POSX Legal · United States
Privacy Policy
How POSX collects, uses, shares, protects and deletes personal information in the POSX app and on POSX websites.
On this page
Users in the United States and in every market where POSX US Inc. is named as the app publisher
Laws of the State of Delaware
1. About this policy and who is responsible for your information
1.1 Who we are
1.1.1 POSX US Inc. ("POSX", "we", "us", "our") is the company responsible for the personal information described in this policy. Our registered office is 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States. Incorporated in Delaware, United States. File / registration no. 10279819. EIN 39-3559683.
1.1.2 In data-protection terms we are the controller of that information: we decide what is collected and why. Where a partner merchant, a payment network or an app store separately decides how to use information about you, that party is a controller in its own right and its own privacy notice applies to what it does.
1.1.3 POSX is part of a group. POSX Commerce Technology Limited (Hong Kong), which operates the POSX network outside the United States, is an affiliate of ours. Where your account is served by that affiliate, its version of this policy applies instead; the two versions describe the same practices and differ only in the entity responsible and the local rights available to you. Both are published at https://posx.io/legal.
1.2 How to reach us about privacy
| Purpose | Contact |
|---|---|
| Privacy enquiries and rights requests | privacy@posx.io |
| Online rights request form | https://posx.io/privacy/requests |
| Account deletion | https://posx.io/account-deletion |
| Data protection officer / privacy lead | our Privacy Lead, reachable at privacy@posx.io |
| EU representative (GDPR Art. 27) | Not appointed. POSX does not offer the app in the European Economic Area — see section 15 |
| UK representative (UK GDPR Art. 27) | Not appointed. POSX does not offer the app in the United Kingdom — see section 15 |
| Postal address | 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States |
1.3 Scope
1.3.1 This policy covers the POSX mobile application, the POSX websites at posx.io and their subdomains, and the customer support, email, SMS and push channels through which we communicate with you.
1.3.2 It does not cover: what a partner merchant does with information it collects from you in its own store, app or checkout; what Apple or Google collect through the app store or the operating system; or what a third-party wallet, exchange or blockchain network does with information you give it directly. Those parties publish their own notices.
2. What the POSX app does, in privacy terms
2.1 POSX is a cross-merchant rewards network. When you make a qualifying purchase at a partner merchant, POSX verifies that the purchase really happened and credits a reward to your POSX account. You can then redeem that reward at merchants in the network.
2.2 Three things follow from that model, and they explain most of what appears in this policy:
(a) We have to see purchases to reward them. POSX receives a record of qualifying transactions — merchant, amount, time, channel and a transaction fingerprint — either from the merchant, from a payment network you have permitted to share it, or from the payment method you have linked. We call this a Proof of Spend record.
(b) We keep the ledger of what you have earned. Your reward balance is a record on our own ledger — not a blockchain token, and not money we hold for you. Keeping that ledger accurate means we must be able to identify you reliably. Where the app also gives you a self-custodial wallet, the assets in it are yours and we cannot move them.
(c) We are required to verify who you are. Because we hold value for you and pay it out at merchants, we run identity verification and sanctions screening, and we keep those records for as long as the law requires — including after you close your account.
3. Personal information we collect
The table below is the complete list of what we collect, why, and — for users in the EEA and the UK — the legal basis we rely on. Categories marked optional are collected only if you choose to provide them or grant the relevant device permission.
