising profiles.

7. How we use information

  • Provide wallet display, market data, and app functionality
  • Route on-ramp checkout to licensed partners with pre-filled order details
  • Deliver community content, notifications, and admin-published configuration
  • Maintain security, prevent abuse, diagnose errors, and improve performance
  • Respond to support requests and enforce our Terms & Conditions
  • Comply with legal obligations and lawful requests from authorities or partners

8. Legal bases (where applicable)

Depending on your region, we process data based on: (a) your consent (e.g. notifications), (b) performance of the service you request, (c) our legitimate interests in operating and securing the Services, balanced against your rights, and (d) compliance with legal obligations.

9. Third-party service providers

We use established providers to operate the Services, including:

  • Google Firebase — backend, messaging, authentication, and functions
  • Privy — embedded wallet authentication and wallet infrastructure
  • MoonPay / Stripe — fiat on-ramp, KYC, and payment processing when enabled
  • Apple & Google — app distribution and platform services
  • Solana RPC & price APIs — balances, transactions, and market data
  • AI / cloud functions — assistant and server-side integrations where enabled

Each provider processes data under its own privacy policy and only as needed for the relevant feature. We encourage you to review: MoonPay Privacy Policy, Privy Privacy Policy, and Google Privacy Policy.

10. Sharing of information

We do not sell your personal information. We may share limited data:

  • With service providers who help us operate the Services (under confidentiality obligations)
  • With on-ramp partners to initiate and fulfil transactions you request
  • When required by law, regulation, court order, or to protect rights, safety, and security
  • In connection with a merger, reorganisation, or asset transfer — with notice where required

11. International transfers

Our providers may process data in countries other than New Zealand (including the United States and European Economic Area). Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by those providers.

By using the Services, you understand that your information may be transferred to and processed in jurisdictions that may have different data-protection laws than your home country.

12. Data retention

We retain information only as long as reasonably necessary for the purposes described in this Policy:

  • On your device: preferences and caches until you clear app data or uninstall (typically until removed by you)
  • Firebase / server configuration: while needed to operate the Services and maintain accurate published content
  • Support emails: up to 24 months after resolution, unless a longer period is required for legal or dispute records
  • Push notification tokens: while notifications remain enabled, or until invalidated by the platform
  • Anonymous auth identifiers: until deleted by Firebase lifecycle rules or no longer needed for public config access
  • Crash / diagnostic logs: according to platform and Firebase retention settings where enabled (often 30–90 days)
  • On-ramp records: primarily retained by the payment provider under its policies

13. Security

We use industry-standard measures including HTTPS/TLS for data in transit and access controls on our backend. No method of storage or transmission is 100% secure. You are responsible for securing your device and not sharing wallet credentials.

14. Your choices & rights

Depending on your location (including New Zealand, the EEA, UK, California, and other regions), you may have the right to:

  • access personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion of personal data, subject to legal exceptions;
  • object to or restrict certain processing;
  • withdraw consent (e.g. disable push notifications in device settings);
  • clear locally stored data from app or browser settings; and
  • request a portable copy of your data where applicable.

14.1 Deletion requests

To request deletion of personal data we control, email manager@maharajacoin.app with enough information to verify your request. We may need to retain certain records where required by law or for legitimate business purposes (such as fraud prevention or unresolved disputes). Data stored on public blockchains or held by third-party providers (e.g. MoonPay) must often be requested directly from those parties.

You may also lodge a complaint with the Office of the Privacy Commissioner (New Zealand) or your local supervisory authority.

For MoonPay-specific data requests, contact MoonPay directly as the payment processor.

15. Cookies & local storage (website)

This website does not use advertising cookies. It uses browser localStorage for non-sensitive cached values (such as last known token price) and Firebase anonymous authentication to read public configuration. You can clear site data through your browser settings.

16. Children’s privacy

The Services are not directed at children under 13. Wallet and on-ramp features are intended for adults 18+. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

17. Changes to this policy

We may update this Privacy Policy from time to time. The effective date and version at the top will change when we do. Continued use after updates means you accept the revised policy.

18. Contact

Privacy questions or data requests:
manager@maharajacoin.app
Malwa Brothers Limited · Auckland, New Zealand

On this page

    Community software · Auckland, New Zealand

    Terms & Conditions Privacy Policy manager@maharajacoin.app

    Operated by Malwa Brothers Limited, Auckland, New Zealand. Maharaja Coin is not a bank, exchange, custodian, money transmitter, broker, or investment adviser. Fiat on-ramp and payment processing may be provided by regulated third parties such as MoonPay under their own Terms and Privacy Policies.

    © 2026 Maharaja Coin. All rights reserved.