Privacy Policy

Last Updated: 2026-07-22

PokePay Technology Co., Ltd. ("PokePay," "we," "our," or "us") is a money services business (MSB) registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), S.C. 2000, c. 17. This Privacy Policy is provided in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 25, and applicable provincial privacy legislation. We respect your privacy and are committed to protecting your personal data. By using this App, you agree to the collection, use, and sharing of your information as described in this Privacy Policy. This Privacy Policy explains how we process your personal data, your rights, and how we safeguard your privacy.


1. Data Controller

2. Legal Bases for Processing

3. Information We Collect

4. How We Use Your Data

5. How We Share Your Data

6. Data Security

7. Your Privacy Rights

8. Children's Privacy

9. Changes to this Privacy Policy

10. Contact Us


1. Data Controller

PokePay Technology Co., Ltd. is the data controller responsible for your personal information. Our designated Privacy Officer can be contacted at:

Email: [email protected]

Mailing Address: [2425 MATHERSON BLVD E 8TH FLOOR MISSISSAUGA ON CANADA].

You may contact the Privacy Officer for any questions about this Policy or to exercise your rights.

2. Legal Bases for Processing

PokePay processes personal information on the following legal bases:

  • (i) Performance of contract — to provide account, payment, and transfer services you have requested;

  • (ii) Legal obligation — to comply with PCMLTFA/PCMLTFR reporting and record-keeping obligations (which are exempt from PIPEDA consent requirements under PIPEDA Schedule 4);

  • (iii) Consent — for marketing communications and optional data uses; and

  • (iv) Legitimate interests — for fraud prevention, platform security, and service improvement, provided those interests are not overridden by your rights.

3. Information We Collect

We collect personal information under the following circumstances to provide efficient and secure services:

3.1 Personal Identification Information

This includes your name, email address, phone number, ID number, date of birth, address, and other identifying information. It is used for account registration, identity verification, and providing the services you need.

3.2 Financial Information

This includes bank account details, credit or debit card information, transaction records, balances, and payment history. This information is used to process transactions, transfers, top-ups, and other financial services. We also collect virtual currency wallet addresses, blockchain transaction identifiers (transaction hashes), on-chain transaction data, and wallet risk scores generated by our blockchain analytics and screening providers (including SlowMist, Sumsub and Didit) in connection with our virtual currency exchange and transfer services, as required under the PCMLTFR.

3.3 Device and Technical Information

This includes information about your device, such as device model, operating system, IP address, unique device identifier, browser type, device location, and app usage data. This information helps us analyze performance, ensure service security, and optimize user experience.

3.4 Location Information

We may collect and process your location information to provide personalized services or verify your identity. You can control whether we access your location data in your device settings.

3.5 Communication and Interaction Information

This includes records of communication with our customer support team, feedback, and submitted support requests. This helps us improve our services and resolve your issues.

3.6 Usage Data

We may collect information about how you use our services, including features accessed, frequency of use, and preference settings. This information is used to analyze user behavior and improve service quality.

3.7 Virtual Currency and Blockchain Data

In connection with our virtual currency exchange and transfer services, PokePay collects the following additional categories of data: (a) virtual currency wallet addresses used to send or receive virtual currency through our platform; (b) blockchain transaction identifiers (transaction hashes) and on-chain transaction data associated with transactions processed through our platform; (c) wallet risk scores, cluster analysis results, and screening flags generated by our blockchain analytics providers (SlowMist, Sumsub and Didit) in respect of wallet addresses associated with your account; and (d) counterparty originator and beneficiary information required to be collected under the PCMLTFR Travel Rule for qualifying virtual currency transfers at or above CAD 1,000. This data is collected and retained as required by the PCMLTFA and PCMLTFR and is used for AML/CTF compliance monitoring and mandatory regulatory reporting to FINTRAC.

4. How We Use Your Data

We commit to using your data in a lawful, transparent, and reasonable manner. Your data may be used for the following purposes:

4.1 Providing and Managing Services

Your data is used to create accounts, process transactions, and manage payments, ensuring you can use our services seamlessly.

