Privacy Statement for Users
0. Executive Summary
0.1 Why, what, where, when, who, and how (long)
Why: The first and foremost reason we ask you for personal details is to be able to offer you a smooth and seamless experience to use our service and the services of the onramps (aka Fiat Gateways) of your choice by providing our trusted Fiat Gateway partners (which offer fiat-to-cryptocurrency conversion services) with your relevant personal information to avoid being bothered to provide this information to each Fiat Gateway again (and again and again...).
To facilitate your use of Fiat Gateways, Onramper collects and stores certain KYC/AML-related data. This can include name, email or phone number, address, identification documents, proof of address, source of funds, wallet address and transaction-related data.
Onramper uses a third-party verification provider, Sumsub, to carry out identity verification. When you complete verification, Onramper holds a verification token linked to your Sumsub verification record. When you select a Fiat Gateway, Onramper shares that token with the selected Fiat Gateway so that it can access your verification data directly from Sumsub, without Onramper transmitting your raw identity documents. Onramper retains KYC-related data for as long as necessary to provide its services and as further described in the retention section below.
What: We (also) collect and process certain personal and non-personally identifiable information to offer, enable and improve our service and Platform. The non-personally identifiable information includes transactional data and product usage data. The personal identifiable information includes your wallet address. We additionally collect your email address.
What else — rights: You will have all rights granted by applicable law, such as the right to know what information we hold, the right to be forgotten, and the right to amend, correct, delete, or block your personal information.
What else — security: We have implemented a range of procedures, controls and measures to prevent unauthorized access to, and the misuse of, your personal data that we process.
When: Upon registration with Onramper (or at any time thereafter), Onramper may ask you to provide, update and complete relevant required personal information in its system through the website, app, or browser extension on which the Onramper service is available to you.
Who: Onramper is responsible for the personal data it collects in relation to Onramper’s product and Account service, and acts as a data controller for such data.
What about the Fiat Gateways: the processing of any (personal) data by the User when making use of the services provided by the Fiat Gateway(s) is subject to and governed by the privacy statement of the relevant Fiat Gateway. Each Fiat Gateway acts as an independent data controller for the personal data it receives or accesses in connection with its own services.
Furthermore, Onramper may share certain personal information with its affiliated group companies (e.g. for customer service) and trusted subcontractors. Onramper is responsible for these parties (which act as data processor subject to a data processor agreement with Onramper).
How (long): We will collect and process your personal information in accordance with this privacy statement and retain your personal data for as long as necessary to provide Onramper services to you, manage our relationship with you, resolve disputes, and for our other legitimate business purposes. Further detail on retention periods by data category is set out in Section 6 below and is available upon request.
The above is a general overview. Depending on the law that applies to you, we might be required to provide some additional information. Please find below more detailed information about the use and process of your personal information.
Glossary: appendix 1 includes a glossary with relevant privacy terms and their definitions.
1. Introduction and Definitions
1.1 About Onramper
1.1.1 We are Onramper Technologies B.V., a private limited liability company, incorporated under the laws of the Netherlands and having its registered office at Prins Hendrikkade 21 E (1012TL) in Amsterdam (trade register: 76602877). Onramper Technologies B.V. may be referred to in this document as ‘we’, ‘us’, ‘our’, or ‘Onramper’.
1.1.2 We collect personal data via our Platform (website, app, and browser extension) and service.
1.1.3 The personal data that Onramper collects in relation to its users depends on the context of the business relationship and their interaction with Onramper, the choices the user makes, and the products, services and functions they use.
1.2 Privacy statement and acceptance
1.2.1 This privacy statement explains how Onramper processes your personal data. ‘You’, ‘your’ or ‘User’ means you, the user of our service as made available on our website, app, or browser extension (the “Platform”), including any other natural person of whom the personal data is provided to Onramper.
1.2.2 This privacy statement applies to every group company of Onramper that is responsible for or involved in the processing of a User’s personal data. Depending on the nature of the business relationship, various group companies of Onramper may be responsible for the processing of that personal data.
1.2.3 By using our services, you acknowledge that you have read and understood this privacy statement. This notice describes how and why we process your personal data. The lawful bases on which we rely for each processing purpose are set out in Section 3.2 below. Where we rely on your consent for a specific processing activity, we will request that consent separately and you may withdraw it at any time.
2. Data Collection
2.1 Personal data that Onramper collects
2.1.1 Personal data that you — as a User — (may) provide to us includes:
Personal data (including KYC/AML-related data)
If you wish to open an account with us, we may collect relevant contact information from Users, such as first and last name, place/date of birth (if required), (email) addresses, (mobile) telephone numbers, preferences or special requests, identification documents, source of funds, proof of address, etc. Furthermore, we process your (public) wallet address.
Transactional data
We collect information about your transaction history with Fiat Gateways, incl. the type of virtual financial assets involved, the order volume, price, value, and information on which bank is used for a transaction identified through the processing of a part of your credit card number. This does not include any personally identifiable information.
Usage data
Information we collect automatically about how you use our Platform (i.e. website, app, or browser extension) and Software (i.e. Onramper widget, API and such other software components as used or built by Onramper to render the Service) (the “Product Usage Data”), including information on the device(s) you may use (the “Device Information”) and information on when, where and how you use our Platform and/or Software, including your IP address and info such as your browser type (the “Log Data”). For a more specific overview of what data and information (including personal data) is collected automatically, see below and our cookie statement.
Other data
When a User communicates with Onramper, we may collect and process information about this communication. During calls with our customer service (including when being in queue or on hold), live listening and calls can be recorded for quality control and training purposes. These recordings can also be used for claims handling and fraud detection.
Recordings are kept for a limited time before they are automatically deleted unless Onramper has a legitimate interest in keeping the recording for longer. This only happens in exceptional cases, such as for fraud investigation, compliance, and legal purposes.
2.2 Information We Collect Automatically
2.2.1 Depending on the business relationship, Onramper may also automatically collect information, some of which may be personal data. This data is collected when a User uses online services such as a registration form or a user account.
The data collected may include:
- Language settings
- IP address
- Place
- Device settings
- Device operating system
- Log information
- Time of use
- URL requested
- Status report
- User-agent (information about the browser version)
- Browsing history
- Browsing behaviour
- The type of data being viewed
2.3 Other information we receive from other sources
Fiat Gateway data
Fiat Gateways may share certain personal data with us. This can include your phone number, country, your email address and your name, but does not include credit card numbers or any other PAN or CVC data. To learn more about the data processing that occurs when making use of the services offered by Fiat Gateways, see relevant Fiat Gateways’ privacy statement for more information.
Data related to requests from law enforcement and tax authorities
Law enforcement or tax authorities may contact Onramper with additional information about Users in the event that they are affected by an investigation.
Fraud detection & prevention, risk management & compliance
In certain cases, and as permitted by applicable law, Onramper may need to collect data from third-party sources for fraud detection and prevention, risk management, and compliance purposes (e.g. sanction/PEP screening).
3. Processing purposes and sharing
3.1 Purposes
3.1.1 Onramper uses the previously described information about Users, some of which may be personal data, where relevant, for the following purposes:
A. Registration and administration
Onramper uses account information, contact details, and financial information to manage and maintain the business relationship with the User and to render its service to you. This also applies to registration and verification purposes.
Important notice: there is no obligation for you to open an Account and provide your personal data to us. You can continue using our services without the need for an Account. The Account is optional and helps you to enjoy the verification service, if desired by you.
B. Render its service (including verification service and customer service)
We may collect email addresses and phone numbers in order to provide quicker check-outs, transaction history functionality and better recommendations.
Your (public) wallet address is used for sending the crypto to your wallet.
The processing and storage of KYC/AML data by Onramper ensures a smoother and less repetitive onboarding experience for users, reducing the need for repeated KYC checks across different fiat gateways and facilitates onboarding to third-party fiat providers. When you complete identity verification through your Onramper Account, your verification is carried out by our verification provider, Sumsub, within Sumsub’s own environment. Onramper receives a verification token confirming the outcome of that verification. When you select a Fiat Gateway, Onramper shares that verification token, not your raw identity documents or images, with the selected Fiat Gateway, enabling it to access your verification data directly from Sumsub. Onramper does not access or process any biometric data; to the extent any biometric processing occurs during identity verification, it takes place solely within Sumsub’s environment and is governed by Sumsub’s own privacy notice.
C. Other activities, including marketing
If a potential User has not yet completed the online registration, Onramper may send a reminder to complete the registration process. We believe that this extra service is useful for our (future) Users because it allows them to complete the registration without having to re-enter all registration details.
Onramper may invite Users to complete user/product reviews, ratings and scores and attend (online) events, seminars, webinars that may be relevant or interesting to them or where they can share crypto or Fiat Gateway related products and services. We may also use personal data to provide and host online forums that allow Users to find answers to frequently asked questions about the range and use of Onramper’s products and services.
Marketing (e.g. newsletters): To the extent relevant to the business relationship, Onramper may use personal data for communication, including providing information about its systems or product updates, sending Onramper newsletters, and inviting Users to participate in references, promotions, or for other marketing communications. When we use personal information to send direct marketing messages electronically not for or related to our service, we offer an active opt-in option.
D. Communication with users
For any User who has signed up for an Account, Onramper may have (access to) communication with you (telephone, chatbot, email, Platform). We may use automated systems to review, scan and analyze communications for the following purposes:
- Safety
- Fraud prevention
- Compliance with legal and regulatory requirements
- Research possible misconduct
- Product development and improvement
- Research
- Customer engagement (including providing information or offers to Users that we think may be of interest to them)
- Customer or technical support
Communications sent or received using Onramper’s means of communication are received and stored by Onramper. We do not record all calls. If a call is recorded, each recording is kept for a limited time before being automatically deleted. This is the case unless we have determined that it is necessary to keep the recording for fraud investigation or legal purposes.
E. Analysis, improvement and research
Onramper uses the information provided to us, which may include personal data, for analytical and research purposes. This is part of our commitment to improve Onramper’s products and services and to improve the user experience in respect of our Platform, Service and Software (e.g. customize the content, user experience and layout of the Platform).
The data can also be used for identification of IT or network issues, testing purposes, troubleshooting and improving the functionality and quality of Onramper’s online services. We may also record some live sessions using tools such as Hotjarsession-recording tools and invite users to participate in surveys and other market research from time to time.
Certain Users may be invited to join a user forum to communicate with Onramper and/or to exchange experiences with other Users.
Please refer to the information Onramper provides when you are invited to participate in a survey, market research or to join an online Platform to understand how your personal data may be treated differently than described in this Privacy Statement.
F. Security, fraud detection, administration and prevention
We process the information provided to us, which may include personal data, to investigate, prevent and detect fraud and other illegal acts and to manage our Platform (including system administration). This may include personal data that a User has provided to Onramper, for example for security and verification purposes as part of the registration process, personal data collected automatically, or personal data obtained from external sources (including from guests). We also use the information to identify mal-intended usage of our Platform, Service and/or Software, prevent fraud, money laundering and unauthorized use of our Service, Platform and Software.
Onramper may also use personal data to facilitate investigation and enforcement by competent authorities, if necessary. For these purposes, personal data may be shared with law enforcement authorities.
Onramper may also use personal data for risk assessment and security purposes, including user authentication, and we use external service providers for third-party risk management. These providers help us assess the business risk profile of our Users. They may also provide us with due diligence reports from third parties, which, as permitted by applicable law, may contain potential information about criminal convictions and owner or User violations.
Onramper may share certain personal data with vetted third parties for the purpose of issuing financial instruments such as cards or IBANs, provided the processing is in line with applicable data protection laws and subject to user consent where required.
G. Legal, regulatory and compliance
In certain cases, Onramper must use the information provided (which may include personal data) to handle and resolve legal disputes or for regulatory investigations, risk management and (regulatory) compliance. We may also use it to enforce our agreement(s) with Users or to resolve any complaint or claim involving a User, and in accordance with internal rules and procedures.
In addition, we may need to share information about Users (including personal data) where required to do so by law or strictly necessary to respond to requests from competent authorities. This includes tax authorities, courts, other government and public authorities, or local municipalities (for example, regarding short-term rental laws).
Onramper may use personal data for screening purposes (including screening against sanctions lists and lists of politically exposed persons) as part of its risk management and fraud-prevention activities.
Onramper does not currently make decisions based solely on automated processing (including profiling) that produce legal effects or similarly significant effects on you. To the extent any such decisions are made by Fiat Gateways or verification providers in connection with their own services, those decisions are governed by those parties’ respective privacy notices.
3.2 Legal grounds
3.2.1 Onramper processes personal data on the basis of one or more lawful grounds depending on the purpose. The table below summarizes the primary lawful basis for each category of processing:
| Processing Purpose | Primary Lawful Basis |
|---|---|
| A. Registration and administration | Performance of a contract (Art. 6(1)(b)) |
| B. Rendering services, including centralized KYC verification and token sharing with selected Fiat Gateways | Performance of a contract (Art. 6(1)(b)) |
| C. Direct marketing communications (electronic) not related to our service | Consent (Art. 6(1)(a)) |
| D. Service-related communications and registration reminders | Legitimate interest (Art. 6(1)(f)) |
| E. Communication with users | Legitimate interest (Art. 6(1)(f)) |
| F. Analysis, improvement and research | Legitimate interest (Art. 6(1)(f)) |
| G. Security, fraud detection and prevention, including screening | Legitimate interest (Art. 6(1)(f)) |
| H. Legal, regulatory and compliance (e.g., responding to lawful requests from competent authorities) | Compliance with a legal obligation (Art. 6(1)(c)) and/or legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interest as the lawful basis, our interest is in providing, securing and improving our services. We balance this interest against your rights and freedoms before undertaking the processing. You have the right to object to processing based on legitimate interests at any time (see Section 7).
3.2.2 Onramper relies on contractual necessity as a legal basis for processing personal data for Purposes A and B. The processing of this data is essential for the execution of the agreement between the User and Onramper. Without the provision of certain required personal data, Onramper may be unable to deliver its core services to the User, including but not limited to identity verification, and customer support.
Specifically, the processing is necessary to:
- Keep the user logged in with underlying fiat gateways;
- Find out which fiat gateway is best suited for the user;
- Enable users to complete identity verification once through Onramper’s centralized verification service and share a verification token with selected Fiat Gateways, reducing the need for repeated KYC checks;
- Provide user support and fulfill operational needs tied to the use of Onramper’s services.
Failure to provide the requested personal data may result in an inability to access or use certain services, including those related to buying, selling or converting crypto via Fiat Gateways.
With regard to the public wallet address, the processing is also necessary for the performance of the contract, as it enables the delivery of crypto assets to your wallet by the selected Fiat Gateway.
The collection and storage of KYC/AML data by Onramper is necessary for the performance of the contract (Purpose B). When you select a Fiat Gateway or other supported partner through the Onramper ID service, the sharing of your verification token with that partner is necessary for the performance of the contract — specifically, to provide you with the Onramper ID service you have requested. Further information about your rights, including how to object to processing based on legitimate interest, is set out in Section 7.
3.2.3 Purposes C to G: Onramper relies on its legitimate interest to provide its services to, or obtain services from Users, to prevent fraud and to improve its services. When we use personal data to serve the legitimate interest of Onramper or a third party, we will always balance the rights and interests of the data subject and the protection of their information against the rights and interests of Onramper and/or the third party.
3.2.4 Purpose G: Onramper also relies, where applicable, on compliance with legal obligations (such as law enforcement requests and other lawful requirements of competent authorities).
3.2.5 Where we rely on your consent for a specific processing activity (such as electronic direct marketing not related to our service), you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. If you wish to object to processing under Purposes D through G (which are based on legitimate interest) and cannot find a way to opt out directly (for example in your account settings), please contact Onramper at compliance@onramper.com.
3.3 Identity Verification and Reuse Service (Onramper ID)
As part of our Services, Onramper offers an optional identity verification and reuse service (“Onramper ID”). This service is designed to allow Users to verify their identity once and reuse that verification across multiple supported fiat gateways and selected partners, reducing the need to repeat verification processes.
Onramper will only share personal data (including KYC/AML data) with partners to the extent strictly necessary for the specific purpose selected by the User. Where technically feasible, Onramper will share a verification token or confirmation of verification status instead of underlying personal data.
Centralized verification and storage
When you choose to use Onramper ID, we collect and process your identification and verification data (including KYC/AML-related data such as identity documents and personal details) and store this data in a secure environment in accordance with applicable legal and regulatory requirements.
Verification through third-party provider (Sumsub)
For the purpose of identity verification, Onramper uses a trusted third-party service provider, Sum and Substance Ltd. (“Sumsub”), which acts as our data processor. Sumsub performs identity verification checks on our behalf and processes personal data in accordance with our instructions and applicable data protection laws.
Tokenization and verification results
Following successful verification, Onramper may generate or receive a verification result or token that represents the outcome of your identity verification. This token does not replace your personal data but serves as a secure reference to your verified status, enabling more efficient reuse of your verification with supported partners.
Reuse of verification data
Where you request to transact with a fiat gateway or other supported partner, Onramper may reuse your previously verified identity data and share the relevant verification data (or verification token, where applicable) with the partner you have selected, in order to facilitate onboarding, compliance checks and transaction processing. When Onramper shares a verification token with a selected partner, that partner uses the token to access your verification data from Sumsub and copy it into the partner’s own verification environment. Onramper does not transmit your raw identity documents directly to any partner.
Such reuse will only take place:
- in relation to partners you actively select, and
- for purposes compatible with the original verification purpose, including compliance with legal and regulatory obligations (such as KYC/AML requirements).
Role allocation
Onramper acts as an independent data controller for the collection, verification, storage and transmission of your personal data in connection with Onramper ID. Each fiat gateway and financial service provider that receives your data acts as an independent data controller for the processing it carries out in its own systems for its own purposes (such as onboarding, compliance, fraud prevention and, where applicable, marketing, subject to your consent where required).
Optional nature of the service
The use of Onramper ID is optional. You may choose to complete verification directly with a fiat gateway instead. Where you use Onramper ID, you can stop using the service at any time, although this may affect your ability to reuse your verification across partners.
3.4 Selling or transferring user data for commercial use
3.4.1 To deliver certain services you request through the Platform — including facilitating onboarding, compliance checks, and transaction processing with integrated wallet providers or other financial service providers (e.g. card issuers) — Onramper may share relevant personal data (including KYC/AML information) with those partners only where you have actively opted in to the use of such service and requested the relevant integration or transaction.
Where such sharing is necessary to provide a service you have explicitly requested, actively selected or initiated (e.g. a transaction with a specific fiat gateway partner), the sharing will take place as part of the performance of the contract.
In all other cases, including where partners wish to use your data for their own independent purposes (such as creating or managing an account with them, internal business purposes, or marketing), Onramper will only share your personal data with your prior explicit consent.
In relation to integrations with wallet providers or card issuers (together, “Financial Service Providers” or “FSPs”), Onramper and the relevant FSP each act as independent data controllers in respect of the personal data they process.
Onramper is responsible for the collection of your personal data through the Platform, the identity verification process (including via its verification partners), and the secure transmission of your data to the FSP you have selected.
The relevant FSP is responsible for processing your personal data within its own systems for its own internal purposes, including onboarding, compliance (such as KYC/AML obligations), account management, fraud prevention and, where applicable and subject to your consent, marketing.
Financial Service Providers are contractually required to process personal data only for the purposes for which it was shared, and are prohibited from using the data for unrelated purposes, including profiling, resale, or sharing with third parties, unless required by law or explicitly authorized by the User.
Each party is responsible for handling your data subject rights in relation to the processing it carries out. You should refer to the privacy statement of the relevant FSP for further information on how it processes your personal data.
You can also find more details in the privacy statement of the relevant FSP.
You may exercise your data subject rights under applicable law against Onramper in relation to the processing carried out by Onramper, and against the relevant FSP in relation to the processing carried out by that FSP.
Where appropriate, Onramper may assist in facilitating your request or redirect it to the relevant FSP.
3.5 Onramper Browser Extension
The Onramper Browser Extension (the “Extension”) provides browser-based access to the existing Onramper checkout widget through a Chrome Side Panel. The Extension does not require an account or login and is designed to minimize data collection.
3.5.1 Data collected by the Extension
The Extension itself collects and stores only the following data, all of which is held locally on your device:
- User preferences (display mode, default fiat currency, default amount, default cryptocurrency, and theme preference);
- Up to five wallet aliases (a label and associated wallet address), saved in your browser’s local storage by default.
3.5.2 Network requests
The Extension makes a single network call outside of the embedded checkout widget: a request to api.onramper.com/supported/defaults/all, used solely to detect your default currency based on your geographic location. This request does not include any user identifier — only the source IP address inherent to any HTTP request and a publishable API key are transmitted. No personal data is sent or collected through this call.
