Current as of May 2026
PLEASE READ THIS PRIVACY POLICY CAREFULLY. This Privacy Policy explains how WeWire Technologies Inc. ("WeWire," "we," "us," or "our") collects, uses, discloses, transfers, retains, and protects Personal Data when you download, install, register for, or use the WeWire mobile application (the "App") and the related Services. This Privacy Policy forms an integral part of, and is incorporated by reference into, the WeWire Mobile Application Terms and Conditions (the "Terms"). Capitalised terms used but not defined in this Privacy Policy have the meanings set out in the Terms.
FINANCIAL SERVICES AND VIRTUAL ASSETS. Because WeWire is a regulated payment service provider and operates in the virtual asset and stablecoin space, our processing of Personal Data is shaped by significant legal obligations, in particular anti-money laundering ("AML"), counter-terrorist financing ("CTF"), counter-proliferation financing, sanctions, fraud-prevention, market-integrity, tax-information-reporting, and Travel Rule obligations. This Privacy Policy describes how those obligations affect the Personal Data we collect, the periods for which we retain it, and the parties with whom we share it.
JURISDICTIONAL APPLICATION. This Privacy Policy is global in scope and applies to all Users who access, use, or interact with the App, regardless of their jurisdiction or location.
Where any provision of this Privacy Policy conflicts with, or provides a lower level of protection than, the privacy or data protection rights available to you under Applicable Law, the provision or requirement that affords you the higher level of protection shall prevail to the extent required by such Applicable Law.
WeWire Technologies Inc., a company incorporated under the laws of Canada with its registered office at 2015 Main Street, Vancouver, British Columbia, V5T 3C2, Canada, is the data controller responsible for Personal Data processed in connection with the App, except where this Privacy Policy expressly identifies a different controller (for example, our Custodians, KYC providers, or Mobile Money operators acting in their own capacity).
WeWire is registered as a Payment Service Provider with the Bank of Canada under the Retail Payment Activities Act and is subject to AML/CTF oversight by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). In jurisdictions where WeWire operates, additional licences, registrations, or notifications may apply. This regulatory status materially shapes how we process Personal Data.
Our Privacy Officer (and, where required, Data Protection Officer) can be contacted at:
This Privacy Policy applies to Personal Data we collect when you: (a) download, install, or use the App; (b) register an Account or attempt to do so; (c) submit identity-verification, KYC, KYB, or source-of-funds information; (d) initiate, complete, or attempt any Transaction (including deposits, withdrawals, transfers, exchanges, conversions, P2P trades, payments, and remittances); (e) communicate with our support, complaints, compliance, or legal teams; (f) interact with our websites, marketing communications, or social-media properties; and (g) take part in surveys, research, promotions, or beta-testing programmes.
This Privacy Policy does not apply to Personal Data processed by third parties whose services you access independently, even where you are introduced to them through the App. Examples include the issuers of stablecoins or tokens (such as Tether, Circle, or other issuers), public blockchains (which are inherently public ledgers operated by no single party), Mobile Money operators acting in their own capacity, your own bank or card issuer, your mobile-network operator, app-store operators (Apple and Google), and any third-party websites or services to which the App may link. You should consult their respective privacy notices.
Where you make or receive on-chain transfers, certain data, including wallet addresses, transaction amounts, timestamps, and transaction graphs, is recorded on a public, immutable, distributed ledger. Such on-chain data is not under WeWire's control, cannot be deleted by us, and may be analysed by anyone (including blockchain-analytics firms, exchanges, regulators, and law-enforcement agencies). Linking on-chain data to your real-world identity is technically possible. You should not assume that on-chain transactions are anonymous.
In addition to the defined terms in the Terms, the following terms have the meanings set out below:
We collect Personal Data directly from you, automatically through your use of the App, and from third parties (including our Partners, public registries, sanctions lists, blockchain-analytics providers, and credit/fraud bureaus). The categories of Personal Data we collect include the following.
Including: full legal name; previous or alternative names; date and place of birth; nationality and country of residence; gender (where required for ID verification); residential and postal address; signature; government-issued photo identification (passport, national ID, driver's licence, residence permit, including ID numbers and document images); a recent live photograph or short video for liveness verification; biometric templates derived from your face for identity verification; tax-identification numbers (e.g., SIN, SSN/ITIN, NINO, NIF/NIE, TIN, Emirates ID number); and beneficial-ownership and control information for entity Users.
