Privacy Policy

Last updated: 17 September 2025

This Privacy Policy explains how OOOIOO (the “App”, “Platform”, or “OOOIOO”), operated by ON MONETARY UNIR DOT COM INC, a Public Benefit Corporation ("ON", "we", "us", or "our"), collects, uses, shares, and safeguards information about you when you access our websites, mobile applications, cards, and related online/offline services (collectively, the “Services”).

Controller: For GDPR/UK GDPR purposes, ON MONETARY UNIR DOT COM INC. is the data controller for Personal Data processed via the Services, unless otherwise stated (e.g., when acting solely as a processor for an enterprise customer).

By using the Services, you acknowledge that we will process your information as described in this Privacy Policy. We do not sell or “share” your Personal Information for cross‑context behavioral advertising as defined under U.S. state privacy laws.

Interpretation and Definitions

Interpretation

Unless otherwise indicated, capitalized terms have the meanings given below. Terms apply whether used in the singular or plural.

Definitions

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

When you use the Services, we may collect the following categories of Personal Data:

Providing certain data may be necessary to deliver the Services (e.g., identity checks for card issuance). Where required by law, we will request your consent. issuance). Where required by law, we will request your consent.

Usage Data (automatic collection)

We automatically collect Usage Data when you interact with the Services. This includes information such as your IP address (and general location derived from IP), device type, operating system, app/browser type and version, device and advertising identifiers (if available), language, time zone, pages/screens viewed, feature usage, click/tap events, session duration, referrer/UTM parameters, diagnostics, crash logs, performance telemetry, and security events (e.g., login attempts, authentication state). On mobile devices, similar data may be collected via embedded SDKs for functionality, diagnostics, and security.

Tracking Technologies, Cookies, and SDKs

We use cookies, SDKs, and similar technologies (such as pixels, tags, and local storage) to operate, secure, and improve the Services.

Types we use:

We do not use cookies or SDKs for cross-context behavioral advertising and do not sell or “share” Personal Information as defined by the CPRA.

Your choices:

Use of Your Personal Data

We use Personal Data only as permitted by law (GDPR/UK GDPR, CPRA, and others). Our main purposes include:

We do not sell Personal Information or “share” it for cross-context behavioral advertising as defined by CPRA.

Sharing and Disclosure of Personal Data

We disclose Personal Data only as needed to operate the Services or as required by law:

A current list of key sub-processors is available upon request at privacy@onmonetaryunit.com.

Retention of Personal Data

We retain Personal Data only as long as necessary for the purposes above and to satisfy legal, accounting, or regulatory requirements. When no longer needed, we delete or anonymize it.

Typical retention periods:

Upon account deletion, we begin deletion within 30 days. Some records may be retained as required by law (e.g., sanctions screening, finance).

International Transfers

We operate globally. When transferring Personal Data outside your jurisdiction (e.g., EEA/UK to the U.S.), we use appropriate safeguards, including:

We do not rely on your general consent as the legal basis for international transfers.

Security of Your Personal Data

We use administrative, technical, and physical safeguards to protect Personal Data, including encryption in transit and at rest, access controls with least privilege, key management, secure software development practices, vulnerability management, and incident-response procedures. Despite our efforts, no method of transmission or electronic storage is 100% secure. If we learn of a breach affecting your Personal Data, we will notify you and regulators as required by law.

Detailed Information on Processing (Categories of Providers)

We engage third-party providers (Processors) that process Personal Data strictly on our instructions and under appropriate data-protection terms. Examples of categories include: Hosting & Storage (infrastructure, databases, backups, CDN); Identity Verification (KYC)Footprint; Payments & Card Program — payment processors, card issuer/program manager, fraud/chargeback tools; Analytics & Crash Reporting; Security & Abuse Prevention; Communications — email/SMS/push, in-app support/ticketing; AI Inference Providers — runtime model inference (we opt out of model training wherever offered). A current list of key sub-processors is available upon request at privacy@onmonetaryunit.com.

Analytics

We use privacy-centric analytics and crash-reporting tools to understand product performance and improve reliability. Where required (e.g., EEA/UK), we obtain your consent before setting non-essential cookies/SDKs.

● What we don’t do: we do not use analytics for cross‑context behavioral advertising,
and we do not sell or “share” Personal Data as defined by CPRA.
● Your choices: manage non‑essential cookies/SDKs via our banner/settings (web) and
app controls (mobile).

Email Marketing

We may send you:

You can opt out of marketing at any time via the unsubscribe link in our emails or by contacting privacy@onmonetaryunit.com. Opting out does not affect transactional messages.

