This Privacy Notice is effective as of 7 September 2026.
Privacy Notice
This Privacy Notice explains how CoinsPaid processes the personal data of customers, users and website visitors (referred to in this Notice as “you” or “your”).
Our contact details
All references to “CoinsPaid”, “we”, “us” or “our” in this Privacy Notice mean CoinsPaid.
Depending on the context, CoinsPaid may act as a data controller or as a data processor on behalf of a client. Where CoinsPaid acts solely as a data processor, the relevant client determines the purposes and means of the processing and is primarily responsible for providing the applicable privacy information and handling data subject requests, unless applicable law provides otherwise.
For questions about how we process personal data, please contact our Data Protection Officer at: [email protected].
The categories of personal data subject to processing
When acting as a data processor, we may process the following categories of personal data on behalf of our clients:
- Information related to cryptocurrency wallets, including wallet addresses and associated data;
- Transaction data, including transaction dates and times, transaction IDs (TxIDs), balances and risk scores;
- Information related to fiat transactions, including SEPA or SWIFT data required for processing payments;
- IP addresses, browser and operating system details, device fingerprints and other technical data used to access or interact with the Services;
- Email addresses of account operators or individuals authorized to access or manage an account;
- Information regarding system fees, transaction limits and other operational parameters for activities such as deposits, withdrawals and exchanges;
- Data related to the version of the API used for integration with the Services;
- Account and authentication information, which may include user IDs, passwords, access keys, other authentication mechanisms and information about authorized users;
- Data used for technical support, service optimization, troubleshooting and performance analysis.
When acting as a data controller, we may process the following categories of personal data:
- Contact information, including name and email address;
- Signatures and authorization information;
- Financial and source-of-funds information, including bank statements, pay slips, tax declarations and similar supporting documents where required;
- Identification and verification information, including identification documents, photographs, passport numbers and information relating to directors, ultimate beneficial owners, account holders and other relevant individuals;
- Professional and role information, including position and CV information where required for due diligence;
- Information contained in corporate and ownership records, including incorporation documents, shareholder and director information, constitutional documents and ownership structures;
- Video interview data where enhanced due diligence or additional verification is required;
- Location information, including country of residence and residential address;
- IP addresses and other technical identifiers;
- Age;
- Website usage information, including logs and activity on the website.
Website Analytics and User Experience
We use Microsoft Clarity and Microsoft Advertising to understand how users interact with our website through behavioral metrics, heatmaps and session replay. Website usage data may be collected through first- and third-party cookies and similar technologies. We may use this information for website optimization, security and fraud prevention, and, where applicable, marketing and advertising. For more information about these technologies and available choices, please refer to our Cookie Policy and the Microsoft Privacy Statement.
Purpose of the processing
We process personal data for the purposes described below.
When acting as a data processor, we process personal data on behalf of our clients to provide services such as:
- Facilitating payments using virtual currency;
- Supporting conversion services for digital assets;
- Managing virtual currency wallets;
- Providing API integrations that enable clients to offer services to their end customers;
- Setting up and administering client accounts.
When acting as a data controller, we may process personal data for purposes such as:
- Regulatory compliance and fraud prevention, including AML, KYC, KYB, counter-terrorist financing and sanctions screening, due diligence, transaction monitoring and prevention of fraud, money laundering and other illicit activity;
- Legal and operational integrity, including regulatory compliance, audits, recordkeeping and dispute resolution;
- Risk and security management, including evaluating risk profiles, protecting assets and accounts from unauthorized access, and preventing fraud and scams;
- Financial and transaction management, including maintaining transaction records, managing invoicing and facilitating fiat currency transactions through financial service providers;
- Communication and assistance, including responding to requests, providing service information, news and updates, and supporting lawful investigations and regulatory requests;
- Protection of rights and interests, including establishing, exercising or defending legal claims and safeguarding users and the organization;
- Website analytics and optimization, including understanding website usage and improving user experience and service performance.
We may use automated tools, including profiling, to support activities such as onboarding, account management, risk assessment and fraud prevention. Where a decision is based solely on automated processing and produces legal effects or similarly significantly affects you, we will provide the additional information and safeguards required by applicable law.
Legal basis of the processing
The legal basis for processing depends on the personal data concerned, the purpose of the processing and the context in which it takes place. Where applicable, we may rely on:
- Contractual necessity — where processing is necessary to enter into or perform an agreement or to provide requested services;
- Compliance with legal obligations — where processing is necessary to comply with regulatory, statutory, accounting or other legal requirements;
- Legitimate interests — where processing is necessary for the operation, security, protection or improvement of our services or for other legitimate business purposes, provided that those interests are not overridden by your rights and freedoms;
- Consent — where we ask for your specific permission to process personal data for a particular purpose, including where consent is required for certain cookies or similar technologies;
- Public interest — only where this legal basis is available under applicable law for the relevant processing activity.
Sources of the personal data we process
We primarily process personal data provided directly by you or by our clients and their authorized users. We may also obtain personal data from publicly available sources and from third-party service providers, including screening databases, identity verification services, anti-fraud solutions, transaction monitoring systems and website analytics tools such as Microsoft Clarity.
The categories of recipients of the personal data we process
Where necessary for the purposes described in this Privacy Notice, we may share personal data with the following categories of recipients:
- Affiliates, agents, contractors and representatives that support our operations;
- Identity verification, compliance, screening and anti-fraud service providers;
- Providers of information from publicly available sources, including sanctions and watchlists;
- Financial service providers that facilitate fiat currency transactions;
- Travel Rule, transaction monitoring and counterparty verification providers;
- Cloud computing, hosting, IT and security service providers;
- Website analytics providers, including Microsoft Clarity;
- Law enforcement, courts, regulators or other public authorities, where required or permitted by law.