Including: phone number(s); email address(es); preferred language; and any messaging-platform handles you provide for support purposes.
Including: username; hashed password; security questions and answers; multi-factor authentication factors (one-time-codes, authenticator-app secrets, biometric authenticators registered on your Device); session tokens; device-binding keys; and recovery-account information.
Including: bank-account details; payment-card details (typically tokenised by our payment processors, with WeWire receiving only a token, last four digits, and brand); Mobile Money wallet identifiers (such as MTN MoMo, Vodafone Cash, AirtelTigo Money, Orange Money, M-Pesa numbers); on-chain wallet addresses you control or interact with; deposit, withdrawal, exchange, conversion, P2P, and payment instructions and history; counterparty details; FX rates and spreads applied; fees charged; and balances held in Fiat and Digital Asset wallets.
Including: occupation; employer name; salary range; business activity; investment background; description of source of wealth (inheritance, savings, business sale, investment returns, etc.); supporting documentary evidence (payslips, tax returns, bank statements, sale agreements, dividend statements); and explanations regarding the rationale for specific Transactions.
Including: matches and possible matches against sanctions lists (OFAC SDN, EU consolidated, UK HMT, UN Security Council, Canadian SEMA, and others); politically-exposed-person (PEP) status (including immediate family and close associates); adverse-media findings; risk-scoring outputs from screening providers; and notes from our compliance reviewers.
Including: IP address; approximate or precise geolocation derived from IP, GPS (where you grant permission), Wi-Fi, or mobile-network triangulation; device identifiers (advertising ID, vendor/install ID, hardware identifiers as exposed by the operating system); device model, manufacturer, OS version, locale, and time zone; mobile-network operator and carrier; SIM-binding indicators; battery status; screen resolution; app version and build; crash logs and error traces; performance metrics; and security signals (jailbreak/root indicators, emulator indicators, integrity-check results from Apple App Attest, Google Play Integrity, or equivalents).
Including: events and actions performed within the App (logins, screen views, button taps, transaction flows started or abandoned); navigation paths; search queries; feature usage; preferences and in-app settings; and engagement with notifications, emails, and other communications.
Including: messages exchanged via in-app chat, email, phone, video call, or chatbot; call recordings (where lawful and with notice); voicemails; transcripts; ticket metadata; complaint particulars; survey responses; and any documents or screenshots you submit.
Including: wallet addresses; transaction hashes; counterparty addresses; cluster attributions; risk scores produced by analytics providers (such as Chainalysis or equivalents); exposure metrics (e.g., proximity to sanctioned addresses, darknet markets, ransomware addresses, or mixers); and provenance trails of Digital Assets you transact.
Including: marketing-consent status; preference-centre selections; channel preferences (email, push, SMS); referral codes; affiliate links used; and the content of marketing emails sent and your engagement with them.
We process certain categories of Sensitive Personal Data only where strictly necessary and lawful, including: (a) biometric data (face geometry/embeddings) for the unique purpose of identity verification and fraud prevention; (b) data that may incidentally reveal sensitive characteristics where contained in your KYC documents; (c) precise geolocation where you have granted permission; and (d) financial-account information that is treated as sensitive personal information under U.S. state privacy laws. Where Applicable Law requires explicit consent for processing of Sensitive Personal Data, we will obtain it before processing, except where another lawful basis applies (such as compliance with AML obligations).
You may provide us with Personal Data about other people, for example, the name, account number, or wallet address of a payment beneficiary, a P2P counterparty, or your beneficial owners or authorised users. By submitting that information, you represent that you are entitled to do so, that you have informed those individuals of our processing, and (where required) that you have obtained their consent.
We obtain Personal Data from the following sources:
We process Personal Data for the purposes and on the lawful bases set out in the table below. Where we rely on "legitimate interests", we have carried out a balancing test to ensure that our interests are not overridden by your rights and freedoms, and you may object to such processing in accordance with Section 12.
We do not "sell" Personal Information for monetary consideration. We do not "share" Personal Information for cross-context behavioural advertising except with your consent.
