Legal

Privacy Policy

Last updated: 22 May 2025. The website and mobile application are owned by Cashtap Global Limited, registered at No.5, 17/F, Strand 50, 50 Bonham Strand, Sheung Wan, Hong Kong.

Our banking infrastructure partner, Vault Fintech Solutions s.r.o., is registered in the Czech Republic (no. 216 27 002, Frýdlantská 1312/19, Kobylisy, 182 00 Praha 8). UK/EU GDPR standards apply for EU users. Our Services are not intended for minors, and we do not knowingly collect data relating to them.

Controllers and providers

Cashtap Global Limited is the controller responsible for your personal data. Service providers include Vero (email), Fireblocks (custody), Zendesk (support), Amazon Web Services (hosting), GitHub (code hosting), SumSub (KYC/AML), and Reap Technologies Limited (payment processing). Contact support@cashtap.io with the subject line "Data Protection Matter".

Data we collect

Identity, contact, AML/KYC, financial (including wallet details), transaction, portfolio, usage and technical, website visit, and marketing preference data. If you do not provide requested personal data, we may be unable to open your account.

How we use data

To perform our contract with you, pursue legitimate interests such as fraud prevention, comply with legal obligations including AML/KYC, manage our relationship, and protect the business and users. Marketing is sent where you have an ongoing relationship and have not opted out, or where you have consented. You can unsubscribe at any time.

Sharing, transfers, security

We may share data with service providers, affiliates, professional advisers, law enforcement, and potential buyers in a business transfer. Providers currently store data in Germany; some, including AWS, may process data in the United States with GDPR safeguards. We generally do not transfer data outside the EEA except where necessary, using adequacy decisions or standard contractual clauses.

Retention and your rights

We generally retain data for up to six years after your customer relationship ends, and in some cases up to ten years for transaction data. You may request access, correction, erasure, objection, restriction, portability, and withdrawal of consent. We aim to respond within one month. You can also complain to your local data protection authority.