
This Privacy Policy explains how AllScale Inc. Limited ("AllScale," "we," "us," or "our"), a company duly incorporated in Hong Kong, collects, uses, discloses, retains, and protects personal data when you visit allscale.io (the "Site"), use the AllScale application, dashboard, APIs, CLI, or other interfaces (the "App"), create or receive an invoice or Claim Link, use a Virtual Account, interact with a Non-Custodial Wallet, or otherwise use an AllScale Service. It applies to account holders and, where relevant, their beneficial owners, control persons, personnel, payers, senders, claimants, recipients, beneficiaries, merchants, customers, website visitors, and other individuals whose personal data we process. Capitalized terms not defined here have the meanings given in the AllScale Terms of Use. AllScale is the controller of personal data for the purposes it independently determines. A Financial Services Provider, Partner Financial Institution, wallet-infrastructure provider, identity-verification provider, or other third party may be a separate controller under its own privacy notice for processing it independently determines.
We collect only the personal data reasonably necessary for the purposes described in this Privacy Policy, subject to Applicable Law. Some information is required to create or secure an AllScale Account, comply with legal or Financial Services Provider requirements, screen transactions, issue or operate a Virtual Account, process a Claim Link, or complete a transaction. If you do not provide required information, or if it cannot be verified, we or an applicable third party may be unable to provide, or may restrict, the affected service. Information identified as optional is provided voluntarily.

By accessing or using an AllScale Service, you acknowledge that this Privacy Policy has been made available to you and describes our processing practices. Where Applicable Law requires consent for a specific activity, we will request it separately or through an appropriate choice. Acknowledging this Privacy Policy does not convert processing that is based on contract, legal obligation, or legitimate interests into consent-based processing.
(a) You are legally permitted to use the relevant AllScale Service and to provide the personal data you submit;
(b) We may process personal data as necessary to perform or take steps relating to our contract with you, comply with legal obligations, pursue legitimate interests that are not overridden by your rights, protect vital interests where applicable, and for purposes to which you have consented;
(c) If you provide personal data about another person, including a beneficial owner, employee, payer, sender, claimant, recipient, beneficiary, or Customer, you represent that you have authority and a lawful basis to do so and that you have provided any notice required by law; and
(d) You will not place sensitive personal data in an invoice, Claim Link, payment memo, blockchain transaction, or other field unless it is strictly necessary, permitted by law, and intended to be disclosed to every relevant recipient or public network.

Where we rely on your consent, you may withdraw it at any time by using the applicable in-product setting or emailing [email protected]. Your request should identify the processing activity for which you withdraw consent.
(a) Provide your name, account email address, and enough information for us to identify the relevant account or processing activity;
(b) We may request information reasonably necessary to verify your identity or authority. Please do not send a full identification document unless we specifically request it through an approved secure channel;
(c) Withdrawal does not affect the lawfulness of processing completed before withdrawal; and
(d) Withdrawal does not require us or an independent third party to stop processing that is necessary for contract performance, compliance, fraud prevention, security, legal claims, recordkeeping, or another lawful basis.
After verifying your request, we will stop the applicable consent-based processing within the period required by law. Withdrawal may prevent us from providing an optional feature, but it does not automatically close your account or require deletion of data that we or a Financial Services Provider, Partner Financial Institution, compliance vendor, or public blockchain must retain. Deletion requests are handled separately under Section IX.
The AllScale Services are not directed to children. You may not use them or provide personal data unless you are at least 18 years old and have legal capacity under Applicable Law. If we learn that we collected personal data from an ineligible child without a lawful basis, we will take appropriate steps to delete or restrict it, subject to legal retention duties.

The personal data we process ("Data") depends on the services you use, your role in a transaction, your jurisdiction, and the requirements of our Financial Services Providers and Partner Financial Institutions. Data may be collected directly from you, automatically, from another participant in a transaction, from a service provider or financial institution, from public blockchains and databases, or from governmental and compliance sources.
3.1 Information You Provide to Us at Registration
When you create or administer an AllScale Account or apply for a service, you may provide identification, contact, authentication, business, financial, and compliance information, including:
• Full legal name and any former or alternate names
• Date and place of birth, nationality or citizenship, and gender where lawfully requested
• Authentication Credentials (including Username, Password, Passkeys, and Google or Email Sign-in tokens)
• E-mail address
• Full personal address and zip code
• Financial information, bank-account information, source of funds, source of wealth, expected activity, and transaction purpose
• Employment, occupation, business, industry, and professional information
• Mobile phone number
• One-Time Passwords (OTP) and verification codes sent to your email or mobile device
• Google authenticator to be used for 2FA verification for improved security.
