Legal
Privacy Policy
How personal information is handled across M2Square websites, business relationships, onboarding, platform access, and services.
Last updated: 27 September 2026
1. Scope and responsible entity
This Policy describes how personal information is collected, used, disclosed, transferred, retained, and protected when you visit a M2Square website, contact us, represent a customer or partner, complete onboarding, access the platform or APIs, or participate in a transaction supported by the services.
M2SquarePay Corporation receives central privacy enquiries and coordinates with the legal entity responsible for the relevant interaction. Depending on the service, that entity may act as an independent controller, joint controller, or processor for a business customer. Service-specific privacy or data-processing terms control where they provide more specific information.
2. Who this policy covers
This Policy may apply to:
- website visitors, prospects, and people who contact us;
- customers, merchants, partners, and their representatives or authorised users;
- directors, officers, beneficial owners, and control persons reviewed during onboarding;
- end users, payers, payees, recipients, beneficiaries, and counterparties involved in transactions; and
- vendors, advisers, applicants, and other business contacts where a specific notice is not provided.
3. Information we collect
The information collected depends on your role, location, and use of the services. It may include:
- Identity and contact information: name, date of birth, address, email, phone number, nationality, signature, and account credentials.
- Business information: employer, role, company details, registration data, ownership, directors, authorised users, business activity, markets, expected volumes, and source of funds.
- Verification information: government identifiers, tax numbers, identity documents, proof of address, verification results, and, where required and lawfully collected, selfie, liveness, or biometric-verification results.
- Financial and transaction information: bank, card, wallet, beneficiary, payment, payout, settlement, FX, refund, dispute, chargeback, balance, and transaction-history data.
- Compliance and risk information: sanctions, politically exposed person, adverse-media, fraud, device, behavioural, blockchain-analysis, and case-review information.
- Technical information: IP address, browser, device, approximate location, operating system, identifiers, API requests, logs, timestamps, and security events.
- Communications: enquiries, support messages, call or meeting notes, survey responses, complaints, and records of consent or preferences.
4. Sources of information
Information may come from:
- you, your organisation, or another participant in a transaction;
- customers that instruct us to process information about their end users or counterparties;
- banks, payment networks, payout partners, wallet or digital-asset providers, and other service partners;
- identity-verification, fraud-prevention, sanctions, credit, corporate-registry, and blockchain-analysis providers;
- public records, government or regulatory authorities, and law-enforcement requests; and
- devices, browsers, platform activity, APIs, and security systems.
5. How we use information
We may use personal information to:
- respond to enquiries and manage prospective and existing business relationships;
- verify identity, business ownership, authority, eligibility, and account access;
- provide, route, reconcile, support, and report on transactions and services;
- perform sanctions, AML, counter-terrorist-financing, fraud, and other risk controls;
- secure, operate, troubleshoot, monitor, and improve websites, APIs, and services;
- communicate service, security, contractual, and policy updates;
- manage fees, accounting, tax, audits, complaints, disputes, and legal claims;
- comply with laws, regulatory expectations, court orders, and lawful requests; and
- create aggregated or de-identified insights where permitted by law.
6. Legal bases
Where applicable law requires a legal basis, processing may be necessary to enter into or perform a contract, comply with a legal or regulatory obligation, protect vital or substantial public interests, or pursue legitimate interests such as providing and securing services, preventing fraud, managing business relationships, and protecting legal rights. We rely on consent where required, including for certain optional marketing, cookies, or sensitive-data processing. Consent may be withdrawn without affecting earlier lawful processing.
7. Verification fraud and compliance
Services may use rules, models, screening tools, and specialist providers to assess identity, sanctions, fraud, transaction, device, and blockchain risk. These tools may flag, delay, restrict, or refer activity for review. Where applicable law provides rights relating to a decision based solely on automated processing, you may request information or human review through the privacy contact below.
We may be legally restricted from providing details about a suspicious-activity review, report, or law-enforcement request.
8. How we disclose information
Information may be disclosed to:
- the M2Square entity responsible for the product or market and entities supporting the relationship;
- banks, payment institutions, card or payment networks, payout partners, liquidity providers, wallet providers, custodians, and digital-asset service providers;
- identity, KYC/KYB, sanctions, fraud, security, blockchain-analysis, cloud, communications, support, and analytics providers;
- customers, beneficiaries, counterparties, and other transaction participants where necessary to execute an instruction;
- auditors, insurers, lawyers, accountants, consultants, and other professional advisers;
- regulators, tax authorities, courts, law enforcement, and other public authorities where required or appropriate; and
- a buyer, investor, lender, or successor in connection with a financing, reorganisation, merger, sale, or similar transaction, subject to appropriate safeguards.
We may also disclose information at your direction, with your consent, or in aggregated or de-identified form where it cannot reasonably identify an individual.
9. Blockchain information
Transactions conducted on a public blockchain may be visible to anyone and recorded permanently. Wallet addresses, asset types, amounts, timestamps, and transaction identifiers may become public and may be linked to other information by third parties. Public blockchain records generally cannot be altered or deleted by M2Square or the applicable Provider.
10. International transfers
M2Square services involve customers, entities, infrastructure, and partners in multiple countries. Personal information may be transferred to or accessed from a country with different data- protection laws. Where required, the responsible entity uses an appropriate transfer mechanism, such as contractual safeguards, an adequacy decision, consent, or another lawful basis. You may request information about the mechanism relevant to your data.
11. Retention
Information is retained for as long as needed for the purposes described in this Policy, including the business relationship, transaction processing, security, audit, tax, accounting, disputes, and legal or regulatory obligations. Identity, transaction, and compliance records may need to be retained after a relationship ends. When information is no longer needed, it is deleted, anonymised, or access-restricted as appropriate.
12. Security
We use administrative, technical, and organisational measures designed to protect personal information against unauthorised access, loss, alteration, misuse, or disclosure. Measures are selected according to the information and service involved and may include access controls, encryption, monitoring, vendor due diligence, incident response, and staff procedures. No system is completely secure, and you should use only designated secure channels for identity, financial, or credential information.
13. Privacy rights and choices
Depending on applicable law, you may have rights to confirm processing; access, correct, or delete information; restrict or object to processing; receive portable information; withdraw consent; opt out of certain disclosures or profiling; and lodge a complaint with a privacy or data-protection authority.
Rights may be limited where information must be retained for compliance, security, legal claims, another person's rights, or other lawful reasons. We may verify your identity and authority before responding. If information was provided by a business customer acting as controller, we may refer your request to that customer.
14. Marketing communications
Where permitted, we may send business communications about relevant products, events, or insights. You can opt out of promotional email using the unsubscribe method in the message or by contacting us. Service, security, legal, and transaction communications are not promotional and may continue while relevant.
16. Children
M2Square services are intended for businesses and are not directed to children. We do not knowingly seek personal information from children through the public website. If you believe a child has provided information improperly, contact us.
17. Third-party services
Links, integrations, and partner services may be governed by another organisation's privacy notice. We do not control how an independent third party processes information outside the services we provide or arrange.
18. Regional notices
Additional disclosures may be provided where local law requires them, including information about the local responsible entity, data-protection officer or representative, regulator, categories collected or disclosed, and region-specific rights. A regional or product notice supplements this Policy and controls for the matter it specifically addresses.
19. Changes to this policy
We may update this Policy as services, entities, providers, or legal requirements change. The revised version will be posted here with a new “Last updated” date. Where required, material changes will be communicated through an additional notice.