Privacy Policy
Last updated: March 2026
1. Introduction
Trustmepay Global Corp. ("Trustpay," "we," "us," or "our"), registered at 970 Burrard St. Vancouver, BC Unit 112, V6Z 1V3, Canada (BC Registration No. BC1540261), is committed to protecting the privacy of individuals who visit our website at trust-pay.ca and use our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
2. Information We Collect
We collect the following categories of personal information:
- Identity Information: Full legal name, date of birth, nationality, government-issued identification documents (passport, driver's licence, or national ID card), and photographs or selfies for identity verification.
- Contact Information: Email address, phone number, and residential address.
- Financial Information: Bank account details, payment card information, transaction history on the Platform, and digital asset wallet addresses.
- Technical Information: IP address, browser type and version, operating system, device identifiers, time zone, and access timestamps.
- Usage Information: Pages viewed, features used, clickstream data, and interactions with our Platform.
- Communication Data: Records of correspondence with our support team, including chat logs and emails.
3. How We Collect Information
We collect personal information directly from you when you register an account, complete identity verification, make transactions, or contact our support team. We also collect information automatically through cookies and similar technologies (see our Cookie Policy), and from third-party sources such as identity verification providers, credit reference agencies, and blockchain analytics services.
4. Purposes of Processing
We use your personal information for the following purposes:
- To create, manage, and secure your account.
- To verify your identity and comply with AML/KYC obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and FINTRAC regulations.
- To process transactions in digital assets, including BTC, ETH, SOL, and USDC.
- To detect, prevent, and investigate fraud, unauthorized access, and other illegal activities.
- To communicate with you regarding your account, transactions, and service updates.
- To improve our Platform, develop new features, and conduct analytics.
- To comply with legal and regulatory requirements.
- To send marketing communications where you have provided consent (you may opt out at any time).
5. Legal Basis for Processing
Under PIPEDA, we process your personal information based on: (a) your consent, which may be express or implied depending on the nature and sensitivity of the information; (b) the necessity to perform a contract with you (i.e., providing our services); and (c) compliance with legal obligations, including AML/KYC regulations.
6. Disclosure of Personal Information
We may disclose your personal information to:
- Service providers: Third-party vendors who assist with identity verification, payment processing, cloud hosting, data analytics, and customer support.
- Regulatory authorities: FINTRAC, law enforcement agencies, and other government bodies as required by law or in response to lawful requests.
- Professional advisors: Lawyers, auditors, and accountants in connection with legal, regulatory, or audit matters.
- Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of our assets.
We do not sell your personal information to third parties for marketing purposes.
7. International Transfers
Your personal information may be transferred to and processed in countries outside of Canada, including jurisdictions that may not offer the same level of data protection. Where such transfers occur, we ensure that appropriate contractual safeguards are in place to protect your information in accordance with PIPEDA.
8. Data Retention
We retain your personal information for as long as your account is active and for a period of at least five (5) years after account closure, as required by PCMLTFA record-keeping obligations. Technical and usage data may be retained for up to two (2) years for analytics and security purposes. We will securely delete or anonymize your information when it is no longer needed.
9. Data Security
We implement industry-standard technical and organizational measures to protect your personal information, including encryption at rest and in transit (TLS 1.3), access controls, multi-factor authentication, regular security audits, and intrusion detection systems. Despite these measures, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
10. Your Rights
Under PIPEDA, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Withdraw your consent to the processing of your information, subject to legal or contractual restrictions.
- File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
To exercise any of these rights, please contact our Privacy Officer at privacy@trust-pay.ca.
10A. GDPR — EEA and UK Data Subjects
Trustpay does not market or solicit clients in the EU/EEA or the UK; any services provided to such clients are accessed exclusively at the client's own initiative. Nevertheless, where we process personal data of individuals located in the EEA or the UK, the EU General Data Protection Regulation (GDPR) and UK GDPR apply and we act as data controller.
We process such data on the legal bases set out in Article 6 GDPR: performance of a contract (Art. 6(1)(b)); compliance with legal obligations, including AML/KYC and sanctions screening (Art. 6(1)(c)); our legitimate interests in fraud prevention, security and service improvement (Art. 6(1)(f)); and consent, which may be withdrawn at any time (Art. 6(1)(a)).
EEA and UK data subjects have the rights set out in Articles 15–22 GDPR, including access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making, subject to statutory retention obligations. To exercise these rights, contact privacy@trust-pay.ca; we respond within one month. You may also lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office.
Personal data is transferred to and processed in Canada, which benefits from a European Commission adequacy decision for data processed under PIPEDA. Where a transfer is not covered by an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum.
11. Children's Privacy
Our Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through a notice on the Platform at least fourteen (14) days before taking effect. Your continued use of the Platform after the effective date constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Privacy Officer
Trustmepay Global Corp.
970 Burrard St. Vancouver, BC Unit 112, V6Z 1V3, Canada
Email: privacy@trust-pay.ca