Privacy Policy
This Privacy Policy explains what personal information DIRE MONEY TRANSMITTER LLC, trading as DireBit, collects about you, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to direbbit.com, to the DireBit mobile applications, and to all related services. DireBit is a United States business and offers its services only in the United States; this policy is written to United States federal and state law.
Contents
- Who is responsible for your data
- Information we collect
- Where we get it from
- How and why we use it
- Our legal grounds
- Who we share it with
- We do not sell your data
- Where we process your information
- How long we keep it
- How we protect it
- Your rights and choices
- U.S. state privacy rights
- Financial privacy (Gramm-Leach-Bliley)
- Children
- Automated decision-making
- Cookies
- Changes to this policy
- How to contact us
Section 1
Who is responsible for your data
The business responsible for your personal information is DIRE MONEY TRANSMITTER LLC, 9000 Renton Ave S Unit 1, Seattle, WA 98118-5059, United States, trading as DireBit.
For any privacy question, or to exercise a right described in this policy, contact [email protected], write to us at the address above, or call +1 206 235 4353.
Section 2
Information we collect
We collect the categories of personal information set out below. Much of it we are legally required to collect, because we are a money services business registered with FinCEN and licensed as a money transmitter. If you do not provide it, we cannot open or maintain your account.
| Category | Examples | Required? |
|---|---|---|
| Identity | Full legal name, date of birth, nationality, gender where shown on an identity document, government identification number (such as a Social Security number, passport number or driver's license number) | Required by law |
| Identity documents | Images of a passport, driver's license or national identity card; a selfie or short video used to confirm the document belongs to you; the biometric template derived from that comparison | Required by law |
| Contact | Residential address, postal address, email address, telephone number | Required by law |
| Financial | Bank account and payment card details, blockchain wallet addresses, account balances, transaction history, source of funds and source of wealth information | Required by law |
| Business customers | Formation documents, ownership structure, and identity information for beneficial owners and controlling persons | Required by law |
| Device and technical | IP address, device identifiers, device model and operating system, browser type, language, application version, crash diagnostics | Collected automatically |
| Usage | Pages and screens viewed, features used, watchlists, settings, session times, referring page | Collected automatically |
| Location | Country and region inferred from IP address, used to confirm eligibility and to meet sanctions obligations | Required by law |
| Communications | Support tickets, emails, chat messages, and call recordings where we tell you a call is recorded | Collected when you contact us |
| Compliance | Sanctions, politically-exposed-person and adverse-media screening results, risk ratings, transaction monitoring alerts, and records of any report we are required to file | Required by law |
Identity document images and the facial comparison used to verify them may constitute biometric information under laws such as the Washington My Health My Data Act and comparable state statutes. We use this information only to verify that you are who you say you are, to prevent fraud, and to meet our legal obligations. We do not use it for advertising, and we do not sell it.
Section 3
Where we get it from
- From you — when you register, verify your identity, transact, change settings or contact support.
- Automatically — from your device and your use of the website and applications, as described in our Cookie Policy.
- From identity verification and screening providers — document authentication results, sanctions and watchlist matches, politically-exposed-person status and adverse media.
- From banking and payment partners — to confirm account ownership and settle transfers.
- From public sources — company registries, public blockchain records and blockchain analytics providers. Note that blockchain transactions are public by design and are not controlled by us.
- From law enforcement and regulators — where they contact us about you.
Section 4
How and why we use it
- To provide the Services — to open and operate your account, execute your instructions, hold your balances, and process deposits and withdrawals.
- To verify your identity — to run our Customer Identification Program and customer due diligence as required by the Bank Secrecy Act.
- To meet legal and regulatory obligations — including sanctions screening, transaction monitoring, recordkeeping, the Travel Rule, and filing Suspicious Activity Reports and Currency Transaction Reports with FinCEN.
- To prevent fraud and protect security — to detect unauthorized access, account takeover, and abuse of the Services.
- To provide support — to answer your questions and investigate complaints.
- To improve the Services — to understand which features are used, diagnose faults and improve reliability.
- To communicate with you — to send service messages, security alerts, and changes to terms. We send marketing only where you have opted in, and you can opt out at any time.
- To establish or defend legal claims — and to enforce our Terms of Service.
We are legally prohibited from telling you if we have filed a Suspicious Activity Report about your activity. Where that is the case, we cannot confirm or deny it, and certain of your access rights may be lawfully restricted.
Section 5
Why we are permitted to process it
We process personal information for these reasons, and for no others:
- To perform our agreement with you — to provide the Services you asked for under our Terms of Service.
- To comply with federal and state law — the Bank Secrecy Act and its implementing regulations, OFAC sanctions programs, the Internal Revenue Code, and the Washington Uniform Money Services Act. Where the law requires us to collect or keep something, we do not have discretion to omit it.
- To protect our customers and our systems — to prevent fraud and account takeover, to secure our infrastructure, and to establish or defend legal claims.
- With your consent — for optional marketing and for the non-essential storage described in our Cookie Policy. You may withdraw consent at any time.
Section 7
We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. We have not done so in the preceding twelve months. We do not use your identity documents, biometric information, financial information or transaction history for advertising.
