1. Information We Collect
When you use Cambio without creating an account, we collect only the data strictly necessary to execute the swap: source cryptocurrency, destination cryptocurrency, source network, destination network, amount, destination wallet address, and the deposit transaction hash. We do not routinely collect your name, postal address, government ID, or date of birth.
For fraud-prevention, sanctions and geographic-eligibility enforcement, and incident response, we also record the IP address and the resolved country from which the swap was initiated, associated with that swap. This information is retained for 12 months and then automatically deleted.
Cambio screens the source (deposit) and destination (payout) wallet addresses of every swap against sanctions lists.
In the exceptional cases described in our AML Policy (sanctions-list match, wallet-screening risk hit, suspected criminal source of funds), we may additionally collect (a) any source-of-funds documentation you voluntarily provide and (b) any identity verification (KYC) data you submit to clear the review. This collection is narrowly scoped to the specific swap under review.
For account holders (optional), we additionally collect: email address, password hash, account preferences, swap history linked to your account, and any address-book entries you add. Account creation is never required to use the Service.
We do not collect biometric data, government-issued identification, payment-card information, social-security numbers, or banking information for users who use the Service without an account and whose swaps do not trigger an AML review.
2. How We Use Information
We use collected information solely for the following purposes: (a) executing your swap and routing the payout to your destination address; (b) running real-time AML and sanctions screening on swaps above the threshold; (c) complying with our legal obligations under the laws of the Republic of Panama and applicable international sanctions regimes; (d) preventing fraud, abuse, and operational misuse of the Service; (e) responding to support tickets you submit; and (f) operating optional account features (history, address book) for account holders.
We do not use your data for advertising. We do not sell your data. We do not share your data with marketing partners. We do not run third-party analytics that profile your behavior across other sites.
3. Who Sees Your Data
Internal: A small number of Cambio engineers and support staff have access to swap data for the purposes of operating the Service and responding to support tickets. Access is logged.
Sanctions screening: The source (deposit) and destination (payout) wallet addresses are screened against a self-hosted sanctions list (the OFAC SDN list). This screening runs on Cambio's own infrastructure; wallet addresses are not shared with a third-party analytics provider for routine screening.
Identity verification: Where a swap is flagged for enhanced due diligence, any identity-verification data you submit is processed by our regulated verification partner, Didit (didit.me), solely to complete that review. This applies only to flagged swaps, not to routine use of the Service.
Exchange providers: Cambio is an aggregator. To price your swap it sends the corridor and amount — never your identity — to the instant exchanges it integrates. The provider that fulfils your order necessarily receives more: the destination address it must pay out to, and the deposit address it issues for you to send to. It does not receive your name, email, IP address, or any account identifier, because Cambio does not collect them for a routine swap. Each provider handles that data under its own privacy policy.
Liquidity venues: Separately from fulfilment, Cambio may transmit trade parameters (asset and amount) to third-party trading venues when rebalancing its own reserves. These venues receive only the trade size and asset; they do not receive your identity, wallet address, or any data linking the trade to a specific user or swap.
Legal compliance: We disclose data to law enforcement or regulatory authorities when compelled by a valid legal order issued by a court of competent jurisdiction in the Republic of Panama, or where required to comply with applicable sanctions regimes.
4. Data Retention
Swap transaction data is retained for 5 years after the swap is completed, in line with industry-standard record-keeping requirements for non-custodial software operators. After 5 years, transaction records are anonymized (wallet addresses hashed, amounts aggregated) and personally identifying linkages are deleted.
The IP address and resolved country associated with a swap are retained for 12 months and then automatically deleted, independent of the anonymized transaction record above.
For account holders, account data is retained for the duration of your account plus 12 months after account closure to permit dispute resolution. Address-book entries are deleted immediately upon account deletion.
Support ticket conversations are retained for 2 years.
5. Your Rights
You have the right to: (a) request a copy of the personal data we hold about you; (b) request correction of inaccurate personal data; (c) request deletion of your account data (subject to the retention obligations described above); (d) request that we stop using your data for any purpose beyond the legal/operational basis identified in this Policy.
To exercise these rights, contact privacy@cambio.one. We will respond within 30 days. There is no fee.
6. Security
Cambio uses industry-standard security practices to protect data in transit (TLS 1.3) and at rest (AES-256 encryption for sensitive fields). Operational signing keys are held in hardware-backed key management systems with multi-party access controls.
No system is ever 100% secure. If we ever experience a security incident affecting your personal data, we will notify affected users via email within 72 hours of discovery in accordance with applicable breach-notification obligations.
8. Contact
Questions about this Privacy Policy or your data: privacy@cambio.one. We respond to all data-rights requests within 30 days.