Privacy Policy

This Privacy Policy explains what personal information DIRE MONEY TRANSMITTER LLC, trading as DireBit, collects about you, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to direbbit.com, to the DireBit mobile applications, and to all related services. DireBit is a United States business and offers its services only in the United States; this policy is written to United States federal and state law.

Contents

  1. Who is responsible for your data
  2. Information we collect
  3. Where we get it from
  4. How and why we use it
  5. Our legal grounds
  6. Who we share it with
  7. We do not sell your data
  8. Where we process your information
  9. How long we keep it
  10. How we protect it
  11. Your rights and choices
  12. U.S. state privacy rights
  13. Financial privacy (Gramm-Leach-Bliley)
  14. Children
  15. Automated decision-making
  16. Cookies
  17. Changes to this policy
  18. How to contact us

Section 1

Who is responsible for your data

The business responsible for your personal information is DIRE MONEY TRANSMITTER LLC, 9000 Renton Ave S Unit 1, Seattle, WA 98118-5059, United States, trading as DireBit.

For any privacy question, or to exercise a right described in this policy, contact [email protected], write to us at the address above, or call +1 206 235 4353.

Section 2

Information we collect

We collect the categories of personal information set out below. Much of it we are legally required to collect, because we are a money services business registered with FinCEN and licensed as a money transmitter. If you do not provide it, we cannot open or maintain your account.

CategoryExamplesRequired?
IdentityFull legal name, date of birth, nationality, gender where shown on an identity document, government identification number (such as a Social Security number, passport number or driver's license number)Required by law
Identity documentsImages of a passport, driver's license or national identity card; a selfie or short video used to confirm the document belongs to you; the biometric template derived from that comparisonRequired by law
ContactResidential address, postal address, email address, telephone numberRequired by law
FinancialBank account and payment card details, blockchain wallet addresses, account balances, transaction history, source of funds and source of wealth informationRequired by law
Business customersFormation documents, ownership structure, and identity information for beneficial owners and controlling personsRequired by law
Device and technicalIP address, device identifiers, device model and operating system, browser type, language, application version, crash diagnosticsCollected automatically
UsagePages and screens viewed, features used, watchlists, settings, session times, referring pageCollected automatically
LocationCountry and region inferred from IP address, used to confirm eligibility and to meet sanctions obligationsRequired by law
CommunicationsSupport tickets, emails, chat messages, and call recordings where we tell you a call is recordedCollected when you contact us
ComplianceSanctions, politically-exposed-person and adverse-media screening results, risk ratings, transaction monitoring alerts, and records of any report we are required to fileRequired by law

Identity document images and the facial comparison used to verify them may constitute biometric information under laws such as the Washington My Health My Data Act and comparable state statutes. We use this information only to verify that you are who you say you are, to prevent fraud, and to meet our legal obligations. We do not use it for advertising, and we do not sell it.

Section 3

Where we get it from

  • From you — when you register, verify your identity, transact, change settings or contact support.
  • Automatically — from your device and your use of the website and applications, as described in our Cookie Policy.
  • From identity verification and screening providers — document authentication results, sanctions and watchlist matches, politically-exposed-person status and adverse media.
  • From banking and payment partners — to confirm account ownership and settle transfers.
  • From public sources — company registries, public blockchain records and blockchain analytics providers. Note that blockchain transactions are public by design and are not controlled by us.
  • From law enforcement and regulators — where they contact us about you.

Section 4

How and why we use it

  • To provide the Services — to open and operate your account, execute your instructions, hold your balances, and process deposits and withdrawals.
  • To verify your identity — to run our Customer Identification Program and customer due diligence as required by the Bank Secrecy Act.
  • To meet legal and regulatory obligations — including sanctions screening, transaction monitoring, recordkeeping, the Travel Rule, and filing Suspicious Activity Reports and Currency Transaction Reports with FinCEN.
  • To prevent fraud and protect security — to detect unauthorized access, account takeover, and abuse of the Services.
  • To provide support — to answer your questions and investigate complaints.
  • To improve the Services — to understand which features are used, diagnose faults and improve reliability.
  • To communicate with you — to send service messages, security alerts, and changes to terms. We send marketing only where you have opted in, and you can opt out at any time.
  • To establish or defend legal claims — and to enforce our Terms of Service.

We are legally prohibited from telling you if we have filed a Suspicious Activity Report about your activity. Where that is the case, we cannot confirm or deny it, and certain of your access rights may be lawfully restricted.

Section 6

Who we share it with

We share personal information only as described here.

RecipientWhy
Identity verification and screening providersTo authenticate identity documents and screen against sanctions and watchlists
Banking and payment partnersTo settle deposits, withdrawals and currency conversion
Blockchain analytics providersTo assess the risk of wallet addresses and detect illicit activity
Cloud hosting, security and IT providersTo operate, host, secure and support our systems
Regulators and law enforcementWhere required by law, court order, subpoena or lawful request — including FinCEN, the Washington State Department of Financial Institutions, OFAC and the IRS
Receiving financial institutionsOriginator and beneficiary details for qualifying transfers, under the Travel Rule
Professional advisersAuditors, lawyers and accountants bound by confidentiality
A successor entityIn connection with a merger, acquisition or sale of assets, subject to this policy

Service providers act on our documented instructions under written contracts, may use the information only to provide their service to us, and must protect it appropriately.

