Privacy Notice
PART II – PRIVACY POLICY
Introduction
Pine Labs S.A. ("Pine", "we", "us", "our") is committed to protecting the privacy of our Users. This Privacy Policy describes how we collect, use, share, and protect personal data in connection with your use of the Pine Platform.
This Policy is incorporated by reference into our Terms and Conditions and should be read together with them.
Data Controller: Pine Labs S.A., Calle Aquilino de la Guardia Calle 47, Ocean Busin, Panama, Panama, Panama, Republic of Panama Contact for privacy matters: support@pinewallet.io Last Updated: 1 June 2026
1. Scope of This Policy
This Policy applies to:
- Users and prospective Users of the Pine web application and mobile application;
- Visitors to Pine's website;
- Representatives of legal entities that use Pine's services.
By creating an account, using the Platform, or providing data to us, you confirm that you have read and understood this Policy.
2. Personal Data We Collect
Depending on the services you use and your profile mode (LITE or NORMAL), we may process the following categories of personal data:
2.1. Registration and Identity Data
| Data | Source | Purpose |
|---|---|---|
| Email address | You | Account creation, authentication, notifications |
| Username | You | Account identification |
| Privy authentication ID (DID) | Privy | Linking your wallet/social login to your Pine account |
| Ethereum/EVM wallet address | You / Privy | Blockchain interactions, smart account derivation |
| Smart account address (Pimlico) | System | Savings/sub-account functionality |
| Profile mode (LITE / NORMAL) | You | Feature access control |
| Language / locale preferences | You | Localisation |
2.2. KYC / Identity Verification Data
When required by applicable law or by Third-Party Providers (VirtuaBroker, Card Provider):
| Data | Provider Processing | Purpose |
|---|---|---|
| Full name | VIRTUABROKER CORP. / Card Provider | Legal identity verification |
| Date of birth | VIRTUABROKER CORP. / Card Provider | Age and identity verification |
| Nationality and country of residence | VIRTUABROKER CORP. / Card Provider | Sanctions screening, eligibility |
| Government-issued ID documents | VIRTUABROKER CORP. / Card Provider | KYC/AML compliance |
| Proof of address | VIRTUABROKER CORP. / Card Provider | AML due diligence |
| Biