Effective: 03/09/2026
1. Who is responsible for your data
This Privacy Policy is issued on behalf of the MS Pay group. The controller of your personal data is the group entity that provides your services: MS Pay Limited (British Columbia, BC1431850) for payment, foreign-exchange, account and digital-asset conversion services; MS Pay Jersey Ltd (Jersey, 159408) for digital-asset and stablecoin settlement services; and MS Pay Inc (Delaware) for US services offered through regulated partner financial institutions. References to “MS Pay”, “we” or “us” mean the entity acting as your controller. Contact: compliance@ms-pay.io, or by post to the registered office of your controller, as set out in Schedule 2 to our Terms and Conditions.
2. Applicable law
We process personal data under the law applicable to your controller: PIPEDA and applicable provincial law (MS Pay Limited); the Data Protection (Jersey) Law 2018 (MS Pay Jersey Ltd); and applicable US federal and state privacy law (MS Pay Inc). Where we offer services to clients established in the United Kingdom or the European Economic Area, the UK GDPR and the EU GDPR also apply to that processing.
3. What we collect
We collect: identity and contact data (name, date of birth, nationality, identification documents, address, email, phone); corporate data for business clients (registration details, directors, beneficial owners, corporate documents); financial data (account and wallet details, source of funds and wealth information, transaction history); verification and screening data (results of identity, sanctions and PEP checks, including data from verification providers); biometric data (facial images and biometric identifiers processed by our identity-verification provider for liveness detection and identity matching); technical data (device, IP address, log-in records); and communications (emails, recorded calls, platform messages). We also process limited personal data of individuals connected to our clients and their transactions — directors, beneficial owners, authorised users, payees, payers and transaction counterparties — for verification, screening and transaction-monitoring purposes, even where those individuals are not our clients. We collect personal data from you directly, from your organisation, from our verification and screening providers, and from public sources and registers.
4. Why we process it
We process personal data: to provide the Services and perform our contract with you; to comply with legal obligations, including anti-money-laundering, counter-terrorist-financing, sanctions, travel-rule and tax reporting obligations; for our legitimate interests in operating, securing and improving the platform, preventing fraud and managing risk; and, where required, with your consent, which you may withdraw at any time. Where we process biometric data for identity verification, we do so with your explicit consent given during onboarding, or as otherwise permitted by the law applicable to your controller. We send service communications about your account and relationship. We send marketing communications only with your consent or where otherwise permitted, and every marketing message includes an opt-out. We do not sell personal data and we do not use it for third-party advertising. We use automated tools to screen applications and transactions for sanctions, politically-exposed-person, fraud and anti-money-laundering risk, which may result in an application being declined or a transaction being delayed, blocked or rejected without human involvement. Where the law applicable to your controller gives you the right to obtain human intervention or to contest such a decision, contact compliance@ms-pay.io. We may be unable to give reasons where disclosure would breach a legal prohibition on tipping off.
5. Who we share it with
We share personal data with: other MS Pay group companies for onboarding, verification, screening, service delivery, security and compliance, under intra-group arrangements; our service providers, including identity-verification, screening, technology and payment infrastructure providers, and financial institutions and counterparties involved in executing your transactions; regulators, law-enforcement and tax authorities where required by law; and professional advisers and auditors under duties of confidentiality.
6. International transfers
Where personal data is transferred internationally, we use lawful transfer mechanisms applicable to the exporting controller, including adequacy decisions, standard contractual clauses and equivalent Jersey and Canadian safeguards, together with intra-group arrangements.
7. Retention
We retain personal data for as long as needed for the purposes described, and thereafter as required by anti-money-laundering, tax and regulatory record-keeping obligations applicable to your controller (typically between five and ten years after the end of the relationship, depending on the entity serving you and the record type). Data no longer required is deleted or irreversibly anonymised.
8. Your rights
Subject to the law applicable to your controller, you may request access to, correction, deletion, restriction or portability of your personal data, and object to certain processing. We may need to retain data where the law requires it. To exercise your rights, contact compliance@ms-pay.io. You may complain to the supervisory authority for your controller: the Office of the Privacy Commissioner of Canada; the Jersey Office of the Information Commissioner; or the relevant US authority.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, monitoring and staff confidentiality obligations. No system is perfectly secure; we will notify you and the relevant authority of a personal-data breach where the law requires.
10. Cookies
Our website uses strictly necessary cookies and, with your consent, analytics cookies. You can manage preferences through the cookie banner or your browser settings.
11. Children and third-party links
The Services are not directed at children and we do not knowingly collect personal data relating to children. Our website may contain links to third-party sites; their privacy practices are their own and this Policy does not apply to them.
12. Changes
We may update this Policy from time to time. Material changes will be notified on the platform or by email. The current version is always available on our website.