FX Wallet Inc. ("FX Wallet," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, platform, and services (collectively, the "Services").
We are a registered Money Services Business (MSB) with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), registration number C100000126, and we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and all applicable Canadian privacy legislation.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not use our Services.
1. Information We Collect
1.1 Information You Provide
- Identity Information: Full legal name, date of birth, nationality, government-issued identification (passport, driver's licence, or provincial ID).
- Contact Information: Email address, phone number, mailing address.
- Financial Information: Bank account details, payment card information, transaction history, source of funds documentation.
- Business Information: Business name, registration number, beneficial ownership details, nature of business, and anticipated transaction volumes (for business accounts).
- Verification Information: Photographs, selfies, or biometric data collected during identity verification processes.
1.2 Information Collected Automatically
- Device Information: IP address, browser type and version, operating system, device identifiers.
- Usage Data: Pages visited, features used, time spent on pages, click patterns, referral sources.
- Location Data: Approximate geographic location derived from your IP address.
- Cookies and Tracking Technologies: See our Cookie Policy for details.
1.3 Information from Third Parties
- Identity Verification Providers: Results from KYC (Know Your Customer) and KYB (Know Your Business) verification services.
- Credit and Fraud Prevention Agencies: Credit reports, fraud screening results, and sanctions list checks.
- Financial Institutions: Account verification and transaction confirmation data from partner banks and payment networks.
1.4 Facial and Biometric Data
As part of our identity verification (KYC) process, we may collect and process facial data, including facial images (selfies) and video recordings, to verify your identity. This data constitutes sensitive personal information and is subject to enhanced protections under applicable privacy legislation, including PIPEDA.
How we use face data:
- Matching your facial image with your government-issued identification to confirm your identity.
- Preventing fraud and identity theft by detecting spoofing, deepfakes, or unauthorized use of another person's identity.
- Complying with regulatory requirements under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and FINTRAC's KYC/AML obligations.
We do not use face data for marketing, advertising, profiling, behavioural analysis, or any purpose unrelated to identity verification and fraud prevention.
Third-party processing:
Face data may be securely processed by trusted third-party identity verification service providers acting on our behalf. These providers are bound by contractual obligations that require them to:
- Use face data solely for the purpose of identity verification.
- Implement appropriate technical and organizational security measures.
- Delete or return face data upon completion of the verification process or as required by our data retention policies.
- Not disclose face data to any other party without our prior written authorization.
Your face data may be stored on secure servers managed by these service providers or by FX Wallet, depending on operational requirements. All storage complies with Canadian data protection standards.
Retention of face data:
We retain face data only for as long as necessary to fulfill identity verification purposes and comply with applicable legal and regulatory requirements (including FINTRAC's record-keeping obligations under the PCMLTFA). Once no longer required, face data is securely deleted or irreversibly anonymized in accordance with industry-standard data destruction practices.
Your consent:
By submitting facial images or video recordings through our identity verification process, you provide your explicit, informed consent to the collection, use, and processing of your face data as described in this section. You may withdraw consent at any time by contacting our Privacy Officer, though withdrawal may affect our ability to verify your identity and provide Services.
2. How We Use Your Information
We use your personal information for the following purposes:
- Service Delivery: To process transactions, manage your account, execute currency conversions, and facilitate domestic and international transfers.
- Regulatory Compliance: To comply with FINTRAC reporting obligations, anti-money laundering (AML) requirements, sanctions screening, and other legal obligations under Canadian law.
- Identity Verification: To verify your identity and conduct due diligence as required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).
- Fraud Prevention: To detect, investigate, and prevent fraudulent transactions and unauthorized access to your account.
- Communication: To send transaction confirmations, security alerts, service updates, and respond to your inquiries.
- Improvement: To analyze usage patterns, improve our Services, develop new features, and enhance user experience.
- Legal Proceedings: To establish, exercise, or defend legal claims as necessary.
3. Legal Basis for Processing
We process your personal information on the following legal grounds:
- Contractual Necessity: Processing required to perform our agreement with you and deliver the Services.
- Legal Obligation: Processing required to comply with FINTRAC regulations, PCMLTFA, tax reporting, and other applicable laws.
- Legitimate Interest: Processing for fraud prevention, security, service improvement, and business operations, balanced against your privacy rights.
- Consent: Where required, we obtain your explicit consent for specific processing activities, such as marketing communications.
4. Disclosure of Your Information
We may share your personal information with the following categories of recipients:
- Financial Institutions: Banks, payment processors, and correspondent institutions involved in executing your transactions.
- Regulatory Authorities: FINTRAC, the Canada Revenue Agency (CRA), and other government bodies as required by law, including suspicious transaction reports (STRs) and large cash transaction reports (LCTRs).
- Service Providers: Third-party vendors who assist with identity verification, fraud detection, cloud hosting, analytics, and customer support, under strict contractual obligations.
- Legal and Compliance: Law enforcement agencies, courts, or other parties when required by law, subpoena, or court order.
- Corporate Transactions: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the successor entity.
We do not sell your personal information to third parties for marketing purposes.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Account Data: Retained for the duration of your account and for 7 years after account closure, as required by FINTRAC record-keeping obligations.
- Transaction Records: Retained for a minimum of 5 years from the date of the transaction, in compliance with PCMLTFA requirements.
- Identity Verification Records: Retained for 5 years after the last transaction or account closure, whichever is later.
- Facial and Biometric Data: Retained only for as long as necessary for identity verification and compliance with FINTRAC record-keeping obligations. Once no longer required, securely deleted or irreversibly anonymized.
- Marketing Preferences: Retained until you withdraw consent or opt out.
6. Data Security
We implement industry-standard security measures to protect your personal information, including:
- 256-bit AES encryption for data at rest and TLS 1.3 for data in transit.
- AWS-hosted infrastructure designed to meet Canadian regulatory requirements.
- Multi-factor authentication and role-based access controls for internal systems.
- Regular penetration testing and vulnerability assessments.
- Strict internal controls and regular third-party security audits.
While we take all reasonable precautions, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
7. Your Privacy Rights
Under PIPEDA and applicable Canadian privacy laws, you have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Withdrawal of Consent: Withdraw consent for processing where consent is the legal basis, subject to legal or contractual restrictions.
- Complaint: File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
To exercise any of these rights, please contact our Privacy Officer at [email protected]. We will respond to your request within 30 days.
Please note that certain information may be exempt from such requests under applicable law, particularly where retention is required for regulatory compliance (e.g., FINTRAC record-keeping obligations).
8. International Data Transfers
Your personal information may be processed or stored in jurisdictions outside of Canada, including the United States, where our service providers operate. When we transfer data internationally, we ensure appropriate safeguards are in place, including contractual data protection agreements that meet Canadian privacy standards.
9. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a person under 18, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on our website and updating the "Effective" date. Your continued use of the Services after any changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact:
FX Wallet Inc. — Privacy Officer
2300 Yonge St, Suite 1600
Toronto, ON M4P 1E4, Canada
Email: [email protected]