• Geolocation of the mobile device, or the IP address of the computer, from which you opened your account;
• Government-issued identification details and images, taxpayer or national identification numbers where required, proof of address, and identity-verification photographs or video
• Entity legal name, registration number, jurisdiction, registered and operating addresses, formation documents, ownership and organizational information
• Names, titles, contact details, authority, identification, and ownership percentages of directors, officers, authorized users, beneficial owners, and control persons
• Tax classification and tax-identification information where required
• Compliance questionnaires, attestations, sanctions and politically exposed person information, verification results, risk ratings, and supporting correspondence
3.2 Information on Special Categories of Personal Data
Identity-verification providers may process facial images, liveness information, or biometric templates to verify identity and prevent fraud where permitted by law. We will request consent or provide another legally required notice where Applicable Law treats this as biometric, sensitive, or special-category data. AllScale may receive the verification result, risk indicators, and limited supporting data rather than the underlying biometric template.
Passkeys or device-level biometric authentication may rely on a fingerprint, face, or device PIN processed locally by your operating-system or credential provider. Unless expressly disclosed, AllScale does not receive the underlying fingerprint or facial scan; we receive an authentication assertion, credential identifier, or similar security signal. Your use of a third-party credential provider is also governed by that provider's privacy notice.
3.3 Information We Collect as You Use AllScale Services
3.3.1 Service Usage Information
When you use the Site, App, APIs, CLI, Claim Links, Virtual Accounts, or other AllScale Services, we and our service providers automatically collect technical, device, log, security, and usage data, such as:
(a) access date and time; (b) IP address and approximate location derived from it; (c) device, browser, operating-system, App-version, language, and unique identifier information; (d) pages, features, links, and actions; (e) session, cookie, referral, error, performance, and diagnostic data; and (f) authentication, security, API, and audit logs.
We and processors acting on our instructions use this information to operate and secure the services, authenticate users, prevent abuse, investigate incidents, troubleshoot errors, measure performance, maintain audit trails, and comply with law. Certain independent providers may collect similar information under their own privacy notices.
3.3.2 Transaction Information
We process transaction and financial-service information relating to supported activity, including wallet and blockchain addresses, asset and currency type, amount, network, transaction hash, timestamp, status, confirmations, account or virtual-account identifiers, sender and beneficiary information, bank and payment-rail metadata, payment references, conversion instructions, rates, spreads, fees, routing and settlement data, provider confirmations, account balances displayed through the interface, returns, recalls, reversals, chargebacks, disputes, negative balances, and related support and compliance records. We may associate public blockchain activity with an account or other identity where necessary for service delivery, compliance, security, fraud prevention, or legal claims.
3.4 Information Related to Non-Custodial Wallet Services
AllScale uses third-party cryptographic infrastructure, including Turnkey, to help generate and operate Non-Custodial Wallets and Claim Wallets. These providers may process account identifiers, public keys, wallet addresses, device and authentication signals, policy or signing requests, and audit logs needed to provide cryptographic infrastructure and security.
(a) Private Keys and Credentials: Private Keys or key material may be generated and protected within secure cryptographic infrastructure and may be exportable by you. AllScale does not receive or control your unencrypted Private Keys or acquire custody of your Digital Assets. You should never provide a Private Key, recovery phrase, or Claim Credential to AllScale support. A Claim Credential may itself constitute sensitive authentication information and may enable access to assets.
(b) Authentication and Transaction Signing: When you register, authenticate, create a Claim Link, or sign or authorize a transaction using email, single sign-on, Passkeys, OTPs, or another configured method, AllScale and relevant infrastructure providers process authentication signals, credential identifiers, device and session information, signing or policy requests, and related audit records to verify authorization and protect the service.
(c) Public Blockchain Data: We process publicly available information associated with relevant wallet, Claim Wallet, Transit Address, or destination addresses, including balances, token holdings, transaction history, counterparties, smart-contract interactions, transaction hashes, risk indicators, and routing outcomes. Blockchain information may be public, globally accessible, immutable, and impossible for AllScale to alter or delete. Public keys and transaction patterns may be correlated with you now or in the future by third parties, including analytics providers and law enforcement. A privacy request to AllScale cannot erase data from a public blockchain.
3.5 Information Related to Invoicing Services
When you generate an invoice, we process the information you provide, which may include the recipient's name, wallet address, email address, description of goods or services, payment amount, tax or reference information, and delivery details. You are responsible for ensuring that you have a lawful basis to provide recipient information and that invoice descriptions do not contain unnecessary sensitive data.
We also process transaction information related to the payment of the invoice, which is collected for all AllScale User accounts.