Payments and Card Program

For paid products/services and any card program features:

Provider identities and data-flow details are available upon request at privacy@onmonetaryunit.com.

GDPR / UK GDPR Privacy Notice

Legal Bases for Processing

We process Personal Data only where a lawful basis applies:

Your Rights (EEA/UK/Switzerland)

Subject to exemptions in law, you have the right to: access, rectify, erase, restrict, object (including to direct marketing), portability, withdraw consent, contest automated decisions, and complain to your data-protection authority.

How to exercise. Use in-app controls or contact privacy@onmonetaryunit.com. We may ask for information to verify your identity. We respond within 1 month (extendable by up to 2 months for complex requests, with notice).

EU/UK representative and DPO. We have appointed a representative/DPO for the EEA/UK.
Contact details: legal name, postal address, email/phone of EU/UK representative or DPO.

U.S. State Privacy Notice (including California CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA)

This section applies to U.S. state residents where we are subject to the relevant state privacy law (e.g., if we “do business” in a state or otherwise meet that law’s applicability thresholds). It supplements the rest of this Policy.

General (All Covered States)

California (CPRA)

Categories of Personal Information Collected (last 12 months):
(Definitions per Cal. Civ. Code §1798.140.)

Sensitive Personal Information (SPI): Processed only for limited permitted purposes (e.g., government ID for KYC) and not to infer characteristics; therefore, the right to limit generally does not apply. If our use changes, we will provide a right-to-limit mechanism.

Disclosures for Business Purposes (last 12 months):
We disclose PI to Service Providers/Processors under contracts that restrict its use to our purposes. Categories disclosed: A, B, D, F (and E only for KYC via Footprint).

CPRA Rights & How to Exercise Them:
You may request Know/Access, Delete, Correct, and other CPRA rights. Submit requests via in-app controls or privacy@onmonetaryunit.com. We respond within 45 days (extendable once by 45 days with notice). We will honor Global Privacy Control (GPC) if we begin selling/sharing PI in the future.

Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA)

If you are a resident of VA, CO, or CT and we are subject to that state’s law, you may have rights to: access, confirm, delete, correct, and data portability; and to opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. Submit requests via in-app controls or privacy@onmonetaryunit.com. Appeals: email privacy@onmonetaryunit.com with subject “Privacy Appeal.”

Utah (UCPA)

If you are a Utah resident and we are subject to UCPA, you may have rights to: access, delete, and data portability; and to opt out of sale or targeted advertising. (UCPA does not include a correction right or a profiling opt-out.) Submit requests via in-app controls or privacy@onmonetaryunit.com.

“Do Not Track” (CalOPPA)

Browser Do Not Track (DNT) signals are not yet standardized, so we do not respond to DNT at this time. If we begin selling or sharing Personal Information in the future, we will honor applicable opt-out signals such as Global Privacy Control (GPC).

Children’s Privacy

Our Services are not directed to children under 16 (or a higher age where required by local law). We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data to us, please contact privacy@onmonetaryunit.com and we will take appropriate action. Where parental consent is required by law (e.g., COPPA for children under 13), we will obtain it before processing.

Links to Other Websites

Our Services may contain links to third-party websites or services. We are not responsible for their content or privacy practices. Please review the privacy policies of every site you visit.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where changes are material, notify you in-app or by email. Your continued use of the Services after the effective date means you accept the changes.

Contact Us


Annex A — Data Map (Overview)

Systems: App, Web, Authentication, Billing, Card program, KYC (Footprint), Support desk, Analytics, Logging/SIEM, File storage, Email, Push notifications, AI inference
Vendors: Hosting, email/SMS, identity, payment/card issuer & program manager, analytics, crash reporting, fraud/security, AI providers
Transfers: EEA/UK → US via SCCs + supplementary measures; UK Addendum; DPF (if certified)


Annex B — Sub-processors (Availability)

For security reasons, we do not publish a public list. A current list of sub-processors (names, roles, locations) is available upon request at privacy@onmonetaryunit.com.


Annex C — Retention Schedule (Summary)

See Retention of Personal Data. Jurisdiction-specific minimums (finance/KYC) may require longer retention (e.g., 5–10 years).


Cookie Notice (Summary)

We use cookies, mobile SDKs, and similar technologies (pixels, tags, local storage) to operate, secure, and improve the Services. Some are essential and cannot be switched off. Others are optional and used only with your consent where required (e.g., EEA/UK).

Categories We Use

Your Controls

Retention

For more details, contact privacy@onmonetaryunit.com. We will update this Notice if our providers or purposes change.