BITPAY
AboutPricingServicesNewsBlogFAQSecurity
Privacy Policy

Privacy Policy

Operating without KYC is the design, not an oversight. This policy explains exactly what data we collect, why we collect it, and what we never touch. BitPay collects the minimum data necessary to operate a virtual debit card program - nothing more.

Last updated: 2026-07-25. Effective immediately. Previous versions are archived in the cabinet under Settings> Legal.

Contents

  1. 1. What this document covers
  2. 2. The data we collect
  3. 3. The data we never collect
  4. 4. How we use the data we collect
  5. 5. Card networks and third-party processors
  6. 6. Cookies, sessions, and analytics
  7. 7. Anti-money laundering and counter-terrorism financing (AML/CFT)
  8. 8. Data retention
  9. 9. Your rights
  10. 10. International transfers
  11. 11. Security
  12. 12. Changes to this policy
  13. 13. Contact

1. What this document covers

This Privacy Policy explains what information BitPay (BitPay Labs) collects when you use our virtual debit card platform, how we use that information, who we share it with, and what we never do with it. Our no-KYC product is built around the principle that collecting less data is better than collecting more, and this document is the operational expression of that principle.

By creating an account, issuing a virtual debit card, or using the Telegram Mini App, you confirm that you have read this policy and agree to the data handling described here. If you do not agree, do not use the service.

2. The data we collect

We collect the minimum data necessary to operate a virtual debit card program. Concretely: an email address (your account identifier), a password (stored as a one-way hash), your Telegram handle if you link the Mini App, your crypto deposit addresses (one per coin), and your transaction history (deposits, conversions, charges, refunds, disputes). That is the full set.

We do not collect your name unless you voluntarily provide it. We do not collect your address. We do not collect your date of birth. We do not collect a government ID. We do not collect a selfie. We do not collect biometric data. We do not run a credit check. We do not maintain a Social Security Number or equivalent national identifier. If a feature would require one of these to function, we do not ship that feature.

3. The data we never collect

The above list of what we do not collect is not exhaustive, but it covers the categories that matter for our product. Specifically: we never collect KYC documents, biometric identifiers, device fingerprints beyond what is technically required to operate the session, social graph data (other than your Telegram handle if you link it), or any category of sensitive personal information defined by GDPR Article 9 or equivalent regulations.

Operating without KYC is not an oversight. It is the design. The reason a BitPay account can be created in under a minute is that we are not running a multi-stage verification process in the background. If we ever did, we would lose the property that makes BitPay useful - fast, private, programmatic access to a USD-denominated card.

4. How we use the data we collect

Your email address is your account identifier. We use it to send account notifications, password recovery, and security alerts. We do not sell it, rent it, or share it with third parties for marketing. Your password is stored as a one-way cryptographic hash using industry-standard algorithms; even our engineers cannot recover it.

Your transaction history is used to provide the card history feed, dispute resolution, and per-card spending analytics. It is stored for 24 months by default, accessible from the cabinet and via the REST API. Custom retention options are available on CUSTOM tier. We do not share transaction history with third parties except as required to process card transactions through the card networks or to comply with legal obligations.

5. Card networks and third-party processors

When you issue a card and make a charge, the transaction flows through standard card networks (Visa, Mastercard). These networks receive the merchant name, amount, time, and your card number. This is standard infrastructure for any card program and is the minimum disclosure required for the charge to clear. BitPay does not control what the card networks log; we operate within their standard data-handling agreements.

Crypto conversion uses third-party liquidity providers. These providers receive the conversion request, the source cryptocurrency, the amount, and the destination wallet address. They do not receive your email, account information, or any identifier that links the conversion to your BitPay account beyond the wallet address you used.

6. Cookies, sessions, and analytics

The cabinet uses session cookies to keep you logged in. These are necessary cookies, not tracking cookies. They are deleted when you log out or close the browser. We do not use third-party analytics on the cabinet - the cabinet is your private workspace, not a marketing surface.

The marketing pages (this site) use minimal analytics to understand traffic patterns. The data is anonymized: we know a page was visited, not who visited it. We do not use this data to build user profiles, retarget ads, or sell to data brokers.

7. Anti-money laundering and counter-terrorism financing (AML/CFT)

Although BitPay does not conduct KYC, the platform operates under a strict AML/CFT policy. This policy includes transaction monitoring for patterns consistent with money laundering, terrorism financing, sanctions evasion, fraud, and other financial crimes. Patterns we monitor include: rapid in-and-out cycles consistent with structuring, transactions involving sanctioned addresses (as identified by blockchain analytics providers), sudden changes in transaction volume inconsistent with account history, and coordination across multiple accounts.

