Privacy Policy

Learn how TokPay collects, uses, and protects your personal data across our blockchain-based financial services, website, app, and all related services.

Table of Contents

1. Introduction

This Privacy Policy (the "Policy") represents the privacy notice of TokPay Inc., a Delaware corporation (together with all subsidiaries thereof, the "Company," "TokPay," "we," "us," or "our") regarding the collection, use, and management of personal information belonging to:

  • All visitors ("Website Visitors") to the Company's website located at www.tokpay.xyz (the "Website")
  • Anyone who downloads or uses ("App Users") the Company's mobile application available on Google Play Store (the "App")
  • Anyone who enrolls for the Services of the Company ("Users" or "Customers")

Important Note:

This Privacy Policy applies specifically to TokPay's blockchain and cryptocurrency services. Digital asset transactions may create additional privacy considerations due to the public nature of blockchain networks.

2. Who We Are

TokPay Inc. is a financial technology company specializing in blockchain-based financial services, with the registered address: Imboswa road, plot 774 Avondale, Lusaka Zambia. Country of Incorporation: Zambia.

For purposes of how we use your personal information across our platforms (e.g., our website and mobile app) in the ways described in this Privacy Policy, TokPay Inc. is the primary data controller.

Our Commitment

We are committed to safeguarding the personal information of our customers, users, employees, and other stakeholders while providing innovative blockchain-based financial services.

3. What Data Do We Collect

The information we may collect about you will vary depending on how you interact with our Services. It may include the following:

3.1 Identity & Verification

  • Personal identification information
  • Government-issued identity documents
  • Social Security Number (SSN) or ITIN
  • Biometric data and facial recognition
  • Address verification documents

3.2 Financial Information

  • Bank account information and statements
  • Income verification and employment data
  • Credit history and creditworthiness
  • Investment portfolio information
  • Tax identification and reporting

3.3 Transaction & Blockchain Data

  • Cryptocurrency wallet addresses
  • Transaction history and amounts
  • Blockchain transaction hashes
  • Cross-border payment details
  • Treasury Bill investment records

3.4 Technical & Device Data

  • Device identifiers and operating system
  • IP address and browser information
  • Location data (when permitted)
  • App usage patterns and preferences
  • Security logs and authentication data

4. Children's Privacy

Age Restrictions

Our Services are not intended for persons under 18 years of age (or 21 years in certain states). We do not knowingly collect personal information from minors.

If you are under the applicable age limit, do not use our Services or provide any information to us. If we learn we have collected personal information from a minor, we will immediately delete that information and close any associated accounts.

If you believe we might have information from a child under the applicable age limit, please contact us at admin@tokpay.xyz

5. How We Collect Your Data

We collect data through various methods when you interact with our Services:

Direct Collection

  • Account registration processes
  • Transaction requests
  • Customer support communications
  • Voluntary surveys and feedback
  • Referral program participation

Automatic Collection

  • App usage and device information
  • Location data (when enabled)
  • Cookies and tracking technologies
  • Network and security logs
  • Error reports and crash data

Third-Party Sources

  • Identity verification services
  • Credit bureaus and financial institutions
  • Blockchain networks and transaction data
  • Fraud prevention and AML screening
  • Government databases and sanctions lists

6. How We Use Your Data

We collect and use your personal information for the following purposes:

6.1 Service Provision

Account Management:

Creating, maintaining, and securing user accounts

Transaction Processing:

Executing cross-border payments, crypto transactions, TB investments

Identity Verification:

Complying with KYC (Know Your Customer) requirements

Customer Support:

Providing assistance and resolving issues

6.2 Legal & Regulatory Compliance

  • AML/BSA Compliance: Anti-money laundering and Bank Secrecy Act requirements
  • Sanctions Screening: OFAC and other sanctions list monitoring
  • Tax Reporting: Generating 1099 forms and other required tax documents
  • Regulatory Reporting: Submitting required reports to FinCEN and other agencies

6.3 Security & Fraud Prevention

  • Transaction Monitoring: Detecting suspicious or fraudulent activity
  • Risk Assessment: Evaluating transaction and account risks
  • Security Enhancement: Protecting against cyber threats
  • Investigation Support: Assisting law enforcement investigations

7. Blockchain-Specific Data Considerations

7.1 Public Blockchain Data

  • Cryptocurrency transactions are recorded on public blockchains
  • Transaction amounts, addresses, and timestamps may be publicly visible
  • While wallet addresses are pseudonymous, they may be linked to your identity
  • Blockchain data is immutable and cannot be deleted or modified

7.2 Privacy Coins & Enhanced Privacy

We may support privacy-focused cryptocurrencies with enhanced anonymity features. Privacy coin transactions may have different visibility characteristics, and we comply with all applicable regulations regarding privacy coins.