3.5.3 Embedded checkout widget
The checkout widget displayed within the Extension is the same hosted Onramper widget available at onramper.com. Any data processed within the widget (such as transaction data or KYC/AML verification data) is governed by the relevant sections of this privacy statement (see Sections 2, 3.1, 3.2, and 3.3 above) and by the privacy notices of the applicable Fiat Gateways.
3.5.4 Local storage and sync
By default, your preferences and wallet aliases are stored only in your browser’s local storage (chrome.storage.local) and are not transmitted to any server. You may opt in to cross-device synchronization (chrome.storage.sync), which uses Google’s Chrome Sync infrastructure to sync your preferences and wallet aliases across devices where you are signed in to Chrome. If you opt in to sync, the synced data is limited to: mode preference, default fiat currency, default amount, default cryptocurrency, theme preference, and wallet aliases. No email address, API key, or other personal identifiers are synced.
Please note that if you enable sync and later uninstall the Extension, the synced data may remain on Google’s servers. To ensure deletion, use the “Erase all data” function in the Extension’s settings before uninstalling.
3.5.5 Context menu and clipboard
The Extension provides a right-click context menu option that detects wallet addresses in selected text using local pattern matching. This detection occurs entirely on your device — no data is transmitted or stored. The Extension also uses clipboard write access to allow you to copy wallet addresses. The Extension cannot read your clipboard.
3.5.6 Omnibox
The Extension allows you to type commands (such as “buy 100 eth”) in the browser address bar. These inputs are parsed locally and are never transmitted to any server.
3.5.7 No analytics or tracking
The Extension does not use any analytics, tracking, or monitoring tools. No cookies, pixels, or third-party tracking scripts are used by the Extension. The Extension does not collect or transmit any usage data, browsing behavior, or session recordings.
3.5.8 Deleting Extension data
To delete all data stored by the Extension, use the “Erase all data” function in the Extension’s settings. This will remove all locally stored preferences and wallet aliases. If you have opted in to Chrome Sync, we recommend using “Erase all data” before uninstalling the Extension, as uninstalling alone may not remove synced data from Google’s infrastructure.
4. Share with others
4.1 Sharing with affiliated group companies
4.1.1 To support the use of Onramper services, your information (which may include personal data) may be shared with or within Onramper affiliates. This is done for the purposes described below, subject to any contractual terms.
The purposes for sharing data within the Onramper group of companies are:
A. to offer, provide or make available services and products and to provide (customer) support;
B. to prevent, detect and investigate fraud and other illegal activities;
C. for quality assurance and service improvement purposes;
D. legal purposes, including the handling of complaints, claims, legal claims, and for the detection of fraud;
E. to ensure compliance with applicable (financial and privacy) laws or law enforcement.
With a view to purpose A, and insofar as applicable, Onramper relies on the legal basis that the processing of personal data is necessary for the performance of the agreement with you.
Onramper further relies on its legitimate interest and that of its group companies to receive, process, and share personal data as described under B to E. This is to provide services to or obtain services from Users, including to improve the services and prevent fraud or other illegal acts. When personal data is used to serve the legitimate interest of Onramper or a third party, Onramper will always balance the rights and interests of the person concerned in protecting their personal data and the rights and interests of Onramper or the third party.
For purpose E, Onramper also relies on compliance with legal obligations where applicable (such as lawful law enforcement requests or enforcing its terms and conditions for use of the service and compliance with financial laws for AML/KYC purposes (including sanction screening)).
Finally, where needed under applicable law, Onramper will obtain your consent prior to processing your personal data, including for email marketing purposes or as otherwise required by law.
If you wish to object to the processing as set out under B to E, and cannot find a way to unsubscribe directly (for example in your account settings), please contact Onramper at compliance@onramper.com.
KYC/AML-related personal data will not be shared with affiliated group companies except where strictly necessary for verification, compliance, or customer support purposes.
4.2 Sharing with third parties
4.2.1 We share Users’ information (which may include personal data) with third parties, as permitted by law and as set out in paragraph 8 and described below:
(a) Fiat Gateways (fiat on/offramp) and other business partners. When you select a Fiat Gateway through Onramper, we share a verification token with that Fiat Gateway that enables it to access your identity verification data directly from our verification provider, Sumsub. We may also share limited account and transaction data (such as your name, email address, and wallet address) with the selected Fiat Gateway as necessary to facilitate the service. We do not transmit copies of your identity documents or images to Fiat Gateways. The Fiat Gateway shall also act as independent data controller upon receipt of the relevant information. Onramper and each Fiat Gateway shall each be solely responsible for the processing of personal data by itself or on its behalf in accordance with applicable data protection laws. You can also find more details in the privacy statement of the relevant fiat gateway.
Onramper acts as an independent controller for the collection of personal data through the Platform, the verification flow it offers, and the transmission of personal data to the partner selected by you. Each selected Fiat Gateway and each selected financial service provider acts as an independent controller for the personal data it receives and processes in its own systems for its own legal, compliance, onboarding, account management, fraud prevention, internal business and, where applicable and consented to by you, marketing purposes.
(b) Service providers (including suppliers, auxiliaries, and subcontractors). We share personal information with selected third-party service providers to provide our products and services, prevent and detect fraud, store data and otherwise support our business processes, or so that they can conduct business on our behalf. Onramper may furthermore share certain personal data with vetted third parties for the purpose of issuing financial instruments such as cards or IBANs, provided the processing is in line with applicable data protection laws and subject to user consent where required.
