| Item | Detail |
|---|
| Legal Entity | Paytex Solutions Ltd. |
|---|
| Trade Name | Monitiva |
|---|
| FINTRAC MSB | Registered — #C100000118 |
|---|
| Bank of Canada PSP | Registered under RPAA — REG-3961 (February 2, 2026) |
|---|
| Privacy Officer Email | privacy@monitiva.com |
|---|
| Registered Office | 807-130 Spadina Ave, Unit 807, Toronto, Ontario, M5V 2L4, Canada |
|---|
| Website | https://monitiva.com |
|---|
1. Introduction and Commitment
Paytex Solutions Ltd., operating under the trade name Monitiva ("we," "us," "our," or "Monitiva"), is committed to protecting the privacy and personal information of all individuals who interact with our services, whether through our waitlist, website, mobile applications, or financial platform. This Privacy Policy explains how we collect, use, disclose, and protect your personal information at every stage of your relationship with us.
1.1 About Monitiva
Monitiva is a Canadian corporation incorporated in the Province of Ontario (Ontario Corporation Registration Number: 1000801222), registered as a Money Services Business (MSB) with FINTRAC (#C100000118) and as a Payment Service Provider (PSP) with the Bank of Canada under RPAA (REG-3961, registered February 2, 2026).
Monitiva provides cross-border domestic payment infrastructure enabling users to maintain a safeguarded Local Balance — held in trust in Canadian dollars with a prudentially regulated Canadian financial institution or trust company — and to execute domestic payments in Destination countries through a Just-in-Time (JIT) FX mechanism. At the exact instant a User confirms a payment instruction, Paytex simultaneously converts the required CAD amount and executes the domestic payment (SPEI in Mexico; additional Destination rails as they become available) from Paytex's own corporate accounts in the Destination jurisdiction. No foreign client balance is created at any point. Client funds never leave Canada until a User-instructed payment or withdrawal executes.
Data Controller Declaration: Paytex Solutions Ltd. dba Monitiva acts as the data controller for all personal data collected through the Platform, waitlist, and associated services.
1.2 Two Operational Phases Covered by This Policy
CURRENT STATUS — PRE-LAUNCH: Monitiva is currently in a pre-launch phase. The only service available today is waitlist registration. Monitiva does not currently open accounts, accept or hold client funds, or process payments. Accordingly, the Phase 2 processing described below — identity verification, biometric verification, risk assessment, location data, and transaction monitoring — does not occur today. It describes the processing that will apply when payment services launch and you open a Monitiva Account. Only the Phase 1 processing described below applies to you at present.
Phase 1 — Waitlist and Pre-Launch: Collection of interest registration information (name, email, city, user profile, urgency indicator, payment frequency, and monthly spend estimate) through landing pages and waitlist forms, including campaign and marketing analytics.
Phase 2 — Full Platform: Processing of personal and financial information necessary to provide payment services, including identity verification (KYC), risk assessment, transaction processing, regulatory reporting, and AML/CTF compliance.
1.4 Acceptance
By accessing our website, submitting your information for our waitlist, or using our services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein, subject to the legal bases set out in Section 4.
