Pine
/// LEGAL // PRIVACY

Privacy Notice

PART II – PRIVACY POLICY


Introduction

Pine Labs S.A. ("Pine", "we", "us", "our") is committed to protecting the privacy of our Users. This Privacy Policy describes how we collect, use, share, and protect personal data in connection with your use of the Pine Platform.

This Policy is incorporated by reference into our Terms and Conditions and should be read together with them.

Data Controller: Pine Labs S.A., Calle Aquilino de la Guardia Calle 47, Ocean Busin, Panama, Panama, Panama, Republic of Panama Contact for privacy matters: support@pinewallet.io Last Updated: 1 June 2026


1. Scope of This Policy

This Policy applies to:

  • Users and prospective Users of the Pine web application and mobile application;
  • Visitors to Pine's website;
  • Representatives of legal entities that use Pine's services.

By creating an account, using the Platform, or providing data to us, you confirm that you have read and understood this Policy.


2. Personal Data We Collect

Depending on the services you use and your profile mode (LITE or NORMAL), we may process the following categories of personal data:

2.1. Registration and Identity Data

DataSourcePurpose
Email addressYouAccount creation, authentication, notifications
UsernameYouAccount identification
Privy authentication ID (DID)PrivyLinking your wallet/social login to your Pine account
Ethereum/EVM wallet addressYou / PrivyBlockchain interactions, smart account derivation
Smart account address (Pimlico)SystemSavings/sub-account functionality
Profile mode (LITE / NORMAL)YouFeature access control
Language / locale preferencesYouLocalisation

2.2. KYC / Identity Verification Data

When required by applicable law or by Third-Party Providers (VirtuaBroker, Card Provider):

DataProvider ProcessingPurpose
Full nameVIRTUABROKER CORP. / Card ProviderLegal identity verification
Date of birthVIRTUABROKER CORP. / Card ProviderAge and identity verification
Nationality and country of residenceVIRTUABROKER CORP. / Card ProviderSanctions screening, eligibility
Government-issued ID documentsVIRTUABROKER CORP. / Card ProviderKYC/AML compliance
Proof of addressVIRTUABROKER CORP. / Card ProviderAML due diligence
Biometric/liveness data and liveness checkSumsub (sub-processor of VIRTUABROKER CORP. / Card Provider)Identity verification
Source of funds informationVIRTUABROKER CORP. / Card ProviderAML enhanced due diligence
Sumsub verification tokenSumsub → VIRTUABROKER CORP. → Card ProviderKYC re-use — avoids duplicate identity verification across providers

Important: KYC/KYB processing is performed by VIRTUABROKER CORP. and the Card Provider using Sumsub (sumsub.com) as their identity verification sub-processor. Sumsub processes identity documents, biometric data, and liveness checks on behalf of these providers under its own privacy obligations. Pine receives only verification status outcomes (pass/fail) and, where applicable, a Sumsub verification token used solely to avoid duplicate KYC across providers — Pine does not receive or store raw identity documents or biometric data. Sumsub’s Privacy Notice is available at sumsub.com/privacy-notice.

2.3. Financial and Transaction Data

DataPurpose
Wallet addresses and transaction hashesDisplaying portfolio and history
On-ramp/off-ramp transaction details (amount, currency, pairs)Order processing via VirtuaBroker
Exchange orders, deposits, withdrawal recordsOrder management and support
Card transaction historyDisplayed in-app (sourced from Card Provider)
Vault deposit/withdrawal data (Morpho)Displaying investment positions
Token balances and asset portfolioPortfolio display via Alchemy
Saved payment methods and beneficiary informationFacilitating repeat transactions, reducing manual entry, payment destination management

2.3.1. Saved Payment Methods and Beneficiary Data

Where supported by the Platform, Users may optionally save payment methods, payout destinations, or beneficiary information for convenience and faster transaction flows.

This information may include:

  • beneficiary or recipient full name;
  • bank account details, IBAN, account identifiers, or payment destination information;
  • phone numbers linked to payment destinations;
  • country or jurisdiction information;
  • national identification numbers or tax identifiers where voluntarily provided by the User or required for a specific payment flow.

This functionality is optional. Users may update or delete saved payment methods through the Platform where available.

2.4. Technical and Device Data

DataPurpose
IP addressSecurity, rate limiting, fraud prevention
Device type, browser, operating systemCompatibility and security
Session data, access logsSecurity monitoring, debugging
Chain ID / network selectionsMulti-chain functionality

2.5. Communications Data

DataPurpose
Email content (support correspondence)Customer support
In-app notification dataService communications via Novu
User-submitted feedbackPlatform improvement

2.6. Encrypted Personal Data

Sensitive personal, financial, and beneficiary profile data stored in our database is encrypted at rest using AES-256 encryption. Decryption requires a server-side key managed by Pine under strict access controls.


3. How We Collect Personal Data

  • Directly from you: when you register, complete KYC, or contact support;
  • Automatically: via cookies, logs, and telemetry when you use the Platform (see Part III – Cookie Policy);
  • From Third-Party Providers: Privy (authentication and wallet identity), VIRTUABROKER CORP. (KYC outcomes, order data), Alchemy / Moralis (transaction and portfolio data), CoinMarketCap (token prices);
  • From public blockchain data: wallet addresses, transaction hashes, and on-chain data are publicly available on the respective blockchains and are not exclusively within Pine's control.

4. Legal Basis for Processing

We process personal data on the following legal bases, in accordance with applicable data protection law (including the GDPR where applicable):

| Processing Activity | Legal Basis | | ---------------------------------------------------------- | ----------------------------------------------- | --- | ------------------------------------------------ | ----------------------------------------------- | | Account creation and management | Performance of a contract | | Authentication via Privy | Performance of a contract | | Smart account creation (Pimlico) | Performance of a contract | | KYC / AML compliance checks | Legal obligation | | Sanctions screening | Legal obligation / legitimate interest | | Transaction processing (on-ramp/off-ramp via VirtuaBroker) | Performance of a contract | | Card programme access (Card Provider) | Performance of a contract | | Portfolio and transaction history display | Performance of a contract / legitimate interest | | Security monitoring, rate limiting, fraud prevention | Legitimate interest | | Notifications and service communications (Novu) | Performance of a contract / legitimate interest | | Marketing communications | Consent (where required) | | Improving the Platform | Legitimate interest | | Reporting to authorities | Legal obligation | | Saved payment methods and beneficiary management | Performance of a contract / Legitimate interest |


5. Third-Party Service Providers and Data Sharing

We may share personal data with the following categories of recipients:

5.1. Technology and Infrastructure Partners

ProviderRoleData SharedPrivacy Reference
Privy (privy.io)Authentication & embedded wallet providerEmail, wallet address, authentication IDprivy.io/privacy
PimlicoERC-4337 bundler and paymasterWallet address, UserOperation datapimlico.io/privacy
Relay (relay.link)Token swaps and cross-chain bridgeWallet address, chain ID, transaction datarelay.link
AlchemyBlockchain RPC and portfolio dataWallet address, chain IDalchemy.com/privacy-policy
MoralisTransaction history indexingWallet address, chain IDmoralis.io/privacy-policy
CoinMarketCapToken price dataAPI queries (no personal data)coinmarketcap.com/privacy
NovuNotification infrastructureUser ID, email, notification preferencesnovu.co/privacy
Sumsub (sumsub.com)Identity verification sub-processor (used by VIRTUABROKER CORP. and Card Provider for KYC/KYB)Identity documents, biometric data, liveness check results, verification tokensumsub.com/privacy-notice
Redis (infrastructure)Caching layerSession tokens, cached dataN/A (infrastructure)
PostgreSQL (infrastructure)DatabaseAll stored user and account dataN/A (infrastructure)

5.2. Financial and Compliance Partners

ProviderRoleData Shared
VIRTUABROKER CORP. (VirtuaBroker)Fiat on/off-ramp, KYC, openbanking exchangeEmail, wallet address, transaction data, KYC documentation
Card Provider (confidential)Virtual/physical card programmesEmail, wallet address, KYC data, card usage data
Morpho ProtocolDeFi lending vault infrastructureWallet address (on-chain, publicly visible)

5.3. Regulatory and Legal Authorities

We may disclose personal data to competent administrative, judicial, fiscal, or regulatory authorities when required by applicable law, court order, or regulatory mandate.

