Current as of May 2026

WeWire Mobile Application Privacy Policy

Important Notice to Users

PLEASE READ THIS PRIVACY POLICY CAREFULLY. This Privacy Policy explains how WeWire Technologies Inc. ("WeWire," "we," "us," or "our") collects, uses, discloses, transfers, retains, and protects Personal Data when you download, install, register for, or use the WeWire mobile application (the "App") and the related Services. This Privacy Policy forms an integral part of, and is incorporated by reference into, the WeWire Mobile Application Terms and Conditions (the "Terms"). Capitalised terms used but not defined in this Privacy Policy have the meanings set out in the Terms.

FINANCIAL SERVICES AND VIRTUAL ASSETS. Because WeWire is a regulated payment service provider and operates in the virtual asset and stablecoin space, our processing of Personal Data is shaped by significant legal obligations, in particular anti-money laundering ("AML"), counter-terrorist financing ("CTF"), counter-proliferation financing, sanctions, fraud-prevention, market-integrity, tax-information-reporting, and Travel Rule obligations. This Privacy Policy describes how those obligations affect the Personal Data we collect, the periods for which we retain it, and the parties with whom we share it.

JURISDICTIONAL APPLICATION. This Privacy Policy is global in scope and applies to all Users who access, use, or interact with the App, regardless of their jurisdiction or location.

Where any provision of this Privacy Policy conflicts with, or provides a lower level of protection than, the privacy or data protection rights available to you under Applicable Law, the provision or requirement that affords you the higher level of protection shall prevail to the extent required by such Applicable Law.

1. Who We Are and How to Contact Us

1.1 Identity of the Controller

WeWire Technologies Inc., a company incorporated under the laws of Canada with its registered office at 2015 Main Street, Vancouver, British Columbia, V5T 3C2, Canada, is the data controller responsible for Personal Data processed in connection with the App, except where this Privacy Policy expressly identifies a different controller (for example, our Custodians, KYC providers, or Mobile Money operators acting in their own capacity).

1.2 Regulatory Status

WeWire is registered as a Payment Service Provider with the Bank of Canada under the Retail Payment Activities Act and is subject to AML/CTF oversight by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). In jurisdictions where WeWire operates, additional licences, registrations, or notifications may apply. This regulatory status materially shapes how we process Personal Data.

1.3 Privacy Office and Data Protection Officer

Our Privacy Officer (and, where required, Data Protection Officer) can be contacted at:

2. Scope of This Privacy Policy

2.1 What is Covered

This Privacy Policy applies to Personal Data we collect when you: (a) download, install, or use the App; (b) register an Account or attempt to do so; (c) submit identity-verification, KYC, KYB, or source-of-funds information; (d) initiate, complete, or attempt any Transaction (including deposits, withdrawals, transfers, exchanges, conversions, P2P trades, payments, and remittances); (e) communicate with our support, complaints, compliance, or legal teams; (f) interact with our websites, marketing communications, or social-media properties; and (g) take part in surveys, research, promotions, or beta-testing programmes.

2.2 What is Not Covered

This Privacy Policy does not apply to Personal Data processed by third parties whose services you access independently, even where you are introduced to them through the App. Examples include the issuers of stablecoins or tokens (such as Tether, Circle, or other issuers), public blockchains (which are inherently public ledgers operated by no single party), Mobile Money operators acting in their own capacity, your own bank or card issuer, your mobile-network operator, app-store operators (Apple and Google), and any third-party websites or services to which the App may link. You should consult their respective privacy notices.

2.3 Public Blockchains

Where you make or receive on-chain transfers, certain data, including wallet addresses, transaction amounts, timestamps, and transaction graphs, is recorded on a public, immutable, distributed ledger. Such on-chain data is not under WeWire's control, cannot be deleted by us, and may be analysed by anyone (including blockchain-analytics firms, exchanges, regulators, and law-enforcement agencies). Linking on-chain data to your real-world identity is technically possible. You should not assume that on-chain transactions are anonymous.