2. Scope and Applicable Law
2.1 Jurisdictional Scope
| Jurisdiction | Applicable Law | Applies To |
|---|
| Canada (Federal) | PIPEDA | All users in Canada; all Monitiva data processing |
| Quebec, Canada | Act 25 — Act Respecting the Protection of Personal Information in the Private Sector | Quebec residents; stricter requirements apply |
| Canada (Federal) | CASL — Canada's Anti-Spam Legislation | All commercial electronic messages and marketing |
| Canada (Federal) | PCMLTFA | Financial service users; regulatory compliance |
| Canada (Federal) | RPAA — Retail Payment Activities Act | Payment service users; operational compliance |
| European Union / EEA | GDPR — General Data Protection Regulation | Users in EU/EEA, including via CA→EU corridor (deferred) |
| Mexico | LFPDPPP — Ley Federal de Protección de Datos Personales | Mexican resident users; CA→MX corridor participants |
3. Information We Collect
3.1 Waitlist and Pre-Launch Registration Data
| Category | Data Collected | Purpose |
|---|
| Identity | First name, last name | Personalizing communications; identifying waitlist participants |
| Contact | Email address | Sending waitlist confirmations, product updates, and launch notifications (CASL consent) |
| Location | City or region (self-selected) | Tailoring landing page content; prioritizing beta launch by geography |
| User Profile | Self-identified category (snowbird, property owner, digital nomad, new arrival, other) | Understanding user segments; prioritizing feature development |
| Urgency Indicator | Timeframe for needing the service | Prioritizing beta access; planning onboarding capacity |
| Payment Frequency | Estimated number of payments per month (self-reported) | Product demand analysis; feature prioritization; onboarding capacity planning |
| Monthly Spend Estimate | Estimated monthly payment volume in CAD (self-reported range) | Market sizing validation; onboarding capacity planning |
| Marketing Consent | Express opt-in consent to receive Monitiva's newsletter and marketing communications (boolean — checkbox, not pre-selected) | Legal basis for sending commercial electronic messages under CASL; consent record retained for 3 years per CASL s.13 |
3.2 Technical and Analytics Data (Automatically Collected)
We automatically collect: IP address (anonymized where feasible); browser type, version, and operating system; device type and screen resolution; referring URL and landing page URL; UTM parameters for campaign attribution; pages visited, time spent, and navigation patterns; cookie identifiers; and A/B test variant exposure.
3.3 Personal Identification Information (Platform Users — KYC)
| Category | Specific Data |
|---|
| Identity | Full legal name, date of birth, nationality, country of residence |
| Identity Documents | Government-issued photo ID (passport, driver's licence, or equivalent): type, issuing authority, number, expiry date |
| Address | Full residential address; proof of address (utility bill or bank statement not older than 90 days) |
| Contact | Email address; mobile phone number |
| PEP Declaration | Self-declaration of Politically Exposed Person status |
3.4 Financial and Transactional Information
We collect: details of the Canadian bank account you link to your Monitiva Account in order to fund your Local Balance by pre-authorized debit (account number, institution, and the name of the account holder of record); your pre-authorized debit authorization and the record of it; your Local Balance and transaction history; source of funds documentation; purpose of transactions; and Beneficiary name and domestic payment identifier (CLABE or equivalent).
Account ownership verification. When you link a Canadian bank account, we verify that the account belongs to you by comparing the name of the account holder of record against your verified legal name. We do this to prevent third-party funding, which we do not permit, and to meet our obligations under PCMLTFA and the requirements of our banking partner. If the names do not match, the account cannot be linked and you will not be able to fund your Local Balance from it. You may ask us to review this outcome (see Section 13).
3.5 Risk Assessment and Suitability Information (KYC)
To meet our risk-based obligations under PCMLTFA and to assign appropriate transaction limits, we collect the following at onboarding and, where applicable, at Enhanced Due Diligence (EDD):
| Category | Specific Data |
|---|
| Employment | Employment status and occupation; employer or business name (optional, contextual); industry category |
| Income | Annual income (range) |
| Intended Use | Declared intended use of the account |
| Expected Volume | Expected monthly payment volume (range) |
| Enhanced Due Diligence (higher-risk or higher-limit users) | Source of funds and supporting documentation; source of wealth declaration; detailed intended use; property ownership documentation where relevant |
How we use employer and business information. Where you provide the name of an employer or business, we use it to assess the risk profile associated with your declared occupation and industry, and it may be screened against adverse media sources as part of our AML/CTF due diligence. This screening is directed at the named organization in the context of your risk assessment.
Data minimization. Consistent with PIPEDA and Quebec Act 25 minimality requirements, Monitiva does not collect your Social Insurance Number (SIN) or your country of birth. These data points are not necessary for our MSB/PSP scope and are excluded by design.
3.6 Biometric Verification Information
We collect biometric information — facial images for liveness verification, and biometric data compared against your identity document — through our identity verification and compliance provider Sumsub. Biometric verification occurs at two points:
- At onboarding, as part of the identity verification process required before we can provide you with any financial service.
- On an ongoing basis, at each Cash Pickup request. Because Cash Pickup releases cash to you in person in a Destination country, we re-verify your identity biometrically each time you request a Cash Pickup, to confirm that the person making the request is you. This is a recurring verification for as long as you use Cash Pickup, not a one-time check.
By initiating identity verification, and by requesting a Cash Pickup, you grant express consent for biometric data collection exclusively for identity verification purposes. Consent is obtained explicitly within the verification flow. We do not use biometric data for any other purpose, and we do not use it to identify you in any context other than verifying your own identity to your own account.
3.7 Location Information
When you use the payment services, we collect information about where you are located. This is distinct from the website analytics described in Section 3.2 and is used for compliance and fraud-prevention purposes.
| Category | Data Collected | Purpose |
|---|
| IP-based location | The IP address from which each transaction and session originates, and the country and region derived from it | Detecting account takeover and fraud; identifying activity from jurisdictions we do not serve or that are subject to sanctions; assessing your risk profile |
| Precise device location (GPS) | GPS coordinates reported by your device at the time you instruct a payment | Fraud detection; and, for Cash Pickup, verifying that you are physically present in the Destination country |
| Device time zone | The time zone reported by your device | Corroborating your reported location, together with IP and GPS signals |
| Location over time | Whether your sessions consistently originate from a given country over an extended period | Risk assessment. Sustained activity from a country other than Canada over an extended period causes us to review your risk profile more frequently. |
Cash Pickup location gating. Cash Pickup requires you to be physically present in the Destination country. We verify this using a combination of the signals above; if we cannot confirm your presence, the Cash Pickup request is declined. You may ask us to review this outcome (see Section 13).
What we do not do with location data. We do not use location information for advertising, marketing, or profiling unrelated to compliance and fraud prevention. We do not sell or share it with marketing platforms. We do not use it to determine your tax residency or your immigration status, and we do not report it to tax or immigration authorities except where we are legally compelled to respond to a valid order or regulatory request. Our use of location data is for AML/CTF compliance, fraud prevention, and risk assessment only.
4. Legal Bases for Processing
4.1 Overview
| Legal Basis | Application | Applicable Law |
|---|
| Contractual Necessity | To provide services; to process transactions; to execute payment instructions | PIPEDA; GDPR Art. 6(1)(b) |
| Legal Obligation | To comply with PCMLTFA, RPAA, FINTRAC, sanctions screening, Travel Rule, and tax laws | PIPEDA; GDPR Art. 6(1)(c); PCMLTFA |
| Legitimate Interests | To prevent fraud and financial crime; to ensure security; to manage operational risk | PIPEDA; GDPR Art. 6(1)(f) |
| Express Consent | Marketing and commercial electronic messages (CASL); biometric data processing; non-essential cookies | PIPEDA; CASL; Quebec Act 25; GDPR Art. 6(1)(a) |
4.1.1 Legal Basis by Activity — Waitlist and Pre-Launch Phase
| Activity | Legal Basis | Notes |
|---|
| Waitlist signup (name, email, city, profile, urgency, payment frequency, monthly spend) | Consent | User submits form voluntarily; consent recorded with timestamp and policy version |
| Sending waitlist confirmation email | Contractual necessity / CASL s.6(6) implied consent | Transactional message; excluded from CASL CEM definition |
| Sending commercial electronic messages | CASL express consent | Separate opt-in checkbox required |
| Analytics — waitlist funnel | Consent (cookie banner) | Only fires after user grants analytics consent |
| Campaign attribution | Consent (cookie banner) | Only fires after user grants marketing consent |
| A/B variant and city variant tracking | Consent (functional cookies) | Required under Quebec Act 25 |
| Security and fraud detection | Legitimate interests | Necessary to protect Platform integrity |
4.2 CASL Compliance
Monitiva fully complies with CASL. We will only send you commercial electronic messages if you have provided express consent through our waitlist form or platform registration. Every commercial message identifies Monitiva as the sender, provides our complete contact information, and includes a clear, functioning unsubscribe mechanism honored within 10 business days. We maintain records of how and when consent was obtained. Withdrawal of consent does not affect transactional or service messages.
