Cookies & Privacy Policy
Last updated: July 7, 2026

1. Scope of this Cookies & Privacy Policy and Who We Are
ADVANCED PAYMENT SOLUTIONS CANADA INC. (“APS”, “Company”, “we”, “us”, “our”, “We”, “Us” or “Our”) respects the privacy of individuals who access or use our web-based on-ramp and off-ramp interface available at https://web3.aps.money/ramp, including any webpages, widget, account, onboarding, identity verification, payment, transaction, support, notification, analytics, security, fraud prevention and related functionalities made available through or in connection with it (the “Widget”).
APS is a company incorporated in Canada with incorporation number BC 1356972, having its registered office at Unit 1, 442 2nd Avenue, Fernie, BC V0B 1M0, Canada. You may contact us at: contacts@cad.aps.money.
This Cookies & Privacy Policy (the “Privacy Notice”) explains what personal information we may collect from individuals who visit, access, use, register for, interact with or submit information through the Widget (“you”, “You”, “your” or “Your”), how we may use, disclose, retain and protect that information, and how you may exercise your privacy rights, including rights to request access to or correction of your personal information.
This Privacy Notice applies to personal information collected, used or disclosed by APS through or in connection with the Widget and the related on-ramp and off-ramp services, including personal information processed in connection with account or user profile creation, onboarding, identity verification, KYC checks, sanctions, anti-money laundering and fraud prevention screening, payment initiation, transaction processing, wallet address submission, transaction status updates, customer support, notifications, cookies and similar technologies, analytics, session monitoring, security, troubleshooting and your other interactions with the Widget.
The Widget may include or interact with services, systems, forms, interfaces or infrastructure provided by third-party service providers, including identity verification providers, payment processing providers, fraud prevention and compliance providers, support providers, analytics or session monitoring providers, notification providers, authentication providers, hosting providers and other technology providers. Where these providers process personal information on behalf of APS, APS remains responsible for personal information under its control in accordance with applicable Canadian privacy laws. Some third-party providers may also process certain personal information as independent organizations for their own legal, compliance, security, fraud prevention or operational purposes, as described in their own privacy notices or terms.
This Privacy Notice does not apply to the APS marketing website available at https://aps.exchange/ or any other separate website, product, service, platform, application or portal that is governed by its own privacy notice, terms and conditions or other applicable documents. If you access the Widget from another APS website, this Privacy Notice applies only to personal information collected, used or disclosed through or in connection with the Widget and the related on-ramp and off-ramp services.
This Privacy Notice also does not apply to third-party websites, services or platforms that are not operated or controlled by APS, except to the extent that APS collects, uses or discloses personal information through or in connection with those third-party services as part of the Widget or the related on-ramp and off-ramp services. We encourage you to review the privacy notices of any third-party websites, services or platforms before providing personal information to them.
For the purposes of applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act and the British Columbia Personal Information Protection Act, APS is responsible for personal information under its control in connection with the Widget and the related on-ramp and off-ramp services.

2. Personal Information We Collect and Purposes for Collection
This section explains the categories of personal information that we, the Widget, and our service providers may collect through or in connection with the Widget and the related on-ramp and off-ramp services, how that information may be collected, and the purposes for which it may be used or disclosed.
The personal information we collect depends on how you access and use the Widget, whether you create or use an account or user profile, whether you complete identity verification, whether you initiate an on-ramp or off-ramp transaction, the payment method you use, and the legal, regulatory, compliance, security and fraud prevention requirements applicable to the relevant transaction.

Personal Information You Provide to Us
We may collect personal information that you provide directly through or in connection with the Widget, including when you access the Widget, create or use user profile, complete onboarding, initiate identity verification, submit information for KYC, sanctions, anti-money laundering or fraud prevention checks, initiate or receive an on-ramp or off-ramp transaction, provide wallet or payment-related information, communicate with us, request support, or otherwise interact with the Widget.

This personal information may include:
  • your full name;
  • your date of birth;
  • your residential address;
  • your nationality;
  • your phone number;
  • your email address;
  • user profile;
  • information contained in government-issued identification documents;
  • selfie, liveness verification and biometric-related verification data, where required for identity verification;
  • wallet addresses and blockchain network information;
  • transaction amount, transaction currency and transaction direction;
  • information about the digital asset, fiat currency, payment method or payment route selected by you;
  • billing, payment-related and transaction-related information;
  • payment method information;
  • bank card-related payment data, where applicable;
  • transaction identifiers, transaction references, transaction statuses and timestamps;
  • support requests, messages, communications and related records.

KYC, Identity Verification and Compliance Information
The Widget may require you to complete identity verification, KYC, sanctions, anti-money laundering, fraud prevention and related compliance checks before you may access or use certain services or complete certain transactions.

For these purposes, we and our identity verification, compliance and fraud prevention service providers may collect or process personal information including:
  • full name;
  • date of birth;
  • residential address;
  • nationality;
  • phone number;
  • email address;
  • government-issued identification documents;
  • document images and extracted document data;
  • selfie and liveness verification data;
  • KYC verification status;
  • verification results;
  • screening results;
  • risk, fraud prevention and compliance-related information;
  • metadata relating to the verification process;
  • records required for legal, regulatory, audit, security, fraud prevention, sanctions, anti-money laundering, counter-terrorist financing, dispute resolution and record-keeping purposes.
Identity verification is performed through a third-party KYC provider, currently SumSub. Identification documents, selfie/liveness verification data and verification artifacts are submitted to and processed by SumSub for verification purposes. KYC documents and verification artifacts are primarily stored within SumSub infrastructure. Selected user-related KYC information, verification results, verification statuses and related metadata may also be returned to APS and stored in our internal systems, including PostgreSQL databases hosted within AWS infrastructure.
Payment and Transaction Information
When you initiate or complete an on-ramp or off-ramp transaction through the Widget, we, the Widget and our payment processing, compliance, fraud prevention and technology service providers may collect or process payment-related and transaction-related personal information.

