Uniform Labs

Privacy Policy

Last Updated: July 16, 2026

1. Introduction

This Privacy Policy (this “Policy”) describes how Uniform Labs, Inc., doing business as Multiliquid (“Multiliquid,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information in connection with our website located at https://www.multiliquid.xyz/ (the “Site”), the Multiliquid web-based user interface (the “Interface”), and any related products, technologies, tools, APIs, or services made available by us (collectively, the “Services”). The Services use or provide access to the core Multiliquid decentralized finance (“DeFi”) smart contract protocol (the “Protocol”). The Protocol is distinct from the Services and may also be used or accessed through products and services offered by third parties. We are committed to protecting your privacy and handling your data in accordance with applicable data protection laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer Privacy Act (“UCPA”), the Texas Data Privacy and Security Act (“TDPSA”), the Oregon Consumer Privacy Act (“OCPA”), the Montana Consumer Data Privacy Act (“MCDPA”), and other applicable U.S. privacy frameworks.

This Policy is incorporated by reference into the Multiliquid Terms of Service (the “Terms”) and should be read in conjunction with the Terms. Capitalized terms used but not defined in this Policy have the meanings given to them in the Terms.

By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, you must not access or use the Services.

This Policy applies to all individuals who interact with Multiliquid, including but not limited to users of the Services, prospective users, website visitors, affiliate partners, and any other individuals whose personal information we process. It applies regardless of how you access our Services, including through our Site, the Interface, APIs, integrations, or offline interactions. This Policy does not apply to products or services independently provided by third parties that use or provide access to the Protocol. Those third parties' privacy notices govern their processing of personal information.

Uniform Labs, Inc. (d/b/a Multiliquid) operates as the data controller for the personal information described in this Policy, meaning we determine the purposes and means of processing your personal data. Our Data Protection contact is Angelo D'Alessandro (COO), angelo@uniformlabs.co. If you have questions about this Policy or our data practices, you may contact us at privacy@multiliquid.xyz or Uniform Labs, Inc., 131 Continental Drive, Suite 305, Newark, DE 19713.

Important Note Regarding Public Blockchain Data: The Protocol consists of open-source smart contracts deployed on public blockchain networks. Transactions conducted through the Protocol are publicly visible on the applicable blockchain network. Multiliquid does not control and cannot ensure the privacy of on-chain transaction data. Public blockchain information, including wallet addresses and transaction details, may be permanently visible, cannot be deleted or altered by Multiliquid, and may be linked by analytics providers or other third parties to wallet addresses, transactions, or individuals.

2. Definitions

For purposes of this Policy:

  • “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual or household. Personal Information does not include publicly available information, deidentified information, or aggregated information that cannot reasonably be used to identify you.
  • “Protocol” means the core Multiliquid smart contract infrastructure deployed on public blockchain networks and designed to facilitate atomic swaps between eligible tokenized assets and stablecoins.
  • “Interface” means the non-custodial, front-end web application that permits eligible users to connect self-custodial wallets to the Protocol.
  • “Services” means the Site, the Interface, and any related products, technologies, tools, APIs, or services made available by Uniform Labs that use or provide access to the Protocol. The Services do not include products or services independently provided by third parties.
  • “Public Blockchain Data” means information that is recorded on and made publicly accessible through a distributed ledger or blockchain network, including transaction records, wallet addresses, smart contract interactions, and token balances.

3. Personal Information We Collect

We may collect and process the following categories of Personal Information. Not all categories are collected from every user; the specific information collected depends on how you interact with the Services and the features you use.

3.1 Information You Provide Directly

  • Account and Registration Data: Name, email address, username, password, and other information you may provide when creating an account or registering with the Services.
  • Wallet and Transaction Data: Public wallet addresses you connect to the Interface, transaction history, token balances, and other information associated with your use of self-custodial wallets in connection with the Services.
  • Identity Verification and Compliance Data (KYC/AML): Government-issued identification documents, photographs, proof of address, source-of-funds documentation, tax identification numbers, and other information required for know-your-customer (“KYC”), anti-money laundering (“AML”), or sanctions compliance purposes. Uniform Labs may request such information for its own compliance screening or risk assessment. Issuer-specific onboarding and KYC are conducted by the relevant issuer or integration partner unless the Interface expressly identifies Uniform Labs as conducting a particular process.
  • Communications and Support Data: Information contained in correspondence, messages, inquiries, or support requests you send to us, including your name, contact information, and the content of your communications.
  • User Content and Feedback: Information you submit, post, or provide through the Services, including feedback, reviews, survey responses, and other user-generated content.
  • Marketing and Communication Preferences: Information about your preferences for receiving communications from us, including opt-in and opt-out selections.

