This Privacy Policy explains how Aurex Financial Technologies Inc., a corporation incorporated under the laws of British Columbia, Canada, Incorporation No. BC1535602, operating under the trading name Coinsfly (“Coinsfly”, the “Company”, “we”, “us”, or “our”), collects, uses, stores, discloses, protects, and otherwise processes personal information.
Coinsfly is registered as a Money Services Business, MSB, with the Financial Transactions and Reports Analysis Centre of Canada, FINTRAC, under registration number C100000967.
Registered office:
2-1130 Hachey Ave, Coquitlam, BC V3K 2H4, Canada
This Privacy Policy is designed to align with applicable Canadian privacy, anti-money laundering, counter-terrorist financing, and financial crime compliance requirements, including:
- The Personal Information Protection and Electronic Documents Act, PIPEDA;
- British Columbia’s Personal Information Protection Act, PIPA;
- The Proceeds of Crime Money Laundering and Terrorist Financing Act, PCMLTFA;
- FINTRAC guidance and reporting obligations applicable to money services businesses;
- Applicable sanctions, tax, law enforcement, and regulatory obligations.
By accessing the Coinsfly website, creating an account, applying for services, using our platform, submitting documents, using a merchant gateway, communicating with us, or otherwise providing personal information to Coinsfly, you acknowledge that you have read and understood this Privacy Policy.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal information processed in connection with:
- The Coinsfly website;
- The Coinsfly client dashboard;
- The Coinsfly merchant gateway;
- Account registration;
- Login and security verification;
- Identity verification and business verification;
- Crypto purchase services;
- Wire and card payment flows;
- Wallet whitelisting;
- Crypto withdrawals to approved external wallets;
- Merchant crypto payment flows;
- Compliance document uploads;
- Customer support;
- Marketing communications, where applicable;
- Technical, security, and fraud-prevention operations.
This Privacy Policy applies to the following categories of individuals.
1.1 Website Visitors
Individuals who access or browse the Coinsfly website.
1.2 Applicants
Individuals or business representatives who begin the account opening process, regardless of whether the account is approved.
1.3 Registered Users
Individuals who create and use a Coinsfly account.
1.4 Business Users
Directors, officers, authorized representatives, employees, shareholders, beneficial owners, controllers, and related persons of a business applying for or using Coinsfly services.
1.5 Merchant Users
Merchants, merchant representatives, and merchant clients using or accessing the Coinsfly merchant gateway.
1.6 Beneficial Owners and Controllers
Individuals who ultimately own, control, benefit from, or exercise authority over an account, transaction, merchant, business, or payment activity.
1.7 Counterparties and Payment Participants
Individuals involved in payments, wallet transactions, banking flows, merchant payments, compliance checks, investigations, disputes, or support matters.
2. Important Product and Jurisdiction Notice
Coinsfly is not a bank and does not provide general banking services. Fiat payment methods are used to support crypto purchase and merchant crypto payment flows, subject to verification, eligibility, jurisdiction restrictions, payment provider availability, transaction limits, and compliance review.
Coinsfly does not market to or serve clients from the United Kingdom. This website and its content are intended for persons outside of the United Kingdom. Coinsfly does not solicit clients in the European Union. EU clients access and request services exclusively on their own initiative.
Access to certain services may be unavailable or restricted based on your location, nationality, residence, verification status, payment method, transaction activity, wallet risk, sanctions screening, or applicable law.
3. Key Definitions
For this Privacy Policy, the following terms apply.
3.1 Personal Information
“Personal Information” means information about an identifiable individual, including factual or subjective information, whether recorded or not. This may include identity data, contact data, financial data, transaction data, technical data, biometric data, and compliance data.
Personal Information generally does not include business contact information used solely for business communications.
3.2 Processing
“Processing” means any operation involving personal information, including collection, recording, storage, organization, use, access, review, analysis, disclosure, transfer, retention, deletion, or destruction.
3.3 Sensitive Personal Information
“Sensitive Personal Information” includes information that may create higher risk if misused, including government identification documents, biometric or liveness data, financial information, source of funds information, sanctions or PEP screening results, wallet risk scores, and compliance investigation records.
3.4 KYC
“KYC” means Know Your Customer procedures used to verify an individual’s identity and assess eligibility.
3.5 KYB
“KYB” means Know Your Business procedures used to verify a business, its ownership, representatives, directors, controllers, business activity, and risk profile.
3.6 AML/CTF
“AML/CTF” means anti-money laundering and counter-terrorist financing controls.
3.7 PEP
“PEP” means Politically Exposed Person and may include certain family members or close associates, depending on applicable law and compliance requirements.
3.8 Whitelisted Wallet
A “Whitelisted Wallet” means an external crypto wallet address submitted by a user, screened by Coinsfly or its service providers, and approved for withdrawals.
4. Personal Information We Collect
Coinsfly collects only the personal information that is reasonably necessary for our services, compliance obligations, security, fraud prevention, and business operations.
4.1 Account Registration Data
When you create an account, we may collect:
- Email address;
- Password or password-related authentication data;
- Phone number;
- Account type;
- Language preference;
- Account creation date;
- User ID or client UID;
- Login credentials and authentication metadata;
- Consent records;
- Terms acceptance records;
- Declaration confirmations.
We do not store your password in plain text.
4.2 Identity Verification Data
For KYC and compliance purposes, we may collect:
- Full legal name;
- Middle name, if applicable;
- Former names or aliases, if required;
- Date of birth;
- Nationality;
- Country of residence;
- Residential address;
- Government-issued identification document;
- Passport, national ID, driver’s licence, or other accepted identification;
- Identification number;
- Document issue date;
- Document expiry date;
- Issuing country or authority;
- Selfie image;
- Liveness verification data;
- Facial comparison results;
- Verification decision;
- Verification status;
- Rejection reason, if applicable;
- Compliance notes.
Identity verification may be performed through third-party verification providers, including Sumsub or other approved KYC/KYB/AML service providers.
4.3 Business Verification Data
For business, corporate, and merchant accounts, we may collect:
- Legal entity name;
- Trading name;
- Registration number;
- Incorporation country;
- Registered address;
- Operating address;
- Business activity;
- Website;
- Industry category;
- Expected transaction volume;
- Source of funds;
- Source of wealth, where required;
- Directors’ details;
- Officers’ details;
- Authorized representatives’ details;
- Shareholders’ details;
- Ultimate beneficial owner details;
- Ownership structure;
- Corporate documents;
- Certificate of incorporation;
- Articles, bylaws, or constitutional documents;
- Proof of business address;
- Licences or regulatory permissions, if applicable;
- Merchant gateway application information;
- Compliance approvals and internal risk notes.
4.4 Contact and Communication Data
We may collect:
- Email address;
- Mobile phone number;
- Mailing address;
- Support messages;
- Chat messages;
- Complaint records;
- Call notes;
- Email correspondence;
- Verification communications;
- Notification delivery records;
- Customer support attachments;
- Communication preferences.
4.5 Financial and Economic Data
For compliance, risk assessment, limits, and transaction monitoring, we may collect:
- Source of funds information;
- Source of wealth information;
- Payslips;
- Bank statements;
- Tax returns or tax declarations;
- Loan agreements;
- Sale agreements;
- Proof of income;
- Proof of address;
- Employment information;
- Occupation;
- Employer details;
- Expected activity;
- Account limits assigned by Compliance;
- Supporting documents requested by Compliance;
- Deposit or payment references;
- Bank account details used in payment flows;
- Payment method details;
- Card-related tokenized or masked payment data;
- Payment provider references.
Coinsfly does not intentionally store full card numbers where payments are processed by a regulated acquiring or card processing provider. Card data should be handled by the acquirer or payment processor according to their own security standards.
