The SmashPay waitlist is open — be first in line.Join now

Privacy Policy

Last updated: 2026

I. Introduction

This SmashPay Privacy Policy (the “Privacy Policy”) governs the privacy relations between you (“Client” or “you”) and SmashTech Ventures Ltd (“SmashPay” or “we”), regarding how we process and protect your personal data while you use the SmashPay Services provided through any SmashPay website, including https://smashpay.io (the “Website”), mobile application(s), SmashPay application programming interfaces (“APIs”), or third-party applications relying on our API (together, our “Apps”), and any other official SmashPay communication channels.

This Privacy Policy constitutes a legally binding agreement (the “Agreement”) between you and SmashPay. We encourage you to read it carefully to understand how we collect, use, and protect your personal data.

The Privacy Policy is regularly reviewed to ensure updates reflect changes in our business model, services, or legal requirements. If material changes occur, we will notify you via our Website, SmashPay Platform, and/or email. Your continued use of the SmashPay Platform after such updates constitutes acceptance of the changes.

Unless stated otherwise, references shall be made to the SmashPay Services General Terms and Conditions, the SmashPay Crypto Credit General Terms and Conditions, the SmashPay Earn Interest Product General Terms and Conditions, and any other applicable SmashPay service terms (jointly the “SmashPay General Terms”). Defined terms used in this Privacy Policy have the same meaning as given in the SmashPay General Terms.

II. Definitions

Controller: Any holding company, subsidiary, or entity belonging to the SmashTech Ventures Ltd group, acting as the personal data controller under this Privacy Policy.

Processor: A natural or legal person, public authority, agency, or body that processes personal data on behalf of the Controller.

SmashPay Platform: Any SmashPay website, mobile application(s), and official SmashPay communication channels, including content and services made available on or through them.

Personal Data: Any information relating to an identified or identifiable individual ("Data Subject"), including names, identification numbers, location data, online identifiers, or characteristics specific to a person.

Privacy Laws: Any applicable personal data protection laws and regulations.

Processing: Any operation or set of operations performed on Personal Data, such as collection, storage, modification, retrieval, or disclosure.

III. Information We Collect

SmashPay may collect the following types of personal data when you visit our Website, use our Apps, register on the SmashPay Platform, use SmashPay Services, or interact with us:

User-Provided Information

Identification Information: Full name, personal ID number, date/place of birth, nationality, copies of ID documents (passport, driver's license), gender, residency status, PEP (Politically Exposed Person) status, social status, and sanctions status.

Contact & Communication: Permanent/current address, phone number, email, social media handles, messages via communication platforms.

Employment Information: Occupation, employer details, income source.

Financial Data: Bank account details, crypto wallet addresses, transaction history, digital assets held on the SmashPay Platform.

Biometric Data: Facial recognition (e.g., selfie images for identity verification), biometric data analysis for fraud prevention.

Other Information: Any additional information provided voluntarily by the user.

Automatically Collected Data

Technical Data: Device type, browser type, time zone, screen resolution, geolocation.

Website Interactions: Pages visited, browsing patterns, session duration, login attempts.

Platform Usage Data: Transaction logs, account activity, purchase history.

Third-Party Data Sources

KYC/KYB Compliance Providers: SmashPay partners with identity verification providers (e.g., SumSub, Onfido) to ensure compliance with AML/KYC laws.

IV. Processing Purposes

SmashPay processes your personal data in compliance with applicable Privacy Laws for the following purposes:

User Identity Verification & Compliance: To prevent fraud, ensure AML/KYC compliance, and verify transactions.

Transaction Processing: To enable seamless crypto-fiat transactions, payments, and deposits/withdrawals.

Personalization & Service Improvement: To enhance user experience and recommend relevant services.

Security & Fraud Prevention: To detect fraudulent activity, unauthorized access, and money laundering.

Marketing & Communications: To provide service updates, special promotions, and notifications (with opt-out options).

VI. Data Security & Retention

SmashPay follows ISO 27001-certified security measures to protect personal data, including:

Data Encryption & Access Control: SSL encryption and multi-factor authentication (MFA).

Transaction Monitoring & AI Fraud Detection: Real-time threat analysis for suspicious activity.

Secure Cloud Storage: Personal data is securely stored within EU data centers with limited access.

Data Retention:

KYC Data: Stored for 5 years after account closure per AML regulations.

Transaction Records: Maintained for legal and audit purposes.

Marketing Preferences: Users may opt out of marketing communications at any time.

VII. Third-Party Disclosures

SmashPay does not sell or share personal data except under the following conditions:

Regulatory Compliance: When required by law enforcement agencies or financial regulators.

Banking & Payment Partners: To facilitate fiat transactions via Jeton Bank, Payeer, Revolut, Mercury, Moonpay, Wert, and Onramper.

Identity Verification Services: KYC/KYB partners (e.g., SumSub, Onfido) for user onboarding.

VIII. International Data Transfers

Your data may be stored/processed in jurisdictions outside your country. SmashPay follows GDPR/UK DPA compliance rules for international data transfers, ensuring:

Standard Contractual Clauses (SCCs) for EU/UK data protection compliance.

Data protection agreements with third-party providers.

Strict security standards to prevent unauthorized access.

IX. User Rights

Under applicable Privacy Laws, you have the right to:

Access, correct, or delete your personal data.

Request data portability (transfer your data to another provider).

Opt-out of direct marketing communications.

Withdraw consent for processing activities requiring your consent.

Contact SmashPay’s Data Protection Officer (DPO): support@smashpay.io

X. Final Remarks

SmashTech Ventures Ltd (SmashPay) is committed to protecting your privacy.

This policy applies to all users of SmashPay Services, Apps, and Websites.

Any updates will be communicated via the SmashPay Platform or email.