1. Scope of This Privacy Policy
This Privacy Policy explains how ALIXPAY FINANCIAL NETWORK INC. (“AlixPay”, “we”, “us” or “our”) collects, uses, discloses, transfers, retains, and protects personal information when you access or use our websites, dashboards, APIs, mobile applications, hosted wallet interfaces, account tools, and related technical and operational solutions that support the Services described in our Terms and Conditions.
This Policy applies to individuals who use the Services, representatives of business customers, directors, beneficial owners, authorized signatories, employees, contractors, counterparties, beneficiaries, and other individuals whose personal information is provided to or processed by AlixPay.
This Policy should be read together with our Terms and Conditions and any applicable service agreement.
2. Privacy Laws and Accountability
AlixPay is subject to Canadian privacy requirements, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable, and other federal, provincial, or territorial privacy laws that may apply to our activities. PIPEDA generally applies to our collection, use and disclosure of personal information in the course of commercial activities; within British Columbia and Alberta, the provincial Personal Information Protection Acts may apply to intra-provincial activities, and in Québec, the Act respecting the protection of personal information in the private sector applies.
AlixPay is responsible for personal information under its control, including personal information transferred to service providers for processing. We use contractual, technical, administrative, and organizational measures designed to provide a comparable level of protection when service providers process personal information for us.
Our Privacy Officer is responsible for overseeing this Policy and our privacy management practices. You may contact the Privacy Officer at [email protected] or by mail at our registered office (Attention: Privacy Officer).
3. Meaning of Personal Information
Personal information means information about an identifiable individual. It may include information that identifies you directly and information that can identify you when combined with other information. Personal information does not generally include business contact information used solely to communicate with you in your business capacity, unless applicable law provides otherwise.
Some information we process may be sensitive, including government identification, biometric-related identity verification data, financial information, source of funds or source of wealth information, sanctions and politically exposed person screening results, wallet analytics, and transaction information.
4. Information We Collect
We collect information directly from you, from business customers and Authorized Users, automatically through the Platform, from Third-Party Providers, from public sources, and from counterparties or regulators where permitted or required by law.
- Identity and profile information: name, date of birth, nationality, address, phone number, email address, occupation, employer, title, tax residency, government identification details, photographs, selfie or video verification records, and account credentials.
- Business and KYB information: legal name, trade name, incorporation or registration number, business address, operating address, website, nature of business, regulatory or licensing status, directors, officers, authorized signatories, beneficial owners, ownership and control information, expected activity, settlement arrangements, and supporting corporate documents.
- Financial and compliance information: source of funds, source of wealth, bank account information, payment method information, card-related information where applicable, fiat and Digital Asset balances, expected activity, transaction purpose, risk ratings, sanctions screening results, politically exposed person screening results, adverse media information, wallet risk scores, and supporting documents.
- Transaction information: wallet addresses, blockchain transaction hashes, tags or memos, originator and beneficiary information, account balances, deposits, withdrawals, exchanges, payment instructions, payment routing information, settlement support information, merchant or checkout information where applicable, fees, exchange rates, receipts, transaction IDs, timestamps, transaction status, disputes, refunds, chargebacks, and related records.
- Device, technical and usage information: IP address, device identifiers, browser type, operating system, application version, language settings, time zone, login history, API usage, crash data, cookies, similar technologies, and security logs.
- Location information: approximate location derived from IP address and, where enabled by your device settings and consent, more precise geolocation information.
- Communications: support messages, emails, call records, chat records, forms, feedback, complaint information, and records of notices sent to you.
- Information from third parties: identity verification providers, KYB providers, blockchain analytics providers, sanctions and screening databases, payment processors, card networks, banks, wallet infrastructure providers, liquidity providers, business partners, public registries, law enforcement, regulators, and other sources permitted by law.
5. Biometric and Identity Verification Data
Where required for identity verification, fraud prevention, or compliance purposes, we or our identity verification providers may process facial images, liveness checks, video verification records, or similar identity verification data. We use this information only for stated verification, security, fraud prevention, and legal compliance purposes, unless we obtain further consent or another lawful basis applies.
If biometric authentication is enabled on your device, such as fingerprint or face unlock, that authentication may be handled by your device manufacturer or operating system provider. AlixPay generally does not receive or store the biometric template used by your device for local authentication.
6. Why We Use Personal Information
We use personal information for purposes that a reasonable person would consider appropriate in the circumstances, including:
- to create, administer, secure, and support Accounts;
- to operate and support hosted virtual currency wallet features, virtual currency exchange services, on-ramp and off-ramp infrastructure, API integrations, payment routing, settlement support, merchant, QR, checkout, card-related or other payment-related features where expressly made available, account dashboards, transaction records, receipts, transaction IDs, support services, and related operational tools;
- to verify identity, business status, beneficial ownership, authority, source of funds, source of wealth, and eligibility;
- to comply with AML/ATF, sanctions, fraud prevention, travel rule, transaction monitoring, tax, payment network, court, law enforcement, and regulatory requirements;
- to screen users, counterparties, wallet addresses, devices, IP addresses, transactions, and related information against sanctions, politically exposed person, adverse media, fraud, blockchain analytics, and other compliance data sources;
- to process or support transactions, display balances, issue receipts, calculate fees and exchange rates, support payment routing and settlement workflows, manage refunds, investigate disputes, respond to chargebacks, and maintain account and transaction records;
- to detect, prevent, investigate, and respond to fraud, cyber incidents, unauthorized access, account compromise, illegal activity, and violations of our Terms;
- to communicate with you about security, compliance, transactions, service updates, legal notices, support, and account administration;
- to improve, test, monitor, troubleshoot, and develop the Platform, Services, controls, and user experience;
- to send marketing communications where permitted by law and subject to your consent or opt-out rights;
- to enforce agreements, protect legal rights, complete corporate transactions, obtain professional advice, and manage business records.
7. Consent and Legal Exceptions
We rely on consent where required by applicable privacy law. Your consent may be express or implied, depending on the sensitivity of the information and the circumstances. For sensitive personal information — including government identification, biometric-related identity verification data (such as facial images, liveness checks and video verification records), and detailed financial information — we will obtain your express consent at or before the time of collection, unless collection, use or disclosure without consent is permitted or required by law (for example, under AML/ATF, sanctions or fraud-prevention obligations).
In some cases, we may collect, use, or disclose personal information without consent where permitted or required by law, including for legal compliance, fraud prevention, investigations, debt collection, emergencies, regulatory reporting, sanctions screening, AML/ATF obligations, or other lawful purposes.
You may withdraw consent for optional uses, such as certain marketing communications, at any time. Withdrawal of consent does not affect processing already completed and may not apply where processing is required to provide the Services, comply with law, protect security, or maintain required records. If you withdraw consent needed to provide the Services, we may be unable to continue providing some or all Services.
8. Marketing and Electronic Messages
We may send service, security, compliance, transactional, and administrative messages because they are necessary for the Services.
We will send commercial electronic messages, such as promotional emails or texts, only where permitted by Canada’s Anti-Spam Legislation (CASL) and other applicable laws. You may unsubscribe from marketing messages using the unsubscribe mechanism in the message or by contacting us. You may still receive non-marketing service messages. We will give effect to an unsubscribe request without delay and in any event within 10 business days, as required by CASL. Each commercial electronic message we send will identify AlixPay and include contact information that remains valid for at least 60 days after the message is sent.
9. How We Share Personal Information
We may disclose personal information to the following categories of recipients where appropriate for the purposes described in this Policy:
- Affiliates and group companies that support the Services, compliance, security, customer support, operations, or corporate administration.
- Service providers, including identity verification providers, KYB providers, blockchain analytics providers, cloud hosting providers, cybersecurity vendors, payment processors, banks, card networks, acquiring banks, issuing banks, wallet infrastructure providers, liquidity providers, customer support tools, analytics providers, auditors, legal counsel, and other professional advisors.
