Privacy Policy
Last Updated: 26 February 2026
1. INTRODUCTION
Thank you for visiting HashWhale. This Privacy Policy (“Policy”) explains how HASHWHALE PTE. LTD. (UEN: 202421340K) (“HashWhale”, “we”, “us”, or “our”) collects, uses, stores, discloses, and otherwise processes Personal Data when you access or use our website www.hashwhale.io, mobile applications, APIs, and related services (collectively, the “Platform” or “Services”).
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with how we process Personal Data as described here, you should not use the Platform.
This Policy does not apply where we act solely as a processor on behalf of another controller (if applicable), nor does it apply to job applicants or employees.
2. CONTROLLER & CONTACT DETAILS
Data Controller: HASHWHALE PTE. LTD. (UEN: 202421340K), Singapore.
Privacy Contact: privacy@hashwhale.io (or support@hashwhale.io if you do not maintain a separate privacy inbox)
Security Contact: security@hashwhale.io (recommended for incident reports)
You may contact us regarding privacy questions, requests, or complaints.
3. DEFINITIONS
“Personal Data” means any information that identifies or can reasonably identify an individual directly or indirectly (e.g., name, ID number, online identifiers).
“Sensitive Personal Data” (where applicable by law) may include biometric identifiers, financial account credentials, or other categories treated as sensitive under local regulations.
“Processing” means any operation performed on Personal Data (collection, storage, use, disclosure, etc.).
4. WHAT PERSONAL DATA WE COLLECT & HOW WE COLLECT IT
We collect Personal Data in the following ways:
4.1 Data you provide to us
Account & identity data: name, email, phone number, nationality, date of birth, residential address.
Verification/KYC data: government ID details, selfies/liveness checks, proof of address, and related verification outputs.
KYB/corporate data (if applicable): legal entity name, registration number, registered address, business description, ownership/UBO information, directors, and authorized signatories.
Customer support & communications: chat logs, emails, call records (where applicable), survey responses, complaint records.
4.2 Data we collect automatically
Device & technical data: IP address, device identifiers, device fingerprinting signals, OS/browser type, app version, session IDs.
Usage data: pages viewed, clickstream, feature usage, timestamps, referral URLs.
Location data: approximate location derived from IP (and precise location only if you
explicitly allow it in your device settings).
4.3 Transaction & platform activity data
Depending on the services you use (e.g., Earn, Loan, Swap, On/Off Ramp, deposits/withdrawals), we may collect:
transaction amounts, timestamps, product selections, service configurations, risk parameters, and status logs;
wallet addresses involved in deposits/withdrawals;
confirmations and reference IDs from third-party providers.
4.4 Data from third parties
We may receive data from:
identity verification providers (e.g., Sumsub or others used by HashWhale);
payment/on-off ramp providers and settlement partners;
blockchain analytics / compliance screening providers (for AML and sanctions risk signals);
marketing or referral partners (where permitted by law).
Note: If you do not provide certain Personal Data we request, we may be unable to provide Services, complete verification, or meet compliance obligations.
5. UNSOLICITED PERSONAL DATA
If we receive Personal Data we did not request, we will delete or de-identify it unless it is necessary for the purposes described in this Policy or required by law.
6. WHOSE PERSONAL DATA WE PROCESS
We may process Personal Data about:
users and prospective users;
corporate users’ representatives (directors, UBOs, signatories);
vendors, service providers, and business partners;
individuals who contact us or interact with our marketing activities.
7. HOW WE USE PERSONAL DATA (PURPOSES & LEGAL BASES)
We use Personal Data for the following purposes (and corresponding legal bases where applicable):
7.1 Provide and operate the Services
create and manage your account;
enable Platform functions (Earn/Loan/Swap/On-Off Ramp);
process deposits/withdrawals and transaction instructions;
maintain service performance and reliability.
Legal basis: contract performance / legitimate interests.
7.2 Compliance, AML/CFT, and fraud prevention
KYC/KYB, sanctions screening, PEP checks, adverse media checks;
transaction monitoring and investigation of suspicious activity;
risk management controls (including limits, restrictions, and account actions);
meeting regulatory reporting and recordkeeping requirements.
Legal basis: legal obligation / legitimate interests.
7.3 Security and platform integrity
detect and prevent unauthorized access, account takeover, and abuse;
protect users and the Platform from malicious activity;
security audits, incident response, and system monitoring.
