Privacy Policy

At Binrora (“we”, “us”, or “our”), safeguarding your privacy and securing your personal and financial data is of paramount importance. This Privacy Policy describes how we collect, use, process, and disclose your information when you access the Binrora financial technology platform, use our virtual card issuance services, access our payment wallets, interact with our APIs, or use our mobile applications (collectively, the “Services”).

By registering for an account or using any of our Services, you consent to the collection, transfer, processing, storage, disclosure, and other uses of your information as described in this Privacy Policy.

1. Scope and Information We Collect

To provide our virtual payment cards, wallets, and spend management controls, we must collect information from you. The types of personal and business information we collect depend on how you interact with our platform and the regulatory requirements of your region.

A. Information You Provide to Us

  • Account Registration Data: When you create an account, we collect your full legal name, business email address, corporate phone number, password, and account preferences.
  • Identity & KYC Verification Data: To satisfy global Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) regulations, we collect:
    1. Government-issued identity documents (e.g., passport, national ID card, or driver’s license).
    2. A live selfie or face scan (biometric matching) to verify that you are the legal holder of the ID document.
    3. Proof of address (e.g., a utility bill, bank statement, or local registration document dated within 90 days).
    4. Entity details for businesses, including registration certificates, Articles of Association, active tax identification numbers (EIN/VAT), and identification data of major shareholders or ultimate beneficial owners (UBOs).
  • Financial & Source of Funds Data: Information demonstrating the source of your deposits, bank statement details, corporate billing information, or wallet funding history.
  • Customer Support and Communication: Content of your inquiries, support tickets, and chat logs with our support representatives.

B. Information We Collect Automatically

  • Transaction & Card Activity: Full details of all transactions executed using Binrora virtual cards or wallet balances, including the timestamp, merchant name, transaction amount, currency, billing code, status, and merchant category.
  • Technical & Device Information: IP addresses, operating system versions, browser types, device IDs, time zones, device models, and network provider details.
  • Usage and Activity Logs: Pages viewed, button interactions, time spent on the dashboard, API call rates, and referrer URLs.
  • Cookies & Trackers: We use essential cookies to manage your login session, prevent fraud, and remember your interface settings.

C. Information Collected from Third Parties

  • Verification Services: Results from third-party identity verification bureaus, credit screening databases, and international sanction search networks (including OFAC, EU Consolidated List, and UN Sanctions Lists).
  • Payment & Banking Networks: Transaction settlements, chargeback notifications, and fraud alerts transmitted from partner banks, Visa, Mastercard, or e-money partners.

We only process your personal information when we have a valid legal basis to do so, typically under the following categories:

  1. Performance of a Contract: To register your account, manage your digital wallet, issue virtual cards, and process transactions under the Terms of Service.
  2. Legal and Regulatory Compliance: To satisfy stringent regulatory rules, including AML/CTF reporting, tax reporting, KYC checks, and requests from financial supervisors.
  3. Legitimate Interests: To protect our platform from cyberattacks, prevent fraud, conduct card transaction monitoring, optimize user experience, and manage our business risks.
  4. Consent: For certain voluntary features, such as marketing communications or biometric face matching during identity checks. You may withdraw your consent at any time, though doing so may prevent you from passing verification or using our Services.

3. How We Use Your Information

We utilize the collected information to operate, support, and enhance our financial technology platform:

  • Service Delivery: To manage your secure wallet balances, issue instant virtual cards, process inbound deposit rails, execute foreign exchanges, and support spend management analytics.
  • Identity Verification & Compliance Audits: To audit your registration details, perform PEP (Politically Exposed Persons) checks, and scan against global sanction lists.
  • Transaction Monitoring & Fraud Prevention: To identify card-testing fraud, unauthorized account access, velocity spikes, and money laundering indicators.
  • Customer Support: To resolve billing disputes, investigate merchant chargebacks, and provide chat assistance.
  • Platform Analytics & Development: To identify performance bugs, optimize page load times, and build new spend-control tools.

4. Information Sharing and Disclosure

Binrora is a financial technology platform, not a licensed bank. To deliver our services, your information is shared with authorized third parties:

Partner Type Scope of Sharing Purpose
Partner Issuing Banks Shared with principal members of Visa and Mastercard. To approve and issue the physical or virtual payment cards bound to your name/business.
Licensed E-Money Institutions (EMIs) Safe safeguarding accounts, balance summaries, and wallet routing numbers. To maintain client safeguarded wallets and process bank transfers (SEPA, ACH, Wire).
Compliance & Verification Vendors ID photos, selfies, address documentation, and company records. To cross-reference global sanctions lists, perform biometric comparison, and confirm address validity.
Cloud Hosting & Infrastructure Encrypted databases, server logs, and API gateway requests. To store platform databases securely (AWS / Google Cloud, using AES-256 at rest).
Law Enforcement & Regulators Suspicious Activity Reports (SARs) and response to judicial subpoenas. To prevent financial crime, counter money laundering, and comply with binding court orders.

We do not sell, trade, or rent your personal or business data to third-party advertisers or marketers.

5. Security & Data Protection

We employ bank-grade security protocols to protect your information from unauthorized access, loss, or disclosure:

  • Encryption standards: All connection paths are encrypted via TLS 1.3 in transit. Databases, transaction history, and compliance records are encrypted at rest using AES-256.
  • Access Management: Employee access to customer details is strictly limited under least-privilege principles, requiring multi-factor authentication (MFA) and audited justification.
  • Card Security Compliance: We do not store raw card verification values (CVVs) or primary account numbers (PANs) on our main servers. All card details are accessed securely using PCI-DSS compliant iframe architectures managed by card network processors.

6. Data Retention

Under global financial regulations (including AML and banking laws), we are legally required to retain your identity documents, registration records, and transaction logs for a minimum period of 5 years (or longer, as specified by regional statutes) after the closure of your Binrora account.

This data is kept securely in archived databases even after your service contract ends. After the legal retention period has expired, your personal data will be permanently deleted, anonymized, or securely shredded.

7. Cross-Border Data Transfers

To facilitate global virtual card usage and cross-border transactions, the personal information we collect may be transferred to, and processed in, countries outside your jurisdiction (including the United States and the European Economic Area).

We ensure that all cross-border transfers comply with local privacy laws, implementing Standard Contractual Clauses (SCCs), adequacy decisions, or other legally approved frameworks to ensure your data receives the equivalent level of protection.

8. Your Privacy Rights

Depending on your country of residence (such as under the GDPR in Europe or the CCPA in California), you may possess specific rights regarding your personal data:

  • Right to Access: The right to request copies of the personal data we hold about you.
  • Right to Correction: The right to request that we correct inaccurate or incomplete data.
  • Right to Erasure (Right to be Forgotten): The right to request data deletion. Note that this right is limited by our legal obligation to retain financial transaction and AML compliance records for specified periods.
  • Right to Restrict or Object to Processing: The right to restrict how we process your data under certain conditions.

Our dashboard or site may contain links to external merchant websites, subscription providers, or partner portals. This Privacy Policy applies solely to Binrora. We are not responsible for the privacy practices, cookie policies, or content of third-party platforms. We recommend reading their respective policies before submitting personal data.

10. Updates to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make material updates, we will notify you by updating the “Last Updated” date at the top of this policy and, if required by law, by displaying a notice on our dashboard or sending an email notification. We encourage you to review this policy periodically to stay informed about how we protect your information.

If you have any questions, feedback, or complaints regarding this Privacy Policy or our data handling procedures, please contact us.