3. Key Definitions

In addition to the defined terms in the Terms, the following terms have the meanings set out below:

  • "Personal Data" / "Personal Information" means any information relating to an identified or identifiable natural person, as defined under the relevant Data Protection Laws.
  • "Sensitive Personal Data" means special-category data under EU/UK GDPR (such as biometric data processed for unique identification, data revealing political opinions or religious beliefs, or health data) and "sensitive personal information" as defined under U.S. state privacy laws (such as government-issued identifiers, account credentials, precise geolocation, financial-account data, and biometric information).
  • "Processing" means any operation performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
  • "Sub-processor" means a third party engaged by WeWire to process Personal Data on our behalf, such as cloud-hosting, identity-verification, blockchain-analytics, fraud-screening, and customer-support providers.
  • "Data Protection Laws" has the meaning given in the Terms and includes (without limitation) PIPEDA, Quebec Law 25, BC PIPA, Alberta PIPA, the EU GDPR, the UK GDPR, the Data Protection Act 2018 (UK), the CCPA/CPRA, the VCDPA, the CPA, the CTDPA, the UCPA, the TDPSA, the UAE PDPL, the DIFC Data Protection Law, the ADGM Data Protection Regulations, and equivalent laws.
  • "Travel Rule" means FATF Recommendation 16 and equivalent rules requiring the exchange of originator and beneficiary information between Virtual Asset Service Providers (VASPs).

4. Categories of Personal Data We Collect

We collect Personal Data directly from you, automatically through your use of the App, and from third parties (including our Partners, public registries, sanctions lists, blockchain-analytics providers, and credit/fraud bureaus). The categories of Personal Data we collect include the following.

4.1 Identification and KYC Data

Including: full legal name; previous or alternative names; date and place of birth; nationality and country of residence; gender (where required for ID verification); residential and postal address; signature; government-issued photo identification (passport, national ID, driver's licence, residence permit, including ID numbers and document images); a recent live photograph or short video for liveness verification; biometric templates derived from your face for identity verification; tax-identification numbers (e.g., SIN, SSN/ITIN, NINO, NIF/NIE, TIN, Emirates ID number); and beneficial-ownership and control information for entity Users.

4.2 Contact Data

Including: phone number(s); email address(es); preferred language; and any messaging-platform handles you provide for support purposes.

4.3 Account and Credentials Data

Including: username; hashed password; security questions and answers; multi-factor authentication factors (one-time-codes, authenticator-app secrets, biometric authenticators registered on your Device); session tokens; device-binding keys; and recovery-account information.

4.4 Financial and Transaction Data

Including: bank-account details; payment-card details (typically tokenised by our payment processors, with WeWire receiving only a token, last four digits, and brand); Mobile Money wallet identifiers (such as MTN MoMo, Vodafone Cash, AirtelTigo Money, Orange Money, M-Pesa numbers); on-chain wallet addresses you control or interact with; deposit, withdrawal, exchange, conversion, P2P, and payment instructions and history; counterparty details; FX rates and spreads applied; fees charged; and balances held in Fiat and Digital Asset wallets.

4.5 Source-of-Funds and Source-of-Wealth Data

Including: occupation; employer name; salary range; business activity; investment background; description of source of wealth (inheritance, savings, business sale, investment returns, etc.); supporting documentary evidence (payslips, tax returns, bank statements, sale agreements, dividend statements); and explanations regarding the rationale for specific Transactions.

4.6 Sanctions, PEP, and Adverse-Media Data

Including: matches and possible matches against sanctions lists (OFAC SDN, EU consolidated, UK HMT, UN Security Council, Canadian SEMA, and others); politically-exposed-person (PEP) status (including immediate family and close associates); adverse-media findings; risk-scoring outputs from screening providers; and notes from our compliance reviewers.

4.7 Device, Technical, and Telemetry Data

Including: IP address; approximate or precise geolocation derived from IP, GPS (where you grant permission), Wi-Fi, or mobile-network triangulation; device identifiers (advertising ID, vendor/install ID, hardware identifiers as exposed by the operating system); device model, manufacturer, OS version, locale, and time zone; mobile-network operator and carrier; SIM-binding indicators; battery status; screen resolution; app version and build; crash logs and error traces; performance metrics; and security signals (jailbreak/root indicators, emulator indicators, integrity-check results from Apple App Attest, Google Play Integrity, or equivalents).

4.8 Behavioural and Usage Data

Including: events and actions performed within the App (logins, screen views, button taps, transaction flows started or abandoned); navigation paths; search queries; feature usage; preferences and in-app settings; and engagement with notifications, emails, and other communications.

4.9 Communications and Support Data

Including: messages exchanged via in-app chat, email, phone, video call, or chatbot; call recordings (where lawful and with notice); voicemails; transcripts; ticket metadata; complaint particulars; survey responses; and any documents or screenshots you submit.

4.10 On-Chain and Blockchain-Analytics Data

Including: wallet addresses; transaction hashes; counterparty addresses; cluster attributions; risk scores produced by analytics providers (such as Chainalysis or equivalents); exposure metrics (e.g., proximity to sanctioned addresses, darknet markets, ransomware addresses, or mixers); and provenance trails of Digital Assets you transact.

4.11 Marketing and Preference Data

Including: marketing-consent status; preference-centre selections; channel preferences (email, push, SMS); referral codes; affiliate links used; and the content of marketing emails sent and your engagement with them.

4.12 Sensitive / Special-Category Data

We process certain categories of Sensitive Personal Data only where strictly necessary and lawful, including: (a) biometric data (face geometry/embeddings) for the unique purpose of identity verification and fraud prevention; (b) data that may incidentally reveal sensitive characteristics where contained in your KYC documents; (c) precise geolocation where you have granted permission; and (d) financial-account information that is treated as sensitive personal information under U.S. state privacy laws. Where Applicable Law requires explicit consent for processing of Sensitive Personal Data, we will obtain it before processing, except where another lawful basis applies (such as compliance with AML obligations).

4.13 Information About Other Persons

You may provide us with Personal Data about other people, for example, the name, account number, or wallet address of a payment beneficiary, a P2P counterparty, or your beneficial owners or authorised users. By submitting that information, you represent that you are entitled to do so, that you have informed those individuals of our processing, and (where required) that you have obtained their consent.

5. Sources of Personal Data

We obtain Personal Data from the following sources:

  • Directly from you — when you register, complete onboarding, transact, contact support, complete forms, or otherwise communicate with us.
  • From your Device — automatically through SDKs, server logs, and analytics tooling embedded in the App.
  • From our Partners and sub-processors — including KYC and identity-verification providers (such as document and biometric verification vendors), Custodians (including Fireblocks and equivalents), Mobile Money operators, banking and card-acquiring partners, blockchain-analytics providers (such as Chainalysis), fraud-screening providers, and FX-execution and liquidity providers.
  • From public and commercial sources — including sanctions lists, PEP databases, adverse-media databases, public registries (companies house, beneficial-ownership registers, court records), credit and fraud bureaus, and public blockchains.
  • From other Users — for example, when another User sends you a payment, initiates a P2P trade with you, refers you, or names you as a beneficiary.
  • From regulators, law-enforcement, and tax authorities — in the form of requests, orders, freezing instructions, levies, or queries.

6. Purposes of Processing and Lawful Bases

We process Personal Data for the purposes and on the lawful bases set out in the table below. Where we rely on "legitimate interests", we have carried out a balancing test to ensure that our interests are not overridden by your rights and freedoms, and you may object to such processing in accordance with Section 12.

Purpose of Processing
Lawful Basis
Account creation and management; provision of the Services as set out in the Terms; processing of deposits, withdrawals, exchanges, conversions, P2P trades, payments, and remittances; settlement and reconciliation; and customer support.
Performance of a contract (the Terms); legitimate interests; consent (where applicable).
KYC, KYB, customer due diligence, enhanced due diligence, sanctions and PEP screening, adverse-media screening, ongoing monitoring, transaction monitoring, blockchain analytics, and source-of-funds verification.
Compliance with legal obligation (AML/CTF, sanctions, RPAA, FINTRAC, and equivalent regimes); legitimate interests in preventing financial crime and protecting our Partners and Users.
Travel Rule data exchange with counterparty Virtual Asset Service Providers; suspicious-transaction reports; large-cash-transaction reports; threshold reporting; tax-information reporting; and other regulatory filings.
Compliance with legal obligation; substantial public interest.
Fraud prevention; security monitoring; abuse and market-integrity controls; investigation of incidents and security events; recovery of mistaken or Glitch-derived credits.
Legitimate interests; compliance with legal obligation; protection of vital interests where applicable.
IT operations, hosting, backups, business continuity, disaster recovery, internal audit, accounting, and corporate governance.
Legitimate interests; compliance with legal obligation.
Product development, analytics, A/B testing, and improvement of the App and the Services.
Legitimate interests (subject to your right to object); consent for non-essential analytics where required.
Direct marketing, promotions, surveys, referral programmes, and personalised in-app communications.
Consent (where required by Applicable Law); legitimate interests for own-product marketing to existing Users where lawful.
Defending or asserting legal claims; complying with court orders; cooperating with regulators and law-enforcement.
Compliance with legal obligation; legitimate interests; establishment, exercise, or defence of legal claims.
Corporate transactions: due-diligence, mergers, acquisitions, reorganisations, financings, and successor transactions.
Legitimate interests in conducting corporate activity, with appropriate confidentiality and data-protection safeguards.

We do not "sell" Personal Information for monetary consideration. We do not "share" Personal Information for cross-context behavioural advertising except with your consent.

7. Automated Decision-Making and Profiling

We use automated tools to support compliance, risk, fraud, security, and product personalisation. Specifically:

  • Identity verification — automated comparison of your selfie/liveness video against your government-issued ID image, supported by document-authenticity checks.
  • Sanctions, PEP, and adverse-media screening — automated matching of your details against external lists, with potential matches reviewed by our compliance team.
  • Transaction monitoring and risk scoring — rule-based and model-based assessment of Transactions for fraud, AML, and market-integrity purposes, including blockchain-analytics scoring of wallet addresses you interact with.
  • Account risk-rating — used to determine verification tier, transaction limits, and the level of due diligence applied.
  • Personalisation — to tailor in-app content, support routing, and (with consent where required) marketing communications.

Some of these processes may produce solely automated decisions that have legal or similarly significant effects on you (for example, an automatic decline of an Account application or a Transaction). Where Applicable Law gives you the right not to be subject to such a decision, you may request human review by contacting help@wewire.com. We may decline such requests where the decision is necessary for entering into or performing the Terms, is authorised by law (including for fraud-prevention or AML purposes), or is based on your explicit consent.

8. Disclosure of Personal Data

We disclose Personal Data only to the extent necessary, proportionate, and lawful. The categories of recipients to whom we disclose Personal Data include:

8.1 Affiliates

Members of the WeWire group of companies, where necessary for the operation, administration, support, and governance of the Services, under intra-group data-protection arrangements.

8.2 Service Providers and Sub-Processors

Third parties acting on our instructions and bound by confidentiality and data-protection obligations, including:

  • Cloud-hosting and infrastructure providers (such as Amazon Web Services, Google Cloud, or Microsoft Azure data centres in Canada, the European Union, the United Kingdom, and the United Arab Emirates).
  • KYC, identity-verification, and biometric-verification providers (document-authenticity, facial-similarity, and liveness vendors).
  • Sanctions, PEP, and adverse-media screening providers and watchlist database providers.
  • Blockchain-analytics and Travel-Rule providers (such as Chainalysis or equivalents and Travel-Rule message-routing networks).
  • Custodians of Digital Assets (including Fireblocks and other regulated custodians).
  • Banking, payment-acquiring, card-network, and FX-execution partners.
  • Mobile Money operators and aggregators (such as MTN MoMo, Vodafone Cash, AirtelTigo Money, Orange Money, M-Pesa, and equivalent operators).
  • Customer-support, contact-centre, ticketing, and chatbot providers.
  • Communications providers for email, push notifications, SMS/OTP, and in-app messaging.
  • Analytics, crash-reporting, and product-telemetry providers.
  • Professional advisers (legal, audit, accounting, tax, and consultants), under duties of confidentiality.
  • Marketing and CRM platform providers (only with your consent where required).

8.3 Counterparties and Other Users

Where you initiate a payment, P2P trade, transfer, or remittance, we share with your counterparty (or with their VASP, bank, or Mobile Money operator) the information necessary to complete the Transaction, which may include your name, account number or wallet address, and the amount and reference of the Transaction. For Travel Rule transfers above applicable thresholds, we are required to share originator and beneficiary information with the counterparty VASP.

