×
Privacy Policy - NorthVault
Privacy Policy
NorthVault Private
Last Updated: January 6, 2026
Effective Date: January 6, 2026
1. Introduction
NorthVault Private ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring the
security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard
your information when you use our cryptocurrency transaction routing service (the "Service").
By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with
this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Personal Information You Provide
We collect personal information that you voluntarily provide when you:
- Register for an account
- Complete identity verification
- Use the Service
- Contact customer support
- Participate in surveys or promotions
This information may include:
- Full legal name
- Date of birth
- Email address
- Phone number
- Residential address
- Government-issued identification documents (passport, driver's license, national ID)
- Identification numbers
- Photographs (for identity verification)
- Social Security Number or Tax Identification Number (where required)
- Financial information (bank account details, payment card information)
- Cryptocurrency wallet addresses
- Biometric data (facial recognition for identity verification)
- Employment information and source of funds documentation
- Business information (for business accounts)
2.2 Transaction Information
We automatically collect information about your transactions, including:
- Transaction amounts and currencies
- Cryptocurrency wallet addresses (sender and recipient)
- Transaction dates and times
- Transaction status and history
- Blockchain network data
- Gas fees and network confirmations
- Transaction metadata
2.3 Technical and Usage Information
We automatically collect technical information when you access the Service:
- IP address and geolocation data
- Device information (device type, operating system, browser type)
- Unique device identifiers
- Log data (access times, pages viewed, links clicked)
- Cookies and similar tracking technologies
- Referral sources
- Session duration and navigation patterns
- Error reports and performance data
2.4 Information from Third Parties
We may receive information from:
- Identity verification services
- Blockchain networks (publicly available transaction data)
- Credit reporting agencies
- Fraud prevention services
- Sanctions screening databases
- Social media platforms (if you link your accounts)
- Analytics providers
- Marketing partners
2.5 Publicly Available Information
We may collect publicly available information about you from:
- Blockchain networks and explorers
- Public records
- Social media platforms
- News sources and media reports
- Professional networking sites
3. How We Use Your Information
3.1 Primary Purposes
We use your information to:
- Provide the Service: Create and manage your account, process transactions, facilitate
cryptocurrency transfers
- Verify Identity: Comply with Know Your Customer (KYC) and Anti-Money Laundering (AML)
requirements
- Prevent Fraud: Detect and prevent fraudulent activities, security breaches, and other
illegal activities
- Comply with Laws: Meet legal and regulatory obligations, including tax reporting and
sanctions screening
- Communicate: Send transaction confirmations, account notifications, security alerts, and
customer support responses
- Improve the Service: Analyze usage patterns, conduct research, develop new features, and
enhance user experience
- Enforce Terms: Monitor compliance with our Terms and Conditions and policies
- Risk Assessment: Evaluate transaction risks and assign risk ratings to accounts
3.2 Marketing and Communications
With your consent, we may use your information to:
- Send promotional materials and marketing communications
- Provide personalized recommendations
- Conduct surveys and request feedback
- Announce new features, products, or services
You can opt out of marketing communications at any time by clicking "unsubscribe" in our emails or adjusting
your account settings.
3.3 Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your personal data based on:
- Contractual Necessity: Processing is necessary to perform our contract with you (providing
the Service)
- Legal Obligation: Processing is required to comply with applicable laws and regulations
- Legitimate Interests: Processing is necessary for our legitimate business interests (fraud
prevention, service improvement)
- Consent: You have provided explicit consent for specific processing activities (marketing
communications)
4. How We Share Your Information
4.1 Service Providers and Partners
We share information with trusted third-party service providers who assist us:
- Identity verification and KYC/AML compliance providers
- Payment processors and financial institutions
- Cloud storage and hosting services
- Customer support platforms
- Analytics and data processing services
- Cybersecurity and fraud prevention services
- Email and communication services
- Legal and accounting services
These providers are contractually obligated to protect your information and use it only for specified purposes.
4.2 Regulatory and Law Enforcement
We may disclose your information to:
- Government agencies and regulators (FinCEN, SEC, OFAC, IRS)
- Law enforcement authorities
- Tax authorities
- Courts and legal tribunals
- Other regulatory bodies with jurisdiction over our operations
We disclose information when:
- Required by law, regulation, or legal process
- Necessary to comply with subpoenas, court orders, or government requests
- Filing Suspicious Activity Reports (SARs) or Currency Transaction Reports (CTRs)
- Responding to regulatory examinations or investigations
- Protecting our legal rights or defending against legal claims
4.3 Business Transfers
If we are involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction, your
information may be transferred as part of that transaction. You will be notified of any such change in ownership
or control of your personal information.
4.4 Blockchain Networks
When you conduct cryptocurrency transactions, certain information is recorded on public blockchain networks and
becomes permanently accessible to anyone. This includes:
- Wallet addresses
- Transaction amounts
- Transaction timestamps
- Transaction hashes
We cannot control or delete information recorded on blockchain networks.
