Anyflo
Use casesDevelopersAboutFAQ
Talk to us

Legal

Privacy Policy

Last updated: 6 October 2026

Contents

Anyflo Technologies, Inc., a Delaware corporation (referred to as "we" and "our" and "us") understands and respects your desire to maintain your privacy. It is our priority to maintain your privacy in all of your dealings with us, including through your use of our services.

We may in the course of providing our services to you be required to collect your personal information. This Privacy Policy is intended to explain how we will collect your personal information and protect your privacy.

Unless indicated otherwise, this Privacy Policy does not apply to third party products or services or the practices of companies that we do not own or control, including other companies you might interact with on or through our services.

In this Privacy Policy, "Services" means our "Anyflo Pay" technology platform (Anyflo Pay), website, APIs, software, systems, sandbox or test environments, products, services and other functionality or technologies that we make available from time to time. This Privacy Policy is intended to apply generally to the Services.

Who this Privacy Policy applies to

This Privacy Policy applies to the following individuals:

  • representatives, employees, directors, beneficial owners and other individuals associated with our business customers, prospective customers, suppliers and partners;
  • individuals who access the Services on behalf of a customer;
  • individuals who send, receive or are otherwise involved in transactions processed through the Services by our customers (End Users and recipients), including where we verify their identity or screen their transactions; and
  • visitors to our website and individuals who interact with us through social media, events or marketing.

We do not offer the Services directly to consumers. If you are an End User of one of our customers, your relationship is with that customer, and the customer's own privacy notice explains how it handles your personal information. Where we process your personal information only on that customer's behalf and on its instructions, we act as its service provider (or "processor"), and the customer is responsible for that processing. Where we process your personal information for our own purposes, including identity and recipient verification, sanctions, fraud and blockchain analytics screening, compliance with our legal obligations, and operating our website and business relationships, we act as a "controller" (or equivalent), and this Privacy Policy applies.

We handle personal information in accordance with applicable privacy and data protection laws. This Privacy Policy includes additional information for individuals in certain jurisdictions.

Please read this Privacy Policy carefully.

What information is covered under this policy?

This Privacy Policy covers your personal information. "Personal information" means any information that identifies, relates to, describes or is reasonably capable of being associated, directly or indirectly, with an identified or identifiable individual. For the purposes of this Privacy Policy, there is no meaningful distinction between the terms "personal information" and "personal data".

Common examples personal information may include your name, username, password or other login or authentication information, IP address, unique device identifiers, signature, address, telephone number, email, date of birth, company or organisation details, job title or role, bank account or other financial account details, digital wallet addresses or details, billing or payment information, identity verification information and identification credentials, information about the purpose of a transaction or source of funds where relevant, transaction, order, reference and blockchain information, photographs or images and other documents you provide, biographical details, and commentary or opinions about you.

Categories of personal information we collect

We collect the following key categories of personal data:

  • Identity data: name, nationality, date of birth, photographs contained in identity documents, national identification or passport numbers, tax identification numbers, and other identification credentials.
  • Contact data: email address, telephone number, residential and billing address, and account username.
  • KYC and verification data: government-issued identity documents, proof of address, source of funds and source of wealth information, and the results of identity and sanctions checks.
  • Blockchain and on-chain data: wallet addresses, on-chain transaction hashes, transaction amounts and timestamps, and related analytics derived from public blockchains.
  • Financial and transaction data: bank account and payment details, transaction amounts, currencies, counterparties, purpose of payment, quotes and transaction status.
  • Compliance and risk data: politically exposed person (PEP) status, sanctions and adverse media screening results, fraud indicators and risk scores, including risk scores derived from blockchain analytics.
  • Technical and usage data: as described under "Information that we collect about you" below.
  • Communications and marketing data: correspondence with us and your marketing preferences.

Where required by applicable privacy laws and principles, we will provide any additional notice and obtain any consent required for the collection, use or disclosure of your personal information.

How personal information is collected

You may choose not to provide some of the personal information described above. Please note, however, that some of our Services require some personal information to operate, so if you choose not to provide the personal information necessary to operate and provide you with a particular Service or feature of that Service, you may not be able to use that Service or feature.

Information that you give us

We may collect your personal information directly from our contact with you. This may include by accessing and using Anyflo Pay, completing forms on our website, social media, APIs, software, sandbox or test environments or other Services, by you creating or using an account or credentials, by you submitting information in connection with a transaction or request, or by you contacting us via email, telephone, social media or other similar functions, either directly through our website or through third party host websites, in person, through marketing channels or events, or through surveys.

You understand that any personal information that you provide to us must be accurate and up to date. We will assume this to be the case.

We may also receive personal information about you from other sources, including your employer or organisation, our customers, business partners and service providers, publicly available professional or business sources, public blockchain networks and other sources where permitted by applicable law.

