Privacy Policy
Last updated: 8 July 2026
1. Who We Are
This Privacy Policy describes how Cryptopawn, Inc. ("CryptoPawn", "we", "us" or "our") collects, uses, shares and protects your personal information when you use our website and services at cryptopawn.com (the "Services"). CryptoPawn provides crypto-backed lending: you pledge cryptocurrency as collateral and receive a fiat loan.
Our registered address is: Suite 004, 901 N Market St Ste 100, Wilmington, DE 19801, United States.
For the purposes of applicable data protection laws — including the EU/UK General Data Protection Regulation ("GDPR"), South Africa's Protection of Personal Information Act ("POPIA"), India's Digital Personal Data Protection Act and applicable US state privacy laws — Cryptopawn, Inc. is the data controller (or "responsible party") of your personal information.
Questions or requests about your data: [email protected].
2. Information We Collect
Account information. When you create an account we collect your name, email address and profile details through our authentication provider.
Identity verification (KYC) information. Before you can enter a loan contract, the law requires us to verify your identity. Through our verification partner Sumsub (see Section 5) we collect: your full name, date of birth, nationality, residential address, government-issued identity documents (passport, ID card or driving licence, including document photos), and a facial image and liveness recording (biometric data) used to confirm the document belongs to you. Your details are also screened against politically exposed persons (PEP), sanctions and criminal watchlists as required by anti-money-laundering ("AML") laws.
Financial and transaction information. Cryptocurrency wallet addresses you provide for payouts and repayments, blockchain transaction identifiers, loan and contract details, bank account details where bank payouts are offered, and payment card transactions processed by our payment provider (we never store full card numbers).
Referral information. If you sign up through a referral link or enter a referral code, we record which referrer introduced you so that we can pay them commission.
Communications. Messages you send us through the contact form or by email, and service emails we send you (contract updates, payment reminders, monthly statements).
Usage data and cookies. Device and browser information, IP address, pages visited and interactions with the site, collected via cookies and similar technologies (including Google Analytics) where you have consented through our cookie banner.
3. Why We Use Your Information (Legal Bases)
We process your personal information:
- To perform our contract with you — creating your account, originating and administering loan contracts, holding collateral, processing payouts and repayments, and paying referral commissions.
- To comply with legal obligations — identity verification, AML/counter-terrorist-financing screening, sanctions compliance, tax and accounting record-keeping, and responding to lawful requests from authorities.
- With your consent — processing of biometric data during identity verification (you are asked for explicit consent in the verification flow before any biometric data is captured), analytics cookies, and any marketing communications. You may withdraw consent at any time; withdrawal does not affect processing already carried out.
- For our legitimate interests — preventing fraud and abuse, securing our platform, improving our Services, and enforcing our agreements — balanced against your rights and freedoms.
Providing KYC information is a legal requirement: if you choose not to provide it, we cannot open a loan contract for you.
4. Automated Screening
Identity documents are checked by automated means (document authenticity analysis, facial matching and liveness detection) and your details are screened against international PEP, sanctions and criminal watchlists. Automated results that would prevent you from using the Services are reviewed by a human before a final decision is made. You may contest a verification outcome by contacting us.
5. Our Identity Verification Partner (Sumsub)
Identity verification is performed on our behalf by Sum and Substance Ltd ("Sumsub"), 30 St. Mary Axe, London, EC3A 8BF, United Kingdom, acting as our data processor under a data processing agreement. Sumsub processes your verification data only on our instructions and stores it on servers located in the European Union. Before starting verification you will be shown Sumsub's consent notice and asked to agree to the processing of your data, including your facial image, for KYC/AML purposes. Sumsub's own privacy notice is available at sumsub.com/privacy-notice-service.
6. Who We Share Information With
- Service providers (processors) — identity verification (Sumsub), authentication (Clerk), card payment processing (Stripe), email delivery, accounting software, cloud hosting and analytics providers. Each is bound by contract to protect your data and use it only to provide services to us.
- Regulators and law enforcement — where required by AML law, court order or other legal obligation.
- Professional advisers — lawyers, auditors and insurers under confidentiality obligations.