Depending on the transaction type, payment method and payment flow, this information may include:
  • full name;
  • email address;
  • phone number;
  • wallet address;
  • blockchain network information;
  • transaction amount and currency;
  • selected payment method;
  • payment route or payment provider information;
  • billing and payment-related information;
  • bank card-related payment data, where applicable;
  • transaction identifiers, references and statuses;
  • transaction timestamps;
  • payment authorization or processing status;
  • fraud, risk, compliance and transaction monitoring metadata;
  • user/account references; and
  • other information reasonably necessary to initiate, process, monitor, complete, review, reverse, refund, investigate or record the relevant transaction.
Where payment card information is required, it is entered into PCI-compliant payment forms handled by payment-processing infrastructure. Sensitive card data are transmitted directly to the relevant payment-processing systems and are not stored by the Web3 platform. APS may receive and store transaction-related metadata, including transaction identifiers, statuses, amounts, currencies, wallet addresses, timestamps and related payment, compliance, risk or fraud prevention metadata.

Technical, Device, Usage and Online Information
When you access or interact with the Widget, we and our service providers may automatically collect technical, device, usage, session and online information, including through cookies, server logs, SDKs, pixels, tags, local storage, session monitoring technologies and similar tools.

This information may include:
  • Internet Protocol (IP) address;
  • device identifiers;
  • browser type and browser version;
  • device type and operating system;
  • language and system settings;
  • referring page or URL and exit page;
  • pages, screens, buttons, forms or features viewed or used within the Widget;
  • date and time of access;
  • session duration;
  • clickstream, interaction and usage data;
  • cookie identifiers and similar online identifiers;
  • authentication/session information;
  • approximate location derived from IP address;
  • diagnostics, error logs and performance information;
  • security, fraud prevention and risk-related metadata;
  • analytics and session monitoring information; and
  • other technical, diagnostic and usage information relating to your interaction with the Widget.
Cookies and similar technologies may be used for authentication, session management, security, fraud prevention, analytics, performance monitoring, customer support functionality, user notifications and related purposes. Further information about our use of cookies and similar technologies is provided in the “Cookies and Similar Technologies” section of this Privacy Notice.

Information from Service Providers and Other Third Parties
We may receive personal information, technical information, verification results, transaction information, risk information, support information or related metadata from service providers and other third parties that support, enable or interact with the Widget and the related on-ramp and off-ramp services.

These service providers and third parties may include:
  • identity verification and KYC providers, including SumSub;
  • payment processing providers and PCI DSS payment infrastructure providers;
  • fraud prevention, risk monitoring, sanctions, anti-money laundering and compliance service providers;
  • hosting, infrastructure, database and cloud service providers, including AWS infrastructure;
  • analytics and session monitoring providers, including Smartlook;
  • customer support providers, including Freshdesk;
  • notification service providers, including OneSignal;
  • authentication providers, including Google authentication services;
  • other technology, operational, compliance, security, analytics, support or business service providers.
For example, SumSub may provide APS with KYC verification results, verification statuses and selected metadata. Payment processing providers may provide APS with transaction results, payment status information and related transaction metadata. Fraud, compliance or analytics providers may provide APS with risk, security, usage, diagnostic or monitoring information. Support providers may process support requests and related communications.

Purposes for Which We Collect, Use or Disclose Personal Information
We collect, use and disclose personal information through or in connection with the Widget for the following purposes:
  • to provide, operate, maintain, administer and improve the Widget and the related on-ramp and off-ramp services;
  • to create, manage, authenticate and secure user accounts, profiles, sessions and access to the Widget;
  • to verify your identity and conduct KYC, sanctions, anti-money laundering, counter-terrorist financing, fraud prevention, risk management and related compliance checks;
  • to determine whether you are eligible to access or use the Widget or any particular service, payment method, transaction type, jurisdiction or feature;
  • to initiate, process, authorize, complete, monitor, record, reconcile, review, reverse, refund or otherwise administer on-ramp and off-ramp transactions;
  • to process wallet addresses, blockchain network information, transaction amounts, currencies, payment methods, transaction statuses and related transaction information;
  • to communicate with you regarding your account, verification, transactions, support requests, service updates, security alerts, notices and other operational matters;
  • to provide customer support, investigate issues and respond to inquiries, complaints or requests;
  • to detect, prevent, investigate and respond to fraud, misuse, unauthorized activity, suspicious transactions, prohibited activity, security incidents, technical issues or unlawful conduct;
  • to monitor, test, troubleshoot, secure, maintain and improve the performance, functionality, reliability and user experience of the Widget;
  • to conduct analytics, diagnostics, session monitoring and performance measurement, where applicable and subject to your cookie choices where required;
  • to send or manage notifications, authentication messages, service communications and other operational messages;
  • to maintain internal records, transaction records, verification records, compliance records, audit logs, business records and support records;
  • to comply with applicable legal, regulatory, licensing, sanctions, anti-money laundering, counter-terrorist financing, tax, accounting, audit, court, law enforcement, governmental, regulatory and record-keeping obligations;
  • to respond to lawful requests from regulators, law enforcement agencies, courts, governmental authorities, financial institutions, payment providers, blockchain analytics providers, compliance counterparties or other competent authorities, where permitted or required by applicable law;
  • to protect, manage and enforce our legal, regulatory, contractual, commercial and business interests, including for legal claims, dispute resolution, investigations, risk management, insurance, audit, accounting, compliance and professional advisory purposes;
  • to enforce our terms, policies, agreements and service requirements;
  • to allow our service providers to provide services to us or to you in connection with the Widget and the related on-ramp and off-ramp services; and
  • for any other purpose that we identify to you at or before the time of collection, or for which we otherwise obtain your consent, unless the collection, use or disclosure is permitted or required by applicable law.