3.5A Information Related to Checkout Services
When you use the AllScale Checkout Services to accept payments in supported Digital Assets from your Customers, we collect and process the following information:
(a) Merchant Configuration Data: information you provide when setting up the Checkout Services, including your designated Non-Custodial Wallet address for receiving payments, API credentials, hosted payment link configurations, and any payment preferences or parameters you configure through the AllScale Dashboard or API.
(b) Customer Transaction Data: when a Customer opens a checkout link, interacts with the hosted page, or initiates a payment, we may process device, log, and usage data and the Customer's originating wallet address, asset type and amount, blockchain network, transaction hash, timestamp, and screening status. Unless a Customer or Merchant supplies it for another feature or support request, Checkout is not designed to require the Customer's name or email address.
(c) Generated Address Data: the Checkout Services may generate temporary, single-use Digital Asset Addresses (including Transit Addresses used for KYT screening) to facilitate individual transactions. We process the address, its associated transaction records, and routing outcomes.
(d) Payment Discrepancy Data: records of underpayments, overpayments, and network fee deductions associated with Checkout transactions, which are retained for dispute resolution and record-keeping purposes.
The Checkout Services operate on a non-custodial basis. AllScale's lack of custody over Digital Assets does not mean that transaction, device, wallet-address, risk, or support information is anonymous or outside data-protection law. Merchants remain independently responsible for any privacy notice, lawful basis, KYC, recordkeeping, or data-subject request obligations applicable to information they collect from their Customers.
3.6 Information Related to Reward System
If you participate in the AllScale Reward System, we collect and process information about your interactions with the platform, which may include on-chain activity, transaction volume, login frequency, feature usage, referrals, eligibility signals, and reward history, to calculate and administer AllScale Points or other rewards under the Terms of Use. Participation does not guarantee any reward or distribution.
3.7 Information Related to KYT (Know Your Transaction) Screening
AllScale may apply automated or semi-automated Know Your Transaction ("KYT"), sanctions, fraud, or risk screening to supported Digital Asset transactions, including Checkout, Claim Link, wallet, and settlement activity where enabled or required. In connection with such screening, we process the following categories of data:
(a) Transaction Data: relevant originating, source, Claim Wallet, Transit Address, destination, and counterparty wallet addresses; transaction hash; blockchain network; Digital Asset type and amount; timestamp; smart-contract interaction; and related account, routing, and transaction metadata.
(b) KYT Screening Results: the risk score, risk category, screening decision (pass or fail), and any flags or alerts generated by the third-party KYT vendor in relation to the transaction.
(c) Routing Outcome Data: whether an activity was allowed, forwarded, claimed, delayed, restricted, rejected, or returned; the applicable wallet addresses and on-chain transaction hashes; and any related review, escalation, or reporting status.
This data may be shared with KYT, sanctions, fraud, blockchain-analytics, Financial Services Provider, Partner Financial Institution, Stablecoin issuer, and governmental recipients as necessary for screening, monitoring, investigation, reporting, transaction handling, and legal compliance. Screening records are retained as required by AML, CTF, sanctions, fraud, recordkeeping, dispute, and other Applicable Law or legitimate risk-management needs. On-chain information remains public and cannot be deleted by AllScale.
3.8 Information Related to Claim Links
When you create, send, open, or claim a Claim Link, we may process the sender's account identifier and wallet address; Claim Wallet and destination wallet addresses; blockchain network; Digital Asset type and amount; creation, sharing, opening, expiration, cancellation, claim, and recovery timestamps and status; transaction hashes; device, IP, browser, session, security, and audit data; and any recipient name, email address, phone number, message, or other information the sender elects to provide.
A sender may provide information about a recipient who does not have an AllScale Account. We receive that information from the sender and use it to generate, deliver, administer, secure, and document the Claim Link and related transaction. The sender is responsible for having authority and a lawful basis to provide it and for directing the recipient to this Privacy Policy where required.
Claim Links may be accessible to anyone who obtains the link or Claim Credential. Link previews, browsers, messaging and email providers, QR-code tools, device backups, security scanners, and other intermediaries may process or expose link information and metadata. Do not include sensitive personal data in a link or message and use an appropriately secure delivery channel. AllScale cannot delete information retained by an independent delivery provider or recorded on a public blockchain.
Claim Link processing is non-custodial. Processing a wallet address, link status, authentication signal, or on-chain transaction does not give AllScale possession or control of the Claim Wallet's Private Key or Digital Assets. However, wallet addresses, link metadata, and blockchain information may constitute personal data when associated or reasonably linkable to an individual.