5.4. Corporate Transfers

In the event of a merger, acquisition, or corporate restructuring, personal data may be transferred to a successor entity, subject to appropriate confidentiality commitments.


6. International Data Transfers

Some of our Third-Party Providers are located outside your country of residence or outside the European Economic Area (EEA). Where personal data is transferred internationally, we ensure that appropriate safeguards are in place, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • adequacy decisions by relevant data protection authorities;
  • compliance with the provider's applicable data transfer frameworks.

You may contact us at support@pinewallet.io to obtain information about the safeguards applicable to specific transfers.


7. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

Data CategoryRetention Period
Account registration dataDuration of active account + applicable legal retention period
KYC / AML dataAs required by applicable AML/CFT law (typically 5–10 years post-relationship)
Transaction and financial recordsAs required by applicable financial regulations
Communication logs / support tickets3 years from last interaction, or as required by law
Security logs (IP, access logs)90 days to 12 months, depending on applicable law
Marketing consent recordsUntil consent is withdrawn + reasonable dispute period
Encrypted user profile dataDuration of active account; deleted upon verified account closure request
Saved payment methods and beneficiary informationDuration of active account, until removed by the User, or for longer periods where required for fraud prevention, compliance, dispute handling, or legal obligations

After the applicable retention period, data is deleted or anonymised in a manner that prevents re-identification.


8. Your Rights as a Data Subject

Depending on your country of residence and applicable law, you may have the following rights:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
Erasure ("Right to be Forgotten")Request deletion of your data where no legal obligation to retain exists
RestrictionRequest that we limit processing of your data in certain circumstances
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interest or for direct marketing
Withdraw ConsentWithdraw consent at any time where processing is consent-based
Automated DecisionsNot be subject to solely automated decision-making that significantly affects you

How to exercise your rights: Submit a request to support@pinewallet.io. We may need to verify your identity before processing your request. We will respond within the timeframe required by applicable law (e.g., 30 days under GDPR).

Supervisory authority: If you are a resident of the European Union or EEA and believe we are not processing your data in accordance with the GDPR, you have the right to lodge a complaint with your local data protection supervisory authority.


9. Children

The Platform and Pine's services are not directed to persons under 18 years of age (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected such data, we will take reasonable steps to delete it promptly.


10. Security Measures

Pine implements technical, administrative, and organisational security measures including:

  • Encryption at rest: sensitive user data is encrypted using AES-256 encryption in the database;
  • Encryption in transit: all data transmitted between users and the Platform uses TLS/HTTPS;
  • Authentication: multi-factor authentication options via Privy;
  • Access controls: role-based access control (RBAC) for internal systems;
  • Rate limiting: API rate limiting via Redis-backed throttling (60 requests/minute per User);
  • Input validation: server-side input sanitisation and validation on all API endpoints;
  • Security monitoring: access logs and anomaly detection.

Notwithstanding the above, no system is completely secure. We cannot guarantee that security incidents will never occur.


11. Links to Third-Party Services

The Platform integrates with or links to third-party services. Pine is not responsible for the privacy practices of those services. We encourage you to review the privacy policies of Third-Party Providers before sharing personal data with them.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the Platform or by email. The updated Policy will be effective from the date indicated at the top. Continued use of the Platform after such changes constitutes acceptance of the updated Policy.



PART III – COOKIE POLICY


Introduction

This Cookie Policy explains how Pine Labs S.A. ("Pine", "we", "us", "our") uses cookies and similar tracking technologies on the Pine web application (the "Platform").

This Policy should be read together with our Privacy Policy (Part II) and Terms and Conditions (Part I).