(c) For the purpose of identity verification, we share your personal data with our verification provider, Sumsub, which carries out identity checks on our behalf. As described in (a) above, we share a verification token (not raw identity data) with selected Fiat Gateways to enable them to access your verification record at Sumsub.
(d) Forced disclosure. When required by law, strictly necessary for the performance of our services, in legal proceedings, or to protect our rights or the rights of users, we disclose personal data to law enforcement agencies, research organizations or group companies.
As applicable and unless indicated otherwise, for purposes (a), (b) and (c) Onramper relies on the legal basis that the processing of personal data is necessary for the performance of a contract, and for purposes (a) to (d), Onramper relies on its legitimate interests to share, process, enable and receive personal data, and, where applicable, for (d) on compliance with legal obligations (such as lawful law enforcement requests).
Fiat Gateways may further process your personal data outside our control. Fiat Gateways may also ask for additional personal data, for instance to provide additional services, or to comply with local regulations and restrictions. If available, please read the privacy statement of the relevant Fiat Gateway to understand how they process your personal data and how to enforce your rights.
IMPORTANT NOTE: Unless expressly stated otherwise for a specific service or integration, Onramper and the selected fiat gateway and/or financial service provider each act as separate independent data controllers for their own respective processing activities.
You may exercise your data subject rights against Onramper in relation to the processing carried out by Onramper, and against the relevant Fiat Gateway or financial service provider in relation to the processing carried out by that party in its own systems.
4.3 Sharing and disclosure of aggregated data
4.3.1 We may share information with third parties in an aggregated form and/or another form in which the recipient cannot identify you, for example for industry analysis or demographic profiling.
5. Security, protection and cross border transfer
5.1 You have access to your personal data via your Account.
5.2 We have procedures and controls in place to prevent unauthorized access to and misuse of personal data.
5.3 We employ industry-standard security measures designed to protect the security of all information submitted through the Software. We use appropriate business systems, controls and procedures to protect and secure information, including personal data. We also use security procedures and technical and physical restrictions to access and use the personal information on our servers. Only authorized personnel have access to personal data in the context of their work.
5.4 Onramper does not itself store any cardholder information and does not qualify as a processor, merchant, or service provider as described under Payment Card Industry Data Security Standards (PCI DSS).
5.5 Please be aware that your data might be transferred to, processed, and stored in the United States or other non-EEA jurisdictions. Whenever we transfer your personal information out of the EEA to countries not deemed by the European Commission to provide an adequate level of protection, the transfer will be based on an appropriate safeguard under applicable law, such as the European Commission’s Standard Contractual Clauses (SCCs) or an adequacy decision, as applicable. Further information regarding the specific safeguards applied to international transfers of your personal data is available upon request by contacting compliance@onramper.com.
6. Data retention
6.1 We retain personal data for as long as is deemed necessary for the purposes for which it was collected. The criteria we use to determine retention periods include:
- Account and contact data: retained for the duration of your Account and for a reasonable period thereafter to allow for reactivation and to resolve any outstanding queries or disputes.
- Verification tokens and KYC-related data: retained for as long as necessary to provide the centralized verification service, and for a reasonable period after your last use of the service, after which the token is invalidated and associated data is deleted or anonymized.
- Usage data and analytics: retained in identifiable form for as long as necessary for analytical and service-improvement purposes, after which it is aggregated or anonymized.
- Communications recordings: retained for a limited period for quality and training purposes, and deleted automatically unless retained longer for fraud investigation or legal proceedings.
- Fraud-prevention and security logs: retained for as long as necessary for fraud detection and prevention and the establishment, exercise or defense of legal claims.
6.2 Upon termination of the agreement with you, we will delete all your personal data within a reasonable period following termination, unless further retention is necessary for the establishment, exercise or defense of legal claims or to comply with a legal obligation to which Onramper is subject.
6.3 Any personal data we hold about you as a User is subject to this privacy statement and our internal retention guidelines. If you have any questions about the specific retention periods for the different types of personal data we process, please contact Onramper at compliance@onramper.com.
7. Your choices and rights
7.1 Depending on where you are located or the entity of Onramper that processes your personal data, different rights may apply to the processing of that data, as set out in this privacy statement. As applicable:
- You can ask us for a copy of the personal data we hold about you,
- You can notify us of any changes to your personal information, or you can ask us to correct the personal information we hold about you,
- In certain situations, you can ask us to delete, block, amend, or restrict the personal information we hold about you, or you can object to certain ways in which we use your personal information,
- In certain situations, you can also ask us to send the personal data you provide to us to a third party.
7.2 Where we use your personal information based on your consent, you have the right to withdraw that consent at any time, subject to applicable law. Where we process your personal data on the basis of legitimate interest, you also have the right to object at any time, subject to applicable law. See Section 3.2 above for details on which processing activities are based on each lawful basis.
7.3 Regardless of your location or the Onramper entity you have a contract with, we rely on our Users to ensure that the personal information we hold is complete, accurate, and current. Always inform us in good time of any changes or inaccuracies in your personal data.
7.4 To protect your privacy and security, we will verify your identity before responding to such request, and your request will be answered within a reasonable timeframe. We may not be able to allow you to access certain personal data in some cases e.g. if your personal data is connected with personal data of other persons, or for legal reasons. In such cases, we will provide you with an explanation why you cannot obtain this information. We may also deny your request for deletion or rectification of your personal data if you have future/ongoing service with us or due to statutory provisions, especially those affecting our accounting processes, processing of claims, for fraud detection or prevention purposes, and mandatory data retention, which may prohibit deletion or anonymization.