We use automated tools to support compliance, risk, fraud, security, and product personalisation. Specifically:
Some of these processes may produce solely automated decisions that have legal or similarly significant effects on you (for example, an automatic decline of an Account application or a Transaction). Where Applicable Law gives you the right not to be subject to such a decision, you may request human review by contacting help@wewire.com. We may decline such requests where the decision is necessary for entering into or performing the Terms, is authorised by law (including for fraud-prevention or AML purposes), or is based on your explicit consent.
We disclose Personal Data only to the extent necessary, proportionate, and lawful. The categories of recipients to whom we disclose Personal Data include:
Members of the WeWire group of companies, where necessary for the operation, administration, support, and governance of the Services, under intra-group data-protection arrangements.
Third parties acting on our instructions and bound by confidentiality and data-protection obligations, including:
Where you initiate a payment, P2P trade, transfer, or remittance, we share with your counterparty (or with their VASP, bank, or Mobile Money operator) the information necessary to complete the Transaction, which may include your name, account number or wallet address, and the amount and reference of the Transaction. For Travel Rule transfers above applicable thresholds, we are required to share originator and beneficiary information with the counterparty VASP.
We disclose Personal Data to regulators, supervisors, financial-intelligence units, tax authorities, courts, tribunals, and law-enforcement agencies where required or permitted by Applicable Law, including FINTRAC, the Bank of Canada, the UK National Crime Agency, His Majesty's Revenue & Customs, the UK Financial Conduct Authority, the European Banking Authority and EU national competent authorities, the UAE Central Bank, the UAE Financial Intelligence Unit, the Virtual Assets Regulatory Authority (VARA), the Financial Services Regulatory Authority of the ADGM, and equivalent authorities in other jurisdictions. You acknowledge that we may be prohibited by Applicable Law from notifying you of an investigation, freeze, report, or compliance action (the so-called tipping-off prohibition).
In the context of a merger, acquisition, financing, reorganisation, insolvency, or sale of all or part of our business, Personal Data may be transferred to a successor or acquirer, with appropriate confidentiality and data-protection safeguards. We will notify you where required by Applicable Law.
We may share Personal Data with other recipients where you have provided consent or directed us to do so (for example, when you connect a third-party application via an API or integration).
We may share aggregated, anonymised, or de-identified information that does not identify you for analytics, research, benchmarking, fraud-prevention consortia, and product-development purposes. Where applicable, we contractually prohibit recipients from attempting to re-identify such data.
The provision of the Services necessarily involves transfers of Personal Data across borders, including to and from Canada, the United States, the United Kingdom, the European Economic Area, the United Arab Emirates, and other jurisdictions where WeWire, its Affiliates, Partners, Custodians, or sub-processors are located.
Where required by Applicable Law, we rely on one or more of the following transfer mechanisms:
Following the Schrems II decision and equivalent guidance, we apply supplementary technical, contractual, and organisational measures where required, including encryption in transit and at rest, pseudonymisation, key-management controls, access logging, vendor due diligence, and government-access transparency reporting where lawful.
Where Personal Data is recorded on a public blockchain (typically a wallet address linked to your Account), the data is replicated globally across nodes in multiple jurisdictions. We cannot control where such on-chain data is stored or processed and have no ability to delete it.
We retain Personal Data only for as long as necessary for the purposes for which it was collected and to comply with our legal, regulatory, and operational obligations.
On Account closure, we delete or anonymise Personal Data within thirty (30) days, save for data we are required to retain as set out above and in Section 22 of the Terms and Schedule B (In-App Account Deletion Flow). During the retention period, retained data is access-restricted and used only for the lawful purposes for which it was retained.
We implement technical and organisational measures appropriate to the risks presented by our processing, including:
No system is fully secure. You also have responsibility for security of your Account and Device, as set out in Section 17 of the Terms. Recommended measures include using a strong, unique password; enabling all available authentication factors; keeping your operating system and the App up to date; not jailbreaking or rooting your Device; never sharing one-time codes or recovery phrases; and being vigilant against phishing and social-engineering attacks. Notify us immediately at security@wewire.com if you suspect unauthorised access to your Account.
In the event of a Personal Data breach, we will notify the relevant supervisory authority and affected individuals where and as required by Applicable Law, including:
We maintain a breach register and conduct a documented post-incident review for each notifiable breach.
Subject to Applicable Law, you may have some or all of the following rights in relation to your Personal Data. The precise scope, exceptions, and exercise mechanics for each right depend on your jurisdiction.