4.3 Quebec Act 25 — Specific Requirements
For Quebec residents, we apply: the principle of minimality (we collect only the minimum personal information necessary); clear, specific information about each purpose before collection; express consent before using information for purposes not identified at collection; Privacy Impact Assessments (PIAs) before implementing new technologies; data portability in structured, machine-readable format; and the ability to request de-indexation of information.
5. How We Use Your Information
5.1 Waitlist and Pre-Launch Activities
- Sending waitlist confirmation, position updates, and launch notifications
- Communicating product developments, beta access invitations, and early adopter offers (with CASL-compliant consent)
- Analyzing demand by geography and user profile
- Running A/B tests on messaging to optimize the product before launch
- Prioritizing beta access based on urgency, profile, and geographic alignment
- Sending newsletter content and marketing communications of potential interest to the User — including cross-border payment tips, product updates, and corridor-specific information — exclusively to Users who have provided separate express opt-in consent in accordance with CASL at the time of waitlist registration. Each communication will identify Monitiva as the sender, include complete contact information, and provide a clear unsubscribe mechanism honored within 10 business days.
5.2 Platform Service Delivery
- Verifying ownership of the Canadian bank account you link, and processing Local Balance funding by pre-authorized debit (PAD) against that account
- Executing JIT FX conversions and domestic payment instructions in the Destination country
- Maintaining RPAA-compliant Trust Account sub-ledgers for each client
- Providing customer support and resolving service issues
5.3 Regulatory Compliance
- Complying with PCMLTFA, including filing Suspicious Transaction Reports (STRs), Electronic Funds Transfer Reports (EFTRs), and Terrorist Property Reports (TPRs) with FINTRAC
- Complying with RPAA operational and incident reporting requirements to the Bank of Canada
- Conducting sanctions screening against applicable Canadian, US, UN, and EU lists
- Implementing and maintaining our AML/CTF program, including transaction monitoring and risk classification
5.4 Travel Rule Compliance
For transfers of CAD $1,000 or more, we are required to share sender and beneficiary information with receiving financial institutions. This is a mandatory legal requirement under PCMLTFA and does not require additional consent.
5.5 Fraud Prevention, Security, and Business Improvement
We use your information to detect and prevent fraudulent activity and account takeover; maintain audit trails for security and compliance; analyze service usage to improve our product; and personalize the user experience based on your profile and preferences.
6. Information Sharing and Disclosure
6.1 Service Providers
We share personal information with service providers strictly as necessary to deliver and safeguard the service. With the exception of Sumsub (named below given its role in identity verification and compliance), providers are described by function rather than by name; where they relate to cookies and analytics, the specific vendors are listed in our Cookie Policy.
