Privacy
Summary
Mo keeps this policy detailed because regulated money movement requires precision. The practical point is simpler: we minimize direct data storage, rely on licensed partners where appropriate, and explain where information is collected, shared, and retained.
What changed
Added a full EU/UK notice, expanded U.S. state privacy coverage (California, Colorado, Connecticut, Virginia, Nevada), listed our service providers by name, and covered Mo Points and Mo Plus. This policy is now available in your language.
This Privacy Policy describes how Mo Technologies Inc. ("Mo," "we," "us," or "our") collects, uses, and discloses personal information in connection with our websites, mobile applications, and related offerings that link to this Privacy Policy (collectively, the "Services"). In this policy, "personal information" includes "personal data" as defined under applicable data protection laws.
The Services include, among others, a non-custodial, unhosted digital asset wallet experience (the "Mo Application").
Disclosure Regarding Customer Data. For most individual users of Mo, this Privacy Policy applies directly to personal information processed in connection with the Services. In some cases, Mo may provide Services to organizations under a written agreement, and Mo may process certain information on that organization's behalf ("Customer Data"). In those cases, the organization's privacy policy governs its relationship with you, and requests regarding Customer Data should be directed to that organization.
Important Note on Data Minimization. Mo keeps minimal data, and stores personal information in one of three ways:
- Minimal data in Mo's own systems. The only identifiers Mo records in full are your email address and wallet address. For a saved bank withdrawal recipient, Mo stores only a reference ID, the recipient's name, and the last four digits of the linked account. For a virtual deposit account, Mo stores only a reference ID and the last four digits — never the full account or routing number. Full account and routing details are retrieved securely from our banking partner (Dakota) only at the moment they need to be shown to you.
- Transient encrypted server-side storage. Travel guest details (name, email, phone) are held in Mo's own encrypted storage for a short window to complete a booking with Nuitee, then automatically deleted.
- Pass-through, never stored by Mo. Store checkout shipping and contact details go directly to Shopify; Mo never persists them.
Identity verification documents and government IDs are handled by compliance partners; Mo does not store those documents.
1. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. If we do, we will post the updated version and revise the "Last updated" date above. In some cases, we may provide additional notice.
Cookie categories and controls for the marketing site are also described in our Cookie Policy.
2. Personal Information We Collect
2.1 Information You Provide
- Account Information. Such as name (if provided), email, and other information you submit to create or manage an account.
- Business Information (KYB). If you use the Services on behalf of a Business User, we may collect information about the entity and its beneficial owners or controllers as required for verification.
- Transaction and Blockchain Information. Such as wallet addresses, transaction hashes, token balances, and activity logs related to your use of supported networks.
- Rewards and Membership Information. Such as your Mo Points balance and activity, and your Mo Plus membership status and term. Mo Points are not currency and are not linked to a financial account; see Section 3 for how this information is used and Section 7 for retention.
- Communications. Such as emails, support requests, and messages you send to us.
2.2 Identity and Business Verification (KYC/KYB)
KYC is not mandatory for use of the Mo App. You may use basic wallet features, interact with protocols, and manage your digital assets without identity verification. Only fiat-related features (such as onramp and offramp services) require proper verification. In such cases, identity or business verification is performed and directly handled by our licensed compliance partners. Mo may receive verification status, risk signals, and compliance-related outcomes from them, but Mo does not itself perform identity verification or store sensitive verification documents.
2.3 Information Collected Automatically
- Device and Usage Information. Such as IP address, browser and device identifiers, app version, crash logs, and usage analytics.
- Analytics Technologies. We use cookies, SDKs, and similar technologies to understand how users interact with our Services. Current tools include:
- Google Analytics 4 (GA4) on the website and mobile app for aggregated usage data. See Google’s Privacy Policy.
- Firebase Analytics on the website and mobile app for aggregated engagement data. See Firebase Privacy Information.
- Firebase App Check on the mobile app to verify that requests to our backend come from our genuine, unmodified app, reducing abuse from bots and tampered clients. App Check does not collect personal information about you.
- Event Categories Collected. Analytics tools capture, in aggregate and without linking to your identity:
- Screen and page views to understand journey flow.
- Funnel progression across onboarding, transaction, and other key flows.