4.2 Security and Risk Management

We use your data for identity verification, fraud detection, and risk assessment to secure your account and transactions.

4.3 Payment Processing and Financial Transactions

Your financial information is used to process your transfers, payments, and top-ups, ensuring smooth financial operations.

4.4 Marketing and Personalized Promotions

Based on your preferences, we may send you promotional offers, product updates, or recommended services. You can opt out of such communications at any time. Under the Canadian Anti-Spam Legislation (CASL), PokePay will obtain express or implied consent before sending commercial electronic messages (CEMs). To withdraw consent, click "Unsubscribe" in any marketing email or contact our Privacy Officer at [email protected].

4.5 Legal Compliance

We may process your data to comply with legal obligations, such as Anti-Money Laundering (AML), Know Your Customer (KYC) procedures, Counter-Terrorism Financing (CTF), and tax reporting.

4.6 Data Analysis and Service Improvement

We may analyze how you use our services to improve product features, enhance user experience, and provide better customer support.

5. How We Share Your Data

We do not sell or rent your personal data to third parties unless for the following reasons:

5.1 Sharing with Service Providers

We may share your data with third-party service providers who help us deliver services, such as payment processing, cloud services, and identity verification. These providers include, without limitation, our identity verification provider, our blockchain analytics and wallet screening providers (SlowMist, Sumsub and Didit), our payment processing partners, and our cloud infrastructure providers. These third parties can only access your data when necessary and are required to maintain confidentiality.

5.2 Compliance with Legal Requirements

We may disclose your data to comply with legal obligations, respond to legal processes, government requests, or judicial orders.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you before the transfer and ensure the new entity continues to protect your data.

5.4 Sharing with Partners

In cases of anonymized or aggregated data, we may share it with business partners for market analysis and service improvement.

5.5 Mandatory Disclosure to FINTRAC and Law Enforcement

Notwithstanding any other provision of this Policy, PokePay is required by the PCMLTFA to disclose your personal information and transaction data to FINTRAC through mandatory transaction reports (including STRs, LVCTRs, EFTRs, and LPEPRs) without your knowledge or consent. PokePay may also be required to disclose your personal information to the RCMP, CSIS, the Canada Revenue Agency (CRA), or other competent authorities pursuant to applicable Canadian law, court orders, judicial warrants, or production orders. These disclosures are mandatory obligations under the PCMLTFA and are exempt from PIPEDA's consent requirements by operation of PIPEDA Schedule 4(1)(c)(ii). PokePay will not notify you of disclosures where prohibited by law (including the tipping off prohibition in the PCMLTFA).

6. Data Security

We take reasonable technical and organizational measures to protect your personal data from unauthorized access, disclosure, modification, or destruction. These measures include data encryption, access controls, multi-factor authentication, and regular security audits.

6.1 Secure Data Transmission

When we transmit data across countries, we ensure that such data is protected under applicable laws and adopt appropriate safeguards in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), including by contractual means to ensure comparable levels of protection when personal information is transferred to service providers in other jurisdictions.

6.2 Data Retention

We retain your personal data in accordance with legal requirements and business needs. As a FINTRAC-registered MSB, PokePay is required under the PCMLTFR to retain client identification records for a minimum of 5 years after the last transaction conducted or the end of the business relationship, and to retain complete and accurate transaction records for a minimum of 5 years after the date of each transaction. These mandatory PCMLTFR retention obligations take precedence over any deletion or erasure request to the extent that such records are required to be retained by law. Once data is no longer needed, we securely delete or anonymize it.

7. Your Privacy Rights

Subject to the limitations set out in Section 7.6 below (which arise from our mandatory obligations under the PCMLTFA and PCMLTFR), you have the following rights regarding your personal information under PIPEDA and applicable provincial privacy legislation:

7.1 Right to Access

You have the right to access the personal data we hold about you and request a copy.

7.2 Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request corrections.