How We Collect Personal Information
We may collect personal information:
  • directly from you, when you submit information through the Widget, create or use an account or user profile, complete onboarding, complete identity verification, initiate a transaction, provide wallet or payment-related information, request support or otherwise communicate with us;
  • automatically, when you access, use or interact with the Widget;
  • through cookies, server logs, SDKs, pixels, tags, local storage, session monitoring technologies and similar technologies, subject to your cookie settings where applicable;
  • from identity verification, KYC, fraud prevention, sanctions, anti-money laundering, compliance, payment processing, authentication, analytics, notification, support, hosting, infrastructure and other service providers;
  • from payment processors, payment infrastructure providers, financial institutions, blockchain-related service providers or other transaction participants involved in processing, monitoring, completing, reviewing, reversing, refunding or investigating a transaction;
  • from our internal systems, databases, logs, compliance tools, support tools and transaction monitoring systems; and
  • from other third parties where you have directed them to provide information to us, where they are involved in providing the Widget or the related on-ramp and off-ramp services, or where collection is otherwise permitted or required by applicable law.

Sensitive Information and Information You Should Not Provide
Because the Widget is used for regulated on-ramp and off-ramp services, we may be required to collect sensitive personal information, including identity verification information, government-issued identification documents, selfie/liveness verification information, wallet addresses, payment-related information, transaction information and compliance-related information.
You should provide sensitive personal information only through the secure flows, forms, interfaces or service provider tools made available through the Widget for that purpose. You should not send passport details, identity documents, payment card details, bank account credentials, private keys, wallet seed phrases, passwords, health information or other sensitive information by email, chat, support message or any other unsecured channel unless we specifically request it through an appropriate secure channel.
APS will not ask you to provide your private keys, wallet seed phrases or wallet recovery phrases.

3. How We Use Your Personal Information
APS uses personal information collected through or in connection with the Widget only for the purposes identified in this Privacy Notice, for purposes identified to you at or before the time of collection, with your consent where required, or as otherwise permitted or required by applicable law.

We may use personal your personal information for the following purposes:
  • to provide, operate, maintain, administer and improve the Widget and the related on-ramp and off-ramp services;
  • to create, manage, authenticate, secure and support your account, user profile, session and access to the Widget;
  • to verify your identity and conduct onboarding, KYC, sanctions, anti-money laundering, counter-terrorist financing, fraud prevention, risk management and related compliance checks;
  • to determine whether you are eligible to access or use the Widget, any particular service, transaction type, payment method, feature or jurisdiction;
  • to process, review and maintain information submitted for identity verification, including government-issued identification documents, selfie/liveness verification data, verification results, verification statuses and related metadata;
  • to initiate, process, authorize, complete, monitor, reconcile, record, review, reverse, refund, investigate or otherwise administer on-ramp and off-ramp transactions;
  • to process wallet addresses, blockchain network information, transaction amounts, currencies, payment methods, transaction identifiers, transaction statuses, timestamps and related transaction information;
  • to receive, process and store transaction-related metadata, including transaction identifiers, transaction statuses, amounts, currencies, wallet addresses, timestamps and related payment, compliance, risk or fraud prevention metadata;
  • to communicate with you about your onboarding, identity verification, transactions, payment status, service updates, support requests, security alerts, operational notices and other matters relating to the Widget or the related on-ramp and off-ramp services;
  • to provide customer support, investigate issues, respond to inquiries, complaints or requests, and maintain support records;
  • to send, manage or deliver authentication messages, notifications, service communications and other operational messages;
  • to detect, prevent, investigate and respond to fraud, misuse, unauthorized access, unauthorized transactions, suspicious transactions, prohibited activity, security incidents, technical issues, errors or unlawful conduct;
  • to monitor, test, troubleshoot, secure, maintain and improve the performance, functionality, reliability, security and user experience of the Widget;
  • to conduct analytics, diagnostics, session monitoring, error monitoring and performance measurement, where applicable and subject to your cookie choices where required;
  • to maintain internal records, transaction records, verification records, compliance records, risk records, audit logs, business records, database records and support records;
  • to comply with applicable legal, regulatory, licensing, sanctions, anti-money laundering, counter-terrorist financing, tax, accounting, audit, court, law enforcement, governmental, regulatory and record-keeping obligations;
  • to respond to lawful requests from regulators, law enforcement agencies, courts, governmental authorities, financial institutions, payment providers, compliance counterparties or other competent authorities, where permitted or required by applicable law;
  • to protect, manage and enforce our legal, regulatory, contractual, commercial and business interests, including for legal claims, dispute resolution, investigations, risk management, insurance, audit, accounting, compliance and professional advisory purposes;
  • to enforce our terms, policies, agreements, service requirements and acceptable use restrictions;
  • to prevent misuse of the Widget, including prohibited transactions, prohibited jurisdictions, sanctions violations, fraud, money laundering, terrorist financing, unauthorized access, abuse of promotions or limits, and other unlawful or unauthorized activity;
  • to allow our service providers to provide services to APS or to you in connection with the Widget and the related on-ramp and off-ramp services, including identity verification, payment processing, compliance, fraud prevention, hosting, infrastructure, analytics, session monitoring, support, notifications, authentication and security services;
  • for any other purpose that we identify to you at or before the time of collection, or for which we otherwise obtain your consent, unless the use is permitted or required by applicable law.

Where payment card information is required, it is entered into PCI-compliant payment forms handled by payment-processing infrastructure. Sensitive card data are transmitted directly to the relevant payment-processing systems and are not stored by the Widget. APS may use transaction-related metadata returned by payment processing providers for transaction processing, reconciliation, fraud prevention, compliance, support, audit, dispute resolution and record-keeping purposes.

4. Disclosure of Your Personal Information
APS does not sell personal information collected through or in connection with the Widget. We disclose or make available personal information collected through or in connection with the Widget only for the purposes identified in this Privacy Notice, with your consent where required, or as otherwise permitted or required by applicable law.
We may disclose or make available personal information collected through or in connection with the Widget to the following categories of recipients.

Service Providers
We use third-party service providers to help us provide, operate, maintain, secure, monitor, support and improve the Widget and the related on-ramp and off-ramp services.