When our monitoring flags a transaction pattern, the affected USD balance is held, the cards are frozen, and the case is reviewed by our compliance team. If the review confirms suspicion, we cooperate with relevant law enforcement and may be required to disclose user data. We do not provide advance notice of disclosure if doing so would impede an investigation, and we comply with all applicable laws.

8. Data retention

Default retention is 24 months for transaction history and account state. CUSTOM tier accounts can request 5-year retention. After retention expires, data is deleted from active systems within 90 days and from backups within 180 days. Anonymized data may be retained indefinitely for statistical purposes.

If you delete your account, your USD balance is settled per standard refund procedures, your cards are frozen, your account state is anonymized, and your identifying data (email address) is removed from active systems within 30 days. Backups are purged within 180 days.

9. Your rights

You have the right to access the data we hold about you. You have the right to correct inaccurate data. You have the right to delete your data subject to our legal retention obligations. You have the right to object to processing. You have the right to data portability.

To exercise these rights, contact us via the support channel in the cabinet or via Telegram. We respond within 30 days. For accounts where we are legally required to retain data (ongoing disputes, regulatory holds), we will explain what we are retaining and why.

10. International transfers

BitPay operates globally. Your data may be transferred to and processed in countries other than your country of residence. We use standard contractual clauses and equivalent legal mechanisms to ensure your data receives equivalent protection regardless of where it is processed.

Specifically: card processing may involve servers in the United States, European Union, and Singapore. Crypto conversion may involve liquidity providers in multiple jurisdictions. By using BitPay, you consent to these transfers. We do not transfer data to jurisdictions with weaker data protection laws without adequate safeguards.

11. Security

Security is built into the architecture: no-KYC means we cannot leak KYC documents; password hashing means we cannot leak plaintext passwords; transaction monitoring means fraud is detected before it scales; freeze controls mean compromised cards can be locked in under a second. Combined with industry-standard encryption, session management, and infrastructure security, this gives a stronger privacy posture than most traditional banks.

You are responsible for your account security: keep your password secret, do not share session tokens, enable two-factor authentication if available, log out of shared devices, and use a unique email address that you control. We will never ask for your password or send you login links via email. If anyone does, treat the message as fraudulent.

12. Changes to this policy

We may update this policy to reflect changes in our product, the regulatory environment, or industry best practices. When we do, we update the date at the top, notify active account holders via email if the change is material, and give 30 days notice before the change takes effect for material changes.

Material changes include: new categories of data collected, new third parties with whom data is shared, new jurisdictions to which data is transferred, or material changes to user rights. Non-material changes (clarifications, typo fixes) do not trigger the notice period.

13. Contact

For privacy questions, data access requests, or to exercise your rights, contact our privacy team via the support channel in the cabinet or via Telegram through the Mini App. We respond within 30 days.

For general product questions, use the standard support channels. For security incidents, use the urgent security contact in the cabinet.

Related reading

User Agreement

Read the User Agreement that governs your use of BitPay - including your sole responsibility for card usage, AML/CFT compliance, and our no-bank, no-financial-services terms.

Security controls

See the technical controls (freeze, 3-D Secure, fraud signals, merchant locks) that protect your account - and how to configure them.

BITPAY

The no-KYC virtual debit card platform for crypto-first users. Fund with Bitcoin, Ethereum, USDT, USDC, BNB, Solana, Litecoin, or Avalanche and spend USD worldwide.

Product

  • Where it works
  • Pricing
  • Security controls
  • Open an account

Resources

  • FAQ
  • Blog
  • News
  • Get your debit card

Company

  • About BitPay
  • Sign in
  • Create account
  • Newsroom
Trusted infrastructure
VISAVisa acceptedWorldwide Visa network
TLS 1.3 secured256-bit encryption
2FA protectedTOTP + recovery codes
AML / CFT policyCompliant operations
GDPR alignedData minimization
No KYC requiredPrivacy by design
Audited codeIndependent reviews
Global coverage180+ countries
Accepted cryptocurrencies
BTCETHUSDTUSDCBNBSOLLTCAVAX

© 2026 BitPay Labs. All rights reserved.

Security·FAQ·About·Privacy Policy·User Agreement

Cryptocurrency deposits are converted to USD balance. Operating without identity verification in selected jurisdictions. No KYC required per current policy — subject to compliance updates.