Privacy Policy
Last updated: July 3, 2026
Important notice: This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our websites, use the Karma app, communicate with us, or otherwise interact with any services, pages, features, or content that link to this Policy (collectively, the "Services"). We have designed it to be concise and readable. If you have any questions, contact us at team@karmapay.xyz.
Glossary
- "Personal data" means any information relating to an identified or identifiable natural person.
- "Controller" means the entity that determines the purposes and means of processing personal data.
- "Processor" means a service provider that processes personal data on our behalf and on our instructions.
- "EEA/UK" means the European Economic Area and the United Kingdom.
- "KYC/AML" means know-your-customer and anti-money-laundering compliance checks.
1. Who we are and scope
The controller of your personal data is Karma Fintech LTD, a company incorporated in the United Kingdom with company number 16581945 and registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("Karma", "we", "us", "our").
Email: team@karmapay.xyz
Postal address: Karma Fintech LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
This Policy applies to karmapay.xyz and its subdomains, the Karma mobile app, and related services, and covers visitors, applicants, and customers who interact with us online or offline. If you are reading a translated version, the English version controls to the extent of any conflict, unless local law provides otherwise.
Partner services. Fiat services (virtual accounts, on-ramp and off-ramp) are provided by Bridge, and card services are provided through Rain (Signify Holdings, Inc.). When you use those services, Bridge and Rain process your personal data as independent controllers under their own privacy policies: Bridge legal policies and the Rain Privacy Policy. See also our Account Opening Privacy Notice and the Card Issuer Privacy Policy.
2. What we do not collect
The Karma Wallet is non-custodial. We do not collect, store, or have access to your private keys, key shares, exported key material, or wallet recovery information. Transaction signing happens on your own device. See our Terms of Service for how the wallet architecture works.
We do not intentionally collect special categories of personal data (such as health or religious data). Where identity verification involves biometric processing, it is performed by our partners and their verification providers as described in Section 5; we do not receive or store biometric templates.
3. Personal data we collect
3.1 Data you provide to us
- Account information: email address, name, username, profile photo, country of residence, phone number (if provided), settings and preferences, referral codes.
- Identity information: where you use partner services that require KYC, most identity data (including government ID documents) is collected directly by the partner through its hosted verification flow. We receive verification outcomes and the identity data needed to operate your account (such as your verified name and date of birth).
- Financial information: bank account details you provide for withdrawals, and tax residency information where legally required.
- Wallet information: the addresses of wallets you create or import in the app.
- Transaction information: amounts, assets, counterparty addresses, payment methods, timestamps, and transaction identifiers for activity conducted through the Services.
- User content: posts, comments, reactions, and other content you submit to the Karma feed, and social accounts you choose to link (such as your X handle).
- Communications: support messages, survey responses, bug reports, and other content you send us.
3.2 Data we collect automatically
- Device and app data: device identifiers, operating system and version, app version, language, push notification tokens, network information.
- Usage data: screens viewed, feature use, session timestamps, referral data.
- Diagnostics: crash logs, performance metrics, error reports.
- Approximate location inferred from IP address. We do not collect precise location.
- Cookies and similar technologies (see Section 10).
3.3 Data from other sources
- Partners and verification providers: KYC/AML outcomes, sanctions and PEP screening results, and fraud signals from Bridge, Rain, and their providers.
- Blockchain data: publicly available on-chain data (transaction hashes, timestamps, wallet addresses, token balances, and related signals).
- Analytics providers: aggregated usage insights.
4. Purposes and legal bases
We only process personal data where we have a lawful basis under the UK GDPR and, where applicable, the EU GDPR:
- Providing and operating the Services (account creation, wallet provisioning, transactions, customer support): performance of a contract.
- Service communications (security and transactional notices): performance of a contract and legitimate interests.
- Supporting KYC/AML, sanctions, and fraud screening for partner services: legal obligation and legitimate interests.
- Security, fraud prevention, and platform integrity (including logs, monitoring, velocity limits, and account freezes): legitimate interests in protecting users and the Services.
- Analytics, product research, and improvement: legitimate interests; you may object.
- Marketing communications and non-essential cookies: consent, which you can withdraw at any time.
- Regulatory compliance, tax, record-keeping, and responding to lawful requests: legal obligation.
- Dispute resolution and establishing or defending legal claims: legitimate interests.
Where data is needed to comply with law or to perform a contract, failure to provide it may mean we cannot offer certain Services. If you do not complete KYC with the relevant partner, you cannot use fiat or card services; the non-custodial wallet does not require identity verification.
5. Identity verification and biometrics
Identity verification for fiat services is performed by Bridge, and for card services by Rain, through their hosted verification flows. These partners and their verification vendors may process biometric data (for example, comparing a selfie to your identity document) as controllers or processors under their own privacy policies, where permitted by law and with any required consent collected in the verification flow. We receive the result of verification and limited identity data; we do not receive, store, or use biometric templates for any purpose.
6. Automated decision-making
We use automated tools to protect the platform, including sanctions screening, transaction velocity limits, and fraud detection that can trigger holds, feature restrictions, or account freezes. Partner services use their own automated KYC/AML tooling. Where an automated decision significantly affects you, you have the right to request human review, express your point of view, and contest the decision.
7. How we share personal data
We share personal data only as described below, with appropriate safeguards. We do not sell your personal data.
- Service providers (processors): cloud hosting and data storage, wallet infrastructure (Privy, which provides the embedded wallet technology described in our Terms), blockchain infrastructure and RPC providers, email and push notification delivery, analytics, customer support tooling, and professional advisors. Processors may use data only on our instructions and must protect it appropriately.
