PoliciesLast updated October 6, 2026
Fraud and Security Policy
Effective date: October 6, 2026
This policy explains how PAYCORE TECHNOLOGY CO., LTD ("Moneyspace", "we") protects customer accounts and money, what we expect from you, how to report fraud, and how we handle security incidents. It forms part of our Terms and Conditions. For practical advice on avoiding scams, see Trust and Safety.
1. Shared responsibility
Security works only if we both play our part. We are responsible for securing our systems, our staff's access and the way we process transactions. You are responsible for securing your email account, your devices and your authenticator app, and for checking the details of each payment before you confirm it.
2. How we protect your account
2.1 Sign-in
- No passwords to steal. You sign in with a one-time code sent to your registered email address. Codes expire after a short time, can be used only once, and allow only a limited number of attempts.
- Two-factor authentication. You can protect your account with a time-based code from an authenticator app (TOTP). We may require a two-factor code for sensitive actions, such as payouts, withdrawals and changes to security settings.
- Notifications. We email you when two-factor authentication is turned on or off, so that you notice changes you did not make.
- Remember me. You decide whether to stay signed in on a device. If you use the App on a shared or public computer, do not choose to stay signed in, and sign out when you are done.
2.2 Team access
The owner and administrators of an account decide who can access it, which of its profiles each Team Member can see, and with which role, including a view-only role. Each Team Member signs in with their own email address, and the account's activity log shows who did what.
2.3 Our systems
- All connections to our website, App and servers are encrypted in transit (TLS).
- Sensitive data, such as full bank account numbers and IBANs of recipients, is encrypted in our database.
- The App's servers and databases are hosted by DigitalOcean in Frankfurt, Germany. Our website is hosted on Cloudflare, and both are protected by Cloudflare against denial-of-service attacks and automated abuse.
- Access to production systems and customer data is limited to staff who need it for their role. Support and compliance staff can open a read-only view of a customer's account; every such access, and every change made through our internal administration tools, is recorded.
2.4 Transaction controls
We set limits on USD and EUR payouts, and we may screen transactions, recipients and blockchain addresses. We may hold a transaction for review if it looks unusual, for example a first payout to a new recipient, a sudden change in activity, or an address associated with fraud or sanctions.
3. What we expect from you
You must:
- keep your email account secure, with a strong, unique password and its own two-factor authentication, because anyone who controls your email can request sign-in codes;
- turn on two-factor authentication in your Moneyspace account (we strongly recommend it), and keep your authenticator app and recovery codes secure;
- never share sign-in or two-factor codes with anyone, including anyone who claims to work for us;
- sign in only at https://app.moneyspace.io, and keep your browser and operating system up to date;
- check the recipient, amount, currency and network carefully before you confirm a payment or withdrawal;
- confirm any change to a supplier's or contractor's bank details through a separate channel before paying;
- remove Team Members' access promptly when they no longer need it;
- tell us immediately if you suspect anything is wrong.
4. Reporting fraud or a security problem
4.1 Your account
If you suspect that someone has accessed your account or your email, or you see a transaction you do not recognise, email support@moneyspace.io immediately with the subject "Urgent: account security". We may temporarily restrict your account while we investigate, to protect your money.
4.2 Vulnerabilities in our systems
If you believe you have found a security vulnerability in our website or App, please report it to support@moneyspace.io with the subject "Security report", with enough detail for us to reproduce it. Please:
- do not access, change or delete data that does not belong to you;
- do not disrupt our services or run automated scans that could affect other users;
- give us reasonable time to fix the issue before telling anyone else.
We will not take legal action against anyone who reports a vulnerability in good faith and follows these rules.
4.3 Suspected misuse by others
If you believe someone is using our services for fraud or another prohibited purpose, please write to legal@moneyspace.io. You do not need to give your name.
5. Unauthorised transactions and our responsibility
How we deal with errors and unauthorised transactions is set out in section 14 of our Terms and Conditions. In summary:
- tell us as soon as possible, and within 60 days of the transaction appearing in your history;
- if a transaction was not authorised by you or a Team Member, or we made an error, we will put your balance right, unless the loss was caused by fraud on your side, by your intentional or grossly negligent failure to keep your sign-in secure, or by incorrect details you gave us;
- payments that you authorised, including payments you were tricked into making, are generally your responsibility, although we will try to help you recover the money;
- crypto withdrawals cannot be reversed once broadcast, by us or by anyone else.
6. How we handle security incidents
If we detect a security incident, we will:
- Contain it, for example by blocking access, rotating keys or pausing affected services.
- Investigate what happened, which accounts and data were affected, and how.
- Notify affected customers without undue delay where the incident creates a real risk of significant harm to them, and notify privacy regulators and other authorities as the law requires.
- Fix the cause and restore normal service.
- Learn from the incident and improve our controls.
We will tell affected customers what happened, what information or funds were involved, what we are doing about it, and what they can do to protect themselves.
7. Cooperation with authorities
We cooperate with law enforcement, FINTRAC and other competent authorities in the prevention and investigation of fraud, money laundering, terrorist financing and sanctions evasion. Where the law requires or allows, we report suspicious transactions, share information in response to lawful requests, and freeze funds. The law may prevent us from telling you about a report or a request.
8. Fraud on your account and our right to act
To protect you, us and others, we may, without notice where necessary:
- hold, refuse or return a transaction;
- ask you to confirm a transaction or your identity;
- temporarily restrict your account or a Team Member's access;
- reset your sign-in methods after verifying who you are.
We will lift restrictions as soon as we are satisfied that it is safe and lawful to do so.
9. Limits of our responsibility
We work hard to protect our services, but no system can be completely secure. Our liability for losses is governed by our Terms and Conditions. We are not responsible for losses caused by malware on your devices, a compromise of your email account that was not caused by us, or your sharing of sign-in codes, except where the law that applies to you says otherwise.
10. Changes to this policy
We may update this policy as threats and technology change. The date at the top shows when it was last updated.
11. Contact
| Purpose | Contact |
|---|---|
| Account security and fraud | support@moneyspace.io |
| Vulnerability reports | support@moneyspace.io |
| Suspected misuse by others | legal@moneyspace.io |
| Personal information | privacy@moneyspace.io |
Questions about this document? legal@moneyspace.io
All documents