3.2 Information Collected Automatically

  • Device and Technical Data: IP address, browser type and version, operating system, device type, device identifiers, screen resolution, language preferences, and hardware information.
  • Usage and Analytics Data: Pages viewed, features used, clickstream data, session duration, referring and exit URLs, frequency of visits, interaction patterns, and other information about how you use the Services.
  • Geolocation and IP Data: Approximate geographic location derived from your IP address, and information used for geographic access controls, including VPN and proxy detection data.
  • Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixels, local storage, and similar tracking technologies, as described further in Section 10 below.
  • Log Data: Server logs, error reports, access logs, and diagnostic data generated in connection with your use of the Services.

3.3 Information from Third-Party Sources

  • Blockchain Analytics and Compliance Vendors: Information from blockchain intelligence tools and compliance service providers, including wallet risk scores, sanctions screening results, and indicators of illicit activity associated with wallet addresses.
  • Issuers, Stablecoin Issuers, and Integration Partners: Information received from issuers of tokenized assets, stablecoin issuers, liquidity sources, balance sheet providers, and other integration partners in connection with permissioning, eligibility, and transaction facilitation.
  • Affiliates and Business Partners: Information shared among our corporate affiliates or received from business partners.
  • Public and Commercially Available Sources: Information from public records, publicly available blockchain data, commercially available databases, and other publicly or commercially accessible sources.
  • Wallet Providers: Limited information that may be transmitted when you connect a self-custodial wallet to the Interface.

3.4 Sensitive Personal Information

In limited circumstances, we may collect information that is classified as “sensitive personal information” under certain U.S. state privacy laws, including government-issued identification numbers such as Social Security numbers, tax identification numbers, or passport numbers, precise geolocation data, and information related to racial or ethnic origin where submitted as part of identity verification documentation. Our KYC and compliance processes may involve biometric data such as a selfie for identity matching, and racial or ethnic origin may be inferable from identification documents. We may collect sensitive personal information only as necessary for the specific purposes described in this Policy and as permitted by applicable law, including for preventing fraud, money laundering, and terrorist financing in connection with financial services.

4. How and Why We Collect and Use Personal Information

We collect and use Personal Information for the following purposes:

4.1 Providing and Operating the Services

  • Providing, operating, and maintaining the Site, Interface, and Services;
  • Enabling you to connect self-custodial wallets and interact with the Protocol through the Interface;
  • Facilitating, processing, and recording transactions initiated through the Interface;
  • Managing user accounts and providing customer support; and
  • Communicating with you regarding the Services, including sending service-related notices and updates.

4.2 Compliance, Security, and Fraud Prevention

  • Verifying user eligibility and enforcing geographic and jurisdictional restrictions;
  • Conducting sanctions screening, AML/KYC checks, and wallet address screening using blockchain intelligence tools and other compliance controls;
  • Detecting, preventing, and responding to fraud, unauthorized access, security incidents, and other prohibited or illegal activities;
  • Implementing IP-based blocking, VPN detection, proxy detection, and other access controls; and
  • Restricting, suspending, or terminating access to the Services, and blocking or restricting wallets, as necessary for compliance or security purposes.

4.3 Legal and Regulatory Compliance

  • Complying with applicable laws, regulations, legal processes, or governmental requests;
  • Establishing, exercising, or defending legal claims;
  • Cooperating with law enforcement, regulatory authorities, or governmental bodies; and
  • Maintaining records required by applicable AML/KYC laws, sanctions regulations, and other legal obligations.

4.4 Improvement and Analytics

  • Analyzing usage patterns and trends to improve, develop, and optimize the Services;
  • Conducting research and development;
  • Performing data analytics and generating aggregated or deidentified information; and
  • Debugging and troubleshooting technical issues.

4.5 Communications and Marketing

  • Sending marketing and promotional communications where permitted by applicable law and in accordance with your preferences;
  • Personalizing your experience with the Services; and
  • Conducting surveys and soliciting feedback.

4.6 Corporate Transactions and Business Operations

  • Facilitating corporate transactions such as mergers, acquisitions, reorganizations, asset sales, or similar transactions;
  • Enforcing our Terms of Service and other agreements; and
  • Protecting the rights, safety, and property of Multiliquid, our users, and third parties.

