Privacy Policy
Last updated: December 2024
At StorspayAi, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cross-border payment services.
1. Information We Collect
Personal Information
- Identity Information: Full name, date of birth, nationality, government-issued ID numbers
- Contact Information: Email address, phone number, residential address
- Financial Information: Bank account details, payment method information, transaction history
- Employment Information: Occupation, employer details, source of funds
Technical Information
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, time spent on site, click patterns, session recordings
- Location Data: Geographic location based on IP address
Verification Information
- Identity Verification: Photos of government IDs, selfies for identity confirmation
- Address Verification: Utility bills, bank statements, official correspondence
- Enhanced Due Diligence: Additional documents for high-value transactions
2. How We Use Your Information
Service Provision
- Process and complete money transfer transactions
- Verify your identity and comply with Know Your Customer (KYC) requirements
- Provide customer support and respond to inquiries
- Send transaction confirmations and status updates
Legal and Regulatory Compliance
- Comply with Anti-Money Laundering (AML) regulations
- Report suspicious activities to relevant authorities
- Maintain records as required by financial regulations
- Respond to legal requests and court orders
Business Operations
- Improve our services and develop new features
- Conduct risk assessment and fraud prevention
- Analyze usage patterns to enhance user experience
- Send important service updates and policy changes
3. Information Sharing and Disclosure
Service Partners
- Banking Partners: Financial institutions that facilitate transfers
- Payment Processors: Third-party payment service providers
- Identity Verification Providers: Services that help verify customer identities
- Technology Partners: Cloud providers and infrastructure services
Legal Requirements
- Government agencies and regulatory bodies
- Law enforcement agencies when legally required
- Courts and legal proceedings
- Tax authorities as required by law
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to this Privacy Policy.
4. International Data Transfers
As a cross-border payment service, we may transfer your information internationally to:
- Complete transactions to destination countries
- Comply with local regulations in operating jurisdictions
- Utilize global service providers and infrastructure
We ensure adequate protection through standard contractual clauses, adequacy decisions, and other legal mechanisms.
5. Data Security
Technical Safeguards
- Encryption: All data is encrypted in transit and at rest using industry-standard protocols
- Access Controls: Role-based access with multi-factor authentication
- Network Security: Firewalls, intrusion detection, and regular security monitoring
- Regular Audits: Independent security assessments and penetration testing
Operational Security
- Background checks for all employees with data access
- Regular security training and awareness programs
- Incident response procedures and breach notification protocols
- Secure development practices and code reviews
Compliance Certifications
- PCI DSS Level 1 compliance for payment card data
- SOC 2 Type II certification for security controls
- ISO 27001 information security management
- Regular compliance audits and assessments
6. Your Rights and Choices
Access and Portability
- Request access to your personal information
- Receive a copy of your data in a portable format
- Review transaction history and account details
Correction and Updates
- Update your personal information through your account
- Request correction of inaccurate information
- Add or modify contact preferences
Deletion and Restriction
- Request deletion of your account and personal data
- Restrict processing for specific purposes
- Object to certain uses of your information
Note: Some information may be retained for legal, regulatory, or legitimate business purposes even after account closure.
7. Cookies and Tracking Technologies
Types of Cookies
- Essential Cookies: Required for basic site functionality and security
- Performance Cookies: Help us understand how visitors use our site
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Used to deliver relevant advertisements
Cookie Management
You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our service.
8. Data Retention
- Active Accounts: Information retained while your account is active
- Closed Accounts: Core information retained for 7 years post-closure
- Transaction Records: Maintained for regulatory compliance periods
- Marketing Data: Deleted when you unsubscribe or object to processing
9. Third-Party Services
Our website may contain links to third-party services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information.
10. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Displaying prominent notices on our platform
Your continued use of our services after the effective date constitutes acceptance of the updated policy.
12. Contact Information
Data Protection Officer
Email: privacy@storspayai.com
Phone: 1-415-943-8576
Address: StorsApp, Inc.
Privacy Department
123 Innovation Drive
Toronto, ON M5V 3A8
Canada
Regulatory Information
FINTRAC Registration: MSB Registration No. M19395067
Business License: Ontario Corporation 2985847
Regulatory Compliance: privacy@storspayai.com
13. Specific Regional Rights
For European Union Residents (GDPR)
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with supervisory authorities
For California Residents (CCPA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information
- Right to non-discrimination for exercising privacy rights
For Canadian Residents (PIPEDA)
- Right to access personal information we hold about you
- Right to request correction of inaccurate information
- Right to file a complaint with the Privacy Commissioner