These service providers may include:
  • identity verification and KYC providers, including SumSub;
  • payment processing providers, payment infrastructure providers, PCI DSS payment infrastructure providers, acquiring banks, card processors, payment gateways, financial institutions and other payment-related service providers;
  • fraud prevention, risk monitoring, sanctions screening, anti-money laundering, counter-terrorist financing, transaction monitoring and compliance service providers;
  • hosting, cloud infrastructure, database, backend, DevOps, security and technology infrastructure providers, including AWS infrastructure;
  • analytics, diagnostics, session monitoring, performance monitoring and error monitoring providers, including Smartlook;
  • customer support and ticketing providers, including Freshdesk;
  • notification and messaging providers, including OneSignal;
  • authentication and login providers, including Google authentication services where applicable;
  • communications, email, SMS, operational messaging and similar service providers;
  • other technology, operational, security, compliance, analytics, support, professional or business service providers that support the Widget, the related on-ramp and off-ramp services or APS’s internal systems.

These service providers may access, collect, store, process, transmit or receive personal information on our behalf or in connection with the services they provide, including to:
  • verify your identity;
  • conduct KYC, sanctions, anti-money laundering, counter-terrorist financing, fraud prevention, risk management and related compliance checks;
  • process, authorize, complete, monitor, review, reverse, refund, investigate or record transactions;
  • operate, host, maintain, secure and administer the Widget and related systems;
  • store transaction, verification, user, account, support, technical and compliance records;
  • provide analytics, diagnostics, session monitoring, performance monitoring, error monitoring, customer support, notifications, authentication and security services; and
  • assist APS in providing, securing, monitoring, supporting and improving the Widget and the related on-ramp and off-ramp services.

KYC, Identity Verification and Compliance Providers
We may disclose or make available personal information to identity verification, KYC, sanctions, anti-money laundering, fraud prevention, risk management and compliance providers, including SumSub.
Information disclosed or made available for these purposes may include your name, date of birth, residential address, nationality, phone number, email address, government-issued identification documents, selfie/liveness verification data, verification metadata, verification results, risk information, screening results, device/session metadata and other information required to complete identity verification and compliance checks.
SumSub and other compliance providers may process and store identification documents, verification artifacts, verification results and related metadata in their own systems. APS may receive verification results, statuses and selected metadata from these providers and may store selected KYC-related information and verification metadata in APS’s internal systems, including PostgreSQL databases hosted within AWS infrastructure.

Payment Processing Providers and Transaction Participants
We may disclose or make available personal information to payment processing providers, payment infrastructure providers, PCI DSS payment infrastructure providers, acquiring banks, card processors, payment gateways, financial institutions and other payment-related service providers involved in initiating, authorizing, processing, completing, monitoring, reviewing, reversing, refunding, investigating or recording on-ramp or off-ramp transactions.
Information disclosed or made available for these purposes may include your name, email address, phone number, selected payment method, billing or payment-related information, transaction amount, transaction currency, transaction identifiers, transaction references, transaction status, timestamps, wallet address, blockchain network information, fraud/risk metadata, compliance metadata and other information reasonably necessary for transaction processing, fraud prevention, compliance, reconciliation, support, audit and record-keeping purposes.
Where payment card information is required, it is entered into PCI-compliant payment forms handled by payment-processing infrastructure. Sensitive card data are transmitted directly to the relevant payment-processing systems and are not stored by the Web3 platform. APS may receive and store transaction-related metadata, including transaction identifiers, statuses, amounts, currencies, wallet addresses, timestamps and related payment, compliance, risk or fraud prevention metadata.

Blockchain Networks and Digital Asset Transaction Processing
Where you initiate or receive a digital asset transaction through or in connection with the Widget, wallet addresses, blockchain network information, transaction amounts, transaction identifiers and other transaction-related information may be disclosed or made available to blockchain networks, wallet infrastructure providers, liquidity providers, transaction monitoring providers, compliance providers or other participants involved in initiating, processing, monitoring, completing, recording or reviewing the relevant transaction.
You should understand that certain blockchain transactions are recorded on public or publicly accessible blockchain networks. Information recorded on a blockchain may be publicly visible and may not be capable of being deleted, changed or removed by APS.

Fraud Prevention, Security and Risk Management
We may disclose or make available personal information to fraud prevention, risk management, security, transaction monitoring, sanctions, anti-money laundering, compliance and related service providers where reasonably necessary to detect, prevent, investigate or respond to fraud, misuse, unauthorized access, unauthorized transactions, suspicious activity, prohibited activity, sanctions violations, money laundering, terrorist financing, security incidents, technical issues or unlawful conduct.
Information disclosed or made available for these purposes may include identity information, account or user profile information, transaction information, wallet addresses, IP address, device/browser information, session metadata, fraud/risk metadata, verification status, payment status, usage information and related technical, compliance or security information.
Analytics, Session Monitoring, Support and Notifications
We may disclose or make available technical, usage, session, support and notification-related information to analytics, diagnostics, session monitoring, customer support, notification and authentication providers.
These providers may include Smartlook, Freshdesk, OneSignal and Google authentication services where applicable.
Information disclosed or made available for these purposes may include device and browser information, IP address, pages or screens viewed, clicks, navigation paths, session duration, error logs, performance information, support requests, notification tokens or identifiers, authentication-related information and other technical, diagnostic, usage or support information.


Where session monitoring or analytics tools are used, we seek to configure them so that sensitive identity verification information, payment card details, passwords, private keys, wallet seed phrases and similar sensitive information are not intentionally recorded.

APS Group, Affiliates and Internal Personnel
We may disclose or make available personal information to APS personnel, departments, group companies, affiliates, contractors, representatives and internal teams where reasonably necessary for the purposes described in this Privacy Notice.
Access is restricted based on role, business need and operational necessity. Any such disclosure or internal access will be limited to what is reasonably necessary for the relevant purpose.

