Cashi — Privacy Policy

Version: 2.4
Effective Date: 4 June 2026
Last Updated: 4 June 2026

1. Effective Date; Scope; Relationship to Terms

This Privacy Policy (the “Policy”) sets out how the Cashi group of companies collects, uses, processes, discloses, retains, and safeguards personal data and other information obtained in connection with the provision of our Services.

The Cashi group (the “Group”) comprises the following customer-facing Operating Entities:

  • Cashi Ltd., a private limited company incorporated in Hong Kong (“Cashi Ltd.”), the principal entity through which you access the Services; and

  • GBP Payments Corp. (BC1550207), a corporation incorporated in Canada, registered with FINTRAC as a Money Services Business under registration number C10001615, the regulated affiliate that performs money-services functions for Canadian residents.

Additional regulated entities may be added as Cashi’s business develops.

This Policy applies to all individuals who access or use any Cashi Services, including the Cashi platform, the Custodial Wallet, the Card, and any related products or features (collectively, the “Services”). This Policy should be read in conjunction with our Terms and Conditions, which govern your access to and use of the Services. Capitalised terms not separately defined in this Policy shall have the meanings ascribed to them in the Terms and Conditions.

By accessing or using any of our Services, you acknowledge that you have read, understood, and consent to the practices described in this Policy, and represent and warrant that you have the valid consent and authority from any Relevant Persons (defined in §2) for us to collect, use, disclose, and process Personal Data as described herein. If you do not agree with any provision of this Policy, you must discontinue use of the Services immediately.

1.1 Data Controllers

Cashi Ltd. is the principal data controller for the Services. Certain regulated activities performed for Canadian residents are carried out by GBP Payments Corp., which acts as the data controller for that processing. Additional regulated entities may act as controllers as Cashi’s business develops.

Where this Policy refers collectively to “Cashi,” “we,” “us,” or “our,” the reference is to whichever Operating Entity is the controller of the processing activity in question.

You agree that the Operating Entities may update this Policy at any time by posting the amended version on our website or mobile application, or by notifying you via email. Your continued use of the Services following any such amendment shall constitute your acceptance of the updated Policy.

2. Information We Collect

We may from time to time collect, process, and store personally identifiable information that can be used to contact or identify you and your beneficial owners, directors, officers, authorised signatories, employees, representatives, and other natural persons related to you (the “Relevant Persons”) via your use of the Services or where you have given your consent (collectively, the “Personal Data”). Such Personal Data may include the following categories:

2.1 Personal Identifying Information

When you register for an Account and undergo identity verification, we may collect: full legal name (including any former names, and names in English and other languages if applicable); date of birth; place of birth; gender; nationality; residential address; country or state of residence; government-issued identification documents (e.g., passport, national ID card, driving licence); identification document type and number; photographs or selfies for biometric verification; email address; phone number; blockchain wallet addresses; and any additional personal data or documentation as may be required at the discretion of our compliance team.

2.2 Personal Financial Information

To comply with our regulatory obligations and to assess risk, we may collect information relating to your financial profile, including: total net wealth (approximately in USD or equivalent); purpose of account opening; initial and ongoing sources of wealth or income; nature and details of your business, occupation, or employment; source of funds or digital assets; credit history and score (where applicable); transaction history and spending patterns; bank account information; and anticipated level of activity on the platform.

2.3 Transaction and Wallet Data

We collect information about your transactions and Custodial Wallet activity, including: deposit and withdrawal addresses; transaction amounts and timestamps; blockchain transaction hashes; Card transaction details (merchant name, amount, date, location); account balances; and counterparty information collected for Travel Rule compliance.

2.4 Device and Usage Information

We may automatically collect technical information about your device and how you interact with our Services, including: IP address; device type; operating system; browser type; unique device identifiers; location data; usage patterns; and access logs.

2.5 Sensitive Personal Information and Biometric Data

In certain cases, we may collect “Sensitive Personal Information” as defined under applicable laws (e.g., GDPR, PDPO, PIPEDA, or equivalent legislation). This may include biometric data, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or criminal records. We collect and use Sensitive Personal Information only to the limited extent necessary for specific, lawful purposes, and where we have obtained your explicit consent or are otherwise permitted by applicable law.