4.6 Payment, Transaction, and Ledger Data
We may collect and process:
- Transaction ID;
- Order ID;
- Date and time;
- Transaction type;
- Payment method;
- Fiat currency;
- Crypto asset;
- Crypto network;
- Amount;
- Exchange rate;
- Quote reference;
- Payment status;
- Provider reference;
- Banking reference;
- Merchant reference;
- Blockchain transaction hash;
- Wallet address;
- Network fee;
- Transaction status;
- Rejection reason;
- Refund or dispute information;
- Chargeback or recall information;
- Ledger entries;
- Balance records;
- Frozen balance records;
- Withdrawal queue records;
- Transaction history;
- Audit trail.
4.7 Crypto Wallet and Blockchain Data
When you use wallet-related features, we may collect:
- External wallet addresses;
- Wallet network;
- Crypto asset;
- Wallet ownership declarations;
- Wallet whitelist status;
- AML wallet screening result;
- Risk score;
- Blockchain transaction hashes;
- Public blockchain metadata;
- Network confirmation data;
- Blockchain explorer references;
- Withdrawal destination address;
- Merchant wallet destination;
- Wallet approval or rejection records.
Blockchain data is generally public, permanent, and not controlled by Coinsfly. Once a transaction is recorded on a public blockchain, Coinsfly cannot erase or modify it.
4.8 Merchant Gateway Data
When a customer uses a merchant gateway link, we may collect:
- Merchant ID;
- Merchant name;
- Gateway link reference;
- Customer account information;
- Order ID;
- Payment amount;
- Crypto asset;
- Network;
- Selected payment route;
- Destination wallet selection;
- Whether funds are directed to the merchant wallet or customer account;
- Email OTP and SMS OTP verification status;
- Payment status;
- Blockchain TxID where applicable;
- Merchant order status;
- Dispute, refund, recall, or chargeback status;
- Merchant client relationship data.
We may share limited payment-related information with the relevant merchant, as described in this Privacy Policy.
4.9 Technical, Device, and Security Data
We may automatically collect:
- IP address;
- Device type;
- Device ID or device fingerprint;
- Browser type;
- Operating system;
- Time zone;
- Language;
- Screen resolution;
- Session identifiers;
- Login history;
- Failed login attempts;
- Authentication events;
- OTP request and verification records;
- Referral source;
- Pages viewed;
- Buttons clicked;
- Activity timestamps;
- Error logs;
- API request logs;
- Security event logs;
- VPN, proxy, or TOR detection signals;
- Geolocation derived from IP address;
- Suspicious activity indicators.
4.10 Cookies and Tracking Data
We may collect cookie and similar technology data, including:
- Essential cookies;
- Session cookies;
- Authentication cookies;
- Security cookies;
- Preference cookies;
- Analytics cookies;
- Marketing cookies, where permitted and consented to.
More details are provided in the Cookies section below.
5. How We Collect Personal Information
Coinsfly may collect personal information directly from you, automatically through your use of the platform, or from third parties.
5.1 Directly from You
We collect information when you:
- Create an account;
- Complete forms;
- Upload documents;
- Submit identity verification;
- Add a wallet address;
- Make a purchase;
- Request a withdrawal;
- Use a merchant gateway;
- Contact support;
- Subscribe to communications;
- Respond to compliance requests.
5.2 Automatically
We collect technical and usage information when you:
- Visit the website;
- Log in;
- Use the dashboard;
- Request OTPs;
- Interact with platform features;
- Use a merchant gateway;
- Trigger security or compliance systems.
5.3 From Service Providers
We may receive information from:
- Sumsub or other KYC/KYB/AML providers;
- Banks and payment providers;
- Card acquirers and processors;
- Liquidity providers;
- Blockchain analytics providers;
- Blockchain RPC providers;
- Email and SMS providers;
- Fraud prevention vendors;
- Hosting and infrastructure providers;
- Customer support providers.
5.4 From Public or Blockchain Sources
We may collect or analyze public data, including:
- Public blockchain records;
- Sanctions lists;
- Government registers;
- Business registries;
- Adverse media sources;
- Public compliance databases;
- Publicly available company information.
