Voted as 🏆   Top 100 Blockchain Startups Globally 2026 🏆   by Paris Blockchain Week (PBW).
Learn More

Privacy Policy

Effective Date: November 2025

Version 2.0

Overview

Rhyno Financial Inc. ("Rhyno", "we", "us", or "our") is a corporation incorporated under the laws of the Province of Alberta, Canada, and is registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a Money Services Business (Registration No. C100000021). Rhyno operates a financial technology platform at https://www.rynopay.io specializing in stablecoin-facilitated cross-border payments for enterprise clients.

This Privacy Policy explains how Rhyno collects, uses, stores, discloses, and protects personal information in connection with the Platform, the Services, and Rhyno's business operations. This Policy applies to all individuals whose personal information Rhyno processes, including Merchants, authorized representatives of Merchants, beneficial owners, directors, and visitors to the Site.

This Privacy Policy is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy legislation. It should be read together with Rhyno's Terms of Service and, where applicable, the Merchant Service Agreement.

Section 1 — Information We Collect

1.1 Information You Provide Directly

We collect personal information that you provide to us when you register for an Account, use the Services, or communicate with us. This includes:

  • Identity information: full legal name, date of birth, government-issued identification number and type;
  • Contact information: email address, telephone number, registered address, and principal place of business;
  • Business information: legal entity name, trade name, business registration number, Canadian Business Number (BN), website URL, business description, and nature of activities;
  • Ownership and control information: names, dates of birth, identification documents, and addresses of beneficial owners (25%+), directors, and senior officers;
  • Financial information: bank account details, account numbers, BIC/SWIFT codes, and digital wallet addresses provided for settlement purposes;
  • Transaction information: transaction history, payment instructions, amounts, currencies, beneficiary details, and wallet addresses;
  • Compliance information: source of funds declarations, sanctions screening responses, PEP status, and other due diligence documentation.

1.2 Information Collected Automatically

When you access the Platform, we may automatically collect:

  • Technical data: IP address, browser type and version, operating system, device identifiers, and access timestamps;
  • Usage data: pages viewed, features accessed, session duration, API call logs, and clickstream data;
  • Cookies and tracking technologies: session cookies and authentication tokens necessary for Platform functionality (see Section 8).

1.3 Information from Third Parties

We may receive personal information about you from:

  • Identity verification providers (such as aiPrise) for the purposes of eIDV, KYC, and sanctions screening;
  • Sanctions screening databases and PEP lists maintained by Canadian and international authorities;
  • Banking partners and payment networks in connection with transaction processing and AML compliance;
  • Publicly available corporate registries, regulatory databases, and credit bureaus where permitted by Applicable Law.

Section 2 — How We Use Your Information

2.1 Legal Bases for Processing

Rhyno processes personal information on the following legal bases under PIPEDA and applicable law:

  • Contractual necessity: to enter into and perform our obligations under the Merchant Service Agreement and to provide the Services;
  • Legal obligation: to comply with PCMLTFA, PCMLTFR, FINTRAC guidelines, RPAA, sanctions legislation, and other applicable regulatory requirements;
  • Consent: where you have provided express consent for a specific processing purpose, which may be withdrawn at any time (subject to legal and contractual limitations);
  • Legitimate interests: for fraud prevention, security, risk management, business analytics, and improving the Platform, where such interests are not overridden by your privacy rights.

2.2 Specific Purposes

We use personal information for the following purposes:

  • Account onboarding, identity verification, and KYC/CDD compliance;
  • Sanctions screening and PEP screening in accordance with PCMLTFA and PCMLTFR;
  • Processing, settling, and reconciling payment transactions through the Platform;
  • Filing Suspicious Transaction Reports (STRs) and Large Cash Transaction Reports (LCTRs) with FINTRAC as required;
  • Travel Rule compliance — transmitting required originator and beneficiary information for in-scope transfers;
  • Fraud detection, transaction monitoring, and security controls;
  • Communicating with you regarding your Account, the Services, and compliance matters;
  • Resolving disputes, processing complaints, and responding to legal and regulatory inquiries;
  • Improving the Platform and Services, and conducting analytics for internal purposes;
  • Meeting our obligations under the RPAA and other applicable financial services legislation.

Section 3 — Disclosure Of Your Information

3.1 Regulatory and Law Enforcement Authorities

Rhyno is required by law to disclose personal information and transaction data to:

  • FINTRAC — for the purpose of meeting mandatory reporting obligations under PCMLTFA, including STRs, LCTRs, Electronic Funds Transfer Reports (EFTRs), and Virtual Currency Transaction Reports (VCTRs);
  • The Bank of Canada — in connection with RPAA registration and oversight;
  • Canadian federal and provincial law enforcement agencies, courts, and regulatory bodies, pursuant to lawful orders, subpoenas, or mandatory disclosure requirements;
  • International law enforcement or regulatory authorities pursuant to mutual legal assistance obligations or applicable sanctions law.

Such disclosures are made without prior notice to you where required or permittedby law.

3.2 Service Providers and Approved Third Parties

We share personal information with trusted third-party service providers ("Approved Third Parties") who assist us in delivering the Services, including:

  • Identity verification and eIDV providers (e.g., aiPrise) for KYC and sanctions screening;
  • Banking partners and correspondent banks for payment processing and settlement;
  • Cloud infrastructure, data storage, and hosting providers;
  • Transaction monitoring and AML analytics providers;
  • Legal, audit, and compliance advisors bound by professional confidentiality obligations.

All Approved Third Parties are required to process personal information solely for the purposes for which it was shared and in accordance with applicable privacy law. We do not sell your personal information to third parties.

3.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or substantially all of Rhyno's assets, personal information may be transferred to the acquiring entity, subject to equivalent privacy protections. We will notify you of any such transfer and your options, as required by Applicable Law.