7.5 Consent management
Where the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time.
How to withdraw consent:
You can withdraw your consent at any time by adjusting your preferences in your account settings (where available), by using the opt-out or unsubscribe functionality provided in communications, or by contacting us at compliance@onramper.com.
Effect of withdrawal:
Withdrawal of consent does not affect the lawfulness of any processing carried out prior to such withdrawal. If you withdraw your consent, we will stop the relevant processing unless we have another legal basis to continue processing your personal data. Please note that withdrawing consent may affect your ability to use certain features or services, including the ability to reuse your identity verification across partners or to receive certain partner services.
Managing your preferences:
Where available, you can manage your consent preferences (including whether your personal data may be shared with selected partners for their own purposes, such as onboarding or marketing) through your account settings or through the options presented to you at the point of data collection. We will always respect your choices and apply them going forward.
8. Third parties we use
All third parties engaged by Onramper are contractually obligated to comply with applicable data protection laws (such as the GDPR) and are only permitted to process personal data for the specified purposes and under strict confidentiality obligations. A full list of subprocessors and their roles may be made available upon request.
We use the following third parties, which act as our data processor (unless indicated otherwise), subject to an appropriate data processing agreement.
For the purpose of KYC/AML verification and/or identity checks, we use Sumsub (Sum and Substance Ltd.), a trusted third-party identity verification provider. Sumsub acts as our processor in respect of the identity verification data it processes on our instructions (such as identity document data and verification results). Onramper does not access or process biometric data. To the extent that any biometric processing occurs during the verification flow, it is carried out solely within Sumsub’s own environment and is governed by Sumsub’s privacy notice. Sumsub may store verification data to facilitate re-verification and smoother onboarding with Fiat Gateways in accordance with our instructions and applicable data protection requirements.
With regard to your wallet address, we share this personal identifiable information with Proper Trust, A.G., a Switzerland corporation (“Exodus”), and Exodus Movement, Inc. (which all act as our (sub)processors).
We use Google Analytics in respect of the Product Usage Dataanalytics providers to analyse your usage of our Platform; this data might be stored on Google Analytics’ servers. Information gathered to use Google Analytics as described in this privacy policy, isUsage data processed by these providers may be stored by Google Analytics, which has earned the independenton their servers in accordance with their own security standard ISO 27001 certificationand privacy standards.
Any information processed on, or through, Amazon Web Services are similarly secure by way of compliance with applicable industry-standard certificationsWe use cloud infrastructure providers to host and best practicesprocess data securely. AWS has achieved numerous internationally-recognizedThese providers maintain industry-standard security certifications and accreditations, demonstrating compliancecomply with rigorous international standards, such as ISO 27017 for cloud security, ISO 27701 for privacy information management, and ISO 27018 for cloud privacy, as well as SOC 2 and SOC 3 complianceapplicable data protection requirements.
Snowflake’s government deployments have achieved Federal Risk & Authorization Management Program (FedRAMP) Authorization to Operate (ATO) at the Moderate level. In addition, support for ITAR compliance, SOC 2 Type 2, PCI DSS compliance, and support for HITRUST compliance all validate the level of Snowflake security required by industries, and state and federal government.
ThoughtSpot has successfully completed the Service Organization Control (SOC) 2 Type II audit. The SOC 2 report verifies the suitability of the design and operating effectiveness of ThoughtSpot’s information security practices, policies, procedures, and operations to meet the standards for security, availability, and confidentiality. The ISO/IEC 27001:2013 certification specifies security management best practices and controls for establishing, implementing, maintaining and continually improving an information security management system (ISMS) — the aim of which is to help organizations make the information assets they hold more secure. It ensures that our ISMS is fine-tuned to keep pace with changes to security threats, essential in the fast-paced world of IT security. ThoughtSpot submits to a re-certification audit every third year, inclusive of an annual surveillance audit. ThoughtSpot’s certificate can be found [LINK].
To enhance your experience with Onramper, weWe may utilise Hotjar to record user sessions. This tool helps ususe session-recording and UX research tools to understand how users interact with Onramper, but will never record your personal data. Hotjar only tracks user’s navigation (e.g. where they click, scroll their mouse, or move in between pages) and protectsThese tools are configured to anonymize user information by blurring images that are uploaded,data and decoding text (e.g. numbers will appeardo not capture personal information such as asterisks; ‘***’). All user session recordings are completely anonymous; IP/MACIP or MAC addresses will not be shared.
9. Disclaimer
9.1 We are not responsible for any interception or interruption of any communications through the internet or for changes to or losses of data. Users of the Software are responsible for maintaining the security of any password (which needs to be unique and strong) or another form of authentication involved in obtaining access to password protected. To protect you and your data, we may suspend your use of any of the Software, without notice, pending an investigation, if any breach of security is suspected.
9.2 Our services are not directed at individuals under the age of 18, and we do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete that data promptly. If you believe we have inadvertently collected personal data from a child, please contact us at compliance@onramper.com.
10. Contact us and complaints
10.1 If you have any questions, wishes, complaints or comments about how we process your personal data, or if you would like to exercise any of the rights you have under this Privacy Statement, please contact us at compliance@onramper.com. You can also contact your local data protection authority.