6. Legal Grounds and Purposes for Processing
Canadian privacy law generally requires organizations to collect, use, and disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances, with valid consent unless an exception applies.
Coinsfly processes personal information for the following purposes.
6.1 Account Creation and Platform Access
We use personal information to:
- Create user accounts;
- Verify email and phone number;
- Authenticate login;
- Manage sessions;
- Maintain user profiles;
- Provide dashboard access;
- Display verification status;
- Manage language preferences;
- Provide account support.
6.2 Identity Verification and Business Verification
We use personal information to:
- Verify your identity;
- Verify your business;
- Verify directors, representatives, and beneficial owners;
- Confirm age and eligibility;
- Review documents;
- Conduct liveness checks;
- Prevent impersonation;
- Confirm account holder details;
- Support compliance decisions;
- Determine whether services can be offered.
If a user is identified as a PEP, or if the compliance review otherwise identifies unacceptable risk, Coinsfly may refuse, restrict, suspend, or terminate services.
6.3 AML, CTF, Sanctions, and Financial Crime Compliance
We use personal information to:
- Conduct sanctions screening;
- Identify PEPs;
- Screen adverse media;
- Detect fraud;
- Assess wallet risk;
- Monitor transactions;
- Review unusual activity;
- Review source of funds;
- Review source of wealth;
- Set account limits;
- Detect suspicious activity;
- Comply with FINTRAC reporting obligations;
- Respond to lawful regulatory and law enforcement requests;
- Prevent money laundering, terrorist financing, sanctions breaches, fraud, scams, and other financial crime.
Coinsfly may be legally restricted from telling you about certain compliance actions, reports, investigations, or information requests.
6.4 Crypto Purchase Services
We use personal information to:
- Generate quotes;
- Match payment method details with account holder details;
- Process card payments;
- Process wire payment instructions;
- Route fiat-to-crypto transactions;
- Execute or arrange crypto purchases;
- Update balances;
- Display purchase status;
- Provide transaction confirmations;
- Manage payment errors, delays, cancellations, or refunds.
6.5 Wallet Whitelisting and Crypto Withdrawals
We use personal information to:
- Add external wallet addresses;
- Screen wallet addresses;
- Approve or reject whitelisted wallets;
- Restrict withdrawals to approved wallets;
- Calculate network fees;
- Process withdrawal requests;
- Apply Email OTP and SMS OTP authentication;
- Place withdrawals into processing queues;
- Track transaction status and TxID;
- Maintain withdrawal records.
6.6 Merchant Gateway Services
We use personal information to:
- Register merchant clients;
- Connect customers to merchant payment orders;
- Process merchant gateway transactions;
- Display merchant wallet destination details;
- Allow customers to choose payment route;
- Confirm payments with OTP where required;
- Track merchant orders;
- Share relevant payment status with merchants;
- Monitor recalls, disputes, refunds, and chargebacks;
- Detect suspicious merchant activity;
- Manage merchant access.
6.7 Security, Fraud Prevention, and Abuse Prevention
We use personal information to:
- Detect suspicious logins;
- Prevent account takeover;
- Detect bot activity;
- Enforce rate limits;
- Investigate unauthorized access;
- Monitor IP, device, and location signals;
- Detect payment fraud;
- Detect wallet abuse;
- Protect platform infrastructure;
- Maintain audit logs;
- Enforce our Terms and Conditions.
6.8 Account Limits and Compliance Document Management
We use personal information to:
- Request updated Source of Funds documents;
- Request Proof of Address or Proof of Identity documents;
- Review compliance uploads;
- Approve or decline documents;
- Set or update account limits;
- Restrict purchases when account limits are reached;
- Re-enable services after updated documentation is approved.
6.9 Customer Support and Complaints
We use personal information to:
- Respond to support requests;
- Investigate complaints;
- Resolve transaction issues;
- Assist with OTP issues;
- Review account access problems;
- Communicate status updates;
- Maintain complaint records.
