Privacy Policy

Last updated: June 11, 2026

Maaarpay ("we", "our", "us"), operated by MAAAR PAY FZCO (located at Unit No: UT-12-CO-194, DMCC Business Centre, Level No 12, Uptown Tower, Dubai, United Arab Emirates), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our website, mobile application, and digital asset services.

1. Information We Collect

We may collect and process the following categories of data to provide our services:

  • Personal Identification Data: Full name, date of birth, nationality, and country of residence.

  • Contact Information: Email address and phone number.

  • Identity Verification Data: Government-issued identification documents (e.g., passports, national identity cards) and self-declared residential addresses.

  • Biometric & Face Data: Facial images, video frames, and biometric liveness metadata voluntarily captured during user onboarding.

  • Transactional & Internal Ledger Data: Wallet balances, transactional history, and off-chain ledger records mapped to our internal accounting database.

  • Card-Related Identifiers: Card IDs, transaction timestamps, card types (physical vs. virtual), merchant data, and spending categories synchronized via partner systems.

  • Technical & Usage Data: IP addresses, device identifiers, unique transaction hashes, and application diagnostic metrics.

2. Biometric Data Processing and Face Data Disclosure

A. What Face Data We Collect

During user identity verification, our mobile application integrates a camera interface to capture temporary facial images and video frames (collectively referred to as "Face Data") provided directly and voluntarily by the user. Maaarpay does not extract or retain raw mathematical biometric templates or proprietary facial-recognition maps on local mobile devices or on our internal backend servers.

B. Planned Uses of Collected Face Data

The collected Face Data is utilized exclusively for the following mandatory compliance and fraud-prevention functions:

  • Regulatory KYC Compliance: To fulfill mandatory statutory Know Your Customer (KYC) and Anti-Money Laundering (AML) identity verification criteria governing our Distributed Ledger Technology Services framework.

  • Biometric Liveness Verification: To perform automated liveness checks ensuring the applicant is a living individual and physically present, preventing account takeovers, spoofing, synthetic identity theft, and forgery.

  • Document Matching: To cross-reference and confirm that the user's physical face matches the photograph embedded within the provided government-issued identification document.

  • Fraud Deterrence: To block bad actors, fraudulent patterns, or hard-banned users from creating duplicate accounts. Face Data is processed strictly for functional security and is never used for commercial profiling, marketing, cross-app tracking, or behavior analytics.

C. Third-Party Sharing and Storage Locations

  • Authorized Processing Subcontractors: To execute secure identity checks, Face Data is routed via encrypted API channels to our dedicated identity verification partner, SumSub (sumsub.com), utilizing their integrated mobile SDK. SumSub acts as an authorized data processor operating under strict data protection protocols.

  • Infrastructure Storage: Face Data is transmitted using secure network protocols and stored within certified, heavily protected cloud infrastructure (AWS environment) managed by our verification provider, utilizing localized data isolation and volume encryption at rest. No Face Data is written to unencrypted internal databases or local device storage.

  • No Commercial Sharing: Maaarpay does not sell, lease, trade, or distribute your Face Data to any third-party marketing networks, commercial brokers, or advertising platforms.

D. Data Retention and Purging

Face Data is retained only for the duration strictly necessary to meet our global financial compliance obligations, anti-money laundering (AML) laws, and regulatory audit windows required under our operating frameworks. Once a user's verification check is completed or the maximum legal data-retention window under applicable financial frameworks has expired following account closure, all associated Face Data is permanently, structurally, and securely erased from our verification provider's storage systems.

3. Public Blockchain Data Disclaimer

By utilizing our services, you acknowledge and agree that certain transactional operations occur on public decentralized blockchains (e.g., Ethereum, Polygon, Base, Optimism, Arbitrum, Avalanche, or zkSync).

  • Immutability: Information broadcasted to public blockchains—such as public wallet addresses, transaction hashes, gas token fees, and asset movements—is entirely public and permanent by design.

  • Exclusion from Deletion Rights: Due to the immutable nature of distributed ledger technologies, public blockchain records cannot be altered, modified, or erased, and are explicitly excluded from data deletion or "Right to be Forgotten" requests.

4. Automated Decision-Making and Risk Profiling

To protect our platform infrastructure and satisfy card-path compliance policies, we employ automated systems and rules engines to scan account actions:

  • Risk Scoring: Every account undergoes real-time transaction monitoring and risk scoring based on metrics such as transaction velocity, amount anomalies, geographic inconsistency, and interactions with high-risk merchant categories.

  • Account Restrictions: Automated scoring engines or triggered compliance alerts may directly result in transactional delays, temporary account locks, spending power adjustments, or card application blocks.

5. Third-Party Data Sharing and Disclosures

Maaarpay operates an exchange master-balance model where we do not touch, hold, or manage fiat currency directly. To deliver our platform card services, we share necessary user and transactional data with selected institutional infrastructure providers:

  • Digital Asset Custody & MPC Rails: Digital asset transactions, cold/hot vault management routing, and internal sub-wallet infrastructure data are managed via Fireblocks under structural data processing addendums.

  • Card-Issuing and Settle Rails: Transaction authorization updates, card profiles, and merchant settlement details are securely synchronized via real-time webhooks with our card issuer and Visa Principal Member partner, Rain, who handles all underlying fiat legs and card paths.

  • Sanctions & PEP Screening: Card applicants are screened against international Politically Exposed Persons (PEP) lists, adverse media, and global sanctions enforcement lists managed by our card partner.

  • Legal and Regulatory Authorities: We may disclose personal data if required to do so by an enforceable administrative order, a competent court, national regulators, or applicable judicial processes.

6. Data Security

Maaarpay enforces rigorous technical, architectural, and organizational security controls to safeguard your information. All platform backend components operate within isolated cloud topographies utilizing first-in-first-out secure event queuing (AWS SQS), pessimistic database row locks to prevent state manipulation, and strict least-privilege identity and access management (IAM). Financial data and user profiles are stored with volume-level encryption both in transit and at rest.

7. Your Rights

Depending on your regional jurisdiction and location, you may possess specific statutory rights regarding your personal information, which may include:

  • The right to look up and access data held by the platform.

  • The right to request the correction of inaccurate or incomplete records.

  • The right to request the deletion of data (subject to overriding anti-money laundering and financial data preservation laws).

  • The right to object to or request restrictions on specific information processing paths.

To exercise any data protection rights or submit compliance inquiries regarding our privacy practices, contact our security desk at compliance@maaarpay.com.

Contact

For privacy-related questions, contact us at:

compliance@maaarpay.com

Cookie Time! 🍪

We use cookies to enhance your experience, analyze traffic, and personalize content.

Learn more in our Cookie Policy
Powered byMAAARPay