8.4 Regulators, Authorities, and Courts

We disclose Personal Data to regulators, supervisors, financial-intelligence units, tax authorities, courts, tribunals, and law-enforcement agencies where required or permitted by Applicable Law, including FINTRAC, the Bank of Canada, the UK National Crime Agency, His Majesty's Revenue & Customs, the UK Financial Conduct Authority, the European Banking Authority and EU national competent authorities, the UAE Central Bank, the UAE Financial Intelligence Unit, the Virtual Assets Regulatory Authority (VARA), the Financial Services Regulatory Authority of the ADGM, and equivalent authorities in other jurisdictions. You acknowledge that we may be prohibited by Applicable Law from notifying you of an investigation, freeze, report, or compliance action (the so-called tipping-off prohibition).

8.5 Successors and Acquirers

In the context of a merger, acquisition, financing, reorganisation, insolvency, or sale of all or part of our business, Personal Data may be transferred to a successor or acquirer, with appropriate confidentiality and data-protection safeguards. We will notify you where required by Applicable Law.

8.6 With Your Consent or At Your Direction

We may share Personal Data with other recipients where you have provided consent or directed us to do so (for example, when you connect a third-party application via an API or integration).

8.7 Aggregated and De-identified Data

We may share aggregated, anonymised, or de-identified information that does not identify you for analytics, research, benchmarking, fraud-prevention consortia, and product-development purposes. Where applicable, we contractually prohibit recipients from attempting to re-identify such data.

9. International Transfers of Personal Data

The provision of the Services necessarily involves transfers of Personal Data across borders, including to and from Canada, the United States, the United Kingdom, the European Economic Area, the United Arab Emirates, and other jurisdictions where WeWire, its Affiliates, Partners, Custodians, or sub-processors are located.

9.1 Transfer Mechanisms

Where required by Applicable Law, we rely on one or more of the following transfer mechanisms:

  • Adequacy decisions — such as the European Commission's adequacy decision regarding Canada (commercial sector) and the United Kingdom's equivalent recognitions.
  • Standard Contractual Clauses — the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Agreement / UK Addendum.
  • EU-U.S. Data Privacy Framework and the UK Extension thereto, where the recipient is certified.
  • Intra-group data-transfer agreements among WeWire Affiliates incorporating GDPR-equivalent safeguards.
  • Approved transfer mechanisms under the UAE PDPL, the DIFC Data Protection Law, and the ADGM Data Protection Regulations (including Standard Contractual Clauses approved by the relevant authorities, adequacy determinations, and binding intra-group rules).
  • Explicit consent or other derogations where lawful and appropriate (e.g., transfers necessary for the performance of your contract with us).

9.2 Supplementary Measures

Following the Schrems II decision and equivalent guidance, we apply supplementary technical, contractual, and organisational measures where required, including encryption in transit and at rest, pseudonymisation, key-management controls, access logging, vendor due diligence, and government-access transparency reporting where lawful.

9.3 Public Blockchains

Where Personal Data is recorded on a public blockchain (typically a wallet address linked to your Account), the data is replicated globally across nodes in multiple jurisdictions. We cannot control where such on-chain data is stored or processed and have no ability to delete it.

10. Data Retention

We retain Personal Data only for as long as necessary for the purposes for which it was collected and to comply with our legal, regulatory, and operational obligations.