| Provider | Purpose | Data Shared |
|---|
| Sumsub (identity verification and compliance provider) | KYC identity verification, biometric liveness check, sanctions/PEP/adverse-media screening, and transaction monitoring | Identity documents, biometric data, KYC and risk-assessment data, transaction data, screening and monitoring results |
| Cloud infrastructure provider | Secure cloud infrastructure and data storage | All customer data (encrypted at rest and in transit) |
| Prudentially regulated Canadian banking partner / trust company | Holding all client funds in trust in the Trust Account; execution of pre-authorized debits and withdrawals; verification of the account holder of record when you link a bank account; operating account management (corporate capital) | Client sub-ledger identifiers; account holder name for verification; transaction data; RPAA-required records |
| Domestic payment rail operator — Destination Corridor (CA→MX) | Domestic payment execution in Mexico via SPEI; operative account management in Mexico (corporate capital only — no client funds are deposited in Mexico) | Transaction data for CA→MX corridor only. No foreign client funds deposited. |
| Domestic payment infrastructure partner — Destination Corridor (CA→EU) | SEPA payment processing for CA→EU corridor (deferred launch); operative account management in Europe (corporate capital only) | Transaction data for EU corridor participants only. No foreign client funds deposited. |
| International settlement / FX rebalancing partner | Bilateral net settlement of Corridor Prefunding Pools between jurisdictions (corporate capital operations only) | Aggregate corporate settlement data only — no individual client personal data |
| Proprietary core banking system (internal — source code owned by Paytex) | Internal sub-ledger management; Local Balance tracking; transaction audit trail. Operated entirely within Paytex infrastructure — not a third-party data processor. | All transaction and balance data. Internal system — not shared externally. |
| Marketing and analytics providers | Campaign performance measurement; waitlist conversion tracking. See our Cookie Policy for the complete list of analytics providers and opt-out mechanisms. | Anonymized or pseudonymized behavioral data; UTM parameters; conversion events. No financial data shared. |
6.2 Regulatory Authorities
| Authority | Report Type | Legal Framework |
|---|
| FINTRAC | STR, EFTR, TPR, large cash transaction reports | PCMLTFA |
| Bank of Canada | RPAA compliance reports, incident reports (within 48 hours for material incidents) | RPAA |
| RCMP / CSIS | As directed by FINTRAC | PCMLTFA |
| Law enforcement agencies | Upon valid court orders or legal requests | Applicable Canadian laws |
| Office of the Privacy Commissioner (OPC) | Material privacy breach notifications | PIPEDA |
| Commission d'accès à l'information (CAI) | Confidentiality incident notifications presenting risk of serious harm | Quebec Act 25 |
6.3 What We Do NOT Do
Monitiva does not, and will not: sell, rent, or trade your personal information to third parties for marketing purposes; share your information with advertisers or ad networks for behavioral targeting on other platforms; or use your financial transaction data or Local Balance information for purposes other than providing and improving our services and complying with legal obligations.
7. International Data Transfers
As a cross-corridor domestic payment service provider, your personal information may be transferred to and processed in countries outside of Canada, including Mexico and, in future phases, other Destination jurisdictions. These transfers are necessary to process cross-border payments, comply with Travel Rule requirements, and work with our international partners. For transfers to the EU/EEA, we use Standard Contractual Clauses (SCCs). For transfers to Mexico, we comply with LFPDPPP requirements. By using our services, you expressly consent to the transfer of your personal information to the Destination countries necessary to complete your transactions.
8. Data Retention
| Record Type | Retention Period | Legal Basis |
|---|
| Waitlist registration data | Until 12 months after platform launch, unless earlier withdrawal of consent | CASL; PIPEDA; legitimate interests |
| Transaction records | At least 5 years from transaction date (PCMLTFA minimum); retained up to 7 years per Monitiva records policy | PCMLTFA / FINTRAC |
| Customer identification and risk-assessment records (KYC) | At least 5 years after end of business relationship (PCMLTFA minimum); retained up to 7 years per Monitiva records policy | PCMLTFA / FINTRAC |
| FINTRAC reports (STR, EFTR, TPR) and related investigation records | Minimum 7 years from date of filing (Monitiva policy; exceeds the 5-year PCMLTFA minimum) | PCMLTFA; Monitiva records policy |