Legal basis: legitimate interests / legal obligation.
7.4 Customer support and communications
respond to inquiries, disputes, and complaints;
send operational notices (e.g., verification status, security alerts, policy updates).
Legal basis: contract performance / legitimate interests.
7.5 Service improvement and analytics
product analytics, troubleshooting, quality assurance;
develop and improve Services and user experience.
Legal basis: legitimate interests.
7.6 Marketing (where permitted and required)
send marketing messages if you opt-in where required by law;
provide promotions and product updates.
You can opt out at any time (see Section 12).
Legal basis: consent / legitimate interests (where allowed).
7.7 Use of automated systems (including AI tools)
We may use automated systems to:
enhance customer support (e.g., routing tickets, drafting responses);
detect fraud and compliance risks by analyzing usage and transaction patterns.
We do not use automated decisions that produce legal or similarly significant effects without appropriate safeguards where required by law.
8. HOW WE DISCLOSE PERSONAL DATA
We may share Personal Data with:
Service providers supporting identity verification, compliance screening, analytics, hosting, customer support, and IT operations (processing only under our instructions);
Payment / On-Off Ramp partners to complete fiat-related processing (where applicable);
Blockchain compliance providers to assess wallet risk indicators for AML purposes;
Professional advisors (legal, accounting, auditors);
Authorities / regulators / law enforcement where required by law, court order, or regulatory request;
Corporate transactions (e.g., merger, acquisition) subject to confidentiality and lawful basis.
We do not sell Personal Data.
9. INTERNATIONAL TRANSFERS
Your Personal Data may be processed and stored in jurisdictions outside your country of residence, including where our vendors or partners operate. Where required, we implement appropriate safeguards (e.g., contractual protections) to ensure an adequate level of protection.
10. DATA RETENTION
We retain Personal Data only as long as necessary to:
provide the Services;
comply with legal and regulatory obligations (including AML recordkeeping);
resolve disputes and enforce agreements.
If you close your account, we may retain certain records as required by law.
11. INFORMATION SECURITY
We implement reasonable technical and organizational measures to protect Personal Data, such as:
encryption in transit (and where appropriate, at rest);
access controls and least-privilege policies;
monitoring, logging, and security reviews;
incident response procedures.
No system is completely secure. You are responsible for maintaining the confidentiality of your credentials and for enabling available security features.
12. COMMUNICATIONS & MARKETING OPT-OUT
You may receive service-related communications (e.g., security alerts, verification updates, policy changes). These are necessary and you may not be able to opt out of them.
Where marketing consent is required, we will obtain it. You can opt out of marketing communications at any time via the unsubscribe link or by contacting us.
13. COOKIES & SIMILAR TECHNOLOGIES
We use cookies or similar technologies to:
enable core site functions;
remember preferences;
analyze usage and improve performance;
support security and compliance monitoring (e.g., detecting unusual logins).
You can control cookie settings through your browser. Disabling cookies may affect functionality.
14. YOUR RIGHTS
Depending on your jurisdiction, you may have rights to:
access and obtain a copy of your Personal Data;
correct or update inaccurate data;
delete Personal Data (subject to legal exceptions);
withdraw consent (where processing is based on consent);
object to or restrict certain processing;
data portability (where applicable).
To submit a request, contact privacy@hashwhale.io with the subject line: “DATA REQUEST”. We may need to verify your identity before processing your request.
15. CHILDREN’S DATA
The Platform is not intended for individuals under 18. We do not knowingly collect Personal Data from minors. If you believe a minor has provided Personal Data, please contact us and we will take appropriate steps.
16. THIRD-PARTY LINKS
Our Platform may contain links to third-party sites or services. Their privacy practices are governed by their own policies. HashWhale is not responsible for third-party privacy practices.
17. CHANGES TO THIS POLICY
We may update this Policy from time to time. The updated version will be posted on the Platform with the “Last Updated” date. Your continued use of the Platform indicates acceptance of the updated Policy where permitted by law.
18. LANGUAGE
This Policy may be provided in multiple languages. In case of inconsistency, the English version will prevail.
19. CONTACT
HASHWHALE PTE. LTD. (UEN: 202421340K)
Singapore
Privacy: privacy@hashwhale.io
Support: support@hashwhale.io