6. Sharing of Personal Information

We may share Personal Information with the following categories of recipients and for the following purposes:

6.1 Service Providers and Processors

We engage third-party service providers to perform functions on our behalf, including hosting and infrastructure providers, cloud infrastructure providers, analytics providers, blockchain analytics and wallet screening vendors, KYC/AML and compliance service providers, security providers, communications and email service providers, customer support platforms, and DNS management, content delivery, DDoS protection, and web application firewall service providers. These providers are contractually obligated to use Personal Information only as necessary to provide services to us and in accordance with applicable law. All processors and service providers engaged by us process personal data on our behalf and in accordance with our instructions, subject to data processing agreements and appropriate security measures.

Our current sub-processor is FS Vector, which we use to provide compliance services. We will update this Policy if we engage or replace sub-processors and, where required by applicable law, provide advance notice of such changes.

6.2 Affiliates

We may share Personal Information with our corporate affiliates and subsidiaries for purposes consistent with this Policy.

6.3 Issuers, Integration Partners, and Liquidity Providers

We may share information with issuers of tokenized assets, stablecoin issuers, liquidity sources, balance sheet providers, and other integration partners as necessary to facilitate transactions, implement permissioning and eligibility requirements, and operate the Protocol.

6.4 Wallet Providers and Blockchain Networks

When you initiate transactions through the Interface, certain information, including your public wallet address and transaction data, is transmitted to blockchain networks and may be visible to wallet providers, validators, and other network participants. This information becomes Public Blockchain Data.

6.5 Compliance, Regulators, and Law Enforcement

We may disclose Personal Information to government authorities, regulators, law enforcement agencies, courts, and other official bodies where required by applicable law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

6.6 Professional Advisors

We may share Personal Information with our legal counsel, auditors, accountants, consultants, and other professional advisors in connection with their provision of services to us.

6.7 Corporate Transactions

In connection with a merger, acquisition, reorganization, sale of assets, financing, bankruptcy, or similar corporate transaction, we may transfer or disclose Personal Information to the relevant counterparties and their advisors, subject to appropriate confidentiality obligations.

6.8 With Your Direction or Consent

We may share Personal Information with third parties where you have directed us to do so or provided your consent.

6.9 Aggregated and Deidentified Data

We may share aggregated, deidentified, or otherwise non-personally identifiable information with third parties for any purpose. Such information cannot reasonably be used to identify you.

7. Sale and Sharing of Personal Information

Multiliquid does not sell Personal Information for monetary consideration. However, certain U.S. state privacy laws, including the California Consumer Privacy Act, as amended (“CCPA”), and similar state laws, define “sale” or “sharing” broadly to include certain disclosures of Personal Information for targeted advertising or cross-context behavioral advertising purposes.

To the extent that our use of cookies, pixels, or similar tracking technologies constitutes a “sale” or “sharing” of Personal Information under applicable state law, you may opt out of such activities as described in Section 10 below. If you wish to exercise an opt-out right, please contact us using the information provided in Section 15 or submit a request to privacy@multiliquid.xyz.

8. Data Retention

We retain Personal Information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to:

  • Provide and operate the Services;
  • Comply with applicable legal, regulatory, and compliance obligations, including AML/KYC record-keeping and sanctions requirements;
  • Prevent fraud and maintain security;
  • Resolve disputes and enforce our agreements, including the Terms of Service; and
  • Support legitimate business purposes such as analytics and service improvement.

The specific retention period for any category of Personal Information depends on the nature of the data, the purposes for which it is processed, applicable legal requirements, and our legitimate business needs. KYC/AML and sanctions screening records may be retained for extended periods as required by applicable law.

Specific retention periods include: user relationship data, including contact and behavioral information, is retained for the duration of the user relationship plus five (5) years; financial and transaction records, including KYC/AML records and tax reporting documentation, are retained for the duration of the relationship plus seven (7) years; and marketing and communications data is retained until you opt out of marketing communications.

Public Blockchain Data: Information recorded on public blockchain networks persists indefinitely and is outside the control of Multiliquid. We cannot delete, modify, or restrict access to on-chain transaction data.

When Personal Information is no longer required for the purposes described above, we will securely delete, destroy, or deidentify it in accordance with our data retention policies and applicable law.