3.9 Information Related to Virtual Accounts and Financial Services Providers
To assess eligibility for and provide a Virtual Account, AllScale and Financial Services Providers, including HIFI Bridge, Inc., may collect and exchange identification, contact, business, beneficial-ownership, control-person, taxpayer, government-identifier, document, selfie or liveness, occupation, expected-activity, source-of-funds, source-of-wealth, sanctions, PEP, adverse-media, fraud, device, and risk information. Providers may request additional information and conduct ongoing KYC, KYB, AML/CTF, sanctions, fraud, and transaction monitoring.
We may process Virtual Account and transfer data, including account and routing numbers or identifiers; beneficiary and verified-name information; payer or sender name, address, bank, account details, and payment reference; amount, currency, rail, date, status, and bank messages; conversion instructions, quoted and executed rates, spreads, fees, and intermediate routing; designated wallet address, blockchain network, Stablecoin, and transaction hash; and any hold, rejection, return, recall, reversal, chargeback, dispute, negative balance, complaint, or investigation.
Virtual Account information may come from you, an authorized user, a payer or sender, HIFI, a Partner Financial Institution, correspondent or intermediary bank, payment network, compliance provider, public blockchain, public or governmental database, or another transaction participant. We may disclose it among those parties to open and administer the service, verify names and eligibility, route and reconcile funds, automatically convert fiat to Stablecoins, deliver assets to a designated wallet, process returns and reversals, provide support, prevent fraud, and comply with legal and regulatory duties.
Fiat associated with a Virtual Account may be received through a provider's omnibus or for-benefit-of (FBO) arrangement and attributed through provider and bank records. Those records may identify or associate you with a beneficial interest, beneficiary profile, Virtual Account identifier, transfer, or destination wallet for reconciliation, compliance, risk, and any legally available pass-through treatment. The Virtual Account is not a bank account opened or controlled by AllScale, and the relevant provider or bank may process Data as an independent controller.
Before using a Virtual Account, you may be required to review and affirmatively accept the applicable Financial Services Provider's user terms and privacy policy. HIFI's current privacy policy is available at https://www.hifi.com/privacy-policy. HIFI and its partners may independently retain and use overlapping User Data, Verification Data, Compliance Data, and transaction records under their agreements, privacy notices, regulatory duties, and risk policies, including after the AllScale relationship ends.
AllScale CLI. The CLI permits eligible Users to access their own AllScale Account from machines they control, including through their own automation scripts and AI assistants, subject to the limited license in the Terms of Use. That license permits installation and operation of unmodified copies for the User's own account; prohibits redistribution, modification, derivative works, removal of proprietary notices, competitive development, and circumvention of authentication or rate limits; treats package-manager caches, internal mirrors, container images, and lockfiles maintained solely for the User's authorized internal use as permitted rather than redistribution; confirms that extracting intentionally recoverable client-embedded build-identity values is not by itself a breach and does not confer authorization; leaves separately installed third-party dependencies subject to their own licenses; and requires use to stop and copies to be deleted following breach or license termination. When you install or use the CLI, AllScale may process the CLI and build version; operating-system, device, IP-address, account, and business information; scoped agent-key identifiers and permission metadata; and command, request, response, transaction, timestamp, error, diagnostic, security, and audit information to authenticate requests, provide and support the service, enforce permissions and rate limits, investigate abuse, comply with law, and maintain security. Credentials, configuration, shell history, local caches, container images, CLI output, and optional sidecar or agent logs may contain personal, confidential, or transaction data and generally remain under your control. If you provide CLI access or output to a script, AI assistant, model provider, CI service, or other third party, that party may process Data under its own terms; you are responsible for least-privilege access, supervision, retention, and security, and authenticated commands may be treated as yours.
3.10 Sources of Personal Data
We collect Data: (a) directly from you; (b) automatically from devices, browsers, the App, APIs, cookies, and security systems; (c) from your employer, organization, administrator, sender, payer, merchant, recipient, claimant, beneficiary, counterparty, or other transaction participant; (d) from Affiliates, processors, wallet and authentication providers, Financial Services Providers, Partner Financial Institutions, banks, payment networks, Stablecoin issuers, liquidity and settlement providers, and compliance vendors; (e) from blockchains and other publicly available sources; and (f) from governmental, sanctions, corporate-registration, identity, fraud, PEP, adverse-media, and other compliance databases.

4.1 To Provide and Maintain Our Services
We use Data to provide, administer, personalize, maintain, and support the AllScale Services; create and secure accounts and wallets; operate and support the CLI; generate, deliver, display, and process invoices and Claim Links; provide access to Virtual Accounts; route, reconcile, convert, settle, return, or reverse transactions; display public blockchain information; calculate rewards; and provide records, receipts, notifications, and customer support.
We use IP addresses, cookies, device identifiers, authentication signals, and security logs to authenticate users, maintain sessions, prevent account takeover and abuse, comply with provider requirements, and operate the services. Certain core processing is necessary to provide an account or service and cannot be disabled while you use it.
4.2 To Protect Our Users
We use Data to protect users, claimants, recipients, counterparties, AllScale, Financial Services Providers, Partner Financial Institutions, and the integrity of the services; to detect credential compromise, phishing, fraud, sanctions risk, money laundering, cyberattacks, unauthorized use, and other harmful activity; and to investigate and remediate incidents.
We use IP addresses and cookie data to protect against automated abuse such as spam, phishing, and Distributed Denial of Service (DDoS) attacks.
We analyze account, authentication, wallet, Claim Link, Virtual Account, bank-rail, and transaction activity to identify suspicious or unauthorized behavior and to prevent or reduce fraud, financial crime, security incidents, chargebacks, reversals, and loss.
4.3 To Comply with Legal and Regulatory Requirements
We may use and disclose Data to comply with Applicable Law, sanctions, AML/CTF, KYC/KYB, tax, accounting, recordkeeping, consumer-protection, privacy, cybersecurity, court, regulatory, law-enforcement, and national-security requirements; respond to lawful requests; protect rights and safety; establish, exercise, or defend legal claims; and cooperate with Financial Services Providers and Partner Financial Institutions. Where legally permitted, we may disclose information without advance notice or consent, including where notice is prohibited or could prejudice an investigation.
We retain Data for the periods described in Section 4.11 and may continue to use or disclose retained Data after account closure when necessary for legal compliance, audits, fraud prevention, transaction completion, reversals, disputes, security, corporate records, or legal claims. Marketing communications remain subject to your choices.
AllScale, Financial Services Providers, Partner Financial Institutions, and compliance vendors may require identity and business verification, beneficial-ownership information, sanctions and PEP screening, source-of-funds or source-of-wealth information, transaction monitoring, requests for information, and ongoing review for personal and enterprise accounts. Different parties may independently determine whether to approve, restrict, suspend, or terminate access.
4.4 To Measure Site Performance
We actively measure and analyze data to understand how our services are used. This review activity is conducted by our operations team to continually improve our platform's performance and to resolve issues with the user experience.
We continuously monitor our systems' activity information and communications with users to look for and quickly fix problems.
4.5 To Communicate with You
We use contact and account information to provide support, respond to complaints and privacy requests, deliver Claim Links or invoices at your direction, request compliance information, and send service, security, login, transaction, Virtual Account, legal, and policy notices. Transactional or legally required messages are not marketing and may continue while an account or obligation remains active.
4.6 To Deliver Our Newsletter, Which Includes Publicity and Sales, When Chosen
Subscribing to our news and publicity services is voluntary. You will always have the option to opt out.
4.7 To Enforce the Terms of Use and Other Agreements and Policies
We use relevant Data to investigate and enforce the Terms of Use, Financial Services Provider Terms, security requirements, and other agreements and policies, including restricting or terminating access, preserving evidence, collecting amounts due, resolving disputes, and establishing or defending legal claims.
4.8 To Administer the Reward System
We process your platform usage data to track your eligibility for AllScale Points and to execute the distribution of rewards in accordance with our User Agreement.
4.9 To Conduct KYT (Know Your Transaction) Screening
We process transaction and associated account, device, wallet-address, and risk data and share it with appropriate compliance and financial-service recipients to assess risk, detect and prevent money laundering, terrorist financing, sanctions evasion, fraud, theft, account takeover, and other prohibited activity, comply with Applicable Law and provider requirements, and decide whether to allow, delay, reject, return, report, or review an activity. Depending on the context and jurisdiction, the legal bases include contract performance, legal obligation, and our or a third party's legitimate interests in security, compliance, and platform integrity.
4.10 Legal Bases for Processing
Where a legal basis is required, we rely on one or more of the following: (a) performance of a contract or steps requested before entering one, including providing an account, Claim Link, Virtual Account, wallet, payment, settlement, or support service; (b) compliance with legal and regulatory obligations; (c) legitimate interests, including security, fraud and financial-crime prevention, service operation and improvement, business administration, enforcement, and legal claims, balanced against individual rights; (d) consent for optional marketing, certain cookies, biometrics, or other processing where specifically requested; and (e) vital interests in exceptional circumstances. A third party may rely on a different lawful basis for its independent processing.