10.1 Retention Schedule

Category
Typical Retention Period
Reason
KYC, AML, sanctions, beneficial-ownership, source-of-funds, and Transaction records.
Minimum 5 to 7 years from end of relationship or completion of Transaction; longer where required by FINTRAC, FinCEN, the FCA, the UAE Central Bank, EU AML rules, or other regulators.
Compliance with AML/CTF and sanctions record-keeping obligations.
Tax-information reporting and tax-related records.
As required by Canadian, EU, UK, UAE, and other applicable tax laws (often 6 to 7 years).
Compliance with tax law.
Account, profile, communications, and support data.
For the duration of the Account plus a residual period (typically up to 7 years) consistent with limitation periods and AML obligations.
Performance of the Terms; defence of legal claims; AML obligations.
Marketing and preference data.
Until you withdraw consent or object, plus a short suppression period required to honour your opt-out.
Demonstrating consent and respecting opt-outs.
Device, telemetry, and security logs.
Typically 12 to 24 months, longer where retained for incident investigation or fraud-prevention.
Security; legitimate interests; legal claims.
CCTV / call-centre recordings (where applicable).
Typically 30 to 90 days unless retained for an incident or claim.
Security; quality assurance; legal claims.
Records relating to ongoing or threatened legal claims, regulatory investigations, or court orders.
Until the matter is finally resolved and any applicable limitation period has expired.
Legal and regulatory necessity.
Anonymised or aggregated data.
May be retained indefinitely.
Such data is no longer Personal Data.

10.2 Retention After Account Deletion

On Account closure, we delete or anonymise Personal Data within thirty (30) days, save for data we are required to retain as set out above and in Section 22 of the Terms and Schedule B (In-App Account Deletion Flow). During the retention period, retained data is access-restricted and used only for the lawful purposes for which it was retained.

11. Information Security

11.1 Technical and Organisational Measures

We implement technical and organisational measures appropriate to the risks presented by our processing, including:

  • Encryption — TLS 1.2+ for data in transit; AES-256 (or equivalent) for data at rest; envelope encryption with hardware-security-module-backed key management for sensitive data.
  • Authentication and access controls — multi-factor authentication for User logins and for staff access to production systems; least-privilege access; just-in-time elevation; segregation of duties; periodic access reviews.
  • Network and platform security — network segmentation; firewalls and web-application firewalls; DDoS protection; intrusion-detection and prevention systems; secure configuration management; centralised logging and security monitoring (SIEM).
  • Application security — secure software-development lifecycle; static and dynamic application security testing; dependency scanning; secrets management; mobile-app integrity checks (Apple App Attest, Google Play Integrity, jailbreak/root detection).
  • Vulnerability and penetration testing — conducted by qualified internal and external testers; tracked through a managed remediation programme; supplemented by a coordinated vulnerability-disclosure process.
  • People controls — background checks where lawful; mandatory privacy and security training; confidentiality agreements; insider-risk monitoring.
  • Vendor risk management — due diligence on Partners and sub-processors; data-processing agreements; ongoing monitoring; right-to-audit clauses where appropriate.
  • Business continuity and incident response — documented incident-response and breach-notification playbooks; tested business-continuity and disaster-recovery plans.

11.2 Your Role in Security

No system is fully secure. You also have responsibility for security of your Account and Device, as set out in Section 17 of the Terms. Recommended measures include using a strong, unique password; enabling all available authentication factors; keeping your operating system and the App up to date; not jailbreaking or rooting your Device; never sharing one-time codes or recovery phrases; and being vigilant against phishing and social-engineering attacks. Notify us immediately at security@wewire.com if you suspect unauthorised access to your Account.

12. Personal Data Breach Notification

In the event of a Personal Data breach, we will notify the relevant supervisory authority and affected individuals where and as required by Applicable Law, including:

  • EU GDPR / UK GDPR — notification to the lead supervisory authority within seventy-two (72) hours of awareness, where the breach is likely to result in a risk to the rights and freedoms of individuals; notification to affected individuals without undue delay where the breach is likely to result in a high risk.
  • PIPEDA — notification to the Office of the Privacy Commissioner of Canada and to affected individuals where the breach gives rise to a real risk of significant harm; record-keeping of all breaches as required.
  • Quebec Law 25 — notification to the Commission d'acces a l'information du Quebec and to affected individuals where there is a risk of serious injury.
  • UAE PDPL, DIFC, ADGM — notification to the relevant Data Office or Commissioner and (where required) to affected individuals.

We maintain a breach register and conduct a documented post-incident review for each notifiable breach.

13. Your Rights and Choices

Subject to Applicable Law, you may have some or all of the following rights in relation to your Personal Data. The precise scope, exceptions, and exercise mechanics for each right depend on your jurisdiction.