10.2 We handle privacy-specific questions, requests, and concerns reported to us using internal policies and procedures based on applicable privacy laws, regulations, and guidelines. We regularly review and improve this policy and procedures, also taking into account User feedback.
11. Changes to this privacy statement
This privacy statement may be amended or supplemented from time to time. If we intend to make material changes or changes that affect you, we will always contact you in advance. An example of this type of change would be if we started processing your personal data for purposes not described above.
Version: 6 September 2026.
Appendix 1 — Glossary and definitions
Some useful terms and definitions:
“Algorithm” means a computational procedure or set of instructions and rules designed to perform a specific task, solve a particular problem, or produce a machine learning or AI model.
“Anonymization” means the process in which individually identifiable data is altered in such a way that it no longer can be related back to a given individual.
“Automated processing” means a processing operation that is performed without any human intervention.
“Caching” means the saving of local copies of downloaded content, reducing the need to repeatedly download content.
“Cookie” means a small text file stored on a client machine that may later be retrieved by a web server from the machine. Cookies allow web servers to keep track of the end user’s browser activities, and connect individual web requests into a session. Cookies can also be used to prevent users from having to be authorized for every password protected page they access during a session by recording that they have successfully supplied their username and password already.
“Data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
“Data controller” means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data.
“Data minimisation”: The principle of “data minimisation” means that a data controller should limit the collection of personal information to what is directly relevant and necessary to accomplish a specified purpose. They should also retain the data only for as long as is necessary to fulfil that purpose.
“Data processor” means a natural or legal person (other than an employee of the controller), public authority, agency or other body which processes personal data on behalf of the controller.
“Personal data” means any information that relates to an identified or identifiable living individual (e.g. name, address, email, etc). Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data (e.g. location data, IP data, ID number, etc). Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR. Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.
“PEP” (politically exposed person) means any of the following persons: (i) head of state, head of government, minister, deputy minister or state secretary, (ii) member of Parliament or member of a similar legislative body, (iii) member of the board of a political party, (iv) member of a Supreme Court, Constitutional Court or other high-level court that gives rulings against which, except in exceptional circumstances, no appeal is possible, (v) member of a court of audit or a board of directors of a central bank, (vi) ambassador, agent or senior officer of the armed forces, (vii) member of the management, supervisory or administrative bodies of a state-owned company, (viii) director, deputy director, member of the board of directors or person holding an equivalent position at an international organization, or (ix) any of their family members (child, sibling or parent) or their spouse or partner.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
COOKIE POLICY
For the processing of Product Usage Data, Device Data and Log Data, and the use thereof as described above, we may use cookies. Cookies are small files that are stored on a user’s computer. They are designed to hold a modest amount of data specific to a particular client or website and can potentially be accessed by us, as well as your personal computer.
Cookies could allow us to collect data automatically (some of which might be considered personal information. Cookies are either “session” cookies which are deleted when you end your browser session, or “persistent” cookies, which remain until their deletion by you (discussed below) or the party who served the cookie. Some Cookies are necessary for certain uses of the Site, and without such Cookies, we would not be able to provide you with functional access to the Site and/or Service.
These ‘Necessary Cookies’ could, for example, enable us to remember your previous actions within the same browsing session and secure our Sites. They could also allow us to, for instance, deliver a page tailored to a user, based on the device you are using and the location you are in. Specifically, they allow us to save your cookie preferences!Aside from this functional purpose, we mainly use cookies for the analytical purposes described in the section on ‘How we use your personal information above’.
These ‘Analytical Cookies’, which allow us to use Google Analytics, may process and store information such as a user’s Internet Protocol (IP) address, internet service provider, device and browser type, browser version and settings, language preference, cache preferences, operating system, platform, device identifier, device type and manufacturer, location information, demographics, the pages or features of our Site and/or Service to which a user browsed and the time spent on those pages or features, the frequency with which the Site and/or Service is used by a user, search terms, the links on our Site that a user clicked on or used, timestamps and other statistics.We may also use Google Analytics to help us offer you a better-optimized user experience. You can find more information about Google Analytics’ use of your data here.
Necessary cookies are crucial for the basic functions of the website and the website will not work in its intended way without them. These cookies do not store any personally identifiable data.
Analytical cookies are used to understand how visitors interact with the Site or Software. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc. and help us optimize the Site or Software.
HOW TO DISABLE COOKIES?
Most internet browsers are initially set up to automatically accept cookies. If you do not want our websites to store cookies on your device, you can change your browser settings so that you receive a warning before certain cookies are stored. You can also adjust your settings so that your browser refuses most of our cookies or only certain cookies from third parties. You can also withdraw your consent to cookies by deleting the cookies that have already been stored. If you disable the cookies that we use, this may impact your experience while on the Unilever website, for example, you may not be able to visit certain areas of a website or you may not receive personalized information when you visit a website.If you use different devices to view and access the Site and/or Software (e.g., your computer, smartphone, tablet) you will need to ensure that each browser on each device is adjusted to suit your cookie preferences. The procedures for changing your settings and cookies differ from browser to browser. If necessary, use the help function on your browser or click on one of the links below to go directly to the user manual for your browser. Internet ExplorerMozilla FirefoxGoogle ChromeSafariOpera
To find out more about cookies, including how to see what cookies have been set on your PC and how to manage and delete them, visit www.allaboutcookies.org.
CONTACT INFO
Email address: compliance@onramper.com