9. Your Privacy Rights

Depending on your jurisdiction of residence, you may have certain rights with respect to your Personal Information under applicable data privacy laws, including the CCPA, the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), and other applicable U.S. state privacy laws. These rights may include:

  • Right to Know / Access: The right to request information about the categories and specific pieces of Personal Information we have collected about you, the sources of collection, the purposes for collection, and the categories of third parties with whom we share your information.
  • Right to Correction: The right to request correction of inaccurate Personal Information we hold about you.
  • Right to Deletion: The right to request deletion of Personal Information we have collected from or about you, subject to certain exceptions, including where retention is required by law or necessary for security or compliance purposes.
  • Right to Data Portability: The right to request a copy of your Personal Information in a portable, readily usable format, where technically feasible.
  • Right to Opt-Out of Sale/Sharing: The right to opt out of the “sale” or “sharing” of your Personal Information for targeted advertising purposes, as those terms are defined under applicable state law.
  • Right to Limit Use of Sensitive Personal Information: The right to limit our use and disclosure of sensitive personal information to purposes permitted under applicable law.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.
  • Right to Appeal: If we deny your privacy request, you may have the right to appeal that decision. We will provide instructions for submitting an appeal in our response to your request.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

How to Exercise Your Rights: To submit a privacy rights request, please contact us using the information provided in Section 15 below. We may need to verify your identity before processing your request. Depending on the nature of your request and applicable law, we may ask you to provide information that allows us to reasonably verify that you are the person about whom we collected Personal Information.

Authorized Agents: You may designate an authorized agent to submit a request on your behalf. We may require that you provide written authorization and verify your identity directly, or that the authorized agent provide proof of a valid power of attorney.

California Residents: If you are a California resident, you may have additional rights under the CCPA, including the right to request disclosure of the categories and specific pieces of Personal Information collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom Personal Information is shared. You also have the right to opt out of the sale or sharing of Personal Information as described in Section 7 above.

Limitations: Certain rights may be subject to limitations or exceptions under applicable law. We cannot delete, modify, or restrict access to Public Blockchain Data recorded on public blockchain networks, as such data is outside our control.

10. Cookies and Tracking Technologies

We and our service providers may use cookies, web beacons, pixels, local storage, and similar tracking technologies to collect information about your interactions with the Services. These technologies serve the following purposes:

10.1 Categories of Cookies and Tracking Technologies

  • Strictly Necessary: Essential for the operation of the Services, including security, authentication, and fraud prevention. These cannot be disabled without affecting core functionality.
  • Performance and Analytics: Used to understand how users interact with the Services, measure performance, and analyze usage trends to improve the user experience.
  • Functional: Used to remember your preferences and settings, such as language, region, and display preferences.
  • Advertising and Marketing: Used to deliver relevant advertisements and measure the effectiveness of marketing campaigns. These may involve sharing data with advertising partners.

10.2 Your Choices

  • Cookie Consent: We obtain your consent for non-essential cookies through a cookie consent banner where required by law. For more information about the cookies we use and how to manage your preferences, please refer to our Cookie Policy.
  • Browser Controls: Most web browsers allow you to manage or delete cookies through browser settings. Please note that disabling cookies may affect the functionality of the Services.
  • Global Privacy Control (GPC) and Do Not Track: We honor browser-based opt-out preference signals, including the Global Privacy Control (“GPC”), where required by applicable law. When we detect a GPC signal, we will treat it as a valid opt-out request for sales or sharing of Personal Information under applicable state law. Some browsers transmit “Do Not Track” (“DNT”) signals. We will process DNT signals in accordance with applicable law.

11. Data Security

We implement appropriate technical and organizational measures to protect Personal Information from unauthorized access, use, disclosure, alteration, or destruction. These measures include, where appropriate, TLS encryption in transit, encryption at rest, role-based access controls, multi-factor authentication on administrative accounts, firewalls, web application firewall protections, secure development practices, tokenized payment credentials, centralized identity and access management with single sign-on, employee training, pseudonymized analytics where possible, and periodic security assessments.

However, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your Personal Information, and any transmission of Personal Information is at your own risk.

Data Breach Notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by applicable law, notify affected individuals without undue delay.

Your Responsibilities: You are responsible for maintaining the security of your self-custodial wallets, private keys, seed phrases, and devices used to access the Services. Multiliquid does not have access to and cannot recover private keys or seed phrases. You are also responsible for maintaining the security of any account credentials associated with the Services.

Blockchain Security: Multiliquid does not control and cannot ensure the security of public blockchain networks, third-party wallets, or third-party protocols. Security risks inherent in blockchain technology, including smart contract vulnerabilities and network attacks, are outside our control.

12. Children's Privacy

The Services are not directed to, and we do not knowingly collect Personal Information from, children under the age of 13, or such other age as may be specified by applicable law. Furthermore, in accordance with our Terms of Service, the Services are intended for use only by individuals who are at least 18 years of age or the age of legal majority in their jurisdiction of residence, whichever is greater.