  • Right of access / right to know — to obtain confirmation that we process your Personal Data and a copy of that data, together with prescribed information about the processing.
  • Right to rectification / correction — to have inaccurate Personal Data corrected and incomplete data completed.
  • Right to erasure / deletion (right to be forgotten) — to have Personal Data erased in certain circumstances, subject to our legal obligations to retain certain data.
  • Right to restriction — to require us to restrict processing in certain circumstances.
  • Right to data portability — to receive Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to object — to object to processing based on legitimate interests or to direct marketing.
  • Right to withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Rights relating to automated decision-making and profiling — including the right not to be subject to a solely automated decision producing legal or similarly significant effects, where applicable.
  • Right to opt out of sale or sharing of Personal Information — where applicable under U.S. state privacy laws.
  • Right to opt out of targeted advertising — where applicable.
  • Right to limit use of sensitive personal information — where applicable under U.S. state privacy laws.
  • Right to non-discrimination — we will not retaliate against you for exercising your privacy rights.
  • Right to lodge a complaint — with the relevant supervisory authority or regulator (see Section 14).

14. How to Exercise Your Rights

14.1 In-App Privacy Controls

Where available, the App provides in-app controls to access, download, correct, and delete certain Personal Data, manage marketing preferences, manage permissions (e.g., location, notifications, biometrics), and submit privacy requests. The path is generally: Profile -> Settings -> Privacy & Data.

14.2 Contacting the Privacy Office

You may also exercise your rights by emailing info@wewire.com or by writing to: Privacy Officer, WeWire Technologies Inc., 2015 Main Street, Vancouver, BC, V5T 3C2, Canada. To help us locate your data, please include your registered email, full name, and a clear description of the right you wish to exercise.

14.3 Authorised Agents

Where Applicable Law permits, you may authorise an agent to submit a request on your behalf. We may require written authorisation, verification of your identity, and direct confirmation from you before acting.

14.4 Verification

To protect your data, we will take reasonable steps to verify your identity before responding to a request. The level of verification will be proportionate to the sensitivity and nature of the request. We may decline to act on a request where we cannot verify the requester's identity, the request is manifestly unfounded or excessive, or where exemptions or exceptions under Applicable Law apply.

14.5 Response Timeframes

  • EU GDPR / UK GDPR: within one (1) month, extendable by two (2) further months for complex requests.
  • PIPEDA: typically within thirty (30) days, with extensions where permitted.
  • UAE PDPL / DIFC / ADGM: within the periods prescribed by the applicable regime (usually thirty (30) days).

14.6 Fees

We do not generally charge a fee for responding to a privacy request. Where Applicable Law permits, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, excessive, or repetitive.

14.7 Limits and Exceptions

Some of your rights may be limited or excepted by Applicable Law, for example, where compliance would conflict with our AML, CTF, sanctions, tax-reporting, or record-keeping obligations; where it would prejudice the rights of others, ongoing investigations, or legal claims; or where data has been irreversibly anonymised. Where we cannot fully comply with your request, we will explain why to the extent permitted by law.

15. Children's Privacy

The App and the Services are intended for use only by persons aged eighteen (18) years or older (or such higher age of majority as applies in the User's jurisdiction). We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected Personal Data from a child, we will close the Account and delete the data without undue delay. If you believe a child has provided us with Personal Data, please contact info@wewire.com.

16. Cookies, SDKs, and Similar Technologies

Within the App and on related websites, we and our service providers use cookies, mobile SDKs, software-development kits, web beacons, pixels, local storage, device identifiers, and similar technologies (collectively, "Tracking Technologies") for the following purposes:

  • Strictly necessary, authentication, session management, fraud-prevention, security, accessibility, and load balancing. These cannot be disabled without breaking functionality.
  • Functional / preference, remembering settings, language, and locale.
  • Performance / analytics, understanding usage, diagnosing crashes, and improving the App.
  • Marketing and attribution, measuring the effectiveness of campaigns, attributing installs, and (with consent where required) personalising marketing.

Where required by Applicable Law (including the EU/UK ePrivacy regime), we obtain your consent before placing non-essential Tracking Technologies, and we provide controls to manage your preferences in-app and on our websites. You can also manage Tracking Technologies through your device and operating-system settings (e.g., Apple App Tracking Transparency, Google Privacy Sandbox / Limit Ad Tracking). Detailed disclosures regarding the specific Tracking Technologies we deploy are set out in our separate Cookie Policy.