Section 8
Where we process your information
DireBit is a United States business serving United States customers. Personal information is collected, stored and processed in the United States, and is subject to United States federal and state law.
A small number of our service providers — for example cloud hosting or identity verification vendors — may process information outside the United States on our behalf. Where that happens they act only on our documented instructions, under written contracts that require them to protect the information and to use it solely to provide their service to us. You may ask what those arrangements are by writing to [email protected].
Section 9
How long we keep it
We keep personal information only as long as necessary, and for the minimum periods the law requires of a money services business.
| Record | Retention period |
|---|---|
| Customer identification records | At least 5 years after the account is closed (Bank Secrecy Act) |
| Transaction records | At least 5 years from the date of the transaction |
| Suspicious Activity Report supporting documentation | At least 5 years from the date of filing |
| Currency Transaction Reports and Travel Rule records | At least 5 years |
| Support communications | Up to 5 years from last contact |
| Website and application technical logs | Up to 24 months |
| Marketing preferences | Until you withdraw consent, plus a suppression record kept indefinitely so we can honor your opt-out |
Where a longer period is required by a legal hold, an investigation or a court order, we retain the records for as long as that requirement lasts. After the applicable period, we delete or irreversibly anonymise the information.
Section 10
How we protect it
We maintain administrative, technical and physical safeguards designed to protect personal information against loss, misuse and unauthorized access. These include encryption of data in transit and at rest, role-based access control on a least-privilege basis, multi-factor authentication for staff, segregation of duties for asset movements, logging and monitoring, vendor due diligence, staff training, and an incident response plan.
No system is perfectly secure. You play an important part: use a strong unique password, enable two-factor authentication, keep your devices patched, and never share a verification code or recovery phrase. DireBit will never ask you for your password, your two-factor code or a wallet recovery phrase.
Where a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable breach-notification law.
Section 11
Your rights and choices
Subject to applicable law and to our legal retention obligations, you may ask us to:
- Access the personal information we hold about you, and receive a copy.
- Correct information that is inaccurate or incomplete.
- Delete information, where we are not required to keep it.
- Port information to another provider in a machine-readable format.
- Restrict or object to certain processing, including processing based on legitimate interests.
- Withdraw consent where processing is based on consent.
- Opt out of marketing at any time, using the unsubscribe link or by contacting us.
To exercise a right, email [email protected]. We will verify your identity before acting and respond within 45 days, extendable once by a further 45 days where the request is complex, as U.S. state privacy law allows. We will not discriminate against you for exercising a right. You may use an authorized agent where the law permits.
Anti-money-laundering law overrides the right to erasure. We cannot delete identity or transaction records we are required to retain, and we cannot disclose information that would tip you off about a regulatory report.
Section 12
U.S. state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Washington and other states with comprehensive privacy laws have the rights described in section 11, including the right to know, to delete, to correct, to obtain a portable copy, and to opt out of sale, targeted advertising and certain profiling. As stated in section 7, we do not sell personal information and do not engage in cross-context behavioral advertising.
Washington residents have additional rights under the My Health My Data Act regarding consumer health data. We do not collect consumer health data, other than where a biometric identifier used for identity verification falls within that definition; we process it only for verification and fraud prevention, and you may withdraw consent and request deletion by contacting [email protected], subject to our legal retention duties.
If we deny your request, you may appeal by replying to our decision with the word "Appeal". If we deny the appeal, you may complain to your state attorney general.
Section 13
Financial privacy (Gramm-Leach-Bliley)
As a money services business we are a financial institution for the purposes of the federal Gramm-Leach-Bliley Act, and the nonpublic personal information you give us is protected by it as well as by the state laws described above.
We do not sell your nonpublic personal information, and we do not disclose it to nonaffiliated third parties for their own marketing. We disclose it only as the law permits — to process the transactions you ask for, to service providers acting on our behalf under contract, to comply with legal and regulatory obligations including Bank Secrecy Act reporting, and in response to lawful requests from regulators, law enforcement or courts.
We provide our financial privacy notice when you open an account and thereafter as required by law. You may request a copy at any time from [email protected].
Section 14
Children
The Services are for adults. We do not knowingly collect personal information from anyone under 18, and account opening requires verified proof of age. If we learn that we hold information about a minor, we will close the account and delete the information except where we are required to retain it. If you believe a minor has given us information, contact [email protected].
Section 15
Automated decision-making
We use automated tools to screen customers against sanctions lists, to score risk and to flag unusual transactions. An automated flag may cause a delay, an additional information request, or a restriction on your account. Material decisions — such as declining an application or closing an account — are reviewed by a member of our compliance team. You may ask for human review of an automated outcome, and may contest it, by contacting [email protected], except where telling you would breach our legal obligations.
Section 16
Cookies
Our use of cookies, local storage and similar technologies is described in the Cookie Policy.
Section 17
Changes to this policy
We may update this policy. The "Last updated" date shows when the current version took effect. Where a change materially affects how we use your information, we will notify you by email or through the application before it takes effect.
Section 18
How to contact us
| Privacy enquiries | [email protected] |
| General support | [email protected] |
| Telephone | +1 206 235 4353 |
| Post | DIRE MONEY TRANSMITTER LLC, 9000 Renton Ave S Unit 1, Seattle, WA 98118-5059, United States |