Where available, the App provides in-app controls to access, download, correct, and delete certain Personal Data, manage marketing preferences, manage permissions (e.g., location, notifications, biometrics), and submit privacy requests. The path is generally: Profile -> Settings -> Privacy & Data.
You may also exercise your rights by emailing info@wewire.com or by writing to: Privacy Officer, WeWire Technologies Inc., 2015 Main Street, Vancouver, BC, V5T 3C2, Canada. To help us locate your data, please include your registered email, full name, and a clear description of the right you wish to exercise.
Where Applicable Law permits, you may authorise an agent to submit a request on your behalf. We may require written authorisation, verification of your identity, and direct confirmation from you before acting.
To protect your data, we will take reasonable steps to verify your identity before responding to a request. The level of verification will be proportionate to the sensitivity and nature of the request. We may decline to act on a request where we cannot verify the requester's identity, the request is manifestly unfounded or excessive, or where exemptions or exceptions under Applicable Law apply.
We do not generally charge a fee for responding to a privacy request. Where Applicable Law permits, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, excessive, or repetitive.
Some of your rights may be limited or excepted by Applicable Law, for example, where compliance would conflict with our AML, CTF, sanctions, tax-reporting, or record-keeping obligations; where it would prejudice the rights of others, ongoing investigations, or legal claims; or where data has been irreversibly anonymised. Where we cannot fully comply with your request, we will explain why to the extent permitted by law.
The App and the Services are intended for use only by persons aged eighteen (18) years or older (or such higher age of majority as applies in the User's jurisdiction). We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected Personal Data from a child, we will close the Account and delete the data without undue delay. If you believe a child has provided us with Personal Data, please contact info@wewire.com.
Within the App and on related websites, we and our service providers use cookies, mobile SDKs, software-development kits, web beacons, pixels, local storage, device identifiers, and similar technologies (collectively, "Tracking Technologies") for the following purposes:
Where required by Applicable Law (including the EU/UK ePrivacy regime), we obtain your consent before placing non-essential Tracking Technologies, and we provide controls to manage your preferences in-app and on our websites. You can also manage Tracking Technologies through your device and operating-system settings (e.g., Apple App Tracking Transparency, Google Privacy Sandbox / Limit Ad Tracking). Detailed disclosures regarding the specific Tracking Technologies we deploy are set out in our separate Cookie Policy.
Where we send you marketing communications, we will do so on a lawful basis (typically your consent, or for own-product marketing to existing Users where lawful). You can opt out at any time by:
Opting out of marketing does not affect transactional, regulatory, security, and service messages, which we will continue to send as necessary for the operation of your Account.
The App relies on Partners and sub-processors as set out in Section 8 and Schedule 2. The App may also integrate with, or link to, third-party services that are not controlled by us, including merchant payment surfaces, social-media platforms, news and market-data providers, identity-wallet apps, and self-custody wallets. Your use of those services is governed by the third party's terms and privacy notice, and we are not responsible for their practices.
When you download the App from the Apple App Store or Google Play, those platforms collect certain Personal Data about you, including device-level identifiers, install events, in-app purchases, and engagement signals, in accordance with their own policies. The terms applicable between you and the platform operator (Apple Inc. or Google LLC) supplement those between you and WeWire as set out in Schedule B of the Terms.
We may update this Privacy Policy from time to time to reflect changes to our processing, our Services, our Partners, or Applicable Law. Where changes are material, we will notify you by in-app notification, email, or prominent notice on our website with reasonable prior notice (typically not less than fourteen (14) days, except where shorter notice is required by Applicable Law, security, regulatory, or risk-management considerations). The Last Updated date at the top of this Privacy Policy indicates when it was most recently revised. Continued use of the App after the effective date of any change constitutes acknowledgement of the updated Privacy Policy. Where Applicable Law requires fresh consent for a new processing purpose, we will obtain your consent before that processing begins.
Questions, concerns, and complaints regarding this Privacy Policy or our processing of your Personal Data may be addressed to:
You also have the right to lodge a complaint with the supervisory authority or regulator competent for your jurisdiction. We would, however, appreciate the opportunity to address your concerns first.
The table below sets out the categories of Partners and sub-processors with whom we share Personal Data, the categories of data shared, and the purpose. The current list of named sub-processors is available on request from info@wewire.com and may be updated from time to time. We will notify Users of material changes in advance where required by Applicable Law.
End of Privacy Policy