Privacy Policy


Last updated: September 11, 2026

1. Introduction

Moto Finance Inc. ("Moto", "we", "our" or "us"), a company incorporated in the State of Delaware, United States, is the data controller for the personal data processed in connection with our website https://moto-card.com (the "Site"), the Moto application (the "App"), our membership application process, and the Moto Card, Moto Membership and related services (together, the "Services"), except where this Privacy Policy states that we act as a data processor for one of our service providers.

This Privacy Policy is drawn up in accordance with Articles 12, 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable national data protection laws. It explains what personal data we collect, where we get it, why we use it and on what legal basis, who we share it with, where it is processed, how long we keep it, and the rights you have. It is incorporated by reference into our Card Terms.

Please read this Privacy Policy carefully. If you do not agree with it, please do not access the Site or apply for membership.

You can contact us about anything in this Privacy Policy at contact@moto-card.com.

‍

2. INFORMATION WE COLLECT

2.1 Personal Information

We may collect personal information that you voluntarily provide to us when you:

  • Register for an account
  • Apply for membership
  • Sign up for our newsletter
  • Contact us through our contact forms
  • Participate in surveys or contests

Depending on how you use the Services, we process the following categories of personal data:

- Identity and contact data: name, date of birth, nationality, residential address, email address, telephone number, and profile photograph.
- Identity verification (KYC) data: copies of government-issued identity documents, selfie images or video used for liveness checks, biometric data derived from those images, verification results, sanctions and politically exposed person screening results, and information on your source of funds or wealth where we are required to collect it.
- Financial and account data: wallet addresses, deposit balances and collateral, spending limits, card details, card transactions (merchant, amount, currency, date and location), EUR Virtual IBAN details and payment transactions, statements, Points and rewards, referral activity, Membership tier and billing information.
- Blockchain data: wallet addresses and on-chain transaction data, which are publicly visible on the relevant blockchain.
- Communications data: support requests, complaints, disputes and chargebacks, emails, in-app messages, and recordings of telephone calls with us.
- Device and usage data: device type, browser type, operating system, IP address, time zone, app version, device identifiers, pages visited, time spent on the Site or App, referring website addresses, crash reports and other diagnostic data, and data collected through cookies and similar technologies.
- Location data: approximate location derived from your IP address, which we use to enforce eligibility and sanctions restrictions.
- Marketing and preference data: newsletter sign-ups, marketing preferences, and responses to surveys or contests.
- Relationship Manager and benefits data: travel and lifestyle preferences, bookings and requests you make through your Relationship Manager or benefit programs.

Biometric data used for identity verification is a special category of personal data under Article 9 GDPR. See section 5.

2.2 Automatically Collected Information

When you access our Site, we may automatically collect certain information about your device and usage, including:

  • Device type
  • Browser type
  • Operating system
  • IP address
  • Time spent on the Site
  • Pages visited
  • Referring website addresses

3. HOW WE USE YOUR INFORMATION

We may use your personal data for the following purposes and rely on the following legal bases under Article 6 GDPR:

- To assess your membership application, create and maintain your account, and provide the Services, including the Moto Card, Memberships, Points, referral programs and benefits. Legal basis: performance of a contract with you, or steps taken at your request before entering into a contract.
- To verify your identity, screen you against sanctions and politically exposed person lists, monitor transactions, and meet our anti-money laundering, counter-terrorist financing, sanctions and record-keeping obligations. Legal basis: compliance with legal obligations to which we or our service providers are subject, and our legitimate interest in preventing financial crime.
- To collect Membership fees, manage collateral and spending limits, and process payments, statements and repayments. Legal basis: performance of a contract with you.
- To detect, prevent and investigate fraud, unauthorized use, abuse of the Points, referral or trial features, and security incidents. Legal basis: our legitimate interest in protecting the Services, our members and ourselves, and compliance with legal obligations.
- To provide customer support, handle complaints, disputes and chargebacks, and record calls for quality, training and evidential purposes. Legal basis: performance of a contract with you and our legitimate interest in resolving issues and defending legal claims.
- To send you administrative information, such as changes to our terms, fees and policies. Legal basis: performance of a contract with you and compliance with legal obligations.
- To send you marketing communications about Moto products, services and events. Legal basis: your consent where required by law; otherwise our legitimate interest in promoting our Services to existing members. You can opt out at any time.
- To improve the Site, App and Services, monitor and analyze usage and trends, and detect and fix technical issues. Legal basis: our legitimate interest in operating and improving the Services.
- To establish, exercise or defend legal claims, and to comply with requests from courts, regulators and law enforcement. Legal basis: compliance with legal obligations and our legitimate interests.

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests, rights and freedoms. You can ask us for more information about that assessment using the contact details in section 17.

4. DISCLOSURE OF YOUR INFORMATION

Providing identity and verification data is a legal requirement: without it we are legally prevented from opening an account or providing the Services. Providing account, financial and contact data is a contractual requirement: without it we cannot deliver the Services you request. Providing marketing and preference data is voluntary.

We may share your information with the following categories of third parties:

Service Providers: We may share your information with service providers that perform services on our behalf, such as web hosting, data analysis, payment processing, and customer service.

Business Partners: We may share your information with our business partners to offer you certain products, services, or promotions.

Legal Requirements: We may disclose your information where required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.With Your Consent: We may disclose your information for any other purpose with your consent.

Identity verification involves the processing of biometric data derived from your identity document and selfie in order to confirm that you are who you say you are. We, and the identity verification provider acting on our behalf, process this data on the basis of your explicit consent under Article 9(2)(a) GDPR, and, where applicable, on the basis of national laws that permit such processing for anti-money laundering purposes. You can withdraw your consent at any time, but without identity verification we are legally unable to provide the Services to you.