| Category | What it includes | Why we collect it | Legal basis (EEA / UK) |
|---|---|---|---|
| A. Account and profile | Name, email address, mobile number, password (stored only as a salted hash), country and language, referral code, profile photo (optional), account status and settings. | Create and run your account; authenticate you; contact you about the service. | Performance of our contract with you |
| B. Identity verification (KYC) | Full legal name, date of birth, nationality, residential address, government identity document type, number, expiry and image; a selfie or short liveness video and the facial-geometry template our verification provider derives from it; proof of address; tax residency where required; sanctions, PEP and adverse-media screening results; the verification decision and its audit trail. | Verify that you are who you say you are; meet anti-money-laundering and sanctions obligations; prevent impersonation and account takeover. | Compliance with a legal obligation; Our legitimate interests (fraud prevention). Biometric data is processed only on your explicit consent — see the note on biometric data below |
| C. Purchases and Proof of Spend | Merchant identity and location, purchase amount and currency, date and time, channel (in-store, online, card-linked), product category where the merchant provides it, a transaction fingerprint, the risk status of the transaction, and any refund, chargeback, reversal or adjustment. | Determine whether a purchase qualifies; calculate and credit the reward; unwind rewards when a purchase is refunded or reversed; detect manipulation of the reward mechanism. | Performance of our contract with you; Our legitimate interests (network integrity) |
| D. Payment method | A tokenised reference to a card you link, the last four digits, card brand, issuing bank and expiry; bank or payout details where you provide them. We do not store your full card number or security code. | Match purchases to your account through the card networks; pay out where a payout method is used. | Performance of our contract with you |
| E. Rewards and wallet | Your reward balance and full ledger of earn, redeem, adjustment and expiry entries; redemption history; tier or status level; referrals; promotions applied. Where the app provides a self-custodial wallet, the public address of that wallet and the transactions associated with it. Reward balances themselves are held on our own ledger and are not written to a blockchain. | Run the reward programme; show you your balance and history; settle redemptions with merchants; produce statements and resolve disputes. | Performance of our contract with you |
| F. Device and technical | Device model, operating system and version, app version, time zone and language, IP address, mobile network, device identifiers (the per-installation vendor identifier on iOS and the app-set identifier on Android; not the advertising identifier), push notification token, crash reports, diagnostic and performance data. | Deliver and secure the app; diagnose crashes and defects; detect fraudulent or automated access; measure reliability. | Performance of our contract with you; Our legitimate interests (security, reliability) |
| G. Location | Approximate location inferred from your IP address; precise device location (optional, only with your operating-system permission); the location of merchants where you transact. | Show nearby participating merchants and location-relevant offers; assess fraud risk; apply country restrictions. | Your consent for precise location; Our legitimate interests for approximate location and fraud checks |
| H. App usage | Screens viewed, features used, in-app searches, session length and frequency, offers shown and opened, notification interactions. | Understand how the app is used, fix what does not work, and decide what to build next. | Our legitimate interests (product improvement); Your consent where analytics uses non-essential SDKs |
| I. Support and communications | Messages, chat and email correspondence with our support team, call notes, the contents of any dispute or complaint you raise, survey and feedback responses. | Answer you; investigate and resolve disputes; train and quality-check our support team; keep a record of what was agreed. | Performance of our contract with you; Our legitimate interests (service quality, defence of claims) |
| J. Marketing and consent records | Your marketing preferences by channel, the date, time and wording of each consent or objection, and suppression records. | Send only what you have agreed to receive, and prove that we honoured your choices. | Your consent; Compliance with a legal obligation (record of consent) |
| K. Security and fraud signals | Sign-in and authentication events, multi-factor status, device and session signals used to recognise your device, IP reputation, velocity and pattern signals, and security incident records. | Keep your account and your reward balance secure; detect account takeover, collusion, split or circular transactions and reward farming. | Our legitimate interests (security); Compliance with a legal obligation |
3.1 Notes on particular categories
3.1.1 Sensitive information. Government identity numbers, precise location, and account credentials are treated as sensitive personal information under California law and as special category or restricted data under other laws. We use them only for the purposes in the table above, never for advertising, and never to infer characteristics about you.
3.1.2 Biometric data. Identity verification uses a facial-geometry template generated from your selfie and compared against your identity document. This is biometric data used to identify you uniquely. We ask for your explicit, separate consent before it is created, we tell you which provider performs the comparison, and the template is deleted once verification concludes and in any event within 30 days of the verification decision, and in no case later than three years after your last interaction with us. We obtain your written release before any template is created, and we never sell, lease, trade or otherwise profit from biometric information. If you do not want biometric verification, choose manual review in the verification screen or contact us, and we will review your documents manually instead — declining does not prevent you from opening an account. Texas CUBI, Colorado and other state biometric rules are applied on the same basis.
3.1.3 Card numbers. POSX does not receive, store or process full payment card numbers. Card linking is performed by our card-linking provider, named in the subprocessor list at posx.io/legal/subprocessors, which returns only a token and the display details listed in category D.