Professional Advisers and Business Support Providers
We may disclose personal information to professional advisers and business support providers, including lawyers, auditors, accountants, consultants, insurers, compliance advisers, tax advisers, forensic specialists, cybersecurity advisers and other professional representatives, where reasonably necessary for the purposes described in this Privacy Notice.
These purposes may include legal, audit, accounting, tax, compliance, insurance, risk management, dispute resolution, cybersecurity, fraud prevention, professional advisory, regulatory, investigation or record-keeping purposes.

Legal, Regulatory and Compliance Disclosures
We may disclose personal information where we believe that disclosure is permitted or required by applicable law, regulation, legal process, court order, regulatory request, governmental request, law enforcement request, sanctions requirement, anti-money laundering requirement, counter-terrorist financing requirement, payment network rule, financial institution requirement or other lawful authority.

We may also disclose personal information where reasonably necessary to:
  • comply with legal, regulatory, licensing, sanctions, anti-money laundering, counter-terrorist financing, tax, accounting, audit or record-keeping obligations;
  • respond to lawful requests from public authorities, regulators, law enforcement agencies, courts, governmental authorities, financial institutions, payment providers, compliance counterparties or other competent authorities;
  • report, investigate or respond to suspected fraud, suspicious transactions, prohibited activity, unauthorized transactions, sanctions issues, money laundering, terrorist financing, security incidents or unlawful conduct;
  • protect the rights, property, security or interests of APS, the Widget, our systems, our users, our service providers, our counterparties or others;
  • detect, prevent, investigate or respond to fraud, misuse, unauthorized access, unauthorized activity, security incidents, technical issues or unlawful conduct;
  • enforce our legal rights, terms, policies, agreements, service requirements or acceptable use restrictions;
  • establish, exercise or defend legal claims.

Business Transactions
We may disclose personal information in connection with a proposed or completed business transaction involving APS, including a merger, acquisition, financing, reorganization, restructuring, sale of assets, transfer of business, due diligence process, insolvency process or similar transaction, but only where permitted by applicable law and subject to appropriate confidentiality and security safeguards.

With Your Consent or at Your Direction
We may disclose personal information to other third parties where you consent to the disclosure, direct us to make the disclosure, or where the disclosure is otherwise permitted or required by applicable law.
For example, we may disclose or make available information to a third party where you choose a particular payment method, initiate a transaction, use a third-party login method, contact support, connect a wallet, provide a wallet address, or otherwise direct us or the Widget to interact with a third-party service.

Third Parties Acting as Independent Organizations
Some third-party providers involved in the Widget or the related on-ramp and off-ramp services may process certain personal information as independent organizations and not solely as service providers acting on behalf of APS. This may include, depending on the circumstances, identity verification providers, payment processors, acquiring banks, card processors, financial institutions, fraud prevention providers, compliance providers, authentication providers, blockchain network participants and other regulated or technology service providers.

These third parties may process personal information for their own legal, regulatory, compliance, security, fraud prevention, audit, risk management, operational or service-related purposes, as described in their own privacy notices, terms or policies.

Transfers Outside British Columbia or Canada
Some of our service providers and other third parties, including identity verification providers, payment processing providers, compliance providers, hosting and cloud infrastructure providers, analytics and session monitoring providers, support providers, notification providers, authentication providers, security providers and technology providers, may process, store or access personal information outside British Columbia or outside Canada.
Where personal information is processed, stored or accessed outside your province or country, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement agencies, regulators, governmental authorities or other competent authorities.
APS remains responsible for personal information under its control and uses contractual, organizational, technical and administrative measures designed to protect personal information handled by service providers on our behalf.

5. Cookies and Similar Technologies

What are cookies and similar technologies?
We and our service providers may use cookies and similar technologies in connection with the Widget. These technologies may include cookies, pixels, tags, scripts, SDKs, local storage, session identifiers, device identifiers, server logs, analytics tools, session monitoring tools and similar technologies.

A cookie is a small text file stored on your browser or device when you visit or use a website or online service. Cookies and similar technologies may help the Widget recognize your browser or device, maintain your session, support security, remember your preferences, process the transaction flow, understand how the Widget is used and diagnose technical issues.

We may use cookies and similar technologies for the following purposes:
  • to operate, provide and maintain the Widget and the related on-ramp and off-ramp services;
  • to authenticate users and maintain secure sessions;
  • to remember settings, choices and cookie preferences;
  • to support onboarding, identity verification, KYC, payment flow, transaction flow and transaction status updates;
  • to protect the Widget, users, transactions and systems against fraud, misuse, unauthorized access, suspicious activity, security incidents and technical issues;
  • to monitor, maintain, troubleshoot and improve the performance, functionality, reliability and security of the Widget;
  • to provide analytics, diagnostics, performance measurement, error monitoring and session monitoring;
  • to provide customer support functionality, notifications, authentication services and operational communications; and
  • to comply with legal, regulatory, security, fraud prevention, sanctions, anti-money laundering, audit, record-keeping and compliance requirements.
We may use the following categories of cookies and similar technologies:

Strictly necessary cookies and technologies. These are required for the Widget to function properly. They may be used for authentication, session management, security, fraud prevention, transaction flow, payment flow, remembering privacy or cookie preferences, and other core functionality. These technologies cannot be disabled through our cookie settings tool. If you block them through your browser settings, the Widget or certain features may not function properly.

Functional cookies and technologies. These help us remember your choices and provide enhanced functionality, such as language settings, interface preferences, account or session-related settings and other user experience features.

Analytics and performance technologies. Where enabled, we may use analytics and performance tools, including Google Analytics, to understand how users access and interact with the Widget, measure usage and performance, identify technical issues, improve the functionality and user experience of the Widget, and generate aggregated or statistical reports. These tools may collect information such as IP address, device and browser information, approximate location, pages or screens viewed, events and interactions, session statistics, referring pages, traffic sources, cookie identifiers and similar online identifiers.