4.11 Data Retention
We retain Data only for as long as reasonably necessary for the purposes described here, including service delivery, security, accounting, audits, legal claims, and compliance. Retention depends on the Data and context. KYC, KYB, AML/CTF, sanctions, Virtual Account, payment, conversion, transaction, complaint, and compliance records may be retained for at least five years after the relevant transaction or end of the relationship, or longer where required by Applicable Law, a Financial Services Provider, a Partner Financial Institution, a litigation hold, an investigation, or a limitation period. Security logs, support records, and corporate records are retained under risk-based schedules. Data may remain longer in backups until securely overwritten. De-identified information may be retained where it cannot reasonably be used to identify an individual. Public blockchain data is retained by the network indefinitely and is outside AllScale's control.
4.12 Automated and Risk-Based Processing
AllScale and third parties may use automated or semi-automated tools to verify identity, screen wallets and transactions, detect fraud or account takeover, generate risk scores and alerts, match beneficiary names, monitor sanctions and PEP exposure, and determine whether activity should proceed, be delayed, be returned, or receive human review. Inputs may include identity, device, behavioral, bank, payment, wallet, blockchain, and third-party risk data. A decision may result in additional information requests or restriction, suspension, rejection, return, or reporting. Where Applicable Law grants rights concerning a solely automated decision with legal or similarly significant effects, you may request the safeguards described in Sections IX and X. AllScale cannot override a decision made independently by a Financial Services Provider or Partner Financial Institution.

Cookies and similar technologies, such as local storage, pixels, SDKs, and device identifiers, may be used to maintain sessions, remember preferences, authenticate users, prevent fraud, measure performance, analyze use, and, where enabled and permitted, support communications or marketing. Strictly necessary technologies are used to provide and secure the Site and App. Where required, we request a choice before using non-essential analytics or advertising technologies. You can manage available choices through our consent tool or browser or device settings, but blocking necessary technologies may impair the services. A separate Cookie Notice or in-product disclosure may provide additional details and will control for the technologies it specifically describes.

AllScale may disclose Data to the following categories of recipients for the purposes described in this Privacy Policy: (a) Affiliates, for service delivery, security, compliance, support, administration, and corporate operations; (b) processors and service providers, including hosting, cloud, communications, analytics, customer-support, cybersecurity, wallet-infrastructure, identity-verification, document-verification, sanctions, fraud, KYT, accounting, legal, audit, and rewards providers; (c) Financial Services Providers, including HIFI Bridge, Inc., and their Partner Financial Institutions, payment networks, correspondent and intermediary banks, processors, compliance providers, liquidity providers, Stablecoin issuers, custodians, and settlement partners; (d) other transaction participants, including payers, senders, recipients, claimants, beneficiaries, merchants, customers, and their service providers, as necessary to carry out an instruction or transaction; (e) courts, regulators, law-enforcement, tax, sanctions, and other governmental authorities, and professional advisers, where permitted or required; (f) counterparties and advisers in a financing, merger, acquisition, reorganization, bankruptcy, asset sale, or similar corporate transaction; and (g) other recipients at your direction or with your consent. Processors are required to protect Data under applicable contracts. Independent controllers process Data under their own privacy notices and legal responsibilities.
KYT, sanctions, fraud, and blockchain-analytics vendors may receive wallet addresses, transaction hashes, blockchain and asset details, amounts, timestamps, routing data, device or account indicators, and other metadata necessary to conduct screening and monitoring. Depending on the service and risk, information supplied to a vendor may be linked to an AllScale account or verified identity. Vendors may generate risk scores, categories, alerts, screening decisions, and investigative records. We limit disclosures to information reasonably necessary for the authorized purpose, subject to legal and provider requirements.
AllScale uses third-party authentication and credential services, including Passkey ecosystems supplied by companies such as Google or Apple. Those providers may receive device, credential, account, or usage information under their own privacy notices. AllScale does not control their independent processing and cannot guarantee the security or availability of a third-party credential service.
When you create an invoice or Claim Link, the information you include and the related payment or claim status may be disclosed to the intended recipient and to providers used to generate, host, transmit, preview, or process it. If you use email, messaging, QR codes, or another third-party delivery channel, that channel may independently collect the link, sender and recipient identifiers, message metadata, device data, or content. A Claim Link or Claim Credential may be copied or forwarded; do not include unnecessary personal data or use an insecure delivery method.
A payer, claimant, or User may be redirected to, or interact through, a third-party payment, on-ramp, off-ramp, identity-verification, or financial-service platform. That provider may collect information directly and process it under its own privacy notice. AllScale may receive identity or eligibility status, transaction and settlement records, risk results, and other information necessary to support the service, even if AllScale does not receive the underlying identity documents.
When you use Checkout, Claim Link, Virtual Account, wallet, conversion, or settlement features, relevant information may be transmitted automatically to compliance vendors and financial-service participants without a separate consent request for each transaction. Such processing is integral to the requested service and may be required by contract, law, provider rules, security, fraud prevention, or legitimate interests. If you do not want this processing, do not initiate or continue using the affected service.