3.1.4 We do not collect your contacts, photo library, microphone, camera roll, health data, SMS content, call logs or a list of the other apps on your device. The camera is used only when you scan a code or capture an identity document, and images taken for that purpose are not retained beyond the purpose.
4. Where the information comes from
— From you — when you register, verify your identity, link a payment method, contact support, or set your preferences.
— From your device — automatically, when you use the app, as described in category F and in our Cookie and Tracking Policy.
— From partner merchants — the transaction records that make a purchase eligible for a reward.
— From payment networks and card-linked-offer providers — where you have authorised them to share qualifying transactions with us.
— From identity, sanctions and fraud providers — verification results, screening matches and risk signals.
— From app stores and attribution providers — install, campaign and, where you have consented, attribution data.
— From public blockchains — where the app provides a self-custodial wallet, the public record of that wallet's transactions. Reward balances are not on a blockchain.
— From someone who refers you — a referrer's code and, where they provide it, the contact detail they used to invite you.
5. Automated decisions, profiling and artificial intelligence
5.1 Automated decisions we make
We use automated systems in three places that can affect you:
| Decision | What the system does | What happens if it goes against you |
|---|---|---|
| Reward eligibility and amount | Scores each Proof of Spend record against merchant, channel, activity, quality and risk coefficients to decide whether a purchase qualifies and what reward it earns. | The reward is withheld, reduced or reversed. You can ask a person to review it. |
| Fraud and abuse controls | Flags patterns such as split or circular transactions, reward farming, collusion between accounts, and account-takeover signals. | Rewards are held or reversed and, in serious cases, the account is suspended pending review. |
| Identity verification | Compares your identity document and selfie, and screens your details against sanctions, PEP and adverse-media lists. | Verification fails and the account cannot be opened or continued. You can submit corrected documents and ask for manual review. |
5.1.1 Because this processing is systematic, large-scale and includes biometric data, we carry out a data protection impact assessment before launch and before any material change to it, we maintain a record of processing activities, and we keep the outcome of the legitimate-interests balancing tests we rely on. A summary of the assessment is available to a supervisory authority on request.
5.1.2 Where a decision is made solely by automated means and has a legal or similarly significant effect on you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to us at privacy@posx.io and a person will review it.
5.1.3 California residents: from 1 January 2027, where we use automated decision-making technology to make a significant decision about you — including the provision or denial of a financial service — you may ask how it was used in your case and may opt out of that use, and we will offer an alternative process.
5.2 Artificial intelligence
5.2.1 We use machine-learning models for fraud detection, transaction classification and support triage. Where a third-party artificial-intelligence service processes personal information on our behalf, we name it in Appendix B, we bind it by contract to use the information only to provide the service to us, and we do not permit it to train its own general-purpose models on your information.
5.2.2 We do not sell or otherwise make your personal information available to a third party for the training of that party's own artificial-intelligence models. If that ever changes we will ask for your permission first.
6. When we share information, and with whom
6.1 We share personal information only in the situations listed below. Every service provider acts on our documented instructions under a written contract that requires at least the same protection this policy promises.
| Who | What they receive | Why |
|---|---|---|
| Partner merchants | Confirmation that a redemption is valid, the reward amount applied and a transaction reference. Your name is shared only where the merchant needs it to complete the transaction. | So the merchant can honour your reward and reconcile settlement. Because a merchant decides for itself what to do with what it receives, this counts as sharing with a third party and is declared as such in our store disclosures. Merchants do not receive your identity documents, your full purchase history with other merchants, or your contact details for their own marketing unless you separately agree. |
| Identity verification and screening providers | Categories B and A. | To verify identity and screen against sanctions and PEP lists. |
| Wallet infrastructure provider (Privy) | Your account identifier, authentication signals and wallet public address. Privy holds key material in a split form; POSX cannot move your assets and neither party holds a complete key on its own. | To provision and operate your self-custodial wallet, and to let you authenticate and sign. |
| Treasury custody provider (Fireblocks) | No user personal information. Fireblocks holds POSX's own treasury assets. | To secure POSX's corporate assets. It has no access to your wallet or your data. |
| Cloud hosting, storage and network providers | All categories, as the infrastructure on which the service runs. | To host and deliver the service. |
| Analytics, crash-reporting and attribution providers | Categories F and H, and identifiers. | To measure reliability and understand product usage. Non-essential SDKs run only with your consent where consent is required. |
| Communications providers | Contact details and message content. | To send transactional email, SMS and push notifications, and marketing you have agreed to. |
| Customer support platform | Category I and enough account data to answer you. | To run the support desk. |
| Payment, card-network and settlement partners | Categories C and D. | To match purchases and settle redemptions. |
| Professional advisers, auditors and insurers | Whatever is strictly necessary. | To take legal, tax and accounting advice, to be audited, and to obtain insurance. |
| Regulators, law enforcement and courts | Whatever the law requires. | To comply with a valid legal obligation, court order or lawful request, and to establish or defend legal claims. We review each request, and we refuse or narrow requests that are overbroad or unlawful. |
| Our affiliates | Account, transaction and security data as needed. | So that POSX Commerce Technology Limited (Hong Kong) and POSX can run one network across markets. |
| An acquirer, investor or successor | Data relevant to the transaction, under confidentiality. | In connection with a financing, merger, acquisition, reorganisation or sale of assets. If control of your information changes, we will tell you before it becomes subject to a different policy. |
6.2 We do not sell your personal information
6.2.1 We do not sell personal information, and we have not sold personal information in the twelve months before the date of this policy. We do not share personal information for cross-context behavioural advertising as those terms are defined under California law, and we do not process the personal information of anyone we know to be under 16 for those purposes.
7. Sending information across borders
7.1 POSX is based in the United States and uses service providers in the United States and elsewhere. If you are in the European Economic Area, the United Kingdom or Switzerland, your information will be transferred outside your home country.
7.2 For those transfers we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum for UK transfers, supported by a transfer impact assessment and, where the assessment requires it, additional technical measures such as encryption in transit and at rest.
7.3 A list of the countries in which our main providers process personal information is in Appendix B. You can ask us for a copy of the transfer safeguards we rely on by writing to privacy@posx.io.
8. How long we keep information
We keep personal information only as long as we need it for the purpose we collected it for, plus any period the law requires. The table sets our standard periods.
| What | How long | Why that long |
|---|---|---|
| Account and profile | Life of the account, then 12 months | To let you reopen an account and to resolve late disputes. |
| Identity verification records and screening results | 5 years after the account closes, or longer where a specific law or an open investigation requires it | Anti-money-laundering record-keeping standards. Retained even if you delete your account. |
| Biometric templates | 30 days after verification concludes — deleted once verification concludes | Only needed for the verification decision itself. |
| Transaction, Proof of Spend and reward ledger records | 7 years from the end of the financial year in which the transaction occurred | Accounting, tax and audit requirements, and dispute resolution. |
| Support correspondence | 24 months from closure of the matter | To handle follow-ups and repeat issues. |
| Marketing consents, objections and suppression lists | Indefinitely, in a minimal form | We must keep a record of your opt-out in order to honour it. |
| Device, analytics and usage data | Up to 26 months, then aggregated or deleted | Long enough to see year-on-year patterns, no longer. |
| Security, access and fraud logs | 12 to 24 months, longer for an active investigation | To investigate incidents and account takeovers. |
| Backups | Rolling 35 days | Deleted records disappear from backups as the cycle rotates. |
| Records written to a public blockchain | Permanent — outside our control | See section 12. |
9. How we protect information
9.1 We maintain a written information security programme with administrative, technical and physical safeguards proportionate to the sensitivity of what we hold. Personal information is encrypted in transit and at rest, access is restricted on a least-privilege basis and requires multi-factor authentication, and privileged access to production systems is logged and reviewed. Our Security Policy, published at https://posx.io/legal, describes the programme, our incident-response commitments and how to report a vulnerability.
9.2 No system is perfectly secure. If a breach affecting your personal information occurs and the law requires us to tell you, or where there is a real risk of harm to you, we will notify you without undue delay. Where the GDPR or UK GDPR applies we notify the supervisory authority within 72 hours of becoming aware of the breach, and we notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
10. Your choices
10.1 Marketing
10.1.1 You can turn marketing email, SMS and push notifications on or off at any time in Settings → Notifications, by using the unsubscribe link in any marketing email, or by writing to privacy@posx.io. We act on an opt-out promptly and in any event within 10 business days, free of charge.