7.3 Blockchain Analytics

We may use blockchain analytics tools to monitor transactions for compliance. These tools help detect suspicious activity and ensure regulatory compliance. Analysis may involve tracing transaction histories across multiple addresses.

8. How We Transfer and Store Your Data

8.1 Data Security

We implement industry-leading security measures to protect your personal information:

  • Encryption: All data is encrypted in transit and at rest using advanced encryption standards
  • Access Controls: Strict role-based access controls and authentication requirements
  • Security Audits: Regular security assessments and penetration testing
  • Incident Response: Comprehensive incident response and breach notification procedures

8.2 International Data Transfers

We may transfer your personal data to third parties or affiliates located outside the United States, including but not limited to Zambia, Africa, United Kingdom, European Union member states, and other jurisdictions where we operate or have service providers.

When we transfer data internationally, we ensure:

  • Compliance with applicable data protection laws
  • Implementation of appropriate safeguards (such as Standard Contractual Clauses)
  • Adequate protection measures for your personal information
  • Binding corporate rules and privacy certifications where applicable

8.3 Storage and Infrastructure

  • Cloud Storage: We use reputable cloud service providers with robust security measures
  • Data Centers: Information is stored in secure, compliant data centers
  • Backup Systems: Regular backups ensure data availability and integrity
  • Geographic Distribution: Data may be stored across multiple secure locations

9. Data Sharing and Disclosure

We may share your personal data in the following circumstances:

9.1 Service Providers and Business Partners

  • Payment processors and financial institutions
  • Blockchain network operators and validators
  • Identity verification and KYC service providers
  • Credit bureaus and background check services
  • Cloud storage and technology infrastructure providers
  • Customer support and call center services
  • Marketing and analytics service providers

9.2 Legal and Regulatory Requirements

  • Law enforcement agencies and government authorities
  • Financial regulators (FinCEN, SEC, CFTC, state regulators)
  • Tax authorities (IRS and state tax agencies)
  • Anti-money laundering and sanctions screening services
  • Court orders, subpoenas, and legal processes

9.3 Business Transactions

  • Mergers, acquisitions, or asset sales
  • Due diligence processes for business transactions
  • Restructuring or bankruptcy proceedings
  • Investor relations and financing activities

9.4 Safety and Security

  • Fraud prevention and investigation
  • Protecting rights and property of TokPay and users
  • Emergency situations involving safety or security
  • Compliance with platform policies and terms of service

10. Cryptocurrency-Specific Disclosures

10.1 Blockchain Transaction Visibility

  • Most cryptocurrency transactions are publicly recorded on blockchains
  • Transaction details may be visible to anyone with access to blockchain explorers
  • Wallet addresses, while pseudonymous, may be linked to your identity through various means

10.2 Third-Party Blockchain Services

  • We may use third-party blockchain infrastructure and analytics services
  • These services may have their own data collection and privacy practices
  • Some blockchain operations require interaction with decentralized networks

10.3 Regulatory Compliance

  • Cryptocurrency transactions are subject to extensive regulatory reporting
  • We may be required to share transaction data with multiple regulatory agencies
  • International transfers may trigger additional compliance requirements

11. Data Retention and Deletion

11.1 Retention Periods

We retain personal information for different periods based on the type of data and legal requirements:

  • Account Information: For the duration of your account relationship plus 7 years
  • Transaction Records: Minimum 5 years as required by financial regulations
  • Identity Verification: 5 years after account closure
  • Tax Records: As required by IRS and state tax authorities (typically 7 years)
  • AML/BSA Records: 5 years from transaction date or account closure

11.2 Account Deletion

Users may request account deletion, subject to:

  • Completion of all pending transactions
  • Resolution of any disputes or claims
  • Compliance with legal retention requirements
  • Satisfaction of regulatory obligations

11.3 Data Anonymization

In some cases, we may anonymize personal information so it can no longer be associated with a specific individual. Anonymized data may be retained and used for legitimate business purposes without restriction.

12. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

Access Rights

  • Right to know what personal information we collect and how we use it
  • Right to request copies of your personal information
  • Right to understand our data sharing practices

Correction Rights

  • Right to request correction of inaccurate personal information
  • Right to complete incomplete personal information
  • Right to update outdated information

Deletion Rights

  • Right to request deletion of personal information (subject to legal limitations)
  • Right to be forgotten where legally permissible
  • Right to close your account and delete associated data

Portability Rights

  • Right to receive your personal information in a portable format
  • Right to transfer your information to another service provider
  • Right to export your transaction history and account data

13. Marketing Communications

13.1 Consent-Based Marketing

We only send marketing communications when you choose to receive them:

  • Marketing messages are sent only with your explicit consent
  • You can opt-in to receive promotional offers and updates
  • Preferences can be managed anytime in your account settings

13.2 Opt-Out Rights

You have full control to stop marketing communications:

  • Unsubscribe from marketing emails at any time
  • Stop text message marketing by replying “STOP”
  • Account-related service messages remain active while your account is open

13.3 Referral Programs

We may offer rewards when you refer others to our services:

  • Referral rewards may be provided for successful referrals
  • Referrers receive only aggregate information about program performance
  • No specific transaction details are shared with referrers

14. Cookies and Tracking Technologies

14.1 Types of Cookies

We use several categories of cookies and similar technologies to operate and improve our services:

  • Essential Cookies: Required for core app functionality
  • Analytics Cookies: Help us understand usage patterns
  • Marketing Cookies: Support targeted advertising and promotions
  • Security Cookies: Protect against fraud and unauthorized access

14.2 Cookie Management

You have full control over how cookies are stored and used on your devices:

  • Adjust cookie settings through your device or browser preferences
  • Disabling certain cookies may limit app functionality
  • We provide in-app cookie preference management tools where available

14.3 Do Not Track

Our services do not currently respond to “Do Not Track” signals. However, we provide other privacy controls and options to help you manage how your data is collected and used.

15. Third-Party Services and Links

15.1 Third-Party Integrations

Our Services may integrate with various third-party providers, such as:

  • Banking and payment providers
  • Cryptocurrency exchanges and platforms
  • Investment and brokerage services
  • Identity verification services

15.2 Third-Party Privacy Policies

Each integrated third-party service maintains its own privacy policy and terms of service. We encourage you to review those policies before using their features or sharing personal information.

15.3 Social Media and External Links

Our Services may include links to external websites or social-media platforms. We are not responsible for the privacy practices or content of these external services.

16. Data Breach Notification

16.1 Incident Response

In the event of a data breach affecting personal information:

  • We will investigate and contain the incident promptly
  • Affected users will be notified as required by applicable law
  • Regulatory authorities will be notified within required timeframes
  • We will provide regular updates on the incident and remediation efforts

16.2 User Responsibilities

If you suspect a security incident:

  • Change your account passwords immediately
  • Contact our customer support team
  • Monitor your accounts for unauthorized activity
  • Report any suspicious activity to appropriate authorities

17. Updates to This Privacy Policy

17.1 Policy Changes

We may update this Privacy Policy from time to time to reflect:

  • Changes in our services or business practices
  • New legal or regulatory requirements
  • Enhanced privacy protections
  • User feedback and requests

17.2 Notification of Changes

When we make changes:

  • Material changes will be communicated with advance notice
  • Updated policies will be posted on our website and app
  • Continued use of our Services constitutes acceptance of changes
  • We may require explicit consent for significant changes

18. International Privacy Considerations

18.1 Cross-Border Operations

As a global financial technology company, we operate across multiple jurisdictions with varying privacy laws. We strive to meet the highest applicable privacy standards.

18.2 Jurisdiction-Specific Rights

Users in different jurisdictions may have different privacy rights. We will honor applicable local privacy laws and regulations.

18.3 Regulatory Cooperation

We cooperate with privacy regulators and data protection authorities in all jurisdictions where we operate.

19. Contact Us

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Officer

TokPay Inc.

Imboswa Road, Plot 774, Avondale, Lusaka, Zambia

Country of Incorporation: Zambia

Email: admin@tokpay.xyz

Privacy Portal: www.tokpay.com/privacy-policy