This Law Enforcement Requests Policy explains how Aurex Financial Technologies Inc., a corporation incorporated under the laws of British Columbia, Canada, Incorporation No. BC1535602, operating under the trading name Coinsfly, receives, reviews, validates, responds to, preserves, and discloses information in response to requests from law enforcement agencies, regulators, courts, tax authorities, sanctions authorities, government institutions, and other competent public authorities.
Aurex Financial Technologies Inc. is registered as a Money Services Business, MSB, with the Financial Transactions and Reports Analysis Centre of Canada, FINTRAC, under registration number C100000967.
Registered office:
2-1130 Hachey Ave, Coquitlam, BC V3K 2H4, Canada
In this Policy, “Coinsfly”, the “Company”, “we”, “us”, and “our” refer to Aurex Financial Technologies Inc. operating as Coinsfly. “Authority” refers to any law enforcement agency, regulator, court, tax authority, sanctions authority, government institution, financial intelligence unit, public prosecutor, or other competent public authority requesting information from Coinsfly.
1. Purpose of this Policy
Coinsfly is committed to supporting lawful investigations while protecting user privacy, platform security, confidential information, and legal rights.
This Policy is designed to:
- Provide clear instructions for law enforcement and public authorities;
- Explain how official requests should be submitted;
- Ensure requests are reviewed by the appropriate Coinsfly team;
- Protect user information from unauthorized disclosure;
- Support compliance with Canadian law;
- Support AML/CTF, sanctions, fraud prevention, and public safety obligations;
- Preserve relevant records where legally appropriate;
- Prevent misuse of Coinsfly communication channels by impersonators, scammers, or unauthorized parties.
Coinsfly will cooperate with valid legal requests while ensuring that any disclosure is lawful, proportionate, properly authorized, and limited to the information required.
2. Scope of this Policy
This Policy applies to requests relating to:
- User accounts;
- Business accounts;
- Merchant accounts;
- Merchant gateway activity;
- Customer onboarding records;
- KYC and KYB information;
- Wallet whitelisting records;
- Crypto wallet addresses;
- Crypto withdrawal records;
- Buy Crypto transactions;
- Card payment activity;
- Wire payment activity;
- vIBAN/account option records where available;
- Transaction history;
- Blockchain transaction IDs;
- Merchant payment orders;
- Chargebacks, recalls, disputes, and refunds;
- IP logs and login history;
- Device and security logs;
- Support communications;
- Compliance records;
- Suspicious activity records;
- Any other information lawfully requested by a competent authority.
This Policy applies to requests from Canadian and foreign authorities, subject to applicable law and the validation process described below.
3. Coinsfly’s Legal Position
Coinsfly handles personal information according to Canadian privacy laws, including PIPEDA and British Columbia PIPA, and according to its Privacy Policy.
Coinsfly may disclose information where:
- Required by law;
- Required by subpoena, warrant, production order, court order, or similar binding legal process;
- Requested by a government institution that has identified its lawful authority and stated the permitted legal purpose;
- Required for AML/CTF, sanctions, suspicious activity, or regulatory reporting;
- Necessary for an emergency involving life, health, or security;
- Necessary to protect Coinsfly, users, merchants, the public, or the integrity of the platform;
- Otherwise permitted by applicable law.
PIPEDA permits disclosure without knowledge or consent in certain law enforcement contexts, including where disclosure is required to comply with a subpoena, warrant, or court order, and where a government institution has made a request, identified lawful authority, and indicated that the information is requested for law enforcement or related purposes. (Office of the Privacy Commissioner)
4. No Informal Disclosure
Coinsfly does not disclose user information based on informal, unofficial, incomplete, or unverifiable requests.
Coinsfly will not usually disclose information based only on:
- A phone call;
- A social media message;
- A personal email account;
- A verbal request;
- An unsupported claim of authority;
- A request from a non-official domain;
- A request from a private investigator;
- A request from a private lawyer without valid legal process;
- A request from a merchant seeking customer data outside approved channels;
- A request from a user asking for another person’s information.
All requests must be submitted through the official process described in this Policy.
5. Official Contact for Law Enforcement Requests
Law enforcement and public authority requests should be sent to:
Emergency requests involving imminent risk to life, health, or security should use the subject line:
URGENT — EMERGENCY DISCLOSURE REQUEST
General support requests, customer complaints, account questions, and merchant disputes should not be sent to the law enforcement address.
For non-law-enforcement matters, contact:
6. Required Information in a Law Enforcement Request
To process a request efficiently, the request should include:
- Name of the requesting agency or authority;
- Country, province, state, or jurisdiction of the authority;
- Name, title, badge number, employee number, or official identifier of the requesting officer or official;
- Official government email address;
- Official phone number;
- Official mailing address;
- Case number, file number, or investigation reference;
- Legal authority relied upon;
- Type of legal process, if applicable;
- Copy of subpoena, warrant, production order, court order, preservation request, summons, regulatory notice, or other formal document;
- Description of the investigation or legal purpose, where permitted;
- Specific information requested;
- Relevant date range;
- Relevant user email, UID, account ID, transaction ID, wallet address, TxID, merchant ID, order ID, payment reference, phone number, or other identifier;
- Deadline for response;
- Whether disclosure to the user is prohibited;
- Any confidentiality, sealing, gag, non-disclosure, or preservation requirement;
- Contact details for follow-up verification.
Coinsfly may reject, delay, or narrow requests that are incomplete, unclear, overbroad, unverifiable, unsupported by lawful authority, or inconsistent with applicable law.
7. Verification of Requests
Before responding, Coinsfly may take steps to verify:
- The identity of the requester;
- The legitimacy of the agency;
- The official nature of the email domain;
- The legal authority cited;
- The validity of any court order, subpoena, warrant, production order, or regulatory request;
- Whether the request is enforceable against Coinsfly;
- Whether the request is properly served;
- Whether the request is sufficiently specific;
- Whether disclosure is legally permitted;
- Whether user notice is permitted or prohibited;
- Whether the request should be challenged, narrowed, or clarified.
Coinsfly may contact the requesting authority through independently verified contact details before disclosing information.
8. Types of Requests Coinsfly May Receive
Coinsfly may receive different types of legal or governmental requests, including:
- Subpoenas;
- Warrants;
- Production orders;
- Court orders;
- Preservation requests;
- Regulatory notices;
- Tax authority requests;
- Sanctions authority requests;
- Law enforcement information requests;
- Emergency disclosure requests;
- Mutual legal assistance requests;
- Financial intelligence requests;
- Requests from FINTRAC or other competent AML authorities;
- Requests related to fraud, scams, ransomware, theft, cybercrime, sanctions, terrorist financing, money laundering, or other suspected crimes.
Coinsfly will review each request individually.
9. Preservation Requests
An authority may request that Coinsfly preserve certain records while the authority obtains formal legal process.
A preservation request should include:
- Requesting agency details;
- Case number;
- Legal basis;
- User or transaction identifiers;
- Specific records to be preserved;
- Relevant date range;
- Requested preservation period;
- Officer contact details;
- Confirmation that formal legal process is expected.
Coinsfly may preserve available records where legally permitted and technically possible.
A preservation request does not automatically authorize disclosure. Coinsfly may require formal legal process before releasing preserved records.
If an extension is required, the authority should submit an updated preservation request before the original preservation period expires.
10. Emergency Disclosure Requests
Coinsfly may consider emergency disclosure requests where there is an imminent threat to life, health, or security.
Examples may include:
- Immediate threat of serious physical harm;
- Kidnapping;
- Human trafficking emergency;
- Terrorist threat;
- Active violent crime;
- Imminent risk of death or serious injury;
- Urgent cybercrime situation involving immediate harm;
- Other emergency circumstances recognized by applicable law.
An emergency request should include:
- Subject line: URGENT — EMERGENCY DISCLOSURE REQUEST;
- Identity of the requesting authority;
- Official contact details;
- Description of the emergency;
- Why the request is urgent;
- The specific information needed;
- How the information may prevent harm;
- Legal authority, where available;
- Certification that the request is made by an authorized official.
PIPEDA allows disclosure to a person who needs the information because of an emergency that threatens the life, health, or security of an individual, and requires notice to the individual without delay if the individual is alive, unless otherwise legally restricted. (Department of Justice Canada)
Coinsfly will review emergency requests urgently but may refuse requests that do not demonstrate a genuine emergency or cannot be verified.
11. Foreign Law Enforcement Requests
Coinsfly is a Canadian entity incorporated in British Columbia.
Foreign authorities should generally submit requests through:
- Mutual Legal Assistance Treaty processes;
- Letters rogatory;
- Canadian law enforcement channels;
- Canadian courts;
- Canadian competent authorities;
- Other legally recognized cross-border cooperation mechanisms.
Coinsfly may respond directly to a foreign authority only where legally permitted, properly supported, and consistent with Canadian law, privacy obligations, and Coinsfly’s internal review.
Coinsfly may require foreign requests to be translated into English and supported by Canadian legal process where appropriate.
12. FINTRAC, AML/CTF, and Suspicious Activity
Coinsfly is subject to Canadian AML/CTF obligations as an MSB.
Coinsfly may report suspicious transactions, suspicious attempted transactions, large transactions, sanctions-related matters, terrorist property, or other reportable matters to FINTRAC or other authorities where required.
FINTRAC guidance states that suspicious transaction reports must be submitted as soon as practicable after measures are completed that allow the reporting entity to determine there are reasonable grounds to suspect that a transaction or attempted transaction relates to a money laundering or terrorist financing offence. (FINTRAC)
Coinsfly may be legally restricted from telling users about certain reports, investigations, monitoring actions, or disclosures.
13. Information Coinsfly May Be Able to Provide
Depending on the request, applicable law, availability, and the scope of legal process, Coinsfly may be able to provide categories of information such as:
13.1 Account Information
- Name;
- Email address;
- Phone number;
- UID;
- Account type;
- Registration date;
- Account status;
- Verification status;
- Language preference;
- Account closure status;
- Merchant status where applicable.
13.2 KYC and KYB Information
- Identity verification information;
- Business verification information;
- Government ID details;
- Proof of address records;
- Source of Funds documents;
- Source of Wealth documents;
- Beneficial ownership records;
- Director and representative records;
- Verification provider results;
- Rejection or approval status;
- Compliance notes, where legally appropriate.
13.3 Transaction Information
- Transaction ID;
- Order ID;
- Date and time;
- Asset;
- Network;
- Amount;
- Fiat currency;
- Crypto amount;
- Exchange rate;
- Payment method;
- Transaction status;
- Reference;
- TxID;
- Network fee;
- Provider reference;
- Merchant reference;
- Refund status;
- Chargeback or dispute status.
13.4 Wallet Information
- Whitelisted wallet addresses;
- Asset and network;
- Wallet status;
- Wallet screening result;
- Withdrawal destination;
- Merchant wallet details;
- Blockchain TxID;
- Public blockchain metadata.
13.5 Payment Information
- Card payment references, where available;
- Masked card data, where available;
- Acquirer reference;
- Wire instructions;
- Sender details;
- Bank reference;
- vIBAN/account option records where applicable;
- Payment status;
- Refund status.
Coinsfly does not intend to store full card numbers where payments are processed by third-party acquirers or card processors.
13.6 Technical and Security Information
- IP addresses;
- Login history;
- Device data;
- Browser information;
- Session logs;
- Failed login attempts;
- OTP events;
- Security alerts;
- API logs;
- Fraud indicators;
- Account access records.
13.7 Merchant Gateway Information
- Merchant ID;
- Merchant name;
- Gateway link reference;
- Customer order details;
- Customer payment route;
- Merchant wallet destination;
- Payment status;
- Transaction status;
- Order references;
- Dispute and chargeback indicators.
14. Information Coinsfly Cannot Provide
Coinsfly may be unable to provide information that it does not possess, cannot access, or is not legally permitted to disclose.
Coinsfly cannot provide:
- A user’s external wallet private keys;
- A user’s external wallet seed phrase;
- Full card numbers where not stored by Coinsfly;
- Passwords in plain text;
- Control over external wallets;
- Private information about another user without lawful basis;
- Information outside the requested and available date range;
- Information deleted or unavailable under retention rules;
- Information held exclusively by third-party providers unless obtained through proper channels;
- Information prohibited from disclosure by law;
- Information that would compromise platform security or investigations.
Coinsfly cannot reverse or modify public blockchain transactions.
15. Blockchain Data
Many blockchain transactions are public and may be independently viewable through blockchain explorers.
Coinsfly may provide platform records related to blockchain transactions where legally required or permitted, including:
- Wallet address;
- TxID;
- Asset;
- Network;
- Amount;
- Timestamp;
- Confirmation status;
- Internal transaction reference;
- Merchant reference where applicable.
Public blockchain data is not controlled by Coinsfly and may remain permanently visible on the relevant blockchain network.
16. User Notice
Coinsfly may notify a user when their information is requested, unless:
- Notice is prohibited by law;
- A court order prohibits notice;
- A regulator or authority prohibits notice;
- Notice may compromise an investigation;
- Notice may create risk of harm;
- Notice may increase fraud or asset movement risk;
- Notice may violate AML/CTF or sanctions obligations;
- Notice may reveal suspicious transaction reporting;
- Notice may compromise platform security;
- Coinsfly is otherwise legally restricted.
In some cases, Coinsfly may delay notice until the restriction expires or until notice is legally permitted.
PIPEDA access rules may also restrict disclosure to an individual of information relating to certain law enforcement or government disclosures in specified circumstances. (Office of the Privacy Commissioner)
17. Data Minimization
Coinsfly will aim to disclose only information that is:
- Relevant to the request;
- Within the valid legal scope;
- Reasonably necessary;
- Available to Coinsfly;
- Lawfully disclosable;
- Proportionate to the stated legal purpose.
Coinsfly may narrow, redact, or challenge requests that are overbroad, vague, excessive, or unrelated to the stated legal purpose.
18. Confidentiality of Requests
Coinsfly treats law enforcement and authority requests as confidential.
Coinsfly may share request details only with:
- Internal legal team;
- Compliance team;
- Risk team;
- Privacy Officer;
- Security team;
- Senior management;
- External legal counsel;
- Relevant providers where necessary;
- Authorities where required;
- Other parties where legally permitted or required.
Coinsfly may not disclose the existence or content of a request to the affected user if prohibited or inappropriate under applicable law.
19. Response Format
Coinsfly may provide responses in one or more of the following formats:
- Secure email;
- Encrypted file;
- Password-protected archive;
- Secure transfer link;
- Formal letter;
- CSV file;
- PDF document;
- Transaction report;
- Screenshot or export;
- Another secure format agreed with the requesting authority.
Coinsfly may require confirmation of receipt and may send passwords or access credentials through a separate channel.
20. Response Timeline
Coinsfly will aim to respond to valid law enforcement requests within a reasonable timeframe.
Timing may depend on:
- Urgency;
- Completeness of request;
- Legal review;
- Scope of requested data;
- Age of records;
- Technical complexity;
- Need for provider input;
- Need for court order clarification;
- Cross-border legal requirements;
- Compliance or privacy review;
- Volume of records requested.
Emergency requests involving imminent threat to life, health, or security will be prioritized.
Coinsfly does not guarantee response within any specific timeframe unless legally required.
21. Cost Recovery
Coinsfly may seek reimbursement for reasonable costs where permitted by law, especially for:
- Broad requests;
- Large-volume data extraction;
- Historical data recovery;
- Complex technical work;
- Expert analysis;
- Repeated requests;
- Manual compilation;
- Translation;
- Production in special formats.
Coinsfly may waive cost recovery for urgent public safety requests or where legally required.
22. Requests from Private Parties
This Policy is intended for law enforcement and public authorities.
Coinsfly does not usually provide user information to private parties, private investigators, private lawyers, civil litigants, merchants, or counterparties unless:
- The user consents;
- Coinsfly is served with valid legal process;
- Disclosure is required or permitted by law;
- Disclosure is necessary for dispute handling or fraud prevention;
- Disclosure is permitted under the Terms & Conditions and Privacy Policy.
Civil requests should be submitted through proper legal channels.
23. Requests from Merchants
Merchants using Coinsfly may see certain transaction and customer-related information through the merchant dashboard where necessary for order management.
Merchants may not use law enforcement channels to obtain additional customer information unless they are acting through valid legal process or competent authority request.
Merchant requests for customer information may be refused if they exceed the merchant’s authorized access.
24. User Requests for Their Own Data
Users requesting access to their own personal information should contact:
Such requests are handled under the Coinsfly Privacy Policy and applicable privacy law, not this Law Enforcement Requests Policy.
Users requesting transaction receipts, account history, or dashboard exports should contact support or use available dashboard tools.
25. Fraud Victims and Scam Reports
If you believe you are a victim of fraud, scam, unauthorized access, or theft involving Coinsfly or a Coinsfly-related transaction, contact:
Subject line:
Fraud Report — [Your Account Email or Transaction ID]
You should also consider contacting your local law enforcement agency, bank, card issuer, wallet provider, and any relevant fraud reporting authority.
Coinsfly may preserve or review relevant information, restrict activity, or cooperate with competent authorities where appropriate.
26. Account Freezing, Blocking, and Preservation
Coinsfly may freeze, block, restrict, or preserve accounts, wallets, transactions, or records where required or appropriate due to:
- Court order;
- Warrant;
- Law enforcement request;
- Regulatory request;
- Sanctions issue;
- AML/CTF concern;
- Fraud concern;
- Suspicious activity;
- Merchant dispute;
- Chargeback or recall issue;
- Provider instruction;
- Internal risk policy;
- Legal obligation.