Section 7

We do not sell your data

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. We have not done so in the preceding twelve months. We do not use your identity documents, biometric information, financial information or transaction history for advertising.

Section 8

Where we process your information

DireBit is a United States business serving United States customers. Personal information is collected, stored and processed in the United States, and is subject to United States federal and state law.

A small number of our service providers — for example cloud hosting or identity verification vendors — may process information outside the United States on our behalf. Where that happens they act only on our documented instructions, under written contracts that require them to protect the information and to use it solely to provide their service to us. You may ask what those arrangements are by writing to [email protected].

Section 9

How long we keep it

We keep personal information only as long as necessary, and for the minimum periods the law requires of a money services business.

RecordRetention period
Customer identification recordsAt least 5 years after the account is closed (Bank Secrecy Act)
Transaction recordsAt least 5 years from the date of the transaction
Suspicious Activity Report supporting documentationAt least 5 years from the date of filing
Currency Transaction Reports and Travel Rule recordsAt least 5 years
Support communicationsUp to 5 years from last contact
Website and application technical logsUp to 24 months
Marketing preferencesUntil you withdraw consent, plus a suppression record kept indefinitely so we can honor your opt-out

Where a longer period is required by a legal hold, an investigation or a court order, we retain the records for as long as that requirement lasts. After the applicable period, we delete or irreversibly anonymise the information.

Section 10

How we protect it

We maintain administrative, technical and physical safeguards designed to protect personal information against loss, misuse and unauthorized access. These include encryption of data in transit and at rest, role-based access control on a least-privilege basis, multi-factor authentication for staff, segregation of duties for asset movements, logging and monitoring, vendor due diligence, staff training, and an incident response plan.

No system is perfectly secure. You play an important part: use a strong unique password, enable two-factor authentication, keep your devices patched, and never share a verification code or recovery phrase. DireBit will never ask you for your password, your two-factor code or a wallet recovery phrase.

Where a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable breach-notification law.

Section 11

Your rights and choices

Subject to applicable law and to our legal retention obligations, you may ask us to:

  • Access the personal information we hold about you, and receive a copy.
  • Correct information that is inaccurate or incomplete.
  • Delete information, where we are not required to keep it.
  • Port information to another provider in a machine-readable format.
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Withdraw consent where processing is based on consent.
  • Opt out of marketing at any time, using the unsubscribe link or by contacting us.

To exercise a right, email [email protected]. We will verify your identity before acting and respond within 45 days, extendable once by a further 45 days where the request is complex, as U.S. state privacy law allows. We will not discriminate against you for exercising a right. You may use an authorized agent where the law permits.

Anti-money-laundering law overrides the right to erasure. We cannot delete identity or transaction records we are required to retain, and we cannot disclose information that would tip you off about a regulatory report.

Section 12

U.S. state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Washington and other states with comprehensive privacy laws have the rights described in section 11, including the right to know, to delete, to correct, to obtain a portable copy, and to opt out of sale, targeted advertising and certain profiling. As stated in section 7, we do not sell personal information and do not engage in cross-context behavioral advertising.

Washington residents have additional rights under the My Health My Data Act regarding consumer health data. We do not collect consumer health data, other than where a biometric identifier used for identity verification falls within that definition; we process it only for verification and fraud prevention, and you may withdraw consent and request deletion by contacting [email protected], subject to our legal retention duties.

If we deny your request, you may appeal by replying to our decision with the word "Appeal". If we deny the appeal, you may complain to your state attorney general.

Section 13

Financial privacy (Gramm-Leach-Bliley)

As a money services business we are a financial institution for the purposes of the federal Gramm-Leach-Bliley Act, and the nonpublic personal information you give us is protected by it as well as by the state laws described above.

We do not sell your nonpublic personal information, and we do not disclose it to nonaffiliated third parties for their own marketing. We disclose it only as the law permits — to process the transactions you ask for, to service providers acting on our behalf under contract, to comply with legal and regulatory obligations including Bank Secrecy Act reporting, and in response to lawful requests from regulators, law enforcement or courts.

We provide our financial privacy notice when you open an account and thereafter as required by law. You may request a copy at any time from [email protected].

Section 14

Children

The Services are for adults. We do not knowingly collect personal information from anyone under 18, and account opening requires verified proof of age. If we learn that we hold information about a minor, we will close the account and delete the information except where we are required to retain it. If you believe a minor has given us information, contact [email protected].

Section 15

Automated decision-making

We use automated tools to screen customers against sanctions lists, to score risk and to flag unusual transactions. An automated flag may cause a delay, an additional information request, or a restriction on your account. Material decisions — such as declining an application or closing an account — are reviewed by a member of our compliance team. You may ask for human review of an automated outcome, and may contest it, by contacting [email protected], except where telling you would breach our legal obligations.

Section 16

Cookies

Our use of cookies, local storage and similar technologies is described in the Cookie Policy.

Section 17

Changes to this policy

We may update this policy. The "Last updated" date shows when the current version took effect. Where a change materially affects how we use your information, we will notify you by email or through the application before it takes effect.

Section 18

How to contact us

Privacy enquiries[email protected]
General support[email protected]
Telephone+1 206 235 4353
PostDIRE MONEY TRANSMITTER LLC, 9000 Renton Ave S Unit 1, Seattle, WA 98118-5059, United States