- Partners (independent controllers): Bridge for fiat services and Rain for card services, to the extent needed to provide those services to you.
- Swap routing providers: when you request a quote or execute a swap, wallet addresses and transaction parameters are shared with decentralized routing APIs (such as Jupiter, DFlow, and Relay). This information is inherently public once a transaction settles on-chain.
- Authorities and third parties for legal reasons: to comply with law, enforce our terms, protect rights, investigate fraud or security issues, or respond to valid legal requests.
- Corporate transactions: in connection with a merger, acquisition, restructuring, or asset sale. Where feasible, we will require the recipient to respect this Policy.
We may share aggregated or anonymised information that cannot reasonably be linked back to you without restriction.
8. On-chain transparency
Public blockchains are public and immutable. Transactions (including amounts, timestamps, wallet addresses, and other metadata) are permanently viewable by anyone. If your wallet address becomes linked to your identity, your on-chain activity may constitute personal data. Consider this when sharing addresses or using the Services. We analyse public blockchain data to detect and prevent fraud, comply with law, and improve the Services. We cannot remove or alter data recorded on public blockchains; where legally required, we can delete or de-link our off-chain records that associate you with a wallet address.
9. Social features and public content
The Karma feed is a social feature. Your username, profile photo, badges, linked social accounts, and any posts, comments, or reactions you publish are visible to other users and may be visible on public web pages when a post or profile is shared outside the app. Posts can include trading activity you choose to share, such as tokens, positions, and performance. Publish only what you are comfortable making public. Deleting a post removes it from the feed, but copies shared or cached outside the Services may persist. You can request removal of your public profile data by contacting us.
10. Cookies and similar technologies
We use essential cookies to make the Services work, and non-essential cookies (such as analytics) in accordance with applicable law and, where required, your consent. You can manage cookies through your browser settings and, where shown, our cookie preferences. See our Cookie Policy for details of the cookies we use.
11. International data transfers
Karma Fintech LTD is established in the United Kingdom, and some of our service providers and partners are located in other jurisdictions, including the United States. Where we transfer personal data outside the UK or EEA to countries without an adequacy decision, we use approved safeguards, including the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, adequacy mechanisms such as the EU-US Data Privacy Framework and UK-US Data Bridge where the recipient is certified, transfer risk assessments, and technical measures such as encryption in transit and at rest.
12. Retention
We retain personal data only as long as necessary for the purposes above and to meet legal, accounting, and reporting requirements. Typical periods, subject to applicable law:
- Account records: life of the account plus up to 6 years.
- Transaction records: up to 6 years after the transaction (statutory and accounting requirements).
- KYC/AML records: held primarily by our partners under their legal obligations, typically at least 5 years after the relationship ends; we retain verification outcomes for the same period.
- Security logs and telemetry: 12 to 24 months.
- Support records: 24 months, unless needed longer for disputes.
- Marketing data: until you opt out or after 24 months of inactivity.
When retention ends, we delete or irreversibly anonymise the data, unless a longer period is required by law or needed for legal claims. Data recorded on public blockchains cannot be deleted (see Section 8).
13. Security
We implement administrative, technical, and physical safeguards appropriate to the nature of the data and the risks, including encryption in transit and at rest, access controls on a need-to-know basis, environment segregation, monitoring and logging, vendor due diligence, and incident response. No system is perfectly secure; we maintain and regularly review our security programme, and where required by law we will notify you and regulators of personal data breaches. You are responsible for keeping your account credentials confidential and for promptly notifying us of any suspected unauthorised access.
14. Your privacy rights
Depending on your location, you have the following rights, subject to legal limits:
- Access to your personal data and information about our processing;
- Rectification of inaccurate or incomplete data;
- Erasure of your data;
- Restriction of processing;
- Portability of data you provided to us;
- Objection to processing based on our legitimate interests, including direct marketing;
- Withdrawal of consent at any time where processing is based on consent;
- Rights regarding automated decision-making, including the right to obtain human review.
To exercise your rights, email team@karmapay.xyz. We respond within one month of receiving your request and may extend by up to two further months for complex or numerous requests, in which case we will inform you. We may need to verify your identity before acting on a request; we will only ask for what is strictly necessary. You may lodge a complaint with the UK Information Commissioner's Office (ICO) or, if you are in the EEA, with your local supervisory authority.
You can opt out of marketing emails at any time using the unsubscribe link in our messages or by contacting us. You will still receive essential service communications.
15. Children
The Services are not intended for individuals under 18. We do not knowingly collect personal data from anyone under 18, and no part of the Services is directed at them. If we learn that we have collected such data, we will delete it and close the account. If you are under 18, do not use the Services or provide any information to us.
16. Third-party sites and integrations
The Services may link to third-party websites, apps, or integrations, including decentralised applications and protocols. Their privacy practices are governed by their own policies, and we are not responsible for them. Review their policies before sharing personal data.
17. Changes to this Policy
We may update this Policy from time to time. If we make material changes (such as new purposes, new controller information, or changes to how you exercise your rights), we will notify you via email, in-app notice, or a notice on our website before the changes take effect. The "Last updated" date above shows when this Policy was last revised. Prior versions are available on request.
18. Contact us
Karma Fintech LTD
Company Number: 16581945 (United Kingdom)
71-75 Shelton Street
Covent Garden, London
United Kingdom, WC2H 9JQ
Email: team@karmapay.xyz