6.10 Legal Claims, Enforcement, and Business Protection
We may use personal information to:
- Enforce legal agreements;
- Protect our legal rights;
- Defend claims;
- Investigate breaches;
- Cooperate with legal proceedings;
- Conduct audits;
- Support insurance and professional advice;
- Maintain evidence for disputes.
6.11 Service Improvement and Analytics
We may use information to:
- Improve platform design;
- Fix bugs;
- Measure feature usage;
- Improve onboarding;
- Improve payment flows;
- Improve security systems;
- Generate aggregated statistics;
- Develop new features.
Where possible, we use aggregated or anonymized information for analytics.
6.12 Marketing Communications
Where permitted by law and where consent is required, we may use your contact information to send:
- Product updates;
- Feature announcements;
- Merchant service updates;
- Security notices;
- Service availability notices;
- Marketing communications.
You may unsubscribe from marketing communications at any time. You cannot unsubscribe from essential service, legal, compliance, transaction, or security communications.
7. Consent
By using Coinsfly services, creating an account, submitting information, uploading documents, or completing verification, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy.
Some processing is necessary for Coinsfly to provide services or comply with legal obligations. If you withdraw consent for essential processing, including KYC, KYB, AML, sanctions screening, transaction monitoring, fraud prevention, or regulatory recordkeeping, Coinsfly may be unable to continue providing services and may suspend or close your account.
8. Automated Processing, Risk Scoring, and Manual Review
Coinsfly may use automated tools to assist with:
- Identity verification;
- Liveness checks;
- Document validation;
- Sanctions screening;
- PEP screening;
- Fraud detection;
- Wallet AML screening;
- Transaction monitoring;
- Account limit enforcement;
- Payment method risk assessment;
- Merchant risk monitoring.
Automated systems may generate risk scores, alerts, approval recommendations, rejection recommendations, or account restrictions.
Where an automated process affects your ability to use services, you may contact Coinsfly to request manual review, subject to legal, AML, CTF, sanctions, fraud prevention, and security restrictions.
Coinsfly may not be able to disclose full details of compliance rules, detection methods, thresholds, risk indicators, or investigation results where disclosure could compromise platform security or legal obligations.
9. When We Share Personal Information
Coinsfly does not sell, rent, or trade your personal information to third parties for their own marketing purposes.
We may disclose personal information only where reasonably necessary for the purposes described in this Privacy Policy, where you have consented, or where permitted or required by law.
9.1 KYC, KYB, AML, and Verification Providers
We may share personal information with identity verification, business verification, sanctions screening, PEP screening, liveness, document verification, fraud prevention, and AML providers, including Sumsub or similar approved providers.
This may include:
- Identity documents;
- Selfie/liveness data;
- Contact details;
- Business documents;
- Beneficial ownership information;
- Wallet addresses;
- Transaction metadata;
- Risk indicators.
9.2 Banks, Payment Providers, and Acquirers
We may share personal information with banks, card acquirers, payment processors, vIBAN/account providers, wire transfer providers, and other payment partners.
This may include:
- Name;
- Address;
- Date of birth;
- Contact details;
- Account holder details;
- Payment instructions;
- Bank details;
- Transaction amount;
- Payment reference;
- Compliance status;
- Merchant or order reference.
These providers may conduct their own compliance, fraud, risk, and legal checks.
9.3 Liquidity Providers
We may share transaction-related information with liquidity providers where necessary to quote, execute, settle, or reconcile fiat-to-crypto transactions.
This may include:
- Asset pair;
- Amount;
- Quote;
- Execution status;
- Settlement reference;
- Wallet details where required;
- Transaction metadata;
- Compliance-related information where required.
9.4 Blockchain Analytics and Wallet Screening Providers
We may share wallet addresses, transaction hashes, network information, and related blockchain metadata with blockchain analytics or AML providers to assess wallet risk and transaction risk.
9.5 Blockchain Networks and RPC Providers
Blockchain transactions involve public networks. When processing blockchain-related actions, transaction information may become visible on the relevant blockchain.