- Counterparties, merchants, banks, payment processors, card networks, wallet infrastructure providers, liquidity providers, and other financial service providers where necessary to process or support a transaction, comply with travel rule requirements, complete payment instructions, support payment routing or settlement workflows, resolve disputes, or manage chargebacks and reversals. For virtual currency transfers of CAD 1,000 or more, this includes transmitting required originator and beneficiary information to counterparty financial institutions or virtual asset service providers under the travel rule.
- Blockchain networks, where transaction information may be broadcast to and permanently recorded on public or private blockchain networks.
- Regulators, FINTRAC, sanctions authorities, tax authorities, courts, law enforcement, government agencies, payment networks, banks, and other competent authorities where required or permitted by law.
- Business transaction parties in connection with a merger, acquisition, financing, reorganization, sale of assets, insolvency, or transfer of all or part of our business, subject to appropriate safeguards.
- Other parties with your consent, at your direction, or as otherwise permitted or required by law.
10. We Do Not Sell Personal Information
AlixPay does not sell personal information. We may use aggregated, anonymized, or de-identified information for analytics, compliance tuning, product development, reporting, and business purposes where the information no longer identifies an individual.
11. International Transfers and Service Providers
We may store or process personal information in Canada and other countries where AlixPay, its affiliates, or service providers operate. Personal information processed outside your province, territory, or country may be subject to lawful access by courts, law enforcement, national security authorities, or regulators in those jurisdictions.
When we transfer personal information to service providers, including service providers outside Canada, we use contractual and other measures designed to protect the information and limit processing to authorized purposes.
12. Public Blockchains
Digital Asset transactions may be recorded on public blockchain networks. Public blockchain records may include wallet addresses, transaction hashes, timestamps, amounts, token types, and other metadata. Public blockchain data may be permanent, transparent, replicated globally, and outside AlixPay’s ability to delete, correct, or control.
You should not include personal information in blockchain transaction fields, tags, memos, or public wallet labels unless you understand the consequences.
13. Cookies and Similar Technologies
We and our service providers may use cookies, pixels, software development kits, local storage, log files, device identifiers, and similar technologies to operate the Platform, keep you signed in, secure sessions, remember preferences, measure performance, detect fraud, analyze usage, and, where permitted, support marketing. Where required by applicable law, including in Québec, we will obtain your consent before using non-essential cookies or similar technologies for marketing purposes, and you may manage your preferences through the cookie settings we make available.
You can adjust browser or device settings to refuse or delete certain cookies. Some features may not work correctly if cookies or similar technologies are disabled. We do not currently respond to browser “Do Not Track” signals unless required by law.
14. Analytics
We may use analytics tools to understand Platform performance, user flows, errors, and aggregate usage patterns. Analytics providers process information on our behalf and may use cookies or similar technologies. We configure analytics tools to support security, product improvement, and compliance with applicable privacy requirements.
15. Security Safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including access controls, encryption where appropriate, multi-factor authentication, logging, monitoring, employee confidentiality obligations, vendor due diligence, secure development practices, incident response procedures, and retention controls.
No system, network, wallet, blockchain, or transmission method is completely secure. You are responsible for protecting your credentials, devices, API keys, and account access, and for notifying us immediately if you suspect unauthorized access or compromise.
16. Retention and Deletion
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law, regulatory guidance, legal hold, dispute, audit, fraud prevention, sanctions, AML/ATF, tax, accounting, or security requirements.
AML/ATF, KYC/KYB, transaction, travel rule, monitoring, sanctions, and regulatory reporting records are generally retained for at least five years from the applicable trigger date, such as the date of transaction, report, verification, record creation, or end of the business relationship, unless a longer period is required or permitted.
When personal information is no longer required, we will securely delete, destroy, anonymize, or de-identify it, subject to technical limitations and legal requirements. We may be unable to delete information recorded on public blockchains or information we are legally required to retain.
17. Accuracy and Updates
We rely on you and business customers to provide accurate, complete, and current information. You must promptly update your Account information and notify us of changes to identity, address, beneficial ownership, authority, regulatory status, source of funds, source of wealth, expected activity, or other information relevant to the Services.