Last Updated: 25 May 2026


1. What Are Cookies?

Cookies are small text files stored on your device (computer, tablet, or mobile) when you visit a website or web application. Cookies are widely used to make applications work efficiently, to improve user experience, and to provide analytics and reporting information.

Similar technologies include:

  • Local Storage / Session Storage: browser-based storage used by JavaScript for persisting session state;
  • Pixels / web beacons: tiny images or scripts used to track user interactions;
  • Device fingerprinting: collecting device-level attributes for security and fraud detection.

2. Types of Cookies and Technologies We Use

2.1. Strictly Necessary Cookies and Technologies

These are essential for the Platform to function. They cannot be disabled without severely impairing core functionality. No consent is required for these.

Name / TechnologyProviderPurposeDuration
JWT authentication tokenPine (internal)Maintains your authenticated session24 hours
Privy session tokenPrivy (privy.io)Manages your embedded wallet and authentication sessionSession / Privy-defined
CSRF protection tokenPine (internal)Prevents cross-site request forgery attacksSession
Rate-limiting identifier (Redis)Pine (internal)Enforces API rate limits to prevent abuse60 seconds rolling
Wallet connection state (localStorage)Pine (internal)Persists connected wallet and chain selectionSession

2.2. Functional Cookies and Technologies

These cookies enable enhanced functionality and personalisation but are not strictly necessary.

Name / TechnologyProviderPurposeDuration
Language/locale preferencePine (internal)Stores your preferred language and regional settingsPersistent (up to 1 year)
Profile mode preferencePine (internal)Remembers your selected profile mode (LITE / NORMAL)Persistent (account lifetime)
Chain selection cachePine (internal)Caches your last selected blockchain networkSession

2.3. Analytics and Performance Cookies

These cookies help us understand how Users interact with the Platform so we can improve it.

Name / TechnologyProviderPurposeDuration
_gaGoogle (Google Analytics 4)Distinguishes unique users; used for page view counting and session measurement across all GA4 properties2 years
_ga_*Google (Google Analytics 4)Stores and counts page views for the Pine GA4 property2 years

Analytics cookies are only set when you have explicitly accepted analytics cookies via the consent banner. You can withdraw consent at any time by clicking "Reject all" in the consent banner or clearing your browser cookies.

2.4. Third-Party Service Cookies

Certain Third-Party Providers integrated into the Platform may set their own cookies or use their own tracking technologies:

ProviderPurposePrivacy Policy
PrivyEmbedded wallet authenticationprivy.io/privacy
Alchemy (API calls)Blockchain data (no client-side cookies, server-side API)alchemy.com/privacy-policy
Novu (in-app notifications)Notification delivery and preferencesnovu.co/privacy

3. Why We Use These Technologies

CategoryPurpose
Authentication and session managementTo verify your identity, maintain your logged-in session, and secure your account
SecurityTo detect and prevent fraud, abuse, and unauthorised access
FunctionalityTo remember your preferences, wallet connections, and application state
PerformanceTo cache data efficiently (e.g., token prices, KYC status) and reduce API calls
AnalyticsTo understand usage patterns and improve the Platform

4. Your Cookie Choices

4.1. Strictly necessary cookies cannot be disabled, as they are essential for the Platform to function securely.

4.2. Functional and analytics cookies can be managed through:

  • your browser settings (most browsers allow you to block or delete cookies; see your browser's help documentation);
  • the in-app privacy settings via the Platform's cookie consent banner (currently active on the web application);
  • opt-out mechanisms provided by Third-Party Providers (see their respective privacy policies).

4.3. Please note that disabling certain cookies may impair your ability to use some features of the Platform, including wallet connections, notifications, and preference persistence.


5. Mobile Application Considerations

The Pine mobile application (built with Capacitor/Ionic on Android) does not use browser cookies in the traditional sense. However, similar data persistence is achieved through:

  • Android SharedPreferences and secure storage for session tokens;
  • Application local storage for user preferences and wallet state;
  • In-app HTTP sessions using HTTPS with server-side session management.