| Local Balance sub-ledger records | At least 5 years; retained as part of RPAA safeguarding records (up to 7 years per Monitiva records policy) | RPAA; PCMLTFA |
| Location data associated with transactions | Retained as part of the transaction record: at least 5 years, up to 7 years per Monitiva records policy | PCMLTFA / FINTRAC |
| Biometric verification data | Each biometric check (at onboarding and at each Cash Pickup request) is retained only until that verification is complete, then deleted per Sumsub's data retention policy. The record that a verification occurred, and its outcome, is retained as part of your KYC and transaction records. | PIPEDA; express consent |
| CASL consent records | 3 years from last interaction or withdrawal of consent | CASL s.13 |
| Security incident and investigation files | Minimum 7 years; longer where required for ongoing regulatory, legal, or investigative purposes | RPAA; PIPEDA; regulatory requirements |
9. Data Security
9.1 Technical Safeguards
- Encryption in transit: TLS 1.3 for all data transmitted over the internet
- Encryption at rest: AES-256 for all stored data on our cloud infrastructure
- Multi-Factor Authentication (MFA): required for account access and all critical administrative systems
- API gateway with rate limiting, authentication enforcement, and attack protection
- Immutable backup systems with daily verification
- Endpoint Detection and Response (EDR) for continuous threat monitoring
- Regular penetration testing and vulnerability assessments
9.2 Organizational Safeguards
- Role-based access controls limiting data access to employees with business need
- Segregation of duties and four-eyes principle for high-risk operations
- Annual employee training on data protection, privacy, and AML/CTF
- Independent security audits (external review at minimum every two years)
9.3 Fund Segregation Security
Client funds (Local Balances) are held in trust in the Trust Account and are segregated from Paytex's own corporate funds. Client funds are not Paytex's property, are not used to fund Paytex's operations, and are not available to Paytex's creditors. This segregation protects client funds and is a non-negotiable operational requirement under RPAA safeguarding obligations.
10. Security Breach Notification
In the event of a security breach affecting your personal information, we will notify you without undue delay, and no later than 72 hours after determining the breach is material. We will notify: the Bank of Canada within 48 hours for material incidents (RPAA requirement); FINTRAC as required by PCMLTFA; the Office of the Privacy Commissioner (OPC) for breaches posing real risk of significant harm; and the Commission d'accès à l'information (CAI) for incidents presenting risk of serious harm to Quebec residents.
11. Your Privacy Rights
11.1 Rights Under PIPEDA (All Canadian Residents)
You have the right to: access the personal information we hold about you; request correction of inaccurate or incomplete information; withdraw consent for processing activities based on consent (subject to mandatory legal retention obligations); and file a complaint with the Office of the Privacy Commissioner of Canada (OPC).
11.2 Additional Rights Under Quebec Act 25
Quebec residents have additional rights including: data portability in structured, machine-readable format; de-indexation requests; information about automated decisions significantly affecting you; and human review of automated decisions.
11.3 Additional Rights Under GDPR (EU/EEA Residents)
EU/EEA residents have additional rights including: data portability; restriction of processing; right to object; erasure ("right to be forgotten", subject to mandatory PCMLTFA retention obligations); and the right not to be subject to solely automated decisions with legal effects.
11.4 CASL Unsubscribe Rights
You may withdraw consent to receive commercial electronic messages at any time by clicking the unsubscribe link in any commercial email, emailing privacy@monitiva.com, or updating your communication preferences in your account settings. We will honor unsubscribe requests within 10 business days.
12. How to Exercise Your Rights
To exercise any of your privacy rights, contact us at: privacy@monitiva.com | Subject: "Privacy Rights Request — [Type of Request]" | or by post: Paytex Solutions Ltd. (Monitiva), Privacy Officer, 807-130 Spadina Ave, Toronto, ON M5V 2L4, Canada. We will verify your identity before processing your request. Standard response timelines: PIPEDA — 30 days (extendable by 30 days with notice); Quebec Act 25 — 30 days (extendable by 10 days); GDPR — 30 days (extendable by 60 days for complex requests).
