bg-img

Privacy Policy

Privacy

How we handle your data.

This policy explains what Palzea Inc. collects, why, who we share it with and what control you have over it. It covers our websites, apps, APIs and services.

Who we are, and what this covers

Controller: Palzea Inc., incorporated under the laws of the Republic of Panama.

This policy covers personal data we process about account holders, P2P counterparties, site visitors, job applicants and support contacts. Product-specific terms may add to it.

What we collect

CategoryExamplesSource
Account and contact Email, username, preferred language, settings. You
Verification status Limited information from external payment and on-ramp providers: whether your profile is verified with them, which methods are available, high-level risk flags. We do not receive or store your identity documents from those checks. Third-party providers you choose to use
Financial and transaction Wallet addresses, deposit and withdrawal details, order history, P2P offers and trades, payment confirmations. We store no full card numbers. You, blockchain networks, payment partners
Technical Device, operating system, browser, IP address, timestamps, activity logs, security events, diagnostics. Collected automatically
Cookies and analytics Strictly necessary, security, preference and limited analytics cookies. No cross-context advertising cookies. Collected automatically
Support and messages Tickets, chat and email content, attachments, dispute evidence. You, P2P counterparties, our support tools

Why we use it, and on what legal basis

PurposeExamplesLegal basis
Running the service Account creation, orders, wallets, P2P escrow, support. Performance of a contract
Compliance and sanctions Meeting AML and CTF requirements, record-keeping, responding to lawful requests. Legal obligation, public interest
Security and fraud prevention 2FA, monitoring, incident response, abuse detection. Legitimate interests, legal obligation
Improving the product Analytics, diagnostics, feature measurement. Legitimate interests, consent where required
Communications Service notices, changes to terms, optional product updates. Contract, legitimate interests, consent where required

Where we rely on consent, you can withdraw it at any time. That does not affect processing carried out beforehand.

Verification by third parties

  • Palzea does not run its own identity verification, and does not ask you to upload identity documents to us. For certain services — card payments, bank transfers, on-ramp and off-ramp — you may be redirected to independent providers who run their own checks.
  • Those checks happen between you and the provider, under their terms and privacy policy. They are responsible for how they handle your documents.
  • We may receive limited information back: whether a method is available, whether your profile is verified with them, whether further checks are needed. We do not access the underlying documents.
  • A provider may pause or block a transaction on their side. That can temporarily affect a specific payment method inside Palzea.

Cookies

  • Strictly necessary: authentication, session security, fraud prevention.
  • Preferences: language, theme, regional settings.
  • Analytics, limited: usage and performance metrics. No cross-context behavioural advertising.

You can manage non-essential cookies in your browser and, where available, in our in-product controls.

Who we share it with

  • Processors: hosting, security, analytics, messaging and customer-support vendors, under contract and data-protection terms.
  • Payment and verification partners: where needed to initiate or confirm a transaction, or to receive status information about their own compliance checks.
  • Counterparties: the minimum needed to complete a P2P trade, such as payment instructions and order details.
  • Affiliates and corporate transactions: as part of a reorganisation, merger or acquisition.
  • Legal and compliance: where required by law or court order, or to enforce our rights and protect users.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

International transfers

We operate globally. Where applicable in the EEA and the UK, we rely on transfer mechanisms such as the EU and UK Standard Contractual Clauses, with supplementary safeguards. Copies or a summary can be provided where the law requires it.

How long we keep it

We retain data while your account is active and for as long as we need it to provide the service and meet legal obligations. Compliance and transaction records may need to be kept for several years after an account closes, depending on local law. Once data is no longer needed we anonymise or securely delete it.

Security

  • Encryption in transit and at rest, role-based access control, monitoring and vulnerability management.
  • 2FA for sensitive actions, anti-phishing code and session controls.
  • Incident response procedures, with user notification where the law requires it.

No method of transmission or storage is completely secure. Use a unique password and turn on 2FA.

Your rights

  • EEA and UK (GDPR): access, rectification, erasure, restriction, portability and objection. You may also lodge a complaint with your supervisory authority.
  • California (CCPA/CPRA): the right to know, delete, correct and opt out of sale or sharing, which we do not practise; and to limit the use of sensitive data, which we use only for security and compliance.
  • Brazil (LGPD) and Canada (PIPEDA): comparable rights of access, correction, deletion and portability, subject to exceptions.

To exercise any of these, contact us through the Support Center. We may need to verify your request, and we respond within the statutory timelines. Authorised agents may act on your behalf where the law permits.

Automated decisions

We use automated checks for fraud, sanctions screening and risk scoring. You can request human review where the law gives you that right.

Children

Palzea is intended for people aged 18 and over. We do not knowingly collect data from anyone below that age. If you believe a minor has created an account, tell us through the Support Center and we will act on it.

Links to other sites

Our services link to third-party sites. Their privacy practices are governed by their own policies, not this one.

Changes to this policy

We update this policy from time to time. Where changes are material, we notify you in-product or by email. Continuing to use Palzea after the effective date means you accept the updated policy.

Contact

For any question about this policy, or to exercise your rights, write to us through the Support Center. Our team is available around the clock.

Open the Support Center

If you are in the EEA or the UK and want to raise a concern formally, you may also contact your local data protection authority.

Effective date: 11 August 2026 · © Palzea. All rights reserved.

Privacy

How we handle your data.

This policy explains what Palzea Inc. collects, why, who we share it with and what control you have over it. It covers our websites, apps, APIs and services.

Who we are, and what this covers

Controller: Palzea Inc., incorporated under the laws of the Republic of Panama.

This policy covers personal data we process about account holders, P2P counterparties, site visitors, job applicants and support contacts. Product-specific terms may add to it.

What we collect

CategoryExamplesSource
Account and contact Email, username, preferred language, settings. You
Verification status Limited information from external payment and on-ramp providers: whether your profile is verified with them, which methods are available, high-level risk flags. We do not receive or store your identity documents from those checks. Third-party providers you choose to use
Financial and transaction Wallet addresses, deposit and withdrawal details, order history, P2P offers and trades, payment confirmations. We store no full card numbers. You, blockchain networks, payment partners
Technical Device, operating system, browser, IP address, timestamps, activity logs, security events, diagnostics. Collected automatically
Cookies and analytics Strictly necessary, security, preference and limited analytics cookies. No cross-context advertising cookies. Collected automatically
Support and messages Tickets, chat and email content, attachments, dispute evidence. You, P2P counterparties, our support tools

Why we use it, and on what legal basis

PurposeExamplesLegal basis
Running the service Account creation, orders, wallets, P2P escrow, support. Performance of a contract
Compliance and sanctions Meeting AML and CTF requirements, record-keeping, responding to lawful requests. Legal obligation, public interest
Security and fraud prevention 2FA, monitoring, incident response, abuse detection. Legitimate interests, legal obligation
Improving the product Analytics, diagnostics, feature measurement. Legitimate interests, consent where required
Communications Service notices, changes to terms, optional product updates. Contract, legitimate interests, consent where required

Where we rely on consent, you can withdraw it at any time. That does not affect processing carried out beforehand.

Verification by third parties

  • Palzea does not run its own identity verification, and does not ask you to upload identity documents to us. For certain services — card payments, bank transfers, on-ramp and off-ramp — you may be redirected to independent providers who run their own checks.
  • Those checks happen between you and the provider, under their terms and privacy policy. They are responsible for how they handle your documents.
  • We may receive limited information back: whether a method is available, whether your profile is verified with them, whether further checks are needed. We do not access the underlying documents.
  • A provider may pause or block a transaction on their side. That can temporarily affect a specific payment method inside Palzea.

Cookies

  • Strictly necessary: authentication, session security, fraud prevention.
  • Preferences: language, theme, regional settings.
  • Analytics, limited: usage and performance metrics. No cross-context behavioural advertising.

You can manage non-essential cookies in your browser and, where available, in our in-product controls.

Who we share it with

  • Processors: hosting, security, analytics, messaging and customer-support vendors, under contract and data-protection terms.
  • Payment and verification partners: where needed to initiate or confirm a transaction, or to receive status information about their own compliance checks.
  • Counterparties: the minimum needed to complete a P2P trade, such as payment instructions and order details.
  • Affiliates and corporate transactions: as part of a reorganisation, merger or acquisition.
  • Legal and compliance: where required by law or court order, or to enforce our rights and protect users.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

International transfers

We operate globally. Where applicable in the EEA and the UK, we rely on transfer mechanisms such as the EU and UK Standard Contractual Clauses, with supplementary safeguards. Copies or a summary can be provided where the law requires it.

How long we keep it

We retain data while your account is active and for as long as we need it to provide the service and meet legal obligations. Compliance and transaction records may need to be kept for several years after an account closes, depending on local law. Once data is no longer needed we anonymise or securely delete it.

Security

  • Encryption in transit and at rest, role-based access control, monitoring and vulnerability management.
  • 2FA for sensitive actions, anti-phishing code and session controls.
  • Incident response procedures, with user notification where the law requires it.

No method of transmission or storage is completely secure. Use a unique password and turn on 2FA.

Your rights

  • EEA and UK (GDPR): access, rectification, erasure, restriction, portability and objection. You may also lodge a complaint with your supervisory authority.
  • California (CCPA/CPRA): the right to know, delete, correct and opt out of sale or sharing, which we do not practise; and to limit the use of sensitive data, which we use only for security and compliance.
  • Brazil (LGPD) and Canada (PIPEDA): comparable rights of access, correction, deletion and portability, subject to exceptions.

To exercise any of these, contact us through the Support Center. We may need to verify your request, and we respond within the statutory timelines. Authorised agents may act on your behalf where the law permits.

Automated decisions

We use automated checks for fraud, sanctions screening and risk scoring. You can request human review where the law gives you that right.

Children

Palzea is intended for people aged 18 and over. We do not knowingly collect data from anyone below that age. If you believe a minor has created an account, tell us through the Support Center and we will act on it.

Links to other sites

Our services link to third-party sites. Their privacy practices are governed by their own policies, not this one.

Changes to this policy

We update this policy from time to time. Where changes are material, we notify you in-product or by email. Continuing to use Palzea after the effective date means you accept the updated policy.

Contact

For any question about this policy, or to exercise your rights, write to us through the Support Center. Our team is available around the clock.

Open the Support Center

If you are in the EEA or the UK and want to raise a concern formally, you may also contact your local data protection authority.

Effective date: 11 August 2026 · © Palzea. All rights reserved.