Biometric data — specific provisions:

  1. What we collect. Biometric data, including facial-image data and biometric templates derived from a selfie or short video provided during identity verification.
  2. Who processes it. Biometric data is processed by our identity verification provider on our behalf, solely for the purpose of identity verification, document-to-face matching, and ongoing periodic re-verification where required.
  3. Legal basis. Explicit consent at the time of identity verification, together with our legal obligation to verify your identity under applicable AML laws.
  4. Retention of biometric templates. Biometric templates derived from your verification are retained for the duration of your Account and for the period required to meet applicable AML recordkeeping obligations (see §6.2). Raw selfie or video files captured during verification are deleted by the identity verification provider in accordance with its retention schedule, which is no longer than is necessary for the verification purpose unless a longer period is required by law.
  5. Deletion. On closure of your Account and expiry of the applicable AML retention period, biometric templates are deleted or irreversibly anonymised.

2.6 Communications

If you contact our support team or communicate with us through any channel, we may collect the content of those communications, including any attachments, metadata, and records of correspondence.

3. How We Use Your Information

We use your Personal Data on the legal bases set out in the table below. Where multiple legal bases apply, we may rely on any of them.

Category of Personal DataSpecific PurposesLegal Basis
A. Personal Identifying InformationIdentity verification and account setup; providing and personalising Services; communicating with you; compliance with KYC/AML/CTF/CPF and sanctions obligations; fraud detection and security.Contractual necessity; consent; legal obligation; legitimate interests.
B. Personal Financial InformationProcessing transactions; risk assessment; generating statements and reports; monitoring fraud or suspicious activity; internal audits and compliance.Contractual necessity; legal obligation; legitimate interests.
C. Transaction and Wallet DataProcessing and recording transactions; monitoring for suspicious or anomalous activity; compliance with AML/CTF/CPF and Travel Rule obligations; generating account statements and transaction records.Contractual necessity; legal obligation; legitimate interests.
D. Device and Usage InformationDetecting and preventing fraud; enhancing user experience; compliance reporting; security monitoring and incident response.Legitimate interests; consent.
E. Sensitive Personal Information (incl. Biometric)Enhanced identity verification; ongoing re-verification; fraud prevention where required by law or regulation.Explicit consent; legal obligation.

In addition to the purposes outlined in the table above, we may use collected Personal Data:

  • To provide and manage our Services: administering, operating, delivering, improving, and personalising the Services; providing customer service; processing payments and transactions; verifying customer information.

  • For security and fraud prevention: monitoring usage and communications; detecting, preventing, and addressing technical issues and security incidents; resisting malicious, deceptive, fraudulent, or illegal actions.

  • For risk management: conducting risk assessment and data analysis; AML and credit analyses; internal management; internal and external audits.

  • For communication: communicating with you in relation to events, our Services, and other products or services offered by Cashi or its affiliates, unless you have opted out; providing statements, invoices, receipts, and related information.

  • For marketing and analytics: conducting market research, surveys, promotions, and contests; analysing preferences, interests, and behaviour in relation to the Services.

  • For compliance: fulfilling applicable legal, regulatory, and compliance requirements, including AML, CTF, CPF, sanctions screening, and tax obligations.

  • For legal purposes: enforcing or defending the rights or property of Cashi, its affiliates, and other users; establishing, exercising, or defending legal claims.

We do not use or disclose Personal Data for any purpose other than those expressly permitted under this Policy and applicable law.

3.1 Automated Decision-Making

Certain aspects of our processing involve automated decision-making, including profiling, where the relevant decision may produce legal or similarly significant effects on you. These include:

  1. Sanctions and watchlist screening — automated comparison of your Personal Data against sanctions, PEP, and adverse-media lists. A positive match may result in your Account being frozen, restricted, or closed.
  2. Transaction monitoring — automated rule-based and risk-scored monitoring of your transactions for suspicious activity. A high-risk alert may result in a temporary hold, request for further information, or escalation to law-enforcement reporting.
  3. Customer risk rating — automated scoring of your KYC profile and behavioural data, used to determine the level of due diligence applied to your Account.