All mobile-side data storage follows the same principles as described in this Policy.


6. Do Not Track

Some browsers include a "Do Not Track" (DNT) feature that signals your preference not to be tracked. The Platform currently does not respond to DNT signals. The Platform relies on its own consent management mechanism — the cookie consent banner — to collect and manage your tracking preferences. We encourage you to use the consent banner to control your cookie settings.


7. Updates to This Cookie Policy

We may update this Cookie Policy to reflect changes in the technologies we use or applicable regulations. We will notify you of material changes through the Platform. The updated Policy is effective from the date indicated at the top.


8. Contact

For any questions about this Cookie Policy or our use of tracking technologies, contact us at: support@pinewallet.io



Appendix A – Third-Party Providers Summary

ProviderService CategoryRegulatory Notes
Privy (privy.io)Authentication, embedded walletNon-custodial; GDPR compliant
Sumsub (sumsub.com)Identity verification sub-processor (KYC/KYB)Used by VIRTUABROKER CORP. and Card Provider; GDPR compliant; processes identity documents and biometrics
VIRTUABROKER CORP. (VirtuaBroker)Fiat on/off-ramp, KYC, openbankingRegulated exchange partner; own KYC/AML obligations; technology infrastructure model; underlying fiat/custody services provided by VirtuaBroker's regulated third-party partners
Card Provider ([CONFIDENTIAL])Virtual/physical card programmeOperates under issuer's financial licence
AlchemyBlockchain RPC, portfolio data, transaction dataEnterprise API; SOC 2 compliant
MoralisTransaction history indexingEnterprise API
MorphoDeFi lending vaults (ERC-4626 / ERC-4337)Decentralised protocol; no regulatory licence
PimlicoERC-4337 bundler and paymasterInfrastructure provider
Relay (relay.link)Token swaps and cross-chain bridgeThird-party protocol; charges service fee per swap/bridge transaction
NovuNotification infrastructureGDPR compliant
CoinMarketCapToken pricing dataData provider

Appendix B – Supported Blockchain Networks and Risk Disclosures

NetworkChain IDNotes
Ethereum Mainnet1High liquidity; highest security assumptions
Polygon (PoS)137Layer 2 / sidechain; additional bridge risk
BNB Smart Chain56Third-party chain; own validator set
Arbitrum One42161Optimistic rollup; fraud proof window
Base8453Optimistic rollup (Coinbase); fraud proof window

Use of any network involves smart contract, validator, bridge, and consensus risks that are beyond Pine's control.


Appendix C – DeFi Vault Risk Disclosure

By accessing the Invest (vaults) section of Pine, you confirm that you have read and understood the following:

  1. No guarantees: Yield rates are variable, not guaranteed, and can be zero or negative.
  2. Smart contract risk: Morpho protocol smart contracts may contain bugs or be exploited.
  3. Liquidity risk: You may not be able to withdraw funds immediately in all market conditions.
  4. Regulatory risk: DeFi protocols are not licensed financial products in most jurisdictions. Regulations may change.
  5. Loss of capital: You may lose part or all of your deposited assets.

This disclosure does not constitute investment advice. Consult a qualified financial advisor before participating in any DeFi product.


END OF LEGAL DOCUMENTS

For questions, legal notices, or data subject requests:

[ PINE WALLET // LEGAL ]

Pine Labs S.A. ("Pine") is a non-custodial, self-custody digital asset technology platform. Pine does not act as a bank, electronic money institution, payment service provider, investment firm, or card issuer. Digital assets are held directly by users — Pine does not custody, hold, or manage user funds on their behalf. Access to exchange, card, and DeFi services is provided through third-party providers operating under their own regulatory frameworks. Pine does not provide financial, legal, tax, or investment advice, and does not guarantee returns on any product or service accessible through the Platform. Use of this Platform is subject to the Terms and Conditions available on this website.

Terms and ConditionsPrivacy Notice
REV 1.0 // PINE WALLET © 2026