We seek to limit disclosures to Data reasonably necessary and proportionate for the disclosed purpose, except where law, a regulator, a Financial Services Provider, or a Partner Financial Institution requires additional information. Consent is not the only lawful basis for these disclosures, and we will not request consent where processing instead relies on contract, legal obligation, or legitimate interests. Third parties may retain Data under their own legal duties and privacy notices.
6.1 Virtual Account and Financial Services Provider Disclosures
For Virtual Accounts and related fiat-to-Stablecoin services, Data may be disclosed to HIFI, Partner Financial Institutions, payment networks, correspondent and intermediary banks, identity and compliance providers, processors, liquidity and settlement providers, Stablecoin issuers, wallet-infrastructure providers, auditors, and regulators. These disclosures may include Verification Data, beneficial-ownership and control-person information, transaction and bank-rail data, wallet addresses, screening results, support records, and evidence of your acceptance of provider terms and privacy notices. HIFI and certain partners may independently determine purposes and means of processing and may process Data globally under their own privacy notices.
We do not disclose a Virtual Account number, bank-account number, Private Key, Claim Credential, or similar access credential to an unaffiliated third party for that third party's own marketing. This does not restrict disclosures necessary to provide, process, service, secure, enforce, or reconcile a transaction or account; prevent fraud; comply with law; or act at your direction.

You may choose whether to receive optional marketing communications and may unsubscribe using the link in an email or an available account setting. You may also manage non-essential cookies where a consent tool is provided. These choices do not stop service, security, compliance, legal, transaction, or account messages.
Processing necessary for account security, wallet functionality, Claim Links, Virtual Accounts, payments, conversions, settlement, KYC/KYB, KYT, sanctions screening, fraud prevention, recordkeeping, legal compliance, disputes, and provider requirements cannot be opted out of while you use the affected service. You may stop future optional processing by discontinuing the service or closing your account, but previously collected Data may continue to be retained and processed on another lawful basis.

AllScale maintains administrative, technical, and physical safeguards designed to protect Data, which may include encryption in transit and at rest, access controls, multi-factor authentication, logging and monitoring, vulnerability management, personnel controls, vendor diligence, incident-response procedures, and secure disposal. Safeguards vary according to the sensitivity and context of the Data and Applicable Law. Independent providers maintain their own security programs.
You are responsible for protecting devices, email and single-sign-on accounts, passwords, Passkeys, OTPs, API keys, Private Keys, recovery material, Claim Links, and Claim Credentials. AllScale cannot protect or recover a credential that it does not possess or control, reverse a confirmed blockchain transaction, or remove public blockchain data. Notify us promptly of suspected unauthorized account or Data access, but do not send us a Private Key, recovery phrase, or Claim Credential.
No Internet transmission, electronic storage, cryptographic system, blockchain, bank rail, provider platform, or authentication method is completely secure. We cannot guarantee absolute security or that unauthorized parties will never access, infer, copy, or misuse Data. Where required by law, we will provide notices of qualifying personal-data breaches to affected individuals or authorities.

Depending on your location and subject to legal exceptions, you may have rights to access or know about Data, correct inaccurate Data, delete Data, restrict or object to processing, obtain portability, withdraw consent, opt out of certain sale, sharing, targeted advertising, or profiling, limit certain uses of sensitive personal data, appeal a decision, and complain to a regulator. Rights do not necessarily apply to a legal entity or to all Data, and may be restricted for AML/CTF, sanctions, fraud, security, confidential supervisory information, legal claims, other persons' rights, or recordkeeping. We cannot alter or delete public blockchain data or Data controlled solely by an independent third party. To submit a request, email [email protected] and: (a) provide your name, registered contact details, and enough information to identify the relevant account, service, or transaction.
(b) We will use a verification method reasonably proportionate to the request and Data involved. We may request account authentication, confirmation through a registered channel, or additional information. Government identification should be submitted only if specifically requested through an approved secure channel.
(c) Clearly describe the right you wish to exercise and the Data, account, service, or time period involved.
(d) An authorized agent must provide legally sufficient proof of authority, and we may verify the request directly with you where permitted.
We will respond within the period required by Applicable Law and may extend that period where permitted. We may deny or limit a request and will explain the basis where required. We will not discriminate against you for exercising a privacy right, although deleting or restricting Data necessary for a service may make that service unavailable. We generally do not charge a fee unless permitted by law, such as for manifestly unfounded, excessive, or repetitive requests.

If the GDPR, UK GDPR, or Swiss data-protection law applies, AllScale processes Data on one or more of the following legal bases: performance of a contract or steps requested before a contract; compliance with legal obligations; legitimate interests in operating, improving, securing, and protecting the services, preventing fraud, enforcing agreements, and establishing legal claims, balanced against your rights; consent where specifically requested; and vital interests in limited circumstances. Financial Services Providers and Partner Financial Institutions may identify their own legal bases in their privacy notices.
(a) Access — obtain confirmation and a copy of Data, together with required processing information;
(b) Rectification — correct inaccurate Data and complete incomplete Data;
(c) Erasure — request deletion in circumstances provided by law, subject to exceptions including legal obligations and claims;
(d) Restriction — request restricted processing in circumstances provided by law;
(e) Objection — object to processing based on legitimate interests and object at any time to direct marketing;
(f) Portability — receive certain Data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where legally required; and (g) withdraw consent without affecting prior lawful processing and lodge a complaint with the competent supervisory authority.
We generally respond to a valid request within one month and may extend the response period as permitted by law. Contact [email protected]. If screening or another process produces a decision based solely on automated processing that has legal or similarly significant effects, we will provide safeguards required by law, which may include an opportunity to request human intervention, express your position, or contest the decision. Compliance or provider decisions may also be made or reviewed independently by a Financial Services Provider or Partner Financial Institution.
AllScale and the recipients described in Section VI may transfer, store, and process Data in Hong Kong, the United States, and other countries that may not provide the same level of protection as your jurisdiction. Virtual Account and related Data may be processed where HIFI, Partner Financial Institutions, payment networks, compliance providers, or their systems operate.
Where required, we use an adequacy decision, European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. You may contact us for information about applicable safeguards, subject to confidentiality and legal restrictions.

California residents may contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs at 1625 North Market Blvd., Sacramento, CA 95834, or by telephone at (916) 445-1254 or (800) 952-5210. This consumer-services notice is separate from the CCPA rights described below.
This section supplements the Privacy Policy for California residents under the California Consumer Privacy Act, as amended ("CCPA"). In the preceding 12 months, AllScale may have collected the categories described in Section III, including identifiers; customer-record and financial information; protected classifications where provided for verification; commercial and transaction information; Internet, device, geolocation, and network activity; professional or employment information; biometric or identity-verification information; sensitive personal information such as government identifiers, account credentials, precise information where collected, and financial details; and inferences or risk indicators derived from such information. We collect these categories from the sources described in Sections III and VI and use and disclose them for the business purposes described in Sections IV and VI.
Recipients may include Affiliates, processors and service providers, Financial Services Providers, Partner Financial Institutions, payment and blockchain participants, compliance and security vendors, governmental authorities, corporate-transaction counterparties, and other recipients described in Section VI. AllScale does not sell personal information for monetary or other valuable consideration and does not share it for cross-context behavioral advertising as those terms are defined by the CCPA. AllScale does not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA, except as otherwise disclosed through a legally compliant notice. We do not knowingly sell or share personal information of individuals under 16.
Subject to exceptions, California residents may request to know the categories and specific pieces of personal information collected; learn the categories of sources, purposes, and recipients; request deletion or correction; opt out of a sale or sharing if one occurs; limit qualifying uses of sensitive personal information; and receive equal service and pricing without unlawful discrimination. Certain Data or entities may be exempt from the CCPA, including information subject to applicable federal financial privacy law. AllScale does not offer financial incentives for personal information unless described in a separate notice.
California residents may submit a request at [email protected]. We will verify the request to the degree required by law and may request additional information appropriate to the sensitivity of the Data. An authorized agent must provide proof of authorization, and we may confirm the request directly with the resident. If AllScale later sells or shares personal information, we will provide the required opt-out method and honor Global Privacy Control signals where applicable.

AllScale may update this Privacy Policy to reflect changes in law, technology, security, providers, services, or our processing practices. We will post the updated version on the Site or App, identify its effective date, and may provide notice by email, in-product message, or another electronic channel. Material changes will receive any additional notice, consent, or choice required by Applicable Law. Your continued use of an affected AllScale Service after the effective date acknowledges the updated notice and, to the extent Applicable Law permits agreement by continued use, constitutes acceptance of it. An updated Privacy Policy does not retroactively authorize processing that requires new consent or another legal basis. If you do not agree with an update, stop using the affected service and close your account, subject to continuing legal and retention obligations.

If you have questions, concerns, complaints, or privacy-rights requests, contact us through the official Support Page or at [email protected]. Do not send Private Keys, recovery phrases, Claim Credentials, full payment credentials, or unrequested identity documents by ordinary email. You may also contact the relevant Financial Services Provider or Partner Financial Institution regarding Data it controls independently under its privacy notice.