10.1.2 Service messages — verification codes, security alerts, changes to these documents, receipts and balance notices — are part of the service and are not marketing. You cannot opt out of them while your account is open.
10.2 Device permissions and tracking
— Location — grant or withdraw at any time in your device settings. The app works without it; you will simply not see nearby-merchant features.
— Notifications — grant or withdraw in your device settings.
— Camera — used only when you scan a code or capture an identity document.
— Tracking (iOS) — POSX does not track you across apps and websites owned by other companies, so the app does not show Apple's App Tracking Transparency prompt. If that ever changes we will ask for your permission through that prompt first, and declining will not change anything about the app or your rewards.
— Advertising identifier (Android) — POSX does not use it for advertising. You can reset or delete it in your device settings at any time.
10.2.1 We honour the Global Privacy Control and other recognised opt-out preference signals sent by your browser or device as a valid opt-out of sale and of sharing for targeted advertising, wherever the law gives that signal effect.
11. Closing your account and deleting your data
11.1 You can delete your POSX account from inside the app at Settings → Account → Delete account. You can also request deletion, without reinstalling the app, at https://posx.io/account-deletion.
11.2 Before you delete, please read this: any unredeemed reward balance is forfeited when your account closes. Rewards have no cash value and cannot be paid out. Redeem what you want to keep first.
What we delete
— Your profile, contact details and credentials.
— Your device, usage and analytics records associated with your account.
— Your marketing preferences, other than the minimum needed to keep honouring your opt-out.
— Your support correspondence, once any open matter is closed.
— Your identity documents and biometric templates, once the retention period in section 8 expires.
What we keep, and why
— Identity verification and screening records, for the anti-money-laundering period in section 8.
— Transaction and reward ledger records, for the accounting and tax period in section 8.
— Records needed to establish, exercise or defend a legal claim, or to comply with a court order, a regulator's direction or a legal hold.
— A minimal suppression record so that we do not contact you again.
— Anything already written to a public blockchain, which we cannot alter or erase.
11.3 Deletion takes effect on our live systems within 30 days of your request, and backups containing the deleted records are overwritten within the backup cycle stated in section 8. We will confirm when it is done.
12. Blockchain records
12.1 Your rewards are not on a blockchain. Reward balances, the earn and redeem ledger and Proof of Spend records are held on POSX's own systems. Nothing about your rewards is written to a public chain.
12.2 Where the app provides a self-custodial wallet, that wallet is a blockchain address, and anything you do with it is public and permanent. Information on a public blockchain is replicated across many computers, can be read by anyone, and cannot be changed or deleted by POSX, by Privy or by anyone else. Blockchain addresses are pseudonymous rather than anonymous: if an address can be connected to you, so can the whole history of that address.
12.3 We do not write your name, contact details, identity documents or any special category data on-chain. Where you exercise a right of erasure we delete the off-chain information that links you to an address; the on-chain record itself will remain, because no one is able to remove it.
13. Children
13.1 POSX is a financial service for adults. The app is not directed to children, and you must be at least 18 years old (or the age of majority where you live, if higher) to hold an account. We do not knowingly collect personal information from children.
13.2 If we learn that we hold information about a child, we will close the account and delete the information promptly, except where a law requires us to keep a record. If you believe a child has given us information, write to privacy@posx.io.
14. Your privacy rights
14.1 Depending on where you live, you have some or all of the rights below. We do not charge for exercising them and we will not treat you differently for doing so.
— Access — get a copy of the personal information we hold about you, and information about how we use it.
— Correct — have inaccurate information corrected.
— Delete — have your information deleted, subject to the exceptions in section 11.
— Portability — receive the information you gave us in a structured, machine-readable format, or have it sent to another provider where technically feasible.
— Object and restrict — object to processing based on our legitimate interests, and ask us to restrict processing while a dispute is resolved.
— Withdraw consent — at any time, without affecting what we did before you withdrew it.
— Opt out — of sale, of sharing for targeted advertising, and of profiling that produces legal or similarly significant effects.
— Limit — restrict our use of sensitive personal information to what is necessary to provide the service.
— Human review — of a solely automated decision that significantly affects you.
— Complain — to your data protection authority.