Session monitoring technologies. Where enabled, we may use session monitoring tools, such as Smartlook, to help us understand how users interact with the Widget, identify usability issues, diagnose errors and improve performance. These tools may collect information such as pages or screens viewed, clicks, scrolling, navigation paths, session duration, device/browser information and error information. We do not intentionally use session monitoring tools to record sensitive identity verification information, payment card details, passwords, private keys, wallet seed phrases, wallet recovery phrases or similar sensitive information. Where such tools are used, we seek to configure them so that sensitive fields, sensitive screens and sensitive user inputs are masked, excluded or not recorded.

Support, notification and authentication technologies. Where enabled, we may use cookies and similar technologies provided by customer support, notification and authentication service providers, including Freshdesk, OneSignal and Google authentication services. These technologies may be used to provide support functionality, manage support requests, enable service notifications, support authentication, maintain session security and provide operational communications relating to the Widget.

Where Google Analytics is enabled, Google may process information collected through Google Analytics in accordance with Google’s own terms and policies. Google Analytics may use cookies and similar technologies to distinguish users and sessions and to measure interactions with the Widget. We do not use Google Analytics to intentionally collect or send to Google Analytics your name, email address, government-issued identification documents, payment card details, bank account credentials, private keys, wallet seed phrases, wallet recovery phrases, passwords or other sensitive information.

The specific cookies and similar technologies used in connection with the Widget may vary depending on the relevant deployment, configuration, browser, device, jurisdiction and service functionality. Where available, further information about specific cookies or technologies, including provider, purpose and duration, will be provided in our cookie banner, cookie settings tool or cookie list.

You can delete all cookies that are already on your device by clearing the browsing history of your browser. This will remove all cookies from all websites you have visited. If You'd like to delete certain cookies or instruct your web browser to delete or refuse cookies, please visit the help pages of your web browser. Listed below are the links to the support documents on how to manage and delete cookies from the major web browsers. If you are using any other web browser, please visit your browser’s official support documents.

6. Consent and Withdrawal of Consent
APS may collect, use and disclose personal information through or in connection with the Widget with your consent, where consent is required by applicable law, or as otherwise permitted or required by applicable law.
Depending on the nature of the personal information, the purposes for which it is collected, used or disclosed, and the circumstances of the processing, your consent may be express, implied or deemed under applicable law.
By accessing or using the Widget, clicking “Continue” button on Welcome screen, completing onboarding or identity verification, submitting information for KYC, sanctions, anti-money laundering or fraud prevention checks, initiating an on-ramp or off-ramp transaction, providing wallet or payment-related information, or otherwise interacting with the Widget, you consent to APS collecting, using and disclosing your personal information for the purposes described in this Privacy Notice, where consent is required by applicable law.
Where the purpose for collecting, using or disclosing personal information is not obvious from the circumstances, or where required by applicable law, we will identify the relevant purpose and obtain your consent before collecting, using or disclosing your personal information for that purpose.
You may withdraw your consent at any time, subject to legal, regulatory or other lawful restrictions and reasonable notice. To withdraw your consent, or to ask questions about how your personal information is collected, used or disclosed, you may contact us at: contacts@cad.aps.money.
If you withdraw consent for APS to collect, use or disclose personal information that is necessary to provide, secure, verify, process or administer the Widget or the related on-ramp and off-ramp services, we may be unable to provide the Widget or certain services to you, complete identity verification, process transactions, provide support, provide on-ramp or off-ramp services or continue related communications.
If you withdraw or change your consent for non-essential cookies, analytics, session monitoring or similar technologies, certain analytics, performance, support, notification, personalization or enhanced functionality may be limited or disabled. This will not affect cookies or technologies that are strictly necessary for the operation, security, fraud prevention, authentication, transaction flow, payment flow or basic functionality of the Widget.
If you withdraw consent, APS will stop collecting, using or disclosing the relevant personal information, unless continued collection, use or disclosure is permitted without consent under applicable privacy law, including the British Columbia Personal Information Protection Act, or is required to comply with applicable legal or regulatory obligations. You may not be able to withdraw consent where doing so would frustrate the performance of a legal obligation.
If you withdraw consent, we will stop collecting, using or disclosing the relevant personal information, unless continued collection, use or disclosure is permitted or required by applicable law.
7. Retention, Storage and Protection of Personal Information
APS retains personal information collected through or in connection with the Widget only for as long as reasonably necessary to fulfil the purposes for which the information was collected, used or disclosed, or for such longer period as may be permitted or required by applicable law.
Because the Widget is used for regulated on-ramp and off-ramp services, APS may retain personal information for legal, regulatory, sanctions, anti-money laundering, counter-terrorist financing, fraud prevention, security, audit, accounting, tax, transaction processing, dispute resolution, investigation, support, compliance and record-keeping purposes.
For example, we may retain account or user profile information, KYC and identity verification information, verification results and statuses, wallet addresses, transaction identifiers, transaction amounts and currencies, transaction statuses, timestamps, payment-related metadata, fraud/risk metadata, compliance records, support records, technical logs and related business records for as long as reasonably necessary for the purposes described in this Privacy Notice or as otherwise permitted or required by applicable law.
Where personal information is used to make a decision that directly affects you, APS may retain that information for the period required under applicable privacy law so that you have a reasonable opportunity to request access to it.
Technical, usage, cookie, analytics, session monitoring and similar information collected through or in connection with the Widget may be retained for the period described in the “Cookies and Similar Technologies” section, in our cookie banner, cookie settings tool or cookie list, where available, or for such other period as is reasonably necessary for security, fraud prevention, diagnostics, analytics, support, compliance, legal or business purposes.
When personal information is no longer required for the purposes for which it was collected, used or disclosed, and is no longer required or permitted to be retained for legal, regulatory, compliance, security, fraud prevention, dispute resolution, investigation, audit, accounting, tax, business or record-keeping purposes, APS will take reasonable steps to destroy, delete or de-identify the personal information, in accordance with applicable law and APS’s internal retention practices.