- Business transfers — if we are involved in a merger, acquisition or asset sale, subject to this policy's protections.
We never sell your personal information.
Note that cryptocurrency transactions are recorded on public blockchains. Wallet addresses and transaction details on a blockchain are public by design and cannot be deleted by us.
7. International Transfers
We operate internationally and serve clients in ZAR, USD, GBP and INR markets. Where your information is transferred outside your home jurisdiction, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or your explicit consent, as applicable. KYC data processed by Sumsub is stored on servers within the European Union.
8. How Long We Keep Your Information
- KYC and transaction records — retained for at least five (5) years after our business relationship ends, as required by AML laws (longer where a specific law or investigation requires it).
- Account information — kept while your account is active and deleted or anonymised within a reasonable period after closure, subject to the legal retention above.
- Biometric data — retained only as long as needed for verification and compliance purposes, then permanently destroyed in line with applicable biometric privacy laws.
- Analytics data — retained per the analytics provider's standard retention settings.
9. Your Rights
Depending on your jurisdiction, you have the right to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate or incomplete information;
- request deletion of your information (subject to legal retention obligations — we cannot delete KYC records the law requires us to keep);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time (including for biometric processing and cookies);
- lodge a complaint with your data protection authority — for example the UK ICO, an EU supervisory authority, or South Africa's Information Regulator.
To exercise any of these rights, email [email protected]. We will respond within the timeframe required by applicable law (normally within one month) and may need to verify your identity before acting on a request.
10. Additional Notices for United States Residents
State privacy rights. If you reside in a US state with a comprehensive privacy law — including the Delaware Personal Data Privacy Act, the California Consumer Privacy Act (CCPA/CPRA), and similar laws in Colorado, Connecticut, Texas, Virginia and other states — you have the right to: (a) know and access the personal data we hold about you; (b) correct inaccurate data; (c) delete your data (subject to the AML retention obligations in Section 8); (d) obtain a portable copy; (e) opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects; and (f) not be discriminated against for exercising these rights.
We do not sell or share your personal data. We do not sell your personal data for money, and we do not share it for cross-context behavioural (targeted) advertising as those terms are defined under Delaware, California and similar state laws. Because we do not sell or share personal data, there is no need to opt out — but you may confirm or exercise any right by emailing [email protected] with the subject line "US Privacy Request".
Appeals. If we decline to act on your request, you may appeal by replying to our decision within 60 days. If your appeal is denied, you may contact your state Attorney General — for Delaware residents, the Delaware Department of Justice at [email protected].
Financial privacy (Gramm-Leach-Bliley Act). As a provider of financial services, we treat non-public personal information (such as your loan, payout and account details) in accordance with the GLBA and its Safeguards Rule. We share such information only as described in Section 6 — with service providers who process it on our behalf, and as required by law. We do not share your non-public personal information with non-affiliated third parties for their own marketing purposes, so no GLBA opt-out is required.
Sensitive data. Biometric identifiers collected during identity verification are processed only with your explicit consent, are never sold, and are destroyed as described in Section 8.
11. Cookies
We use essential cookies needed for the site to function (such as keeping you signed in) and, with your consent, analytics cookies (Google Analytics) to understand how the site is used. You can accept or decline analytics cookies in the banner shown on your first visit, and change your choice at any time by clearing your browser's site data for cryptopawn.com.
12. Security
We protect your information with technical and organisational measures including encryption in transit (TLS), encryption of sensitive records at rest, strict access controls, and segregation of customer collateral wallets. No system is completely secure; if a breach affecting your personal information occurs we will notify you and the relevant authorities as required by law.
13. Children
Our Services are not directed at, and may not be used by, anyone under 18. In accordance with the US Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13, and identity verification prevents minors from entering loan contracts. If you believe a minor has provided us with data, contact us and we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top shows the latest revision. For material changes we will give you notice through the site or by email before the changes take effect.
15. Contact Us
Cryptopawn, Inc.
Suite 004, 901 N Market St Ste 100
Wilmington, DE 19801, United States
Email: [email protected]
Support: [email protected]