14.2 How to make a request
14.2.1 Use the form at https://posx.io/privacy/requests, or write to privacy@posx.io. We will verify your identity before we act — usually by asking you to make the request from inside your account or from the email address on file. An authorised agent may make a request for you if they provide written proof of authority.
14.2.2 We answer within the period the law allows: one month under the GDPR and UK GDPR (extendable by two further months for complex requests), 45 days under most US state laws (extendable once by a further 45 days), and 40 days under the Personal Data (Privacy) Ordinance. If we refuse a request we will tell you why and how to challenge it.
14.2.3 You always have the right to complain to the attorney general of your state and, if you are a California resident, the California Privacy Protection Agency, or to the supervisory authority in your country. We would rather you came to us first so we can put it right.
14.2.4 Region-specific rights, and the disclosures each region requires, are set out in Appendix A.
15. Other things you should know
15.1 Links and third-party services
15.1.1 The app and our sites link to merchant sites, payment providers and other third parties. We do not control them and we are not responsible for their privacy practices. Read their notices before you give them information.
15.2 App stores
15.2.1 Apple and Google collect information about your download and use of the app under their own policies. What we declare to them about our data practices is set out in our App Store privacy details and our Google Play Data safety section, both of which are consistent with this policy.
15.3 Where we offer the app, and which POSX company you deal with
15.3.1 The app is offered in the United States and in Hong Kong. If you registered with a United States address, your account is with POSX US Inc and this policy applies to you in the version published for that company. If you registered anywhere else, your account is with POSX Commerce Technology Limited. Both versions are published side by side at https://posx.io/legal, and your account settings show which one applies to you.
15.4 Changes to this policy
15.4.1 We will update this policy when our practices change. The version number and effective date at the front of the document always tell you which version you are reading, and we keep the previous versions available at https://posx.io/legal. If a change materially affects your rights, we will tell you in the app or by email at least 30 days before it takes effect.
15.5 How to contact us
15.5.1 Write to privacy@posx.io, or by post to POSX US Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States. If you are not satisfied with our answer, you may escalate to the POSX Legal team, legal@posx.io, marked "Escalation" and then to your data protection authority.
Appendix A — Region-specific disclosures
A.1 European Economic Area, United Kingdom and Switzerland
A.1.1 The controller is POSX US Inc.. Our representative under Article 27 is named in section 1.2. The legal bases we rely on are in the table in section 3; where we rely on legitimate interests, those interests are securing the network, preventing fraud, improving the product and defending legal claims, and we have carried out a balancing assessment which we will share on request.
A.1.2 You have the rights listed in section 14 and the right to lodge a complaint with your local supervisory authority. Providing identity verification data is a requirement of entering into the contract with us; if you do not provide it we cannot open or continue your account.
A.2 California
A.2.1 This section is our notice at collection and our privacy policy for the purposes of the California Consumer Privacy Act as amended.
| CCPA category of personal information | Collected? | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers (name, email, phone, IP, device and account identifiers) | Yes | Account, service, security, communications | Service providers, merchants (limited), authorities |
| Customer records (Cal. Civ. Code §1798.80) including financial details | Yes | Account, rewards, payouts | Service providers, payment partners |
| Commercial information (purchases, redemptions, reward history) | Yes | Reward calculation, service, fraud | Service providers, merchants (limited) |
| Biometric information (facial-geometry template for verification) | Yes, with consent | Identity verification | Verification provider only |
| Internet or network activity (app usage, diagnostics) | Yes | Reliability, product improvement | Analytics providers |
| Geolocation data | Yes | Nearby merchants, fraud, country restrictions | Service providers |
| Audio, visual or similar (identity document images, support recordings) | Yes | Verification, support quality | Verification and support providers |
| Professional, employment or education information | No | — | — |
| Sensitive personal information (government ID number, account credentials, precise geolocation, biometric data) | Yes | Only to verify identity, secure the account and provide the service | Verification and security providers |
| Inferences drawn to create a profile | Limited — risk and eligibility scoring only | Fraud prevention and reward eligibility | Not disclosed for advertising |
A.2.2 We do not sell or share personal information as those terms are defined by the CCPA. We do not use or disclose sensitive personal information for purposes beyond those permitted by section 1798.121, so the right to limit does not restrict anything we do — you may still ask us to limit and we will confirm.