13. Automated Decision-Making
Monitiva uses automated systems (operated through Sumsub) to support onboarding, risk classification, and monitoring. You are never shown the underlying risk score, weights, or thresholds; you see only the outcome (for example, an assigned limit, a request for additional documentation, or a decision on your application).
| Area | Purpose | Potential Impact |
|---|
| KYC Verification | AI-powered identity document validation and liveness check | Account opening approval or rejection |
| Transaction Monitoring | Detection of suspicious activities and unusual patterns | Transaction hold or block; compliance alerts; FINTRAC reporting |
| Risk Assessment | Customer risk classification for AML/CTF due diligence | Assigned transaction limits; Enhanced Due Diligence requirements; account approval or denial |
| Fraud Detection | Identification of fraudulent patterns in real time | Temporary account suspension; hold on transactions |
| Account Ownership Verification | Comparison of the account holder of record on the bank account you link against your verified legal name | Refusal to link the account; inability to fund your Local Balance from that account |
| Cash Pickup Location Gating | Verification, from IP, GPS, and device time zone signals, that you are physically present in the Destination country, together with biometric re-verification | Real-time refusal of a Cash Pickup request |
| Payment Hold and Review | Automated flagging of a payment instruction against our transaction monitoring rules | The payment is paused pending review before it is executed |
You have the right to request human review of any automated decision that significantly affects you, including a refusal to link a bank account, a declined Cash Pickup request, an assigned limit, a paused payment, or a decision on your application. A manual review path exists for these decisions, and a member of our compliance team — not an automated system — makes the final determination on review. Contact compliance@monitiva.com with the subject "Automated Decision Review".
Where we are legally prohibited from disclosing the reason for a decision — for example, where disclosure would constitute prohibited tipping-off under PCMLTFA — we will tell you that a review has been conducted, without disclosing the underlying reason.
14. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and platform. For a complete description of the cookies we use, your consent options, and how to manage your preferences, please read our Cookie Policy at https://monitiva.com/cookies.
15. Marketing Communications
Service-related messages (waitlist confirmation, account security alerts, transaction receipts, regulatory notifications, material policy changes) are sent without additional consent. Commercial electronic messages are sent only with CASL express consent obtained through a clear, separate opt-in mechanism. You may withdraw consent at any time.
16. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, legal requirements, or data practices. We will notify you of material changes by updating the "Last Updated" date, posting a notice on our website, sending an email notification to registered users, and requesting renewed consent where required by law.
| Version | Date | Summary |
|---|
| 1.0 | April 2026 | Initial version |
| 2.1 | July 2026 | Added a pre-launch status disclosure (§1.2). Added a location information section (§3.7) disclosing IP, GPS, device time zone, and location-over-time processing and their purposes. Disclosed that biometric verification recurs at each Cash Pickup request, not only at onboarding, and updated the corresponding retention entry. Described funding as a pre-authorized debit against a linked account, and disclosed account ownership verification at linking (§3.4). Disclosed the use of employer and business name for adverse-media screening (§3.5). Added account ownership verification, Cash Pickup location gating, and payment hold-and-review to the automated decision-making table (§13). Replaced the "FBO Account" label with the Trust Account structure and aligned the fund segregation description (§1.1, §5.2, §6.1, §9.3). |
| 2.0 | June 2026 | Aligned to the per-transaction pricing model (removed subscription "plan preference" and plan-based purposes). Migrated to the Local/Destination lexicon ("Local Balance"). Updated Compliance Officer to Ruairi Austin. Named Sumsub as the identity-verification and compliance provider; other providers described by function. Added risk-assessment KYC data (§3.5) and an explicit data-minimization statement (no SIN, no country of birth). Set funding to EFT only. Updated retention to reflect the 7-year records policy. Clarified automated decision-making. |
17. Contact and Supervisory Authorities
17.2 Supervisory Authorities
| Jurisdiction | Authority |
|---|
| Canada (Federal) | Office of the Privacy Commissioner of Canada — www.priv.gc.ca | 1-800-282-1376 |
| Quebec | Commission d'accès à l'information du Québec (CAI) — www.cai.gouv.qc.ca | 1-888-528-7741 |
| EU/EEA | Data protection authority in your country of residence. See: https://edpb.europa.eu |