4.5 With Your Consent
We may share your information with other parties when you provide explicit consent or direct us to do so.
4.6 Aggregated and Anonymized Data
We may share aggregated or anonymized data that cannot identify you personally for:
- Research and analytics
- Industry reports and benchmarking
- Marketing and promotional purposes
- Service improvement
5. Data Retention
5.1 Retention Periods
We retain your personal information for as long as necessary to:
- Provide the Service to you
- Comply with legal obligations (typically 5–7 years for financial records)
- Resolve disputes and enforce agreements
- Prevent fraud and enhance security
- Meet regulatory requirements
5.2 Specific Retention Requirements
- Account Information: Duration of account relationship plus 5 years after closure
- Transaction Records: 5 years from transaction date (or longer if required by law)
- Identity Verification Documents: 5 years after account closure
- AML/Compliance Records: Minimum 5 years, potentially longer for investigations
- Communication Records: 3–5 years depending on type
- Technical Logs: 1–2 years unless needed for security or legal purposes
5.3 Data Deletion
After retention periods expire, we securely delete or anonymize your information unless:
- Longer retention is required by law
- Information is needed for ongoing legal proceedings
- You have consented to longer retention
6. Data Security
6.1 Security Measures
We implement robust security measures to protect your information:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Role-based access restrictions and multi-factor authentication
- Network Security: Firewalls, intrusion detection systems, and DDoS protection
- Secure Infrastructure: SOC 2 compliant data centers with physical security
- Security Monitoring: 24/7 monitoring for suspicious activities and breaches
- Penetration Testing: Regular security audits and vulnerability assessments
- Employee Training: Mandatory security and privacy training for all staff
- Incident Response: Documented procedures for security breach response
6.2 Cryptocurrency Security
For cryptocurrency-related operations:
- Private keys stored in cold storage and hardware security modules (HSMs)
- Multi-signature wallet requirements for large transactions
- Transaction limits and velocity checks
- Withdrawal whitelist and verification procedures
- Regular security audits of smart contracts and infrastructure
6.3 Your Responsibility
You are responsible for:
- Maintaining confidentiality of your account credentials
- Using strong, unique passwords
- Enabling two-factor authentication
- Keeping your device and software secure
- Not sharing your account access with others
- Promptly reporting suspicious activity
6.4 No Absolute Security
Important: No security system is completely impenetrable. While we implement industry-standard
security
measures, we cannot guarantee absolute security of your information. You use the Service at your own risk.
7. Your Rights and Choices
7.1 Access and Correction
You have the right to:
- Access the personal information we hold about you
- Request corrections to inaccurate or incomplete information
- Download a copy of your data in a portable format
To exercise these rights, contact us at privacy@northvaultprivate.com.
You may request deletion of your personal information, subject to:
- Legal retention requirements
- Pending transactions or investigations
- Outstanding balances or disputes
- Contractual obligations
Note: We cannot delete information recorded on blockchain networks.
7.3 Restriction and Objection
You may:
- Restrict processing of your information under certain circumstances
- Object to processing based on legitimate interests
- Object to automated decision-making and profiling
7.4 Marketing Opt-Out
You can opt out of marketing communications by:
- Clicking "unsubscribe" in emails
- Adjusting notification settings in your account
- Contacting customer support
- Emailing privacy@northvaultprivate.com
7.5 Cookie Management
You can control cookies through:
- Browser settings (blocking or deleting cookies)
- Opt-out mechanisms for analytics services
- Privacy settings in your account
Note: Disabling certain cookies may limit Service functionality.
7.6 Do Not Track Signals
Our Service does not currently respond to "Do Not Track" browser signals, as there is no industry standard for
compliance.
8. International Data Transfers
8.1 Cross-Border Transfers
Your information may be transferred to and processed in countries other than your country of residence,
including:
- United States
- European Union
- [Other jurisdictions where we operate]
These countries may have different data protection laws than your jurisdiction.
8.2 Transfer Safeguards
For transfers from the EEA, we implement appropriate safeguards:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Privacy Shield certification (where applicable)
- Binding Corporate Rules
- Explicit consent for specific transfers
8.3 Data Localization
Where required by local law, we may store data within specific jurisdictions or implement data localization
measures.
9. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal
information from minors. If we discover we have collected information from a minor, we will promptly delete it.
If you believe we have collected information from a minor, contact us immediately at privacy@northvaultprivate.com.
10. Cookies and Tracking Technologies
10.1 Types of Cookies We Use
- Essential Cookies: Required for Service functionality (authentication, security,
transaction processing)
- Analytics Cookies: Help us understand usage patterns and improve the Service (Google
Analytics, Mixpanel)
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Track effectiveness of marketing campaigns and provide personalized
content
10.2 Third-Party Tracking
We use third-party services that may collect information:
- Google Analytics
- Facebook Pixel
- [Other analytics and marketing tools]
These services have their own privacy policies governing data collection and use.