Transfers of personal data to third countries
Personal data may be transferred to and processed in countries outside the country or region in which it was collected, including outside the European Economic Area (EEA). Where applicable data protection law restricts such transfers, we use a lawful transfer mechanism, which may include:
- Adequate Level of Protection: The destination country provides a level of personal data protection deemed adequate by the European Commission’s decision.
- Appropriate Safeguards: We implement safeguards to protect your rights as a data subject, such as Standard Contractual Clauses (SCCs) or obtaining your explicit consent for the transfer.
- Legal or Public Interest Exceptions: Specific derogations may apply if the transfer is necessary for the establishment, exercise, or defense of legal claims, or is required for important reasons of public interest.
You may request information about the transfer safeguards applicable to your personal data by contacting us at [email protected].
Personal data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Notice, including to provide services, comply with legal and regulatory obligations, maintain records, resolve disputes, prevent fraud and protect our legitimate interests. Retention periods vary depending on the category of data, the purpose for which it is processed and the applicable legal requirements. Where no fixed period applies, we use these factors to determine an appropriate retention period.
You may request deletion of your personal data where applicable. In some cases, we may be required or permitted to retain certain information despite a deletion request, including for legal, regulatory, security, fraud prevention or dispute-resolution purposes.
Your rights
Subject to applicable law and the circumstances of the processing, you may have the following rights:
- Right of access — to request information about and copies of your personal data;
- Right to rectification — to ask us to correct inaccurate personal data or complete incomplete data;
- Right to erasure — to request deletion of your personal data in applicable circumstances;
- Right to restriction of processing — to ask us to limit processing in applicable circumstances;
- Right to object — to object to certain processing, including processing based on legitimate interests and, where applicable, direct marketing;
- Right to data portability — to request your personal data in a portable format and, where applicable, have it transmitted to another organization;
- Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal;
- Rights relating to automated decision-making — where applicable, to obtain information and exercise the rights available under applicable law in relation to decisions based solely on automated processing that produce legal or similarly significant effects;
- Right to lodge a complaint — to complain to a competent data protection or privacy authority.
These rights are not absolute and may be subject to conditions, exceptions and limitations under applicable law. If we cannot fully comply with a request, we will explain the reason where required.
Where CoinsPaid processes personal data solely as a data processor on behalf of a client, requests concerning that processing may need to be directed to the relevant client. We will support the relevant controller in responding to requests where required.
Certain services require personal data for KYC, KYB, AML and counter-terrorist financing checks, identity verification and ongoing activity monitoring. We may also need additional data or documents to meet legal and regulatory obligations. If required information is not provided, we may be unable to provide some or all of the relevant services.
To exercise your rights or withdraw consent where applicable, contact us at [email protected].
Additional rights depending on your location
Depending on where you live, applicable privacy laws may provide additional rights. These may include rights to opt out of the sale or sharing of personal data, targeted advertising or certain profiling; to receive information about third parties that receive personal data; to appeal a decision on a privacy request; and to receive non-discriminatory treatment for exercising privacy rights. Where these rights apply, we will provide the required method for exercising them.
If we introduce a financial incentive, loyalty benefit or material difference in price or service in exchange for personal data and applicable law requires a specific notice or consent, we will provide that information before you participate.
For Delaware consumers only
In addition to the rights listed in the section “Your rights” you benefit in addition to the following rights:
You have the right to limit the processing and/or disclosure of your Sensitive Personal Information (SPI). However, please note that we do not process SPI for secondary purposes, including:
- Targeted advertising or marketing based on sensitive financial data.
- Selling SPI to third parties (which many financial institutions do not engage in).
- Consumer profiling for purposes unrelated to fraud prevention or service delivery.
If we offer a financial incentive or a price or service difference in exchange for your personal information, we will notify you in advance and provide details on how you can opt in.
We do not sell or share your personal information for cross-context behavioral advertising. If this policy changes, we will notify you and provide information on how to opt out of such data processing. Additionally, we do not sell personal information to third parties, and therefore, no opt-out process is currently provided.
You have the right to not receive discriminatory treatment for exercising any of your privacy rights. We will not treat you differently unless we can demonstrate that the value of the personal information you provide is reasonably related to the difference in price or service offered.
Our Products and Services are not directed to or intended for use by minors. We do not intend to and we do not knowingly collect personal information from children under the age of 16. If you have reason to believe that a child under the age of 16 has provided us with personal information through this website, please contact us at [email protected] and we will take appropriate steps to remove the data from our records.
Children
Our products and services are not directed to or intended for use by children under the age of 16, and we do not knowingly collect personal data from children under 16. If you believe that a child under 16 has provided personal data through our website, please contact us at [email protected] so that we can take appropriate steps.
Personal data security
CoinsPaid uses technical and organizational measures designed to protect personal data. These measures may include:
- Encryption of communication channels;
- Encryption at rest;
- Access management controls;
- Anti-malware tools;
- Technical vulnerability management and remediation;
- Application security testing;
- Data masking.
Our platform uses SSL or TLS encryption to help protect confidential information transmitted when you send requests to us.
Changes to the Privacy Notice
We may update this Privacy Notice from time to time. Any changes will be posted on the relevant page, and where required by applicable law, we will provide additional notice through appropriate channels. The updated Privacy Notice will apply from the effective date stated in the revised version.