Back to home

Privacy Policy

Last updated: 14 March 2026

Entity: Moneyr Limited (Company No. 79829784), incorporated in Hong Kong SAR

Registered Address: Unit P25, 13/F, Kaiser Estate 3rd Phase, No. 11 Hok Yuen Street, Hung Hom, Kowloon, Hong Kong SAR

Contact: support@moneyr.app | legal@moneyr.app


1. Introduction and Scope

Moneyr Limited, together with its affiliates and subsidiaries (collectively “Moneyr,” “we,” “us,” or “our”), has prepared this Privacy Policy to explain how we collect, use, store, share, and protect your personal data when you interact with our services, including:

  • Moneyr Mobile Application: Our iOS and Android mobile applications.
  • Website: Our website at https://www.moneyr.app/ and related online platforms.
  • Moneyr API: Our application programming interface and any third-party applications that depend on it.
  • Social Media Channels: Our official presence across social media platforms.

This Privacy Policy is governed by the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong) (“PDPO”) and is structured around the six Data Protection Principles set out in Schedule 1 of the PDPO.

Please read this policy carefully. If you have any questions, contact us at support@moneyr.app. By using our services, you acknowledge and accept the practices described herein. If you do not agree with any part of this policy, please discontinue use of our services.


2. Definition of Personal Data

“Personal data” means any data relating directly or indirectly to a living individual, from which it is practicable for the identity of the individual to be directly or indirectly ascertained, and which is in a form in which access to or processing of the data is practicable. This definition is aligned with Section 2(1) of the PDPO.


3. Data We Collect

We collect personal data necessary to provide our services, comply with legal and regulatory requirements, and as further described below. Data fields marked with an asterisk (*) are mandatory for service provision.

3.1 Account and Authentication Data

Data CollectedPurpose
Email address*Account creation, login, communications, account recovery
Password (stored as hash only)*Authentication — we never store your plaintext password
Date of birth*Age verification (you must be at least 18 years old)
NameDisplay in the user interface
Username (auto-generated)Unique account identifier

You may also register or sign in using Google Sign-In or Apple Sign-In. When you do so, we receive your email address, name, and a unique provider identifier to link the social sign-in to your Moneyr account.

3.2 Profile Data

Data CollectedPurpose
First name, last nameProfile display, identity verification
BioPublic profile description
NationalityRegulatory compliance, profile information
Avatar imageProfile display

3.3 KYC / Identity Verification Data

To comply with anti-money laundering (AML) and know-your-customer (KYC) regulatory requirements, we collect:

Data CollectedPurpose
Identity document type (passport, driver's license, or ID card)KYC processing
Identity document images (front and back)*Identity verification
Selfie image*Face matching against the document photo
KYC verification statusTracking verification progress

Your identity document images may be processed using automated tools to extract information such as your name, document number, nationality, date of birth, and document expiry date. This extracted data is used to populate your profile and verify your identity.

3.4 Wallet and Financial Data

Moneyr offers cryptocurrency wallet services through a custodian partner. The following data is collected and processed:

Data CollectedPurpose
Wallet account identifiersLinking your Moneyr account to your custodial wallet
Crypto asset balancesDisplaying your wallet balances
Deposit addressesReceiving cryptocurrency deposits
Transaction history (deposits, swaps, withdrawals, transfers)Transaction records and account statements

When you send or receive cryptocurrency via Moneyr Pay, the recipient's username, asset type, and transfer amount are processed by our custodian partner.

3.5 Device and Local Storage Data

The following data is stored locally on your device and is not transmitted to our servers:

Data StoredPurpose
Session tokensAuthentication and session management
PIN hashApp lock authentication — we never store your plaintext PIN
Notification preferencesUser preferences
Theme and language preferencesDisplay customization and localization
App lock and biometric unlock settingsSecurity preferences

If you enable biometric unlock (Face ID or fingerprint), the authentication is handled entirely by your device's operating system. Moneyr does not receive, access, or store the biometric templates used by your device's Face ID or fingerprint sensor.