Storage of Personal Information
Personal information collected through or in connection with the Widget may be stored and processed in systems operated by APS or by our service providers and other third parties.
KYC documents, selfie/liveness verification data and verification artifacts are primarily stored within the infrastructure of our third-party KYC provider, currently SumSub. Selected user-related KYC information, verification results, verification statuses and related metadata may also be stored in APS’s internal systems.
Transaction-related data, including transaction identifiers, amounts, currencies, wallet addresses, statuses, timestamps, KYC/payment-related metadata and user/account references, may be stored in PostgreSQL databases hosted within AWS infrastructure.
Sensitive card data are transmitted directly to the relevant payment-processing systems and are not stored by us. APS may receive and store transaction-related metadata returned by payment processing providers, including transaction identifiers, statuses, amounts, currencies, wallet addresses, timestamps and related payment, compliance, risk or fraud prevention metadata.
Personal information may also be stored or processed by service providers that support the Widget, including identity verification providers, payment processing providers, fraud prevention and compliance providers, hosting and cloud infrastructure providers, analytics and session monitoring providers, customer support providers, notification providers, authentication providers, security providers and other technology or operational service providers.
Our systems and the systems of our service providers may be located in British Columbia, elsewhere in Canada, or in other jurisdictions. As a result, personal information may be processed, stored or accessed outside British Columbia or outside Canada. Where personal information is processed, stored or accessed outside your province or country, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement agencies, regulators, governmental authorities, national security authorities or other competent authorities.
APS remains responsible for personal information under its control and uses contractual, organizational, technical and administrative measures designed to protect personal information handled by service providers on our behalf.

Access to Personal Information
Access to personal information collected through or in connection with the Widget is restricted based on role, business need and operational necessity.
Depending on operational responsibilities, access may be limited to APS support personnel, APS affiliates, contractors, representatives and service providers who require access for the purposes described in this Privacy Notice or as otherwise permitted or required by applicable law.

Protection of Personal Information
APS uses reasonable security safeguards appropriate to the sensitivity of the personal information. These safeguards may include:
  • administrative measures, including internal policies, procedures, training, access management and compliance controls;
  • organizational measures, including limiting access to personal information on a need-to-know basis and restricting access according to role and business necessity;
  • technical measures, including authentication, access controls, logging, monitoring, encryption or other IT security controls where appropriate;
  • contractual measures with service providers that process personal information on our behalf.
Because the Widget may involve sensitive personal information, including identity verification information, government-issued identification documents, selfie/liveness verification data, wallet addresses, transaction information, payment-related metadata and fraud/compliance information, APS applies safeguards designed to reduce the risk of unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks.
Although APS takes reasonable steps to protect personal information, no website, widget, network, system, transmission or storage method is completely secure. We cannot guarantee the absolute security of personal information transmitted to, from or through the Widget.
If you believe that your interaction with us is no longer secure, or that personal information submitted through or in connection with the Widget may have been compromised, please contact us at: contacts@cad.aps.money.

8. Your Access and Correction Rights
Subject to applicable law and certain legal exceptions, you have the right to request access to personal information about you that is under APS’s control.

You may request that APS:
  • confirm whether we hold personal information about you;
  • provide you with access to personal information about you that is under our control;
  • provide information about how your personal information has been and is being used by APS;
  • provide the names of individuals and organizations to whom your personal information has been disclosed by APS, where required by applicable law.
Personal information that may be subject to an access request may include, depending on your use of the Widget, account or user profile information, KYC and identity verification information, verification results and statuses, transaction information, wallet addresses, transaction identifiers, amounts, currencies, timestamps, payment-related metadata, fraud/risk metadata, support records, technical logs and other personal information processed through or in connection with the Widget.
You may also request that APS correct personal information about you if you believe that it is inaccurate or incomplete.
To make an access or correction request, please contact us at:
ADVANCED PAYMENT SOLUTIONS CANADA INC.
Unit 1, 442 2nd Avenue, Fernie, BC V0B 1M0, Canada
Email: contacts@cad.aps.money
Your request must be made in writing and should provide sufficient detail to allow us to identify you, understand the personal information or correction to which your request relates, and process your request. We may ask you to provide additional information to verify your identity before responding to an access or correction request.
APS will respond to access and correction requests within 30 days after receiving the request.
Where permitted by applicable law, we may extend the time for responding to a request, for example where additional time is required to locate records, review a large volume of information, verify your identity, or consult with a service provider, another organization or a public body before responding.
If we provide access to personal information, we will provide the information in a form that is generally understandable, where reasonably possible.
If APS is satisfied on reasonable grounds that personal information under its control is inaccurate or incomplete, APS will correct the information as soon as reasonably possible. Where required by applicable law, APS may also send the corrected personal information to each organization to which the information was disclosed during the period required by applicable law.
If APS does not make a requested correction, we may annotate the relevant record to indicate that a correction was requested but not made, where required by applicable law.
Certain information may not be capable of being deleted, changed or removed by APS in the ordinary course. For example, certain blockchain transaction information may be recorded on public or publicly accessible blockchain networks and may not be capable of being deleted, changed or removed by APS.
This does not limit your right to request correction of inaccurate or incomplete personal information that is under APS’s control. If APS is satisfied on reasonable grounds that personal information under its control is inaccurate or incomplete, APS will correct it as soon as reasonably possible. If APS does not make a requested correction, APS may annotate the relevant record to indicate that a correction was requested but not made, where required by applicable law.
APS may also be required or permitted to retain certain KYC, transaction, payment, fraud prevention, compliance, audit, legal, regulatory, dispute resolution or record-keeping information for legal, regulatory, business or compliance purposes.
APS may refuse access to all or part of your personal information where permitted or required by applicable law. For example, access may be refused where disclosure would reveal personal information about another individual, reveal confidential commercial information, compromise an investigation, threaten the safety or health of another individual, or disclose information protected by solicitor-client privilege, litigation privilege or other legal restrictions.
If we refuse your access or correction request, in whole or in part, we will inform you of the reasons for the refusal where required by applicable law and explain any further steps available to you.
Some personal information may be held or processed by third-party service providers or other organizations, including identity verification providers, payment processing providers, financial institutions, blockchain network participants, fraud prevention providers, support providers, analytics providers or authentication providers. Where personal information is under APS’s control, APS will handle access and correction requests in accordance with applicable law. Where a third party processes personal information as an independent organization, you may also need to contact that third party directly to exercise any rights available under its privacy notice or applicable law.