Coinsfly may not be able to disclose details of freezes, blocks, restrictions, or preservation actions to users.
27. Sanctions and Terrorist Property
Coinsfly may take immediate action where information suggests sanctions exposure, terrorist financing risk, terrorist property, prohibited wallet exposure, or restricted jurisdiction activity.
Actions may include:
- Freezing assets;
- Blocking transactions;
- Rejecting transfers;
- Refusing withdrawals;
- Reporting to authorities;
- Closing accounts;
- Preserving records;
- Cooperating with law enforcement or regulators.
Coinsfly may be legally restricted from providing details to the user.
28. Preservation of Audit Trails
Coinsfly may maintain audit trails related to:
- Request receipt;
- Request validation;
- Internal review;
- Legal review;
- Data searches;
- Data exports;
- Disclosure approval;
- Information provided;
- Date and method of response;
- Staff involved;
- Authorities contacted;
- User notice decisions;
- Retention and deletion.
Audit trails are maintained for security, legal, regulatory, compliance, and accountability purposes.
29. Data Retention
Coinsfly retains law enforcement request records, disclosures, preservation actions, communications, and related internal notes for legal, regulatory, AML/CTF, sanctions, privacy, audit, fraud prevention, dispute, and business purposes.
Coinsfly may retain certain MSB records for at least five years where required under Canadian AML/CTF recordkeeping obligations. FINTRAC recordkeeping guidance for MSBs includes five-year retention periods for several categories of MSB records. (FINTRAC)
30. Security of Disclosures
Coinsfly applies security safeguards when disclosing information.
Safeguards may include:
- Verification of requester identity;
- Legal review;
- Access control;
- Internal approval;
- Encryption;
- Secure transfer;
- Password protection;
- Redaction;
- Limited access;
- Separate credential transmission;
- Disclosure logs;
- Audit trails.
Coinsfly may refuse insecure transmission methods.
31. Challenges, Objections, and Narrowing
Coinsfly may challenge, object to, narrow, or seek clarification of a request where:
- The request is invalid;
- The request is not properly served;
- The request is not legally binding;
- The request is overbroad;
- The request is vague;
- The request seeks irrelevant data;
- The request conflicts with Canadian law;
- The request conflicts with privacy obligations;
- The request seeks information outside Coinsfly’s control;
- The request could compromise security;
- The request lacks required authorization;
- The request comes from an unverifiable authority.
Coinsfly may consult external legal counsel before responding.
32. International Conflicts of Law
If a foreign request conflicts with Canadian law, privacy obligations, sanctions requirements, contractual obligations, or user rights, Coinsfly may require the request to proceed through Canadian legal channels.
Coinsfly may refuse, limit, or delay foreign requests where legally necessary.
33. No Waiver of Rights
Nothing in this Policy waives any rights, objections, privileges, protections, remedies, immunities, or legal positions available to Coinsfly, its users, merchants, officers, directors, employees, contractors, affiliates, or service providers.
Coinsfly reserves all rights to object to requests and to seek judicial or regulatory guidance.
34. Updates to this Policy
Coinsfly may update this Law Enforcement Requests Policy from time to time to reflect:
- Legal changes;
- Regulatory guidance;
- Operational changes;
- Product changes;
- Provider changes;
- Security requirements;
- AML/CTF obligations;
- Privacy obligations;
- Internal governance;
- Law enforcement process improvements.
The updated Policy will be posted on the Coinsfly website with a revised effective date.
35. Contact Information
For official law enforcement, regulatory, court, or public authority requests:
Aurex Financial Technologies Inc., operating as Coinsfly
Attn: Law Enforcement Requests / Legal Department
Registered Office: 2-1130 Hachey Ave, Coquitlam, BC V3K 2H4, Canada
Law Enforcement Requests: lawenforcement@coinsfly.org
Legal: legal@coinsfly.org
Compliance: compliance@coinsfly.org
For customer support or fraud victim reports:
For privacy rights requests:
36. Final Notice
This Policy is intended to guide law enforcement agencies, regulators, courts, public authorities, users, merchants, and other stakeholders regarding Coinsfly’s approach to legal requests.
Coinsfly will cooperate with valid legal requests while protecting user privacy, complying with Canadian law, maintaining platform security, and preserving the integrity of its compliance program.