You have the right to: (i) request human review of any automated decision that significantly affects you; (ii) express your point of view and contest the decision; and (iii) obtain meaningful information about the logic involved, where applicable law so requires. To exercise these rights, contact privacy@cashi.com.

4. How We Share Your Information

We may share your Personal Data with the following categories of recipients, for the purposes described in this Policy.

Identity Verification and Compliance Providers: We share your Personal Data with KYC, blockchain analytics, and other compliance service providers to verify your identity, screen transactions, and comply with AML and sanctions regulations.

Payment Processors and Financial Institutions: We share your Personal Data with card networks, banks, financial institutions, payment processors, the card issuing partner, the card processor, and merchants to facilitate deposits, withdrawals, card transactions, and other payment services.

Sub-Custodian: We share Personal Data necessary for the operation of the Custodial Wallet with our institutional Sub-Custodian.

IT and Infrastructure Providers: We share your Personal Data with service providers that provide website hosting, data analysis, information technology, cloud storage, telecommunications, and data processing services.

Marketing and Analytics Partners: We may share your Personal Data with social media platforms, online platforms, or third-party analytics providers for marketing, advertising, or promoting our Services, but only where you have provided your prior express consent for such sharing.

Professional Advisers: We share your Personal Data with our legal, accounting, tax, and other professional advisers as necessary to administer, operate, deliver, and improve the Services, or to comply with applicable legal or regulatory obligations.

Affiliates within the Group: Personal Data may be shared between Operating Entities within the Group where necessary to provide the Services, manage intra-group data sharing, conduct group-level risk management, or comply with applicable law. Each Operating Entity is bound by a duty of confidentiality with respect to such intra-group transfers.

Governmental and Regulatory Authorities: We may disclose your Personal Data to any governmental, regulatory, law enforcement, or judicial authority where required by applicable law, regulation, court order, or governmental request, or where we reasonably believe such disclosure is necessary to protect our rights, your safety, or the safety of others. For Canadian residents, this includes reports filed with FINTRAC by GBP Payments Corp.

Others: We may share your Personal Data with persons or entities that you authorise or consent to receive your Personal Data, such as your authorised representatives, agents, advisors, or beneficiaries.

We do not allow these third-party service providers to use your Personal Data for their own purposes and only permit them to process your Personal Data for specified purposes and in accordance with our instructions.

5. International Data Transfers

Your information, including Personal Data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. By submitting Personal Data to us, you consent to such transfer and processing.

We will take reasonable measures to ensure that your Personal Data is treated securely and in accordance with this Policy, and no transfer of your Personal Data will take place to an organisation or a country unless there are adequate controls in place.

We rely on appropriate safeguards for data transfers, which may include:

  • Standard Contractual Clauses (SCCs): EU Standard Contractual Clauses approved by the European Commission for transfers from the EEA to third countries.

  • Data Protection Impact Assessments (DPIAs): Conducted for high-risk processing activities, including transfers to countries without an adequacy decision.

  • Due Diligence: Information-security due diligence on all third-party service providers who will receive your data.

No data transfer mechanism can guarantee absolute security, and you acknowledge the inherent risks associated with cross-border data transfers.

6. Data Retention

6.1 General Retention Principles

Cashi retains your Personal Data for as long as reasonably necessary to fulfil the purposes described in this Policy, to comply with applicable legal and regulatory obligations, to resolve disputes, and to enforce our agreements. Specific retention periods are set out below.

6.2 Account and KYC Data

Personal Data collected during account registration and identity verification (including name, date of birth, nationality, government-issued identification, proof of address, and customer due diligence or enhanced due diligence records) is retained for the duration of your Account and for a minimum of seven (7) years following account closure.

6.3 Transaction Data

Records of all transactions conducted through the Services (including deposits, withdrawals, transfers, card transactions, and associated metadata) are retained for a minimum of seven (7) years from the date of the transaction.