9. Accuracy
APS takes reasonable steps to ensure that personal information collected through or in connection with the Widget is accurate, complete and up to date to the extent necessary for the purposes for which it is collected, used or disclosed.
Because the Widget may be used for identity verification, KYC, sanctions, anti-money laundering, fraud prevention, payment processing and on-ramp or off-ramp transactions, it is important that the information you provide is accurate, complete and current.
We rely on you to provide accurate, complete and up-to-date information when you complete onboarding or identity verification, submit KYC information, provide wallet addresses, initiate transactions, provide payment-related information, contact support or otherwise interact with the Widget.
You are responsible for ensuring that wallet addresses, blockchain network information, payment details, transaction information and other information submitted by you through the Widget are accurate before you submit or confirm them. APS may be unable to reverse, correct or recover certain transactions where inaccurate information has been provided, including where a digital asset transaction has been submitted to a blockchain network.
If you believe that personal information we hold about you is inaccurate, incomplete or out of date, you may request that we correct or update it by contacting us at: contacts@cad.aps.money.
Where required by applicable law, if APS is satisfied on reasonable grounds that personal information under its control is inaccurate or incomplete, APS will correct the information as soon as reasonably possible. If APS does not make a requested correction, APS may annotate the relevant record to indicate that a correction was requested but not made, where required by applicable law.

10. Complaints and Privacy Officer

Privacy Officer
APS designates an individual to be responsible for ensuring that APS complies with applicable Canadian privacy legislation in respect of personal information under its control, including the British Columbia Personal Information Protection Act and, where applicable, the Personal Information Protection and Electronic Documents Act.
The designated individual acts as APS’s Privacy Officer for the purposes of this Privacy Notice. The Privacy Officer is responsible for receiving and responding to privacy-related questions, access and correction requests, withdrawal of consent requests, and complaints regarding APS’s handling of personal information collected through or in connection with the Widget and the related on-ramp and off-ramp services.
You may contact APS’s Privacy Officer at:
ADVANCED PAYMENT SOLUTIONS CANADA INC.
Attention: Privacy Officer
Unit 1, 442 2nd Avenue, Fernie, BC V0B 1M0, Canada
Email: contacts@cad.aps.money

Privacy Complaints
If you have a concern or complaint about how APS collects, uses, discloses, retains, protects or otherwise handles personal information collected through or in connection with the Widget, including in connection with identity verification, KYC, sanctions screening, anti-money laundering checks, fraud prevention, payment processing, wallet addresses, transactions, support, cookies, analytics, session monitoring or notifications, you may contact our Privacy Officer using the contact details above.

To help us review and respond to your complaint, please include sufficient details about your concern, including:
  • your name and contact details;
  • the nature of your privacy concern or complaint;
  • the personal information, account, verification, transaction, support request, cookie, session or Widget interaction to which your complaint relates;
  • any relevant dates, transaction references, communications or supporting information;
  • the outcome or resolution you are seeking.
APS may request additional information where reasonably necessary to verify your identity, understand your complaint, investigate the matter and respond appropriately.
APS will review and investigate privacy complaints in a fair and reasonable manner. Where we determine that a complaint is justified, we will take appropriate steps to address the matter, which may include correcting or updating personal information, restricting access to personal information, improving safeguards, changing our policies or practices, updating this Privacy Notice, contacting relevant service providers, or taking other remedial measures as appropriate in the circumstances.
APS will respond to privacy complaints within a reasonable time. If additional time is required to investigate or respond to your complaint, including where we need to review technical records, transaction records, KYC records, support records or information held by service providers, we may inform you of the reason for the delay and the expected timing of our response.

External Privacy Authorities
We encourage you to contact APS’s Privacy Officer first so that we have an opportunity to review and address your concern.
If you are not satisfied with our response, or if you believe that your concern has not been adequately addressed, you may contact the Office of the Information and Privacy Commissioner for British Columbia. Where another Canadian privacy law applies to the relevant collection, use or disclosure of your personal information, you may also have the right to contact the Office of the Privacy Commissioner of Canada or another applicable privacy authority.

11. Children’s Privacy
The Widget and the related on-ramp and off-ramp services are not intended for, directed to, or available to children, minors or any person who has not reached the age of majority in their jurisdiction of residence.
You must not access or use the Widget, create an account or user profile, complete onboarding or identity verification, submit KYC information, initiate an on-ramp or off-ramp transaction, provide wallet or payment-related information, or otherwise submit personal information through the Widget if you are a child, minor or otherwise do not have legal capacity to use the Widget and the related services.
APS does not knowingly collect, use or disclose personal information from children or minors through or in connection with the Widget. If APS becomes aware that personal information has been submitted by or about a child or minor through or in connection with the Widget, APS may take reasonable steps to restrict access to the Widget, suspend or terminate the relevant account or transaction, and delete, de-identify or otherwise address the information, subject to applicable legal, regulatory, compliance, security, fraud prevention, dispute resolution, investigation and record-keeping requirements.
If you believe that a child or minor has provided personal information to APS through or in connection with the Widget, please contact us at: contacts@cad.aps.money.

12. Changes to this Privacy Notice
APS may update this Privacy Notice from time to time to reflect changes in our Website, our personal information handling practices, our service providers, legal or regulatory requirements, or for other operational, legal or business reasons.
When we update this Privacy Notice, we will revise the “Last Updated” date at the top of this page. The updated version will be effective when it is posted on the Widget, unless otherwise stated.