We may request updated information or documentation from time to time. Failure to provide updated information may result in limits, suspension, termination, or refusal of Services.
18. Access, Correction and Privacy Requests
Subject to lawful exceptions, you may request access to personal information we hold about you and information about how it has been used or disclosed. You may also request correction of inaccurate or incomplete personal information.
To make a request, contact [email protected] with the subject line “Privacy Request”. We may need to verify your identity and request sufficient information to locate the relevant records. We will respond within the period required by applicable law, generally within 30 days under PIPEDA, unless an extension or exception applies.
We may refuse access or correction where permitted or required by law, including where disclosure would reveal information about another person, confidential commercial information, legal privilege, security controls, anti-fraud measures, AML/ATF investigations, regulatory reports, or information that cannot be disclosed because of legal restrictions. If we refuse a request, we will explain the reason where required and permitted.
19. Complaints
You may submit a privacy complaint to our Privacy Officer at [email protected] with the subject line “Privacy Complaint”. We will review and respond to privacy complaints in accordance with our internal procedures and applicable law.
If you are not satisfied with our response, you may have the right to complain to the Office of the Privacy Commissioner of Canada or another applicable federal, provincial, or territorial privacy regulator.
20. Privacy Breaches
If we become aware of a breach of security safeguards involving personal information under our control, we will assess the breach and take steps required by applicable law. Where required, we will keep breach records and notify affected individuals, the Office of the Privacy Commissioner of Canada, the Commission d’acces a l’information du Quebec, or other applicable regulators where the legal threshold for notification is met. We will notify affected individuals and report to the Office of the Privacy Commissioner of Canada any breach of security safeguards that creates a real risk of significant harm to an individual, as soon as feasible, and we will maintain records of all breaches of security safeguards for at least 24 months.
21. Automated Tools and Risk Scoring
We may use automated tools, rules, analytics, and risk scoring to support identity verification, fraud prevention, sanctions screening, wallet screening, transaction monitoring, account security, and compliance decisions. These tools help identify risks but may be reviewed by personnel where appropriate or required.
Where applicable law gives you a right to information about an automated decision that produces legal or similarly significant effects, you may contact us using the Privacy Request process.
22. Residents of Québec
If you reside in Québec, the Act respecting the protection of personal information in the private sector applies to our processing of your personal information. Our Privacy Officer acts as the person in charge of the protection of personal information and can be reached at [email protected]. We conduct privacy impact assessments before communicating personal information outside Québec and ensure that the information receives protection equivalent to that required by that Act.
Where we render a decision based exclusively on automated processing of your personal information, we will inform you at or before the time of the decision. You may ask which personal information was used to render the decision, the reasons and the principal factors that led to it, and you may have that information corrected and submit observations for review by a member of our personnel.
You may also request that we cease disseminating your personal information or de-index certain hyperlinks where the law so provides, and you may request computerized personal information that you provided to us in a structured, commonly used technological format. Ce document est disponible en français sur demande et sur notre site web.
23. Children and Minors
The Services are not directed to children or individuals under 18 years old. We do not knowingly collect personal information from children for the Services. If we learn that we have collected personal information from a child without appropriate authorization, we will take steps to delete or de-identify the information unless retention is required by law.
24. Third-Party Links and Services
The Platform may contain links to third-party websites, wallets, applications, payment services, blockchain explorers, or other services. This Policy does not apply to third-party privacy practices. You should review the privacy policies of those third parties before using their services.
25. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy on the Platform and update the effective date. If we make material changes, we will provide notice by email, in-app notice, website notice, or another reasonable method. Your continued use of the Services after the effective date means you acknowledge the updated Policy.
26. Contact Us
For privacy questions, access or correction requests, consent withdrawals, or complaints, contact AlixPay at [email protected] with the subject line “Privacy Officer”.
Registered office: ALIXPAY FINANCIAL NETWORK INC., A7160 Tahoma Place, Chilliwack, BC V4Z 0E1, Canada.