7.3 Right to Erasure

In certain circumstances, you can request that we delete your personal data, especially when it is no longer relevant for the original purposes for which it was collected. Subject to the mandatory retention limitations described in Section 7.6 below, PokePay will process valid erasure requests in a timely manner. However, PokePay cannot delete records that we are legally required to retain under the PCMLTFR (minimum 5-year retention period) or pursuant to any other applicable mandatory retention obligation. If you submit an erasure request, we will inform you of any records that cannot be deleted due to mandatory legal retention requirements.

As a FINTRAC-registered MSB under the PCMLTFA, PokePay is specifically required to: (a) verify client identity and retain identification records under the PCMLTFR; (b) file Suspicious Transaction Reports (STRs), Large Virtual Currency Transaction Reports (LVCTRs), Electronic Funds Transfer Reports (EFTRs), and Listed Person or Entity Property Reports (LPEPRs) with FINTRAC as required; (c) collect and transmit originator and beneficiary information for qualifying transactions under the Travel Rule; (d) screen clients, transactions, and wallet addresses against applicable Canadian and international sanctions lists; and (e) retain client and transaction records for at least 5 years under the PCMLTFR. These processing activities are mandatory under the PCMLTFA and are exempt from PIPEDA's consent requirements. PokePay is prohibited by law from notifying you if a Suspicious Transaction Report has been or may be filed in relation to your account (tipping off prohibition, PCMLTFA).

7.4 Right to Data Portability

You have the right to request that we provide your personal data in a structured, commonly used, and machine-readable format or transfer it to another service provider, where technically feasible.

7.5 Right to Restrict Processing and Object

You can request that we restrict the processing of your data in certain circumstances and object to us processing your personal data, particularly for legitimate interests or direct marketing.

7.6 Limitations on Your Privacy Rights Under the PCMLTFA

Your rights under PIPEDA and applicable provincial privacy legislation are subject to the following limitations arising from our mandatory obligations under the PCMLTFA and PCMLTFR: (i) we cannot delete records that we are required to retain for the mandatory 5-year period under the PCMLTFR; (ii) we may be prohibited from informing you whether a Suspicious Transaction Report has been or may be filed in relation to your account (tipping off prohibition); (iii) we may restrict your access to certain information where providing such access would reveal the existence of an STR investigation or otherwise prejudice the purposes for which information was collected under the PCMLTFA; and (iv) your access rights may be limited to the extent that PIPEDA permits denial of access in connection with law enforcement matters. To exercise any of your privacy rights or to request information about these limitations, please contact our Privacy Officer at [email protected].

7.7 Breach of Security Safeguards Notification

In the event of a breach of security safeguards involving your personal information that creates a real risk of significant harm to you (as defined under PIPEDA and the Breach of Security Safeguards Regulations, SOR/2018-64), PokePay will notify you and the Office of the Privacy Commissioner of Canada (OPC) in a timely manner as required by those instruments. The notification to you will include: (a) a description of the breach; (b) the personal information involved; (c) the steps PokePay has taken or proposes to take to reduce the risk of harm; (d) steps you may take to reduce the risk of harm; and (e) contact details for follow-up enquiries. PokePay maintains a breach register recording all breaches of security safeguards for a minimum period of 24 months as required by PIPEDA.

7.8 Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) if you believe PokePay has collected, used, or disclosed your personal information in a manner that does not comply with PIPEDA or applicable provincial privacy legislation. The OPC may be contacted at: Toll-free: 1-800-282-1376 | Website: www.priv.gc.ca | 30 Victoria Street, Gatineau, QC K1A 1H3. You may also file a complaint with the relevant provincial privacy commissioner where applicable.

8. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect or store personal information from minors. If we become aware that we have unintentionally collected data from a minor, we will take steps to delete that information.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or privacy standards. When changes are made, we will notify you through the app. Please review this policy regularly to stay informed of how we protect your privacy.

10. Contact Us

If you have any questions or wish to exercise your rights regarding your personal data, please contact us using the following details:
Email: [email protected]