Legal

Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains how RePay (“RePay”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you visit our website, submit an access request, create an account, or use our ad-account funding and related services (the “Services”). By using the Services, you acknowledge this Policy.

1. Who we are

RePay provides private funding of advertising accounts (including Google Ads, Meta Ads, and TikTok Ads) and related digital payments, typically settled in USDC, for professional media-buying teams.

Company legal entity name, registration number, registered address, and data-protection contact details will be published here once finalized. Until then, privacy requests may be submitted through the contact form on our website or via the Telegram contact provided during onboarding.

2. Scope

This Policy applies to personal data processed in connection with our website, application / lead forms, onboarding and simplified verification, customer dashboards, customer support, and communications related to the Services.

It does not apply to third-party advertising platforms (Google, Meta, TikTok, and others) or crypto rails / custody providers you interact with independently. Those parties process data under their own policies.

3. Personal data we collect

Depending on how you interact with us, we may collect the following categories of data:

  • Identity and contact data: name, Telegram handle or other messenger ID, email address, phone number (if provided), company / team name, and role.
  • Application and onboarding data: platforms you intend to fund, account ownership model, declared monthly budget range, vertical / business description, and information needed for simplified verification or access review.
  • Account and service data: dashboard identifiers, invoices, top-up and balance activity, card or funding references associated with your account, support tickets, and operational notes.
  • Technical data: IP address, device / browser type, approximate location derived from IP, pages visited, referral source, and cookies or similar technologies used for security and basic analytics.
  • Communications: messages you send to us and our replies.

4. How we collect data

  • Directly from you when you submit forms, register, verify, top up, or contact support.
  • Automatically through the website and dashboard (logs, cookies, security telemetry).
  • From service providers that help us operate payments, hosting, analytics, or communications, where permitted.
  • From publicly available sources or information you voluntarily share during the access review, where relevant to eligibility or risk assessment.

5. Purposes and legal bases

We process personal data for the following purposes. Where a local privacy law requires a legal basis, we rely on contract performance, legitimate interests, legal obligation, and/or consent as applicable:

  • Providing and operating the Services (access review, onboarding, invoicing, funding, balance management, support).
  • Communicating with you about applications, invitations, invoices, security events, and service updates.
  • Fraud prevention, AML/CFT screening, sanctions checks, abuse detection, and protecting the integrity of our BIN and payment flows.
  • Improving the website and Services, measuring demand, and maintaining security.
  • Complying with applicable laws, responding to lawful requests, and establishing, exercising, or defending legal claims.
  • Marketing or product updates only where permitted — and you may opt out of non-essential marketing communications.

6. Sharing of personal data

We do not sell your personal data. We may share data with:

  • Service providers acting on our instructions (hosting, infrastructure, analytics, messaging, KYC/AML tooling, payment or blockchain infrastructure partners).
  • Advertising platforms or partners only to the extent necessary to deliver the funding service you requested.
  • Professional advisors (legal, compliance, accounting) under confidentiality obligations.
  • Authorities, courts, or regulators when required by law or necessary to protect rights, safety, or the Services.
  • A successor entity in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards.

7. International transfers

We may process and store data in countries other than your country of residence. Where required, we use appropriate transfer safeguards (such as contractual protections) and limit access to personnel and providers who need the data to operate the Services.

8. Retention

We retain personal data only as long as needed for the purposes described above, including to provide the Services, meet AML record-keeping and legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type; transaction and compliance records are typically kept longer than marketing or website analytics data. When data is no longer needed, we delete or anonymize it where feasible.

9. Security

We apply technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure; you are responsible for keeping your login credentials and messaging accounts confidential and for notifying us promptly of suspected unauthorized access.

10. Cookies and similar technologies

Our website may use essential cookies required for security and basic functionality, and limited analytics cookies to understand traffic. Where required by law, non-essential cookies are used only with consent. You can control cookies through your browser settings; disabling some cookies may affect site functionality.

11. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data, to withdraw consent where processing is consent-based, and to lodge a complaint with a supervisory authority. To exercise these rights, contact us using the channels described in section 1. We may need to verify your identity before responding. Some rights may be limited where we must retain data for legal, AML, or contractual reasons.

12. Children

The Services are intended for professional business users and are not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us data, contact us and we will take appropriate steps to delete it.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated through the website, dashboard, or your contact channel. Continued use of the Services after an update constitutes acceptance of the revised Policy where permitted by law.

14. Contact

For privacy questions or requests, use the contact form on our website or the support channel provided during onboarding. Formal legal entity and DPO / privacy contact details will be added here when available.

Back to home