3.6 Automatically Collected Data

When you use our services, we may automatically collect:

DataPurpose
IP addressSecurity, fraud prevention, approximate location
Device information and identifiersApp functionality, usage analytics
Operating system and versionCompatibility, troubleshooting
App or browser versionVersion management, feature compatibility
Platform (iOS or Android)Service delivery
Pages visited and interaction data (web)Improving service design and user experience
Date and time of accessSecurity logging, analytics

4. How We Use Your Data

We use your personal data for the following purposes:

Service Provision:

  • Creating and managing your account
  • Authenticating your identity upon login
  • Displaying your profile to you and other users
  • Processing KYC identity verification
  • Providing cryptocurrency wallet services, including deposits, swaps, withdrawals, and peer-to-peer transfers via Moneyr Pay

Security and Fraud Prevention:

  • Verifying your age (18+ requirement) at registration
  • Matching your face to your identity document during KYC
  • Securing your account with PIN and optional biometric lock
  • Detecting, preventing, and investigating fraud or other prohibited activities

Regulatory Compliance:

  • Fulfilling AML and KYC obligations under applicable laws
  • Maintaining identity verification records as required by law
  • Responding to lawful requests from regulators and authorities

Service Improvement:

  • Analyzing usage patterns to improve app functionality and design
  • Monitoring app performance and resolving technical issues
  • Managing minimum supported app version requirements

Communications:

  • Sending account notifications, security alerts, and KYC status updates
  • With your explicit consent, sending marketing communications about our products and services

5. Data Sharing and Disclosure

We may share your information with affiliates, service providers, government bodies, or other third parties under certain conditions, including but not limited to when third parties perform part of our services on our behalf (e.g., for data processing, analytics, delivery of services, and verification), when complying with legal obligations, or to protect the rights, property, or safety of our company, users, or others.

Some third parties processing your personal data on Moneyr's behalf may be located in a different country from the point of collection of your personal data, including but not limited to the location of servers or cloud-based services. Despite the international nature of our data processing, we are committed to enforcing robust data and privacy protection standards.

We do not sell your personal data to any third party.

Where your personal data must be shared with a third party in circumstances outside our standard relationship with you, we will request your consent unless the disclosure is: (a) requested by an authority or law enforcement agency; (b) clearly in your interests and consent cannot be obtained in a timely manner; (c) necessary to respond to an emergency threatening life, health, or safety; or (d) required, permitted, or authorized under applicable laws and regulations.


6. Data Security

We are committed to protecting the security of your personal data. We implement the following technical and organizational measures:

  • Password Protection: Passwords are hashed before storage. We never store plaintext passwords.
  • PIN Protection: PINs are hashed before being stored in your device's secure storage. We never store plaintext PINs.
  • Transport Encryption: All communications between the app and our servers use HTTPS/TLS encryption.
  • Access Controls: Files and data are protected by access controls with least-privilege permissions.
  • Database Security: Our database uses parameterized queries to prevent injection attacks.
  • Account Deactivation: Deleted accounts are deactivated rather than immediately purged, allowing for recovery in case of accidental deletion and ensuring compliance with regulatory retention requirements.

Despite these measures, no method of electronic transmission or storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a data breach, we will follow the procedures outlined in Section 8 of this policy.


7. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws. The following retention periods apply:

Data CategoryRetention PeriodBasis
Account data (email, name, username, DOB)Duration of active account + 7 years after account closureAML/regulatory record-keeping requirements
KYC documents and selfie imagesDuration of active account + 7 years after account closureAML/regulatory requirements
Wallet dataDuration of active account + 7 years after account closureFinancial record-keeping
Session tokensAccess token: 30 minutes; Refresh token: 7 daysTechnical necessity (auto-expire)
Local device storage (preferences, PIN hash)Cleared upon sign-out or app uninstallDevice-local
Automatically collected data (IP, device info)Up to 2 yearsSecurity and analytics purposes

Account Deletion:

You may delete your account through the app (Settings > Privacy > Delete Account). Upon deletion, your account is deactivated. To request full erasure of your personal data, please contact legal@moneyr.app. We will process erasure requests subject to any overriding legal obligations to retain certain data (e.g., AML record-keeping requirements).


8. Data Breach Notification

In the event of a personal data breach that is likely to result in a real risk of significant harm to affected individuals, Moneyr will:

  1. Notify the Privacy Commissioner for Personal Data, Hong Kong as soon as reasonably practicable, and where feasible, within 72 hours of becoming aware of the breach.
  2. Notify affected individuals without undue delay, providing:
    • The nature of the breach
    • The types of personal data affected
    • The likely consequences of the breach
    • The measures taken or proposed to address the breach and mitigate potential harm

Moneyr maintains incident response procedures including containment, investigation, remediation, and notification protocols.


