Privacy & Sovereign Vault Policy
Last Updated: July 2026 • Singapore Jurisdiction
1. Zero-Knowledge Identity Integration
SHAN Holdings enforces a strict client-side isolation policy for Personally Identifiable Information (PII). Authentication is delegated entirely to the decentralized network UID.one.
No customer passport numbers, national ID details, or raw email hashes are held or processed by SHAN Holdings database registries. Verifications occur through zero-knowledge proofs (ZKP) to ensure full sovereignty over personal data.
2. Singapore PDPA Compliance
In compliance with the Personal Data Protection Act (PDPA) of Singapore, our parent registry limits tracking actions to dynamic loyalty membership ID mapping (Voyager, Navigator, Sovereign). External integrations (such as travel bookings on Trip.express) verify tier statuses using secure claims tokens, preventing the transmission of address details or secondary financial records.
3. Sovereign Vault Cryptographic Auditing
Subscribers requesting access to co-branded HNWI real estate trusts or yield sweeps under SHAN Wealth & Capital store their verified KYC/AML certification within local passkey-encrypted secure vaults. During compliance sweeps, auditing requests verify certificate validity without revealing underlying financial profiles.