We may use RPC infrastructure providers, including Alchemy or other providers, to read blockchain data, monitor transactions, detect confirmations, and broadcast transactions where applicable.
9.6 Merchants
If you use a merchant gateway link, we may share limited information with the relevant merchant, including:
- Order ID;
- Payment status;
- Payment amount;
- Crypto asset;
- Network;
- Destination status;
- Transaction reference;
- TxID where applicable;
- Refund, dispute, cancellation, or chargeback status;
- Customer identification information where necessary for order management, compliance, or dispute handling.
Merchants may be independent businesses with their own privacy practices. You should review the merchant’s own privacy information before purchasing goods or services from them.
9.7 Infrastructure, Hosting, and Technology Providers
We may use trusted technology providers for:
- Cloud hosting;
- Server infrastructure;
- Database hosting;
- Data storage;
- Email delivery;
- SMS delivery;
- Support chat;
- Monitoring and analytics;
- Error tracking;
- Security tools;
- Development operations.
This may include providers such as DigitalOcean, GitHub, email/SMS vendors, monitoring providers, and customer support tools.
9.8 Professional Advisers
We may share limited information with:
- Lawyers;
- Accountants;
- Auditors;
- Compliance consultants;
- Tax advisers;
- Insurance providers;
- Corporate advisers.
9.9 Regulators, Authorities, and Law Enforcement
We may disclose personal information to:
- FINTRAC;
- Canada Revenue Agency;
- Canadian law enforcement agencies;
- Courts;
- Regulators;
- Sanctions authorities;
- Foreign authorities where legally required or permitted;
- Other competent authorities.
Such disclosures may be made in response to reporting obligations, lawful requests, subpoenas, warrants, court orders, investigations, audits, or legal requirements.
9.10 Corporate Transactions
If Coinsfly or Aurex Financial Technologies Inc. is involved in a merger, acquisition, restructuring, financing, sale of assets, corporate reorganization, insolvency process, or similar transaction, personal information may be disclosed or transferred as part of that transaction, subject to appropriate confidentiality and legal protections.
10. International Transfers and Storage
Your personal information may be stored or processed in Canada or in other countries where Coinsfly, its affiliates, or its service providers operate.
This may include the United States, the European Economic Area, the United Kingdom where legally permitted, or other jurisdictions depending on provider infrastructure.
When personal information is processed outside Canada, it may be subject to the laws of that jurisdiction, including lawful access by courts, regulators, law enforcement, or government authorities.
Coinsfly remains responsible for personal information under its control and uses contractual, technical, and organizational safeguards designed to protect personal information transferred to service providers.
11. Data Retention
Coinsfly retains personal information only as long as reasonably necessary for the purposes for which it was collected, or as required by law, regulatory obligations, accounting obligations, legal claims, dispute resolution, fraud prevention, AML/CTF obligations, or platform security.
11.1 AML and FINTRAC Record Retention
As an MSB, Coinsfly may be required to retain certain records for at least five years, including:
- Identity verification records;
- Business verification records;
- Beneficial ownership records;
- Transaction records;
- Large transaction records where applicable;
- Suspicious transaction records and reports;
- Compliance review records;
- Source of funds records;
- Wallet screening records;
- Account activity records;
- Records submitted to FINTRAC.
The applicable retention period may run from the transaction date, account closure date, report date, or other legally relevant date, depending on the type of record.
11.2 Account Records
We may retain account, verification, transaction, wallet, security, and compliance records after account closure where necessary to comply with law, prevent fraud, resolve disputes, respond to regulators, maintain audit trails, or protect legal rights.
11.3 Marketing Records
Marketing preferences are retained until you unsubscribe, withdraw consent, or the information is no longer necessary.
11.4 Support Records
Support and complaint records may be retained for quality assurance, legal, compliance, fraud prevention, and dispute purposes.
11.5 Deletion and Anonymization
When information is no longer required, Coinsfly will securely delete, destroy, or anonymize it, subject to legal and technical limitations.
Some blockchain-related information cannot be deleted because public blockchain records are maintained by decentralized networks outside Coinsfly’s control.
12. Data Security
Coinsfly uses technical and organizational safeguards designed to protect personal information against unauthorized access, collection, use, disclosure, copying, modification, loss, theft, and destruction.
12.1 Technical Safeguards
Security controls may include:
- TLS encryption for data in transit;
- Encryption at rest where appropriate;
- Secure password hashing;
- Multi-factor authentication for administrative access;
- Role-based access controls;
- IP restrictions for sensitive internal tools;
- Firewall protection;
- Network segmentation;
- Secure API authentication;
- Webhook signature validation;
- Audit logging;
- Security monitoring;
- Intrusion detection where applicable;
- Backup and recovery procedures;
- Secrets management;
- Vulnerability scanning;
- Penetration testing where appropriate.
12.2 Organizational Safeguards
Organizational controls may include:
- Employee confidentiality obligations;
- Access on a need-to-know basis;
- Compliance training;
- Security awareness training;
- Vendor due diligence;
- Internal policies and procedures;
- Incident response planning;
- Access reviews;
- Approval workflows for sensitive actions.
12.3 User Responsibilities
You are responsible for:
- Keeping your login credentials secure;
- Using a strong password;
- Not sharing OTP codes;
- Not allowing others to access your account;
- Keeping your email and phone secure;
- Ensuring wallet addresses are accurate;
- Reviewing transaction details before confirming;
- Immediately notifying Coinsfly of suspicious activity.
Coinsfly will never ask you for your private wallet keys or seed phrase.
13. Data Breach and Incident Notification
If Coinsfly becomes aware of unauthorized access, use, disclosure, loss, or theft of personal information, we will assess the incident and take appropriate steps to contain, investigate, and remediate it.
Where required by applicable law, including where there is a real risk of significant harm, Coinsfly will:
- Notify affected individuals;
- Notify the Office of the Privacy Commissioner of Canada;
- Notify other authorities where required;
- Keep records of the breach;
- Provide information about steps users may take to reduce risk.
Security incident notices may be provided by email, platform notification, website notice, or other appropriate method.
14. Your Privacy Rights
Subject to applicable law, verification of identity, and legal exceptions, you may have the following rights.
14.1 Right to Access
You may request access to personal information Coinsfly holds about you.
We will respond within the timeframe required by applicable law, generally within 30 days, unless an extension is permitted.
14.2 Right to Correction
You may request correction of inaccurate or incomplete personal information.
Certain information, such as identity verification data, legal name, date of birth, business registration details, or compliance records, may require additional verification or compliance review before it can be changed.
14.3 Right to Withdraw Consent
You may withdraw consent where processing is based on consent.
However, withdrawal of consent for essential processing may prevent Coinsfly from providing services. For example, Coinsfly cannot provide services without processing required KYC, KYB, AML, sanctions, fraud prevention, transaction, and regulatory records.
14.4 Right to Challenge Compliance
You may challenge Coinsfly’s compliance with this Privacy Policy by contacting our Privacy Officer.
14.5 Right to Complain
If you are not satisfied with Coinsfly’s response, you may contact the Office of the Privacy Commissioner of Canada or, where applicable, the Office of the Information and Privacy Commissioner for British Columbia.
15. How to Make a Privacy Request
To protect your information, Coinsfly may require you to verify your identity before responding to a privacy request.
We may request:
- Account email;
- Phone verification;
- Identification details;
- Transaction references;
- Additional information needed to confirm identity.
We may refuse or limit requests where permitted by law, including where disclosure would reveal confidential commercial information, affect another person’s privacy, compromise an investigation, violate legal obligations, or interfere with AML/CTF, sanctions, fraud prevention, or security controls.
16. Cookies and Similar Technologies
Coinsfly uses cookies, pixels, tags, local storage, and similar technologies to operate and improve the website and platform.
16.1 Essential Cookies
Essential cookies are required for:
- Website operation;
- Login sessions;
- Account security;
- Fraud prevention;
- Load balancing;
- Transaction security;
- User authentication.
You cannot disable essential cookies through our platform because they are necessary for secure operation.
16.2 Preference Cookies
Preference cookies may remember:
- Language preference;
- Display settings;
- Session preferences;
- Region settings where applicable.
16.3 Analytics Cookies
Analytics cookies help us understand:
- Page visits;
- User journey;
- Feature usage;
- Performance issues;
- Error patterns;
- Conversion rates.
Where required, analytics cookies will be used with consent.
16.4 Marketing Cookies
Marketing cookies may be used to measure campaigns or deliver relevant updates, where permitted by law and subject to consent requirements.
16.5 Managing Cookies
You may manage cookies through your browser settings or through our cookie banner where available.
Disabling certain cookies may affect platform functionality, login security, and transaction flows.
17. Marketing Communications
Coinsfly may send marketing communications only where permitted by law and, where required, with your consent.
You may unsubscribe from marketing emails at any time by using the unsubscribe link or contacting us.
Even if you unsubscribe from marketing, Coinsfly may still send you:
- Transaction emails;
- OTP codes;
- Security alerts;
- Legal notices;
- Service notices;
- Compliance requests;
- Account status updates;
- Verification notices.
18. Protection of Minors
Coinsfly services are not intended for individuals under 18 years of age or under the age of majority in their jurisdiction, whichever is higher.
We do not knowingly collect personal information from minors. If we discover that a minor has provided personal information, we may delete the information, close the account, and take any required compliance steps.
19. Third-Party Websites and Services
Coinsfly may contain links to third-party websites, platforms, merchants, payment providers, verification providers, blockchain explorers, or support services.
This Privacy Policy applies only to Coinsfly’s processing of personal information.
Third-party websites and providers may have their own privacy policies, terms, cookies, and data practices. Coinsfly is not responsible for the privacy practices of third parties.
20. Public Blockchain Notice
Crypto transactions may be recorded on public blockchain networks.
Public blockchain data may include:
- Wallet addresses;
- Transaction hashes;
- Amounts;
- Token information;
- Timestamps;
- Network fees;
- Smart contract interactions where applicable.
Public blockchain data is generally permanent, transparent, and not controlled by Coinsfly. Coinsfly cannot delete, reverse, hide, or modify public blockchain records.
Users should not use Coinsfly services if they are not comfortable with the public nature of blockchain transactions.
21. Accuracy of Information
You are responsible for ensuring that personal information provided to Coinsfly is accurate, complete, and up to date.
Providing false, inaccurate, incomplete, misleading, or outdated information may result in:
- Rejection of verification;
- Account restrictions;
- Transaction delays;
- Withdrawal restrictions;
- Compliance review;
- Account suspension;
- Account closure;
- Reports to authorities where required by law.
22. Changes to this Privacy Policy
Coinsfly may update this Privacy Policy from time to time to reflect:
- Changes in law;
- Changes in regulatory guidance;
- Changes in services;
- Changes in providers;
- Changes in security practices;
- Changes in operational processes.
The updated version will be posted on the Coinsfly website with a revised effective date.
Where required, we may notify users by email, platform notice, or other appropriate means.
Continued use of Coinsfly after an updated Privacy Policy becomes effective means you acknowledge the updated Policy.
23. Contact Our Privacy Officer
For questions, requests, complaints, or concerns regarding this Privacy Policy or Coinsfly’s handling of personal information, contact:
Aurex Financial Technologies Inc., operating as Coinsfly
Attn: Privacy Officer / Compliance Unit
Registered Office: 2-1130 Hachey Ave, Coquitlam, BC V3K 2H4, Canada
Email: privacy@coinsfly.org
Support: support@coinsfly.org
24. Final Acknowledgment
By using Coinsfly services, accessing the platform, creating an account, submitting documents, using the merchant gateway, adding a wallet, requesting a transaction, or communicating with us, you acknowledge that you have read and understood this Privacy Policy.