Other sources include identity verification providers, sanctions, politically exposed person and adverse media screening providers, and blockchain analytics providers.

Information that we collect about you

Our website, social media and/or other Services may automatically collect the following information about you each time you visit or otherwise use our website, social media and/or other Services:

  • technical information including but not limited to the IP address used to connect your device to the internet, the internet browser and version that you are using when accessing our website, social media or other Services, any additional plug-ins that you are using, and your device's operating system and platform;
  • information about the time and date you accessed our website, social media or other Services, and what you accessed on our website, social media or other Services. This includes links that you clicked on, what content you accessed, how long you accessed that content for, whether you downloaded any content, whether supplied by us or downloaded from a third party host, and how you navigated to and from our website, social media or other Services to other sites, applications or other pages hosted by us;
  • details about the computer, device, hardware, or software used to access our Services, such as IP address, device identifiers, internet service provider, plugins, device make and model, operating system, browser type, and other system specifications; and
  • general location of your device derived from your IP address.

We use technologies like cookies, log files, and web beacons to collect this information. These tools help us and our service providers recognise your device, manage authentication, remember preferences, personalise experiences and conduct data analytics.

Sensitive information

The only sensitive information we expect to process is information revealed by our compliance screening, such as information about criminal offences or sanctions (including adverse media) and political exposure (for example, politically exposed person status). We do not intentionally collect health, genetic or biometric information.

If we do collect any of your sensitive information, we will only collect it in accordance with applicable privacy laws and principles. We may process such information where necessary to comply with our legal obligations (for example, anti-money laundering, counter-terrorist financing and sanctions screening, which may reveal information about criminal offences or political exposure), for the prevention or detection of unlawful acts, or with your explicit consent where required.

How we use your personal information

We may collect, use and disclose your personal information to third parties where necessary and for the purposes for which it was collected, subject to applicable law. This may include:

  • providing our Services;
  • investigating and/or preventing suspected fraud or other criminal activities or misuse of our Services;
  • where we collect or disclose information that is or relates to the IP Address used to connect your device to the internet, for the purpose of fraud detection and management of the integrity of the Services. This may include detecting when users engage in illegal activities or breach our Terms of Service;
  • where information is or relates to system version information of your device, or the make and model of your device, for the purpose of our compatibility assessments with our software versions and other aspects of our Services;
  • operating the website, APIs, software, systems, sandbox or test environments and other Services;
  • using your personal information to provide you with information that you have requested from us and to provide, support or administer the Services;
  • communicate with you, including to inform you of updates to the website, the Services, our Terms of Service and/or this Privacy Policy;
  • using your personal information for marketing purposes to provide or offer services to you, where permitted by applicable law. This includes, but is not limited to, keeping you up to date with our latest news, events, special offers and promotion of our brand or other similar products that we think that you may be interested in. We do not use personal information that we receive about End Users or recipients from our customers for marketing purposes;
  • notifying you about any changes to our products, website, software, systems, brand or Services offered;
  • seeking your opinion and feedback on any of our Services, including for the purposes of product improvement and customisation, website or software improvement and personalisation and other general services;
  • for customer engagement and/or customer service purposes, including but not limited to identifying the effectiveness of advertising, allowing you to participate in website sharing features or other community features where available;
  • analysing the usage of, and improving, our Services;
  • for other general services such as website, software and systems security, maintenance, identification of fraud or errors, internal accounting and administration, compliance and risk management, and for any other purpose that we are required or permitted to do by law;
  • managing our relationships with you and our other customers, prospective customers, business partners, suppliers and service providers;
  • where relevant to the Services, processing and administering transactions or transfer requests, verifying or screening information, managing risk, preventing fraud or misuse, and complying with legal, regulatory, sanctions, anti-money laundering or other compliance obligations; and
  • verifying the identity of End Users and recipients where our customer's verification is insufficient or where required by applicable law, and sharing originator and beneficiary information with other financial institutions and virtual asset service providers as required by the Travel Rule.

Automated screening and decisions

We and our service providers use automated screening, including blockchain analytics and sanctions screening, to assess the risk associated with wallets, digital assets and transactions. Where a transaction fails these checks, it may be automatically declined or paused without human review at that stage. These checks are necessary to comply with our legal obligations and to prevent financial crime. If you believe a decision affecting you was made in error, you can contact us, or the customer through which the transaction was made, to request human review, express your point of view or contest the decision, subject to applicable law, including any restrictions on disclosing the reasons for a decision.

Children

Our Services are intended for businesses and are not directed at individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected personal information about a child, please contact us at privacy@anyflo.io.

Who we share your personal information with

We may disclose your personal information for the purposes for which it was collected, including:

  • as required by law;
  • to our customers, liquidity providers, on-ramp providers and other third-party providers where necessary to process transactions and provide the Services; and
  • on a confidential basis to our external service providers and advisors.

To be clear, we may disclose your personal information to our business partners, suppliers, subcontractors or the like, analytics providers and other third parties provided the disclosure of your personal information is for the purpose or ancillary to the Services that we or these third parties offer you and for the purposes for which the information was originally collected, and is permitted by applicable law.

The third parties to whom we may disclose personal information include: our customers (including where you are their End User or a recipient of a transaction); liquidity providers, on-ramp providers and other financial institutions or virtual asset service providers involved in a transaction; identity verification, sanctions screening and blockchain analytics providers; cloud hosting, IT, communications and customer support providers; professional advisers, auditors and insurers; and regulators, law enforcement agencies, courts and other public authorities where required or permitted by law. Liquidity providers, on-ramp providers and other financial institutions may use your personal information as independent controllers under their own privacy notices.

We may disclose your personal information to third parties if we buy or sell any business or assets, including our business, if we are under a duty to disclose your information, or if the disclosure of your personal information is necessary for us to conduct an investigation into any unlawful activity that we know or suspect has or may be engaged in.

We may disclose information where necessary for our company to comply with any relevant reporting obligations (if any) under applicable laws.

Transactions processed through the Services may be recorded on public blockchains. Information recorded on a public blockchain, such as wallet addresses and transaction details, is publicly visible, may be linked to you by others, and cannot be changed or deleted by us or anyone else.

How we store your personal information

We maintain commercially reasonable technical, administrative, and physical security measures designed to protect your information from loss, misuse, unauthorised access, disclosure, alteration, and destruction.

Where financial account, payment, digital wallet, transaction or similar information is transmitted to or through the Services, we take reasonable steps designed to protect that information and may use third party service providers in connection with the relevant Service. Where third party service providers receive or process personal information on our behalf, we require them to handle that information in accordance with applicable confidentiality, security and data protection obligations.

However, we cannot guarantee that transmissions of your information will always be secure or that unauthorised third parties will never be able to defeat the security measures taken by us or our third party service providers.

We will only keep your information for as long as reasonably necessary to fulfil the purposes for which your personal information was originally collected, including as reasonably necessary to provide the Services, resolve disputes, enforce agreements, maintain business and transaction records, and comply with applicable legal, regulatory, accounting or reporting requirements. For example, we generally retain identity verification and transaction records for at least five years after the end of the relevant business relationship or transaction, or longer where required by applicable anti-money laundering or other laws.

We will delete or de-identify your information after a reasonable time when it is no longer required for the purposes for which it was collected, subject to applicable legal, regulatory, accounting or reporting requirements.

Your personal information may be stored and processed in the United States and in other countries in which we or our service providers operate.

Where applicable law requires safeguards for an international transfer of personal information, we will take reasonable steps to implement appropriate safeguards. These may include the European Commission's standard contractual clauses, the UK International Data Transfer Addendum, or other mechanisms permitted by applicable law. You can request further information about these safeguards by contacting us.

We will take all reasonable steps and precautions to ensure that any transmission of your personal information via the internet is secure. However, we cannot guarantee the security of any data transmitted to our website or through the Services.

Once we receive your information, we take reasonable steps to protect your personal information. This may include storing any information on a secure server and employing procedures and security features to protect your personal information from any unauthorised recipients and to prevent unauthorised access to the same. We may also store your personal information in physical form.

Collection of your information using cookies and other tracking technologies

Our website and other Services may use "cookies" and similar technologies. Cookies are small pieces of data sent from a website and stored in your web browser. These pieces of data may allow our website or Services to remember who you are and to obtain information from you which allows us to deliver you a better and more customised service.

As a result of our website or Services' use of cookies and similar technologies, we may collect information such as your IP address, online activity and your web browser details. Information that we will not intentionally collect or store through cookies includes your passwords or other sensitive information.

We may use both persistent cookies, which remain on your device until their expiration or deletion, and session cookies, which are temporary files removed from your device once your browser is closed.

The types of cookies we may use include analytical and tracking cookies, which allow us to recognise and count the number of visitors and analyse use of the Services, as well as to support security and verify or administer transactions where relevant.

Where applicable law requires consent for non-essential cookies or similar technologies, we will seek that consent through the cookie banner or other preference mechanism made available through the relevant Service. You may also be able to manage cookies through your browser settings.

Please note that you should also refer to our Terms of Service for further information on this issue.

Legal bases for processing (EEA and UK)

Where EEA or UK data protection law applies and we process personal information as a controller, we rely on the legal basis appropriate to the relevant processing. This may include: (a) our legitimate interests, or those of a third party, in operating, securing and improving the Services, administering our business relationships, preventing fraud and misuse, managing compliance and risk, and establishing, exercising or defending legal rights, except where those interests are overridden by your rights and interests; (b) compliance with a legal obligation that applies to us; (c) performance of a contract with you, or taking steps at your request before entering into a contract, where you are personally a party to that contract; or (d) your consent, where required or otherwise appropriate.

Where we process personal information solely on behalf of a customer as its processor or service provider, the customer is responsible for determining the applicable lawful basis for that processing, subject to applicable law.

Your rights

You have the right to request access to the personal information we hold about you by contacting us or our Privacy Officer by emailing privacy@anyflo.io.

If we cannot provide you with access, we will write to you and provide you with the reasons why we are unable to provide you with access, where required by applicable law.

If any personal information that we hold about you is inaccurate, incomplete or not up to date, you may write to us or our Privacy Officer and request that we correct the information at the above address.

You may request that we do not disclose or otherwise process your personal information for certain purposes (for example, for marketing purposes) where applicable law gives you that right. You can exercise applicable rights by contacting us or our Privacy Officer at privacy@anyflo.io. If we process your personal information only on behalf of one of our customers, please direct your request to that customer, and we will assist it in responding.

You may choose to opt out of receiving any further marketing correspondence from us by writing to us at the above address or emailing us at the above email address.

We recognise the below rights which you enjoy under the applicable data protection law with respect to your personal data:

  • Right to be informed: You have the right to be informed about the collection and use of your personal data. This information is set out in the terms of our Privacy Policy.
  • Right of access: You may request information from us at any time as to whether we have stored your personal data and which personal data we have stored. We are required to provide this information to you free of charge.
  • Right to rectification: If your personal data stored by us is inaccurate or incomplete, you have the right to demand at any time that we correct the information.
  • Right to erasure: You have the right to demand that we erase your personal data if and to the extent that the data is no longer needed for the purposes for which it was collected or if the data is processed on the basis of your consent and you have opted to revoke your consent. In such cases, we will erase your personal data unless an exception applies.

You do not have a right to erasure if:

  • The data may not be deleted due to a statutory obligation or must be processed due to a statutory obligation.
  • The processing of data is necessary for the establishment, exercise or defence of legal claims.
  • Right to restriction of processing: In certain circumstances, for example where you contest the accuracy of your personal data or have objected to our processing, you have the right to ask us to restrict the processing of your personal data.
  • Right to data portability: You have the right to receive the personal data that you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit this data to another controller, where technically feasible. This right applies only if the processing is based on your consent or a contract and is carried out by automated means.
  • Right in relation to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This right does not apply if the decision is needed for a contract with us, is required by law, or is based on your consent.
  • Right to object to processing: If your data is processed by us on the basis of Article 6(1)(f) GDPR, you may object at any time to processing by us. You may assert any and all of the rights of data subjects described above against us by addressing your specific requests by contacting our Privacy Officer via privacy@anyflo.io.
  • Right to lodge a complaint with a data protection supervisory authority: Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.
  • Right to withdraw consent: Where we rely on your consent, you may withdraw it at any time. This does not affect the lawfulness of processing carried out before you withdraw it.

Jurisdiction-specific provisions - United States residents

Depending on where you live, you may have rights under US state privacy laws, such as the California Consumer Privacy Act, to know about, access, correct and delete your personal information, to opt out of the sale or sharing of your personal information or its use for targeted advertising, and not to be discriminated against for exercising these rights. Some of these laws do not apply to information processed in a business-to-business context or that is subject to federal financial privacy laws. We do not sell your personal information or share it for cross-context behavioural advertising. To exercise a right, contact us at privacy@anyflo.io. We will need to verify your identity before responding, and you may use an authorised agent where permitted by law.

Complaints

If you have a concern about how we handle your personal information, please contact us or our Privacy Officer at privacy@anyflo.io. We will consider your complaint and respond within a reasonable period. You may also have the right to lodge a complaint with an applicable privacy or data protection authority.

Privacy Policy updates

We reserve the right to make changes to this Privacy Policy at any time. We encourage you to regularly review this Privacy Policy to make sure you are aware of any changes and how your information may be used. If we make material changes, we will notify you by updating the date at the top of this Privacy Policy and, where appropriate, through the Services or by email.

Contact us

If you have any questions about this Privacy Policy or how we handle your personal information, please contact us by email at privacy@anyflo.io.

Anyflo

Schedule time with our team

Tell us about your needs. We'll come back within one business day with a tailored plan.

Copyright © 2026 Anyflo Technologies Inc. All rights reserved.
Privacy PolicyTerms of Service
What are you interested in?
Explore API docs
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.