9. Your Rights Regarding Personal Data

As a user of Moneyr services, you have the following rights under the PDPO:

Data Access Request (DAR): You may request a copy of the personal data we hold about you, in accordance with Section 18 of the PDPO. Submit your request in writing (in Chinese or English) to support@moneyr.app.

Data Correction Request (DCR): You may request correction of any inaccurate personal data we hold about you, in accordance with Section 22 of the PDPO. Submit your request in writing (in Chinese or English) to support@moneyr.app.

Response Timeline: We will respond to DARs and DCRs within 40 calendar days of receiving your request.

Objecting to Data Use: You may object to our use of your personal data by contacting support@moneyr.app. Please note that this may impact your ability to use some or all of our services.

Withdrawal of Consent: If you wish to withdraw your consent for the use of your personal data, please discontinue using our services and notify us at legal@moneyr.app. Upon receiving your request, we will process it promptly. Withdrawal of consent may result in the termination of your access to our services and may have legal implications for our ongoing relationship.

Grounds for Declining Requests:

We may decline to comply with a DAR or DCR in the following circumstances:

  1. A government agency or regulator with jurisdiction over Moneyr directs us not to comply;
  2. The information may, in our assessment, affect the safety of any person;
  3. The data may be relevant to a regulator or official investigation involving criminal conduct or breach of applicable laws;
  4. The request is not submitted in Chinese or English;
  5. We are unable to verify the identity and authority of the requestor;
  6. We are not satisfied that the personal data to which a DCR relates is inaccurate;
  7. We are not provided with sufficient information to determine that the data is inaccurate; or
  8. We are not satisfied that the correction provided in the DCR is accurate.

Right to Erasure: You have the right to request erasure of your personal data. We will comply with erasure requests where the data is no longer needed for its original purpose, except where law, regulatory requirements, or public interest prevent such erasure. When you submit an erasure request, we may ask for identification to verify your identity.

Right to Complain: If you are not satisfied with our handling of your personal data, you have the right to lodge a complaint with the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).


10. Children's Restriction

Moneyr services are not available to individuals under the age of 18. Age verification is enforced at registration: you must provide a date of birth confirming you are at least 18 years of age to create an account.

Moneyr does not knowingly collect personal data from individuals under 18. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data promptly.

If you believe that a person under 18 has provided personal data to Moneyr, please contact us at support@moneyr.app.


11. External Links

Our app and website may contain links to external websites or applications not operated by Moneyr. When you follow these links, this Privacy Policy no longer applies. We encourage you to review the privacy policies of any external platforms you visit. Moneyr is not responsible for the privacy practices of third-party websites or applications.


12. Cookies and Tracking

Website: Our website (moneyr.app) may use cookies — small data files stored on your device — for the following purposes:

  • Keeping you signed in to your account
  • Remembering your preferences and settings
  • Analyzing site usage to improve design and functionality

Mobile Application: Our mobile application does not use browser cookies. Instead, it uses secure on-device storage for authentication tokens and local preferences storage for settings and user preferences.

Third-Party Tracking: Moneyr does not use third-party advertising trackers in our mobile application.

Managing Cookies: Most browsers accept cookies automatically. You can adjust your browser settings to reject cookies or to notify you when cookies are placed. Disabling cookies may affect your ability to use some features of our website.

Do Not Track (DNT): We acknowledge DNT signals from your browser. However, third-party services accessed through our platforms may not honor DNT requests. This Privacy Policy does not cover third-party tracking practices.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this policy. If the changes are material, we will notify you by email (to the address associated with your account) or by providing notice through our services.

We encourage you to review this Privacy Policy whenever you access our services to stay informed about our data practices.

By continuing to use our services after changes to this Privacy Policy take effect, you agree to be bound by the revised policy.


14. Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or need to make a Data Access Request or Data Correction Request, please contact us:

General Queries and Support:
support@moneyr.app

Legal and Privacy Matters (including DAR, DCR, erasure, and consent withdrawal):
legal@moneyr.app

Moneyr Limited
Company No. 79829784
Unit P25, 13/F, Kaiser Estate 3rd Phase
No. 11 Hok Yuen Street, Hung Hom
Kowloon, Hong Kong SAR

Privacy Commissioner:
If you wish to lodge a complaint regarding our handling of your personal data, you may contact the Privacy Commissioner for Personal Data, Hong Kong at www.pcpd.org.hk.