6.4 Device and Usage Data

Technical and behavioural data (device identifiers, IP addresses, browser type, operating system, access logs, and usage patterns) is retained for up to two (2) years from the date of collection, or until no longer necessary, whichever is shorter, unless a longer period is required for security, fraud investigation, or compliance with law.

6.5 Communications

Records of communications between you and Cashi (customer support enquiries, emails, in-app messages, and any other correspondence) are retained for three (3) years following the date of the last communication. Communications relating to compliance matters (suspicious activity reports, regulatory enquiries, dispute resolution, and internal investigations) are retained for at least seven (7) years in alignment with §6.2.

6.6 Biometric Data

Biometric templates are retained in line with §6.2 (Account and KYC Data). Raw biometric capture (selfie, video) is deleted by the identity verification provider on completion of verification, save where a longer period is required by law.

6.7 Deletion and Anonymisation

Upon expiry of the applicable retention period, and subject to any overriding legal, regulatory, or contractual obligation requiring further retention, Cashi shall delete or irreversibly anonymise your Personal Data in accordance with our internal data management procedures. Where deletion or anonymisation is not immediately practicable due to technical constraints, Cashi shall ensure that such data is securely isolated and protected from any further processing until deletion or anonymisation can be completed.

6.8 Overriding Legal and Regulatory Obligations

Cashi reserves the right to retain any data for such additional period as may be necessary to comply with applicable laws, regulations, court orders, or requests from governmental or regulatory authorities, or to establish, exercise, or defend legal claims.

7. Marketing Communications

We may communicate company news, promotions, and information relating to our products and Services. We will only send you marketing communications where we have received your prior express consent through the relevant channels within the Services.

If you wish to opt out of marketing communications, you may do so at any time by following the unsubscribe instructions in those communications, or by contacting us at privacy@cashi.com.

Opting out of marketing communications does not affect service-related communications, such as transaction confirmations, security alerts, amendments to Terms and Conditions, platform updates, and compliance notifications. You understand that you will not be able to opt out of receiving such operational communications.

8. Security and Breach Notification

8.1 Security Measures

Cashi implements reasonable technical and organisational measures designed to protect your Personal Data against unauthorised access, alteration, disclosure, or destruction. These measures include, where appropriate:

  • Encryption of data in transit and at rest (SSL/TLS and equivalent);

  • Mandatory two-factor authentication (2FA) for Account access;

  • Strict access controls on a need-to-know basis;

  • Regular security assessments, penetration testing, and vulnerability reviews;

  • Periodic review of our data collection, storage, and processing practices; and

  • Restricted access to your Personal Data to authorised personnel only.

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information using commercially acceptable means, we cannot guarantee its absolute security. You are responsible for maintaining the security of your Account credentials and devices, as described in our Terms and Conditions.

8.2 Personal Data Breach Notification

In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, Cashi will, without undue delay and where feasible within seventy-two (72) hours of becoming aware of the breach:

  1. notify the relevant supervisory authority or authorities where required by applicable law;
  2. notify you directly where the breach is likely to result in a high risk to your rights and freedoms; and
  3. provide information on the nature of the breach, the categories and approximate number of affected individuals, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects.

9. Your Rights and Choices

9.1 Right of Access and Correction

Subject to applicable law, you may request access to the Personal Data we hold about you and request correction of any inaccurate or incomplete data. This includes the right to request disclosure of the categories of Personal Data collected, the categories of sources, the purposes for collection, the categories of third parties with whom we share data, and the specific pieces of Personal Data we hold about you.

9.2 Right to Deletion

Where applicable law provides a right to deletion, you may request that we delete your Personal Data. Certain data may need to be retained for legal, regulatory, or compliance purposes (including AML recordkeeping). We will inform you if a deletion request cannot be fully accommodated and explain the reasons.

9.3 Right to Data Portability

Where applicable law provides a right to data portability, you may request a copy of your Personal Data in a structured, commonly used, and machine-readable format. To exercise this right, contact privacy@cashi.com.