We share personal data with, and receive personal data from, the third-party service providers we have engaged to provide the Services. They include:
‍
- Our card issuer, Third National, and the card program partners that service the Moto Card on its behalf, together with the Visa card network, with which we exchange identity, account, spending limit and transaction data so that your Card can be issued, authorized, settled and disputed.
- Identity verification, sanctions screening and fraud prevention providers.
- Blockchain infrastructure, smart contract wallet, price oracle and liquidation service providers.
- Cloud hosting, data storage, analytics, communications, email, messaging and customer support providers.
- Payment and billing processors that collect Membership fees.
- Benefit partners that deliver airport lounge access, travel redemptions, Relationship Manager and concierge services, Moto Lens and Moto Spaces, with which we share the data needed to deliver the benefit you request.
- For users in Nigeria, BANEX Microfinance Bank Limited, which markets the Card in Nigeria and is responsible for compliance with the Nigeria Data Protection Act in respect of its processing.
- Our professional advisers, auditors, insurers and, in the event of a merger, financing, sale of assets or acquisition of all or part of our business, the prospective or actual acquirer and their advisers.

We also disclose personal data to courts, regulators, supervisory authorities, financial intelligence units, tax authorities and law enforcement where required by law or in response to valid requests, and to any other recipient with your consent.

Our service providers may only use your personal data for the purposes for which we engaged them or, where they are independent controllers, for their own legally required purposes. We do not sell your personal data.

5. DATA SECURITY

We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. However, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Site.

We use automated processes, including tools provided by our service providers, to verify your identity, screen you against sanctions lists, detect fraud, set and adjust your spending limit by reference to the value of your collateral, and trigger liquidation of collateral in the circumstances described in the Card Terms. Some of these decisions are made without human involvement and may result in your application being declined, a transaction being blocked, or your access being suspended. Where a decision is based solely on automated processing and has legal or similarly significant effects on you, you have the right to request human intervention, to express your point of view, and to contest the decision by contacting us using the details in section 17.

6. DATA RETENTION

We keep personal data only for as long as necessary for the purposes set out in this Privacy Policy, and determine retention periods using the following criteria:

- Identity verification, account and transaction records are kept for the duration of our relationship and for at least five years after it ends, and for up to ten years where required by anti-money laundering legislation.
- Financial and billing records are kept for the period required by applicable accounting and tax laws.
- Call recordings and support communications are kept for as long as needed to resolve the matter and to defend legal claims, typically no longer than twelve months unless a dispute is open.
- Device and usage data is kept in identifiable form for no longer than twenty-four months.
- Marketing data is kept until you opt out or withdraw your consent.
- Data relating to declined applications is kept for as long as required to meet our legal obligations and to prevent repeat or fraudulent applications.

Wallet addresses and on-chain transaction data recorded on public blockchains are immutable and cannot be deleted by us. When personal data is no longer needed we delete or anonymize it.

Your personal data is processed in the European Union and the European Economic Area, and in the Netherlands, where our team is based, and in the United States, where Moto Finance Inc. is incorporated and where our card issuer and a number of our technology providers are located. Some service providers may process data in other jurisdictions in which they operate.

Where personal data collected in the European Economic Area, the United Kingdom or Switzerland is transferred to a country that has not been recognized as providing an adequate level of data protection, including the United States, we rely on appropriate safeguards under Chapter V GDPR, principally the Standard Contractual Clauses approved by the European Commission, supplemented where necessary by additional technical and organizational measures, or on a recognized adequacy mechanism where the recipient is certified under it. You can obtain a copy of the relevant safeguards by contacting us. Please note that the laws of the United States may not provide the same level of protection for personal data as the laws of your home country.

7. YOUR PRIVACY RIGHTS

Under the GDPR and, depending on where you live, other applicable laws, you have the right to:

- Access your personal data and receive a copy of it, together with information about how we process it.
- Have inaccurate personal data corrected and incomplete personal data completed.
- Have your personal data erased in the circumstances set out in Article 17 GDPR, subject to our legal retention obligations.
- Restrict our processing of your personal data in the circumstances set out in Article 18 GDPR.
- Receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means.
- Object to processing based on our legitimate interests, and object at any time to direct marketing.
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you, except where permitted by Article 22 GDPR, and to obtain human intervention as described in section 6.

To exercise any of these rights, contact us at contact@moto-card.com. We may need to verify your identity before responding. We will respond without undue delay and within one month of receiving your request; that period may be extended by up to two further months where requests are complex or numerous, in which case we will inform you of the extension and the reasons for it. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. We would appreciate the opportunity to address your concerns before you approach a supervisory authority.

8. CHILDREN'S PRIVACY

Our Site is not intended for children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately.

9. THIRD-PARTY WEBSITES

Our Site may contain links to third-party websites and applications. We are not responsible for the privacy practices or the content of such websites or applications. We encourage you to read the privacy policies of these third parties before providing any information to them.

10. CHANGES TO OUR PRIVACY POLICY

Our processing of personal data is governed by the GDPR and applicable national data protection laws in the EU and EEA member states in which our members reside, including the Nigeria Data Protection Act 2023 in respect of users in Nigeria. Much of the processing described in this Privacy Policy is required by financial regulation, including Directive (EU) 2015/849 on the prevention of money laundering and terrorist financing and the national laws implementing it, Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, Regulation (EU) 2023/1114 on markets in crypto-assets and Directive (EU) 2015/2366 on payment services where applicable to our service providers, and sanctions regimes administered by the United Nations, the European Union and the United States Office of Foreign Assets Control.

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

11. CONTACT US

If you have any questions or concerns about this Privacy Policy, please contact us at:Moto Finance Inc.

contact@moto-card.com‍

Last updatedSeptember 11, 2026