If we become aware that we have collected Personal Information from a child under the age of 13 without verified parental consent, we will take steps to delete such information promptly. If you believe we have inadvertently collected information from a child under 13, please contact us using the information provided in Section 15 below.

13. International Data Transfers

Multiliquid is based in the United States, and Personal Information we collect is primarily processed and stored in the United States. If you access the Services from outside the United States, please be aware that your Personal Information may be transferred to, stored in, and processed in the United States or other countries whose data protection laws may differ from those in your country of residence.

Where required by applicable law, we will implement appropriate safeguards for international transfers of Personal Information, which may include standard contractual clauses, data processing agreements, or other mechanisms recognized under applicable law.

By using the Services, you acknowledge and consent to the transfer of your Personal Information to the United States and other jurisdictions as described in this Policy.

14. Automated Decision-Making and Profiling

We may use automated tools and processes to support compliance, security, and fraud prevention activities. These include:

  • Automated wallet screening against sanctions lists, watchlists, and illicit activity indicators using blockchain intelligence tools;
  • IP-based geographic restriction enforcement, VPN and proxy detection; and
  • Risk scoring and fraud detection algorithms.

These automated processes may result in the restriction, suspension, or termination of access to the Services, or the blocking of wallet addresses. Where automated decisions significantly affect you, you have the right to obtain human intervention, express your point of view, and contest the decision, as provided under applicable law.

15. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, or if you wish to exercise any of your privacy rights, please contact us at:

Uniform Labs, Inc.
Address: 131 Continental Drive, Suite 305, Newark, DE 19713
Email: privacy@multiliquid.xyz
Website: https://www.multiliquid.xyz/

You may also . We will respond to your inquiry or request within the time periods required by applicable law.

16. Third-Party Links and Services

The Services may contain links to third-party websites, applications, or services that are not owned or controlled by Multiliquid, including wallet provider interfaces, issuer onboarding portals, and other DeFi protocols or platforms. This Policy does not apply to the privacy practices of such third parties.

We encourage you to review the privacy policies of any third-party services before providing them with your Personal Information. Multiliquid is not responsible for the privacy practices, content, or security of third-party websites or services.

Some assets available through the Protocol may require users to complete onboarding and KYC checks directly with relevant issuers or integration partners. Such processes are governed by those parties' own privacy policies and data practices, and Multiliquid is not responsible for the collection or processing of Personal Information by those third parties.

17. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, applicable law, or for other operational, legal, or regulatory reasons. When we make material changes, we will update the “Last Updated” date at the top of this Policy and provide notice as appropriate, which may include posting the updated Policy on the Site, displaying a notice through the Interface, or other means reasonably determined to reach you.

Your continued use of the Services following the posting of an updated Policy constitutes your acknowledgment of, and agreement to be bound by, the updated Policy. We encourage you to review this Policy periodically to stay informed about our data practices.

18. Additional State-Specific Disclosures

18.1 California Residents

This section provides additional disclosures for California residents as required by the CCPA:

  • Categories of Personal Information Collected: We may collect identifiers, customer records, commercial information, internet or electronic network activity, geolocation data, professional or employment-related information if provided, inferences, and sensitive personal information.
  • Sale or Sharing: We do not sell Personal Information for monetary consideration. To the extent tracking technologies constitute “sharing” under the CCPA, you may opt out as described in Section 10.
  • Rights: California residents may exercise the rights described in Section 9, including the right to know, correct, delete, and opt out.
  • Shine the Light: California Civil Code Section 1798.83 permits California residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. We do not disclose Personal Information to third parties for their direct marketing purposes.

18.2 Virginia, Colorado, Connecticut, and Other State Residents

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws may exercise the rights described in Section 9 to the extent provided by applicable state law. If you believe we have not adequately addressed your privacy request, you may have the right to appeal our decision by contacting us using the information in Section 15.

19. Miscellaneous

19.1 Non-Custodial Services

Multiliquid provides non-custodial services and does not take custody, possession, or control of users' digital assets. Certain limitations on our ability to fulfill data-related requests may arise from the non-custodial and decentralized nature of the Services and the Protocol. We will inform you of any such limitations in connection with your request.

19.2 No Waiver

Our failure to exercise or enforce any right or provision of this Policy shall not constitute a waiver of such right or provision.

19.3 Severability

If any provision of this Policy is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

19.4 Governing Law

This Policy and any dispute or claim arising out of or in connection with them or their subject matter or formation, including non-contractual disputes or claims, shall be governed by and construed in accordance with the laws of the State of California, United States of America, without regard to its conflict of laws principles.