9.4 Right to Restrict Processing

You may request that we limit or restrict the processing of your Personal Data in certain circumstances, including where you contest the accuracy of the data, where the processing is unlawful, or where you have objected to processing pending verification of our legitimate grounds.

9.5 Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing your Personal Data, you have the right to withdraw your consent at any time. Where you or a Relevant Person withdraws consent or fails to supply information required for us to provide our Services, we may be unable to provide or continue to provide certain Services. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.

9.6 Right to Object to Automated Decision-Making

As described in §3.1, you have the right to request human review of automated decisions that significantly affect you, and to obtain meaningful information about the logic involved.

9.7 Marketing Opt-Out

If we send you marketing communications, you may opt out at any time by following the unsubscribe instructions or by contacting us at privacy@cashi.com. Opting out of marketing does not affect service-related communications.

9.8 Exercising Your Rights

To exercise any of the rights set out above, please contact privacy@cashi.com. In order to process your request, we may need to verify your identity. We will use reasonable efforts to respond to your request within fifteen (15) working days of receipt, subject to extension where the request is complex. While we aim to process requests free of charge, we reserve the right to charge a reasonable fee where requests are manifestly unfounded, excessive, or repetitive.

10. Children’s Privacy

Cashi Services are not directed at, and are not intended for use by, individuals under the age of eighteen (18) years or the minimum age required by the laws of your jurisdiction to form a binding contract, whichever is higher. We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without appropriate consent, we will take steps to delete such data promptly. If you believe a child has provided us with Personal Data, please contact privacy@cashi.com.

11. Cookies and Tracking Technologies

When you access or use the Cashi Services, we may place small data files on your device. These may include cookies, pixel tags, “Flash cookies,” or other local storage technologies (collectively, “Cookies”). We use Cookies to recognise you as a Cashi user, personalise the Services and content, measure the effectiveness of promotions, help ensure the security of your Account, and reduce risk and prevent fraud.

You may refuse or disable Cookies through your browser settings, unless such Cookies are strictly necessary to prevent fraud and/or ensure the security of the Services. Refusing or disabling Cookies may affect the functionality of the Services.

12. Links to Other Sites

Our platform may contain links to other websites or services that are not operated by Cashi. We strongly advise you to review the privacy policy of every site you visit. Cashi has no control over and assumes no responsibility for the content, privacy policies, or practices of any third-party sites or services.

13. Your Contact with Other Users

You understand and acknowledge that you are solely responsible for your interactions with other users of the Services. Cashi reserves the right, but has no obligation, to monitor disputes between you and other users.

14. Privacy Officer; Data Protection Officer; Complaints

14.1 Privacy Officer (Canada — PIPEDA)

GBP Payments Corp. has appointed a Privacy Officer who is responsible for compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and oversight of Personal Data processed in connection with Canadian residents.

Contact: privacy@cashi.com (reference: Canada Privacy Officer)

14.2 Data Protection Officer (Hong Kong — PDPO)

Cashi Ltd. has appointed a Data Protection Officer (DPO) who is responsible for compliance with the Hong Kong Personal Data (Privacy) Ordinance (PDPO) and oversight of Personal Data processed by Cashi Ltd.

Contact: privacy@cashi.com (reference: Hong Kong DPO)

14.3 EU Representative (GDPR Article 27)

To the extent that the EU General Data Protection Regulation (GDPR) applies to our processing of your Personal Data — for example, where we monitor the behaviour of individuals located in the European Economic Area (EEA) — we have appointed a representative in the European Union pursuant to Article 27 of the GDPR. You may contact our EU Representative on any matter relating to our processing of your Personal Data or to exercise your rights under the GDPR.

The appointment of an EU Representative is made solely to satisfy Article 27 of the GDPR. It does not constitute, and shall not be construed as, an offer of, or a solicitation to use, the Services in any EEA jurisdiction.

