Правовые документыОбновлено 6 октября 2026
Privacy Policy
Юридически значимая версия документов — на английском языке.
Effective date: October 6, 2026
This Privacy Policy explains what personal information PAYCORE TECHNOLOGY CO., LTD ("Moneyspace", "we", "us") collects, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to our website https://moneyspace.io, our web app https://app.moneyspace.io, and our emails and support.
1. Who is responsible for your information
PAYCORE TECHNOLOGY CO., LTD is responsible for your personal information (in European terms, we are the "controller"). We have appointed a Privacy Officer, who is accountable for our compliance with this policy and with privacy law. You can reach our Privacy Officer at privacy@moneyspace.io.
We are a Canadian company, so the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where relevant, provincial privacy laws apply to us. Because we serve customers in other countries, other privacy laws may also apply, such as the EU and UK General Data Protection Regulation (GDPR). Where they apply, you have the rights they give you.
2. The short version
- We collect what we need to open and run your account, move your money and meet anti-money laundering law.
- Identity documents and selfies for verification are collected by our partner Bridge and its verification provider, not by us.
- We do not sell your personal information, and we do not use it for third-party advertising.
- We do not use analytics or advertising cookies.
- The law requires us to keep records of customers and transactions for at least five years.
3. Information we collect
3.1 Information you give us
- Contact and account information: your email address, your name, your phone number if you add it, the contact email of each profile, the language you prefer, and your settings.
- Business information: for business profiles, the business's legal name, registration number, country and website. Its address, activity, owners, directors and controllers are collected by Bridge during business verification.
- Recipient information: the names, bank account details and wallet addresses of the people and businesses you pay. We store recipient bank details in encrypted form.
- Team information: the email addresses of Team Members you invite, their roles and the profiles they can access.
- Communications: messages you send us, such as support requests and complaints, and any information you include in them.
- Information we request for compliance: for example, information about the source of your funds, the purpose of a transaction or your occupation, if we ask for it.
3.2 Information we receive from others
- From Bridge, about verification: when you verify your identity or business for USD and EUR services, Bridge tells us the result and gives us information we need to provide the services, such as your verified name, address and verification status. Bridge and its identity verification provider collect your identity documents, selfie or video and other verification data directly from you, under Bridge's own privacy policy, available at bridge.xyz/legal.
- From Bridge and banks, about payments: details of payments you send and receive, such as the sender's or recipient's name, bank and account details, amounts and references.
- From our custody provider and from blockchains: deposit addresses, transaction hashes, amounts and other information recorded on public blockchains.
- From screening: the results of sanctions, politically-exposed-person and blockchain-risk checks carried out by Bridge and by our custody provider and, where we carry out our own checks, public sanctions lists and company registers.
- From the person who invites you: if you are invited as a Team Member, your email address and your role.
3.3 Information collected automatically
- Technical information: IP address, browser and device type, operating system, and the dates and times of your visits and sign-ins.
- Security information: sign-in events, two-factor authentication events, and logs of important actions in your account, such as payouts and changes to settings.
- Browser storage: the App stores your session and preferences in your browser. See our Cookie Policy.
3.4 Transaction information
Your Balances, deposits, payouts, withdrawals, exchanges, fees, quotes and the status of each transaction.
4. How we use your information, and our legal grounds
| Purpose | Examples | Legal ground (where GDPR applies) |
|---|---|---|
| Providing the Services | opening your account, signing you in, processing transfers and exchanges, showing your history, sending service emails | Performance of our contract with you |
| Verification and compliance | verifying identity, screening against sanctions lists, monitoring transactions, keeping records, reporting to FINTRAC and other authorities | Legal obligation; where the obligation arises under non-EU law, such as Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act, our legitimate interest in complying with it |
| Security and fraud prevention | detecting unusual sign-ins, protecting accounts, investigating fraud | Legitimate interests (keeping customers and our services safe); legal obligation |
| Support and complaints | answering your questions, handling complaints | Performance of contract; legitimate interests |
| Improving the Services | understanding which features work well, fixing errors, using information that is aggregated or does not identify you where possible | Legitimate interests |
| Legal claims | establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
| Marketing | product news, only if you agree to receive it | Consent |
Under Canadian law, we rely on your consent, which you give when you open an account and use the Services, or which is implied where the purpose is obvious, except where the law allows or requires us to collect, use or disclose information without consent (for example, for anti-money laundering reporting or fraud prevention).
We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. Bridge and its verification provider may use automated tools, such as document checks and face matching, in their verification process; their decisions are governed by Bridge's privacy policy.
5. Who we share your information with
We share personal information only as described here.
5.1 Service providers that work for us
| Provider | What they do | Location |
|---|---|---|
| Bridge | USD and EUR account details, bank payouts, identity and business verification | United States, European Economic Area and other countries where Bridge operates |
| Bridge's identity verification provider | Document, selfie and database checks during verification | As described in Bridge's privacy policy |
| Our digital-asset custody provider | Generating deposit addresses, screening incoming deposits and processing withdrawals. Receives your account identifier, deposit addresses and transaction details, not your name or email address | Varies by provider |
| Blockchain infrastructure providers | Broadcasting and reading transactions (node, relay and wallet services). Receive wallet addresses and amounts only | United States and other countries |
| DigitalOcean | Hosting the App's servers, databases and error logs | Frankfurt, Germany (European Union) |
| Cloudflare | Hosting our website, content delivery, DNS, protection against attacks, and sending our emails | Global network, including the United States |
Bridge also acts as an independent organisation responsible for the verification data it collects. Our other providers may use your information only to provide services to us, and they must protect it.