3.4 Consent-Based Disclosures

We may disclose your personal information to other parties with your express consent, for purposes communicated to you at the time of obtaining such consent.

Section 4 — Retention Of Personal Information

4.1 Retention Periods

Rhyno retains personal information for as long as necessary to fulfill the purposes for which it was collected and to comply with our legal and regulatory obligations, including:

  • KYC and identity verification records: a minimum of five (5) years following the end of the business relationship, in accordance with PCMLTFA;
  • Transaction records: a minimum of five (5) years from the date of the transaction, in accordance with PCMLTFA and PCMLTFR;
  • STR and compliance filing records: a minimum of five (5) years from the date of filing, in accordance with FINTRAC requirements;
  • Account and contractual records: for the duration of the Merchant relationship and seven (7) years thereafter, consistent with the Merchant Service Agreement;
  • General correspondence and communications: three (3) years unless a longer period is required.

4.2 Secure Disposal

When personal information is no longer required, Rhyno will securely destroy, anonymize, or de-identify it in accordance with Applicable Law and industry best practices.

Section 5 — Cross-border Data Transfers

As a cross-border payments platform serving markets in Sub-Saharan Africa and other international corridors, Rhyno may transfer personal information to service providers, banking partners, and regulators located outside of Canada, including in jurisdictions where privacy laws may differ from Canadian standards.

Where we transfer personal information outside of Canada, we take appropriate steps to ensure that the receiving party provides a comparable level of protection, including through contractual obligations, data transfer agreements, or reliance on legally recognized transfer mechanisms. You acknowledge and consent to such transfers as necessary for the provision of the Services.

Section 6 — Your Privacy Rights

6.1 Right of Access

You have the right to request access to the personal information Rhyno holds about you. We will provide you with a copy of your personal information within thirty (30) days of a verified written request, subject to applicable exceptions under PIPEDA.

6.2 Right to Correction

If you believe that personal information we hold about you is inaccurate, incomplete, or outdated, you may request that we correct it. We will correct or update your information within a reasonable time, or note your correction request in our records if we are unable to make the requested change.

6.3 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw consent at any time by contacting us at compliance@rynopay.io. Withdrawal of consent will not affect the lawfulness of processing that occurred prior to withdrawal. Please note that withdrawal of consent may result in Rhyno being unable to continue providing the Services.

6.4 Limitations on Privacy Rights

Your privacy rights are subject to limitations where Rhyno is required to retain or process personal information to comply with legal obligations under PCMLTFA, PCMLTFR, FINTRAC directions, court orders, or other Applicable Law. In such cases, we will inform you of the limitation to the extent permitted by law.

6.5 How to Exercise Your Rights

To exercise your privacy rights, please submit a written request to: compliance@rynopay.io. We may require you to verify your identity before processing your request. We will respond within thirty (30) days of receiving a complete and verified request.

Section 7 — Security Of Personal Information

Rhyno implements appropriate technical, administrative, and physical security measures to protect personal information from unauthorized access, disclosure, alteration, loss, or destruction. These measures include:

  • encryption of data in transit and at rest;
  • access controls and role-based permissions limiting access to personal information to authorized personnel only;
  • multi-factor authentication (MFA) for Platform access;
  • regular security assessments and vulnerability monitoring;
  • data backup and disaster recovery procedures.

While Rhyno maintains these controls, no security measure is infallible. You are responsible for maintaining the security of your own Account credentials and devices. In the event of a security incident involving your personal information, we will notify you and applicable regulatory authorities as required by Applicable Law.

Section 8 — Cookies And Tracking Technologies

Rhyno uses cookies and similar tracking technologies on the Platform for the following purposes:

  • Session management: authentication cookies to maintain your login session and secure your Account;
  • Security: tokens used to detect and prevent unauthorized access, CSRF attacks, and session hijacking;
  • Analytics: aggregated, anonymized usage data to understand how the Platform is used and to improve its performance and features.

Rhyno does not use third-party advertising cookies or behavioral tracking cookies. Essential cookies required for Platform security and functionality cannot be disabled. You may configure your browser to block non-essential cookies, though this may affect certain Platform features. By using the Platform, you consent to the use of cookies as described in this Policy.

Section 9 — Minors

The Platform and Services are intended exclusively for business entities and individuals who are at least 18 years of age. Rhyno does not knowingly collect personal information from individuals under the age of 18. If you believe that we have inadvertently collected personal information from a minor, please contact us immediately at compliance@rynopay.io and we will take prompt steps to delete such information.

Section 10 — Changes To This Privacy Policy

Rhyno may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or the Services. We will indicate the effective date of any update at the top of this Policy. Where changes are material, we will provide reasonable advance notice to registered users via email or Platform notification. Your continued use of the Platform following the effective date of any amendment constitutes acceptance of the updated Privacy Policy.

Section 11 — Accountability And Pipeda Compliance

Rhyno is committed to compliance with PIPEDA and has appointed a Privacy Officer responsible for overseeing the organization's privacy program and ensuring compliance with applicable privacy law. The Privacy Officer can be contacted at: compliance@rynopay.io.

If you have a concern about Rhyno's privacy practices, you may submit a complaint in writing to our Privacy Officer. We will investigate all complaints in good faith and respond within thirty (30) days. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or by telephone at 1-800-282-1376.

Section 12 — Contact Information

For all privacy-related inquiries, access requests, or complaints:

Rhyno Financial Inc.

Privacy Officer

Email: compliance@rynopay.io

Legal notices: legal@rynopay.io

Platform: https://www.rynopay.io

FINTRAC Registration No. C100000021

This Privacy Policy is governed by the laws of the Province of Alberta and the applicable federal laws of Canada.