17. Marketing Communications

Where we send you marketing communications, we will do so on a lawful basis (typically your consent, or for own-product marketing to existing Users where lawful). You can opt out at any time by:

  • using the unsubscribe link in any marketing email;
  • changing your preferences in the App (Profile -> Settings -> Notifications & Marketing); or
  • emailing help@wewire.com.

Opting out of marketing does not affect transactional, regulatory, security, and service messages, which we will continue to send as necessary for the operation of your Account.

18. Third-Party Services, Links, and App-Store Integrations

18.1 Third-Party Services

The App relies on Partners and sub-processors as set out in Section 8 and Schedule 2. The App may also integrate with, or link to, third-party services that are not controlled by us, including merchant payment surfaces, social-media platforms, news and market-data providers, identity-wallet apps, and self-custody wallets. Your use of those services is governed by the third party's terms and privacy notice, and we are not responsible for their practices.

18.2 Apple App Store and Google Play

When you download the App from the Apple App Store or Google Play, those platforms collect certain Personal Data about you, including device-level identifiers, install events, in-app purchases, and engagement signals, in accordance with their own policies. The terms applicable between you and the platform operator (Apple Inc. or Google LLC) supplement those between you and WeWire as set out in Schedule B of the Terms.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our processing, our Services, our Partners, or Applicable Law. Where changes are material, we will notify you by in-app notification, email, or prominent notice on our website with reasonable prior notice (typically not less than fourteen (14) days, except where shorter notice is required by Applicable Law, security, regulatory, or risk-management considerations). The Last Updated date at the top of this Privacy Policy indicates when it was most recently revised. Continued use of the App after the effective date of any change constitutes acknowledgement of the updated Privacy Policy. Where Applicable Law requires fresh consent for a new processing purpose, we will obtain your consent before that processing begins.

20. Contact Us and Complaints

Questions, concerns, and complaints regarding this Privacy Policy or our processing of your Personal Data may be addressed to:

You also have the right to lodge a complaint with the supervisory authority or regulator competent for your jurisdiction. We would, however, appreciate the opportunity to address your concerns first.

Schedule 1 - Categories of Partners, Service Providers, and Sub-Processors

The table below sets out the categories of Partners and sub-processors with whom we share Personal Data, the categories of data shared, and the purpose. The current list of named sub-processors is available on request from info@wewire.com and may be updated from time to time. We will notify Users of material changes in advance where required by Applicable Law.

Category
Examples
Purpose
Cloud and infrastructure
AWS, Google Cloud, Microsoft Azure (data centres in CA, EU, UK, UAE).
Hosting, storage, backup, business continuity.
KYC / identity / biometrics
Document-authenticity, facial-similarity, and liveness vendors.
Onboarding, identity verification, fraud prevention.
Sanctions / PEP / adverse-media
Watchlist database providers; screening engines.
Compliance with sanctions and AML obligations.
Blockchain analytics / Travel Rule
Chainalysis or equivalents; Travel Rule message-routing networks.
AML monitoring, transaction risk scoring, Travel Rule compliance.
Custodians
Fireblocks and other regulated custodians.
Custody and movement of Digital Assets.
Banking / cards / FX
Banking partners, card acquirers, FX-execution and liquidity providers.
Fiat funding, payouts, settlement, conversion.
Mobile Money
MTN MoMo, Vodafone Cash, AirtelTigo Money, Orange Money, M-Pesa, and equivalents.
Mobile-money funding, payouts, and remittance.
Customer support
Ticketing, chat, and contact-centre platforms.
Support, complaints handling, quality assurance.
Communications
Email, SMS/OTP, push-notification providers.
Service messages, OTPs, marketing (with consent).
Analytics and crash-reporting
Mobile-app analytics and crash-reporting SDKs.
Product improvement, performance monitoring.
Professional advisers
Lawyers, auditors, accountants, tax advisers, consultants.
Advice, audit, tax filings, dispute defence.
Marketing and CRM
CRM platforms; attribution providers (with consent).
Permitted marketing and engagement.

End of Privacy Policy