5.2 Others
- Payment recipients and senders. When you send a payment, information such as your name may be passed to the recipient, their bank and intermediaries, as payment systems and the law require. The same applies in reverse when you receive money.
- Other digital-asset service providers. Where the "travel rule" applies to a crypto transfer, we may share information about the sender and recipient with the other provider involved.
- Email providers. Our emails pass through your email provider and, for emails to Team Members, theirs.
- The account owner. If you are a Team Member, the account's owner and administrators can see your actions in its activity log.
- Partner brands. If you use the Services through a partner's own brand and app, that partner can see your profiles, balances and transactions and can freeze a profile. Its own privacy policy also applies to what it does with your information.
- Our staff. Authorised support and compliance staff can open a read-only view of your account, as you see it, to help you or to meet legal obligations. They cannot make changes through it, and every access is recorded.
- Authorities. We disclose information to FINTRAC, law enforcement, courts, tax authorities and other public authorities where the law requires or allows us to. The law may prohibit us from telling you about some of these disclosures.
- Professional advisers. Our lawyers, auditors and accountants, under a duty of confidentiality.
- Business transfers. A buyer or successor of all or part of our business, under a duty to protect your information as this policy describes.
- With your consent. Anyone else, if you ask us to or agree.
We do not sell or rent your personal information, and we do not share it with advertisers.
6. International transfers
We are based in Canada. The App's servers and databases are in the European Union (Frankfurt, Germany), our website is served from Cloudflare's global network, and some providers, including Bridge and Cloudflare, process information in the United States and other countries. This means that your information may be stored and processed outside the country where you live, where privacy laws may offer different protection, and where it may be accessible to courts, law enforcement and national security authorities under local law.
When we transfer personal information, we use contracts and other measures to make sure it continues to be protected. Where the GDPR applies, we rely on adequacy decisions (for example, the European Commission's decision for Canada) or on standard contractual clauses approved by the European Commission and, for the United Kingdom, the International Data Transfer Addendum. You can ask us for more information at privacy@moneyspace.io.
7. How long we keep your information
| Information | How long we keep it |
|---|---|
| Customer identification records, business ownership information, and records of transactions | At least five years, as required by Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act, counted from the date of the transaction or from the date your account is closed, depending on the type of record |
| Reports to authorities and related records | As long as the law requires |
| Support and complaint correspondence | Up to five years after the matter is closed |
| Security and access logs | For a limited period proportionate to security needs, longer where needed for an investigation |
| Marketing preferences | Until you withdraw consent, plus a record that you did |
When we no longer need information, we delete it or make it anonymous. We may keep information longer if we need it for a legal claim, an investigation, or because a law or authority requires it.
8. How we protect your information
We use administrative, technical and physical safeguards that are appropriate to the sensitivity of the information, including encryption in transit, encryption of sensitive data such as recipient bank details, passwordless sign-in with one-time codes, optional two-factor authentication, staff access limited to what each role needs, and an audit trail of changes made through our internal administration tools. No system is perfectly secure, but we work to protect your information and we review our safeguards regularly. More detail is in our Fraud and Security Policy.
If a breach of security safeguards involving your personal information creates a real risk of significant harm to you, we will notify you and the relevant privacy regulator as the law requires.
9. Your rights
Depending on where you live, you have some or all of these rights:
- Access: to know whether we hold personal information about you and to receive a copy of it;
- Correction: to have inaccurate or incomplete information corrected;
- Deletion: to have information deleted, where we are not required or allowed to keep it;
- Portability: to receive information you gave us in a structured, machine-readable format;
- Objection and restriction: to object to, or ask us to restrict, processing based on our legitimate interests;
- Withdrawal of consent: to withdraw consent at any time, for example to marketing emails. This does not affect processing that took place before you withdrew it;
- Complaint: to complain to a privacy regulator.
Limits. We cannot delete information that anti-money laundering or other laws require us to keep, and the law may prevent us from giving you access to some information, such as information about reports we have made to FINTRAC. If you withdraw consent to processing that we need in order to provide the Services, we may not be able to continue to provide them.
How to make a request. Email privacy@moneyspace.io from the email address registered to your account. We will verify your identity before responding, and we will respond within 30 days, or tell you if we need more time and why, as the law allows. We do not charge for reasonable requests.
Complaints to a regulator. If you are not satisfied with our response, you may complain to:
- the Office of the Privacy Commissioner of Canada, or the privacy regulator of your province;
- if you are in the European Economic Area, your national data protection authority;
- if you are in the United Kingdom, the Information Commissioner's Office;
- elsewhere, the privacy regulator of your country.
We would appreciate the chance to resolve your concern first, so please contact us at privacy@moneyspace.io before going to a regulator.
10. Marketing
We send service emails, such as sign-in codes, transaction notifications, security alerts and notices about changes to our terms, as part of the Services; you cannot opt out of these while you have an account. We send marketing emails only if you have agreed, and every marketing email contains a link to unsubscribe.
11. Children
Our Services are not intended for anyone under 18 or under the age of majority where they live, and we do not knowingly collect information from them. If you believe that a child has given us personal information, please contact privacy@moneyspace.io.
12. Links to other websites
Our website and App link to websites that we do not operate, including Bridge's verification pages. Their privacy practices are governed by their own policies.
13. Changes to this policy
We may update this policy from time to time. If we make a significant change, we will tell you by email or in the App before it takes effect. The date at the top shows when the policy was last updated.
14. Contact
| Purpose | Contact |
|---|---|
| Privacy Officer | privacy@moneyspace.io |
| General support | support@moneyspace.io |
Вопросы по документу? legal@moneyspace.io
Далее: Cookie Policy