- Feature interactions such as taps, clicks, and engagement patterns.
- Quality and error events including crash reports, failed operations, and performance signals.
- Store review prompt events when a native app-store review prompt is displayed after a positive milestone.
How analytics consent currently works: On the website, we show an analytics consent prompt when required by applicable law. For jurisdictions that require opt-in, analytics stays off until you accept. For jurisdictions that permit opt-out, analytics may be enabled by default and you can turn it off from the prompt. We do not request Apple's App Tracking Transparency permission, collect the IDFA, or create persistent user-level analytics IDs that link website events to an identified individual.
App Store Review Prompts. Our mobile application may display a native app-store review prompt after you reach a positive milestone within the app. These prompts are handled entirely by the operating system. Mo does not transmit personally identifiable information in connection with the prompt, and your choice to leave a review, or not, is not shared with us.
Sentry
We use Sentry (Functional Software, Inc.) to monitor app stability and performance. Sentry collects technical data such as device information, stack traces, and interaction events (“breadcrumbs”) leading up to a crash. This data is used solely to identify and fix software bugs. IP addresses are captured for diagnostic purposes but are not used to cross-reference your identity.
Google Firebase Analytics
We use Google Firebase Analytics to understand how users interact with Mo. We have configured Firebase to NOT collect advertising identifiers (IDFA/AAID). The data collected includes app engagement metrics and general device properties (e.g., OS version, device model).
Geo-Detection & Consent
We use Cloudflare to identify your general jurisdiction (region/country) based on your IP address. This is used solely to determine if we must show you specific privacy consent options (e.g., for GDPR or CCPA compliance). We do not store your precise GPS location. On the website, this geo-detection is used to decide whether analytics should remain disabled until opt-in, or whether an opt-out banner should be shown.
2.4 Information from Third Parties
We may receive information from third parties you connect with, such as OAuth providers, and from service providers that help us operate the Services, such as fraud prevention or compliance providers, consistent with your settings and applicable law.
3. How We Use Personal Information
We use personal information to:
- Provide, operate, maintain, and improve the Services.
- Create and administer accounts and provide customer support.
- Facilitate transactions and display relevant transaction history.
- Administer Mo Points and Mo Plus, including tracking balances, membership status, and eligibility.
- Conduct security, fraud prevention, sanctions screening, and risk management.
- Comply with legal obligations and enforce our Terms.
- Conduct analytics and research to improve product performance.
- Send service communications and, where permitted, marketing communications with opt-out options.
4. How We Disclose Personal Information
We work with the following categories of service providers and partners. Where a specific vendor is named below, it is because the information it receives is material to how a Service works; other vendors that receive only aggregated or de-identified information are described in Section 2.3.
| Provider | Role | Services it supports |
|---|---|---|
| Dakota | Banking and compliance partner | Virtual accounts, bank withdrawal, KYC/KYB verification |
| Nuitee | Travel supplier | Hotel search, booking, cancellation, and amendment |
| Shopify | Commerce platform | Store catalog, order fulfilment, refunds |
| Coinbase Developer Platform (CDP) | Wallet infrastructure | Non-custodial wallet creation, transaction signing, Base gas sponsorship, and reading your Base balances and transaction history |
| Pimlico | Gas sponsorship infrastructure | Sponsors gas for transactions on non-Base chains, as a subprocessor of CDP |
| Relay | Cross-chain routing | Bridging deposits from other networks into your Base wallet, and outbound withdrawals from your Base wallet to other chains |
| OKX | Swap liquidity | Token swap execution |
| Alchemy | Blockchain infrastructure | Reading on-chain balances and activity via RPC on non-Base networks |
| Sentry, Google Analytics 4, Firebase | Analytics and stability monitoring | See Section 2.3 |
We may also disclose personal information:
- Legal and Safety. Where disclosure is required by law, regulation, legal process, or to protect rights, safety, and security.
- Corporate Transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
- Third-Party Services You Use. When you choose to interact with Third-Party Services, disclosures may occur as needed to fulfill your request.
Public Blockchain Disclosures. Transactions on public blockchains may be publicly visible and searchable. We do not control and cannot delete public blockchain records.