A.2.3 California residents have the rights in section 14, including the right to know, delete, correct, opt out and to be free from discrimination. Requests are answered within 45 days, extendable once. You may use an authorised agent. Contact us as set out in section 14.2.
A.3 Other US states
A.3.1 If you live in a state with a comprehensive privacy law — including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, and further states as their laws take effect — you have the rights in section 14 as your state grants them. Most of those states also give you the right to appeal a refusal: write to privacy@posx.io with "privacy appeal" in the subject line and we will respond within 45 days and tell you how to contact your attorney general if you remain dissatisfied.
A.4 Hong Kong
A.4.1 This section, together with the collection notice shown when you register, is our Personal Information Collection Statement under Data Protection Principle 1(3) of the Personal Data (Privacy) Ordinance (Cap. 486).
— Providing the data in categories A to D is obligatory — we cannot open or run your account without it. Providing the data in categories G and J is voluntary.
— The purposes of collection are those in section 3, and the classes of transferee are those in section 6.
— You may request access to and correction of your personal data under sections 18 and 22 of the Ordinance. We respond within 40 days. We may charge a fee for complying with a data access request, which will not be excessive and will be limited to the direct costs of compliance.
— You may at any time, free of charge, require us to stop using your personal data in direct marketing.
— Requests should be sent to privacy@posx.io or by post to the address in section 1.1, marked for the attention of the Data Protection Officer.
A.5 Markets where we do not offer the app
A.5.1 POSX offers the app in the United States and in Hong Kong. We do not offer it, market it or accept registrations in the European Economic Area, the United Kingdom or Switzerland, and we have not appointed a representative under Article 27 of the GDPR because we do not target those markets.
A.5.2 We nonetheless hold ourselves to the standard the GDPR sets, because it is the right standard and because people travel. If you are in a country where we do not offer the app and you have contacted us anyway, the rights in section 14 are available to you on the same terms as to everyone else.
A.5.3 When we open a new market we will add the disclosures and the local complaint routes that market requires — Canada, Brazil and Australia each have their own — before the app becomes available there, and we will publish the updated policy first.
Appendix B — Service providers and recipients
The table below sets out what is processed on our behalf and by which kind of provider. The current name and processing location of each provider is published, and kept up to date, at posx.io/legal/subprocessors. We keep the list there rather than in this policy so that changing a supplier does not mean redrafting a document you have already read — the list is part of this policy and carries the same commitments.
We will tell you at least 30 days before adding a provider that materially changes where or how your information is processed, and you can subscribe to changes to that page.
| Function | What it processes | Named at posx.io/legal/subprocessors |
|---|---|---|
| Cloud hosting and storage | All categories | Yes |
| Identity verification and liveness detection | Category B | Yes |
| Sanctions, PEP and adverse-media screening | Category B | Yes |
| Wallet infrastructure — self-custodial | Categories A, E, K | Privy. Privy provisions your wallet and holds key material in a split form. Neither Privy nor POSX holds a complete key, and POSX cannot move your assets. |
| Treasury custody — POSX's own assets | No user personal information | Fireblocks. Fireblocks holds POSX's corporate assets. It has no access to your wallet and no access to your personal information. |
| Card linking and payment tokenisation | Categories C and D | Yes |
| Analytics and product measurement | Categories F and H | Yes |
| Crash and performance reporting | Category F | Yes |
| Attribution and install measurement | Category F | None at present. We do not run install attribution. |
| Email, SMS and push delivery | Categories A and J | Yes |
| Customer support platform | Categories A and I | Yes |
| Fraud and risk scoring | Categories C, F and K | Yes |
| Artificial-intelligence services used in the product | See the subprocessor list | Named there if any is used, together with a written commitment that it may not train its own models on your information. |
B.1 Every provider on that list is bound by a written data processing agreement covering purpose limitation, confidentiality, security, sub-processing, breach notification to us without undue delay, audit rights, international transfer safeguards and deletion on termination. Transfers out of the EEA or the UK rely on the European Commission's Standard Contractual Clauses and the UK Addendum, as described in section 7.
Questions about this document
Contact POSX Legal
We can explain how this document applies to the POSX service.