EU Representative:

Instant EU GDPR Representative Ltd.
Attn: Adam Brogden
Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland
Email: contact@gdprlocal.com
Tel: +353 1 554 9700

14.4 UK Representative (UK GDPR Article 27)

To the extent that the UK GDPR applies to our processing of your Personal Data — for example, where we monitor the behaviour of individuals located in the United Kingdom — we have appointed a representative in the UK pursuant to Article 27 of the UK GDPR. You may contact our UK Representative on any matter relating to our processing of your Personal Data or to exercise your rights under the UK GDPR.

The appointment of a UK Representative is made solely to satisfy Article 27 of the UK GDPR. It does not constitute, and shall not be construed as, an offer of, or a solicitation to use, the Services in the United Kingdom.

UK Representative:

GDPR Local Ltd.
Attn: Adam Brogden
1st Floor Front Suite, 27–29 North Street, Brighton, England
Email: contact@gdprlocal.com
Tel: +44 1772 217800

14.5 Complaints

We are committed to resolving complaints about our collection or use of your Personal Data in a timely manner. If you wish to make a complaint, please contact the relevant Privacy Officer, DPO, or Representative at privacy@cashi.com. We will acknowledge receipt of your complaint and endeavour to respond within fifteen (15) working days.

If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority, including:

  • Canada: Office of the Privacy Commissioner of Canada;

  • Hong Kong: Office of the Privacy Commissioner for Personal Data (PCPD);

  • European Economic Area: the supervisory authority of the EEA member state in which you reside, work, or where the alleged infringement occurred;

  • United Kingdom: the Information Commissioner’s Office (ICO).

15. Jurisdiction-Specific Provisions

15.1 Canadian Residents (PIPEDA)

The following supplemental provisions apply if you are a Canadian resident or your Personal Data is processed by GBP Payments Corp.:

  1. Controller and accountability: GBP Payments Corp. is the controller of your Personal Data for the purposes of PIPEDA and is accountable for compliance with the ten PIPEDA fair information principles.
  2. Consent: We rely on your consent for the collection, use, and disclosure of your Personal Data, except where collection, use, or disclosure without consent is permitted or required by PIPEDA (including for AML reporting, fraud prevention, and lawful investigation purposes).
  3. Access requests: You may direct PIPEDA access requests to the Canada Privacy Officer (§14.1).

15.2 Hong Kong Residents (PDPO)

The following supplemental provisions apply if you are a Hong Kong resident or your Personal Data is processed by Cashi Ltd.:

  1. Data user: Cashi Ltd. is the data user for the purposes of the PDPO.
  2. Collection statement: This Policy, together with the relevant Account-opening notices, constitutes the personal information collection statement required under the PDPO.
  3. Direct-marketing opt-out: You have the right to require Cashi to cease using your Personal Data for direct marketing, exercisable in accordance with §7 and §9.7.
  4. Access and correction requests: You may direct PDPO data-access and data-correction requests to the Hong Kong DPO (§14.2).

16. Language

The official and controlling language of this Policy is English. In the event that this Policy is translated into any other language, the English language version shall prevail to the extent of any inconsistency.

17. Updates to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will use reasonable efforts to notify you (by email, in-app notification, or by posting a notice on the Cashi platform) prior to the changes taking effect. The “Last Updated” date at the top of this Policy indicates when it was last revised. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy.

18. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through the following channels:

General privacy enquiries: privacy@cashi.com

In-app support: accessible via the Help section of the Cashi app

If the GDPR or UK GDPR applies to the processing of your Personal Data, you may also contact our appointed representatives:

  • EU Representative (EEA data subjects) — Instant EU GDPR Representative Ltd., Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland; contact@gdprlocal.com

  • UK Representative (UK data subjects) — GDPR Local Ltd., 1st Floor Front Suite, 27–29 North Street, Brighton, England; contact@gdprlocal.com

Last updated: 4 June 2026

Copyright © 2026 Cashi All Rights Reserved. Cashi provides technology services only, in which the financial products and services are issued and managed by licensed and regulated third parties. Availability is subject to local laws, regulations, and applicable terms.

Terms & Conditions Privacy Policy FAQ Contact