10.3 Cookie Management
Most browsers allow you to:
- View and delete cookies
- Block third-party cookies
- Receive notifications when cookies are set
- Disable cookies entirely
Refer to your browser's help documentation for instructions.
11. California Privacy Rights (CCPA/CPRA)
11.1 California Consumer Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA):
Right to Know: Request disclosure of personal information collected, sources, purposes, and
categories of third parties with whom we share information
Right to Delete: Request deletion of personal information (subject to legal exceptions)
Right to Opt-Out: Opt out of "sale" or "sharing" of personal information
Right to Correct: Request correction of inaccurate information
Right to Limit: Limit use of sensitive personal information
Non-Discrimination: We will not discriminate against you for exercising your privacy rights
11.2 Information We Collect (CCPA Categories)
- Identifiers (name, email, address, IP address)
- Commercial information (transaction history)
- Financial information (payment details, wallet addresses)
- Internet activity (browsing history, interactions)
- Geolocation data
- Biometric information (facial recognition)
- Professional information (employment, source of funds)
- Inferences (risk profiles, preferences)
11.3 Sale and Sharing
We do not "sell" personal information as traditionally defined. However, certain data sharing practices may
constitute "sale" or "sharing" under CCPA:
- Sharing with advertising partners for targeted advertising
- Using analytics services that track across websites
To opt out: Email privacy@northvaultprivate.com with "CCPA Opt-Out" in the
subject line.
11.4 Submitting CCPA Requests
To exercise your California privacy rights:
Email: privacy@northvaultprivate.com
We will respond within 45 days (with possible 45-day extension).
11.5 Authorized Agents
You may designate an authorized agent to submit requests on your behalf by providing written authorization.
12. European Privacy Rights (GDPR)
12.1 Legal Basis for Processing
We process your data based on:
- Contract performance
- Legal obligations
- Legitimate interests
- Your consent
12.2 Your GDPR Rights
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
12.3 Data Protection Officer
For GDPR inquiries, contact our Data Protection Officer:
Email: dpo@northvaultprivate.com
12.4 Supervisory Authority
You have the right to lodge a complaint with your local data protection authority if you believe we have
violated your privacy rights.
13. Automated Decision-Making and Profiling
We may use automated systems to:
- Assess transaction risk
- Detect fraud and suspicious activity
- Assign account risk ratings
- Screen against sanctions lists
- Evaluate creditworthiness
You have the right to:
- Request human review of automated decisions
- Express your point of view
- Contest automated decisions
14. Changes to This Privacy Policy
14.1 Updates
We may update this Privacy Policy to reflect:
- Changes in our practices
- New legal requirements
- Service enhancements
- User feedback
14.2 Notification
We will notify you of material changes by:
- Posting updated Policy on our website
- Updating the "Last Updated" date
- Sending email notifications (for significant changes)
- In-app notifications
14.3 Continued Use
Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy. If you do
not agree with changes, you must stop using the Service.
15. Third-Party Links
The Service may contain links to third-party websites, services, or applications. We are not responsible for
the privacy practices of these third parties. We encourage you to review their privacy policies before providing
any information.
16. Contact Us
For privacy-related questions, requests, or concerns:
Privacy Team
Email: privacy@northvaultprivate.com
Data Protection Officer (GDPR)
Email: dpo@northvaultprivate.com
California Privacy Requests (CCPA)
Email: privacy@northvaultprivate.com (subject: CCPA Request)
Response Time: We aim to respond to all privacy inquiries within 30 days.
17. Specific Jurisdictions
17.1 Additional Regional Requirements
Nevada Residents: You may opt out of the sale of covered information by emailing
privacy@northvaultprivate.com.
Virginia, Colorado, Connecticut, Utah Residents: You have rights similar to CCPA, including access, deletion,
correction, and opt-out rights.
Canadian Residents: You have rights under PIPEDA to access and correct your personal
information.
Brazilian Residents: You have rights under LGPD similar to GDPR, including access, correction,
deletion, and portability.
17.2 Country-Specific Practices
Data handling practices may vary by jurisdiction to comply with local laws. Contact us for
jurisdiction-specific information.
18. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms:
- We will notify you within 72 hours of discovery (where required by law)
- We will notify relevant supervisory authorities
- We will provide information about the breach, affected data, and remedial actions
- We will assist you in protecting your information
19. Business Contact Information
General Inquiries: info@northvaultprivate.com
Support: support@northvaultprivate.com
Privacy: privacy@northvaultprivate.com
Compliance: compliance@northvaultprivate.com
Last Updated: January 6, 2026
Effective Date: January 6, 2026
Version: 1.0
By using NorthVault Private, you acknowledge that you have read and understood this Privacy Policy and agree to
its terms.