5. Your Privacy Choices and Rights
- Marketing. You may opt out of marketing emails by using the unsubscribe link or adjusting account preferences. We may still send essential service messages.
- Device Controls. You can control push notifications and certain permissions through your device settings.
- Access and Deletion. Depending on your location, you may have rights to access, correct, delete, or port your information. Contact legal@mo.xyz to exercise those rights.
- Account Deletion. You may request account deletion through the app settings, if available, or by emailing legal@mo.xyz. We will delete or anonymize personal information under our control except where retention is required by law, regulation, or legitimate compliance obligations.
6. International Transfers
We may process and store information in the United States and other countries where we or our service providers operate. If you are located outside the U.S., your information may be transferred internationally. Where required, we use appropriate safeguards, such as standard contractual clauses.
7. Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and protect the Services. Standard retention periods are listed below.
| Data Type | Retention Period |
|---|---|
| Account information (email) | Duration of account plus 3 years after deletion |
| Transaction records | 7 years for AML and tax compliance |
| KYC and KYB verification data | Held by third-party Compliance Providers under their retention policies, typically 5 to 7 years |
| Mo Points and Mo Plus membership records | Duration of account, consistent with account information above |
| Saved bank recipients (reference ID, name, last 4 digits) and virtual accounts (reference ID, last 4 digits) | Duration of the saved recipient or account |
| GA4 event-level data | 2 months under the current minimal retention setting |
| Firebase Analytics aggregate data | Platform defaults for aggregated and anonymized data |
| Customer support communications | 3 years after resolution |
Longer retention may apply where required by law, regulation, ongoing litigation, or audit requirements.
8. Notice to European Users (EU and UK GDPR)
If you are located in the European Economic Area or the United Kingdom, the following additional information applies to you.
8.1 Data Controller
Mo Technologies Inc. is the data controller for personal information processed under this Privacy Policy.
8.2 Legal Bases for Processing
We process personal information under the following legal bases under GDPR Article 6:
| Purpose | Personal information involved | Legal basis |
|---|---|---|
| Provide, operate, and improve the Services; administer accounts, Mo Points, and Mo Plus | Account information, transaction and blockchain information, rewards and membership information | Contract Performance |
| Facilitate transactions and display transaction history | Transaction and blockchain information | Contract Performance |
| Identity and business verification for fiat features | Information shared with Compliance Providers | Legal Obligation |
| Security, fraud prevention, sanctions screening, risk management | Account, device, and transaction information | Legal Obligation and Legitimate Interests |
| Analytics and product research | Device and usage information (see Section 2.3) | Legitimate Interests, or Consent where required by your jurisdiction |
| Service communications | Account information | Contract Performance |
| Marketing communications | Account information | Consent |
8.3 No Sensitive Personal Information
We ask that you not provide us with any sensitive personal information (for example, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics, genetic characteristics, criminal background, or trade union membership) through the Services. Where identity or business verification is required for fiat features, that process is performed by our compliance partners directly, and Mo does not receive or store the underlying documents (see Section 2.2).
8.4 Automated Decision-Making and Profiling
Some of our fraud prevention, sanctions screening, and risk management processes (Section 3) involve automated evaluation of account and transaction information, which can result in a transaction being delayed, held, or an account being restricted. Where such automated processing produces legal or similarly significant effects concerning you, you have the right not to be subject to a decision based solely on that processing, subject to the exceptions permitted by GDPR Article 22 (for example, where the processing is necessary to enter into or perform a contract with you, is authorized by law, such as sanctions screening, or is based on your explicit consent). To exercise this right, contact us using the details in Section 12.
8.5 Your Rights
Subject to applicable law, you may have the right to:
- Access your personal data and receive a copy.
- Rectify inaccurate or incomplete personal data.
- Request erasure of your personal data.
- Restrict processing of your personal data.
- Object to processing based on legitimate interests or direct marketing.
- Receive your data in a structured, machine-readable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority in your jurisdiction, including the UK Information Commissioner’s Office (ICO) if you are in the United Kingdom.
To exercise your rights, contact legal@mo.xyz.
8.6 International Data Transfers From the EEA/UK
The United States has not received an adequacy decision from the European Commission or the UK government. Where we or our service providers transfer personal information out of the EEA or UK to the United States or another country without an adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the UK's International Data Transfer Addendum, or, where those are not available, an applicable derogation such as your explicit consent to the specific transfer.
8.7 EU/UK Representative
Mo has not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR. If you are in the EEA or UK and wish to exercise your rights or raise a question about this Privacy Policy, please contact us directly at legal@mo.xyz.
8.8 Required Information
Providing certain personal information may be required to perform a contract or comply with legal obligations. If you choose not to provide required information, some features may be unavailable.
9. Supplemental State Privacy Notices (United States)
If you are a resident of a U.S. state with a comprehensive consumer privacy law, the following supplemental notices apply to you in addition to the rest of this Privacy Policy.
9.1 California
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides you with specific rights regarding your personal information.
Categories of Personal Information. In the preceding 12 months, we have collected the following categories of personal information:
- Identifiers: Email address, wallet addresses, IP address, and device identifiers.
- Commercial Information: Transaction history and records of digital assets held or transferred.
- Internet or Network Activity: Browsing history on our site, app usage data, and interactions with our Services.
- Geolocation Data: Approximate location derived from IP address.
- Professional or Employment Information: For Business Users, company name and role if provided.
Sources. We collect personal information from you directly, automatically through your use of the Services, from third-party Compliance Providers, and from analytics providers.
Use. We use personal information for the business purposes described in Section 3 of this Privacy Policy.
Disclosure and Sale. We do not sell your personal information as defined under CCPA and CPRA. We do not share personal information for cross-context behavioral advertising.
Your California Privacy Rights. As a California resident, you have the right to:
- Know: Request information about categories and specific pieces of personal information collected, sources, business purposes, and categories of third parties with whom it is shared.
- Delete: Request deletion of personal information, subject to legal exceptions.
- Correct: Request correction of inaccurate personal information.
- Opt Out of Sale or Sharing: We do not sell or share personal information for targeted advertising.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise your California privacy rights, contact legal@mo.xyz or submit a request through the app settings, if available. We will verify your identity before processing your request.
9.2 Colorado
If you are a Colorado resident, the Colorado Privacy Act (CPA) gives you the right to access, correct, and delete your personal data, to obtain a portable copy of it, and to opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. As described in Section 9.1, we do not sell personal information or use it for targeted advertising. To exercise your rights, contact legal@mo.xyz; if we deny your request, you may appeal by replying to our decision, and if the appeal is denied you may contact the Colorado Attorney General.
9.3 Connecticut
If you are a Connecticut resident, the Connecticut Data Privacy Act (CTDPA) gives you the right to confirm whether we process your personal data, access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, sale, or certain profiling. To exercise your rights, contact legal@mo.xyz. If we deny your request, you may appeal by replying to our decision.
9.4 Virginia
If you are a Virginia resident, the Virginia Consumer Data Protection Act (VCDPA) gives you the right to confirm whether we process your personal data, access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, sale, or certain profiling. To exercise your rights, contact legal@mo.xyz. If we deny your request, you may appeal by replying to our decision.
9.5 Nevada
Nevada residents may opt out of the sale of certain covered information under NRS 603A. As described in Section 9.1, we do not sell personal information. If you would like to submit a request under Nevada law regardless, contact legal@mo.xyz.
9.6 Other States
If you reside in a U.S. state with a comprehensive consumer privacy law not listed above, you may have similar rights to access, correct, delete, or port your personal information, and to opt out of certain processing. Contact legal@mo.xyz to submit a request, and we will honor applicable rights under the law of your state.
10. Children’s Privacy
The Services are intended for users who are at least 18 years old, or the age of majority in their jurisdiction, whichever is higher. We do not knowingly collect personal information from children under 18.
11. Third-Party Websites and Applications
The Services may link to third-party websites or applications. We are not responsible for their privacy practices. Your interactions with third parties are governed by their policies.
12. Contact Us
Mo Technologies Inc. is the controller of your personal information under this Privacy Policy. If you have questions, want to exercise your rights, or have concerns about our privacy practices, contact us at:
Mo Technologies Inc.1908 Thomes Ave STE 12342
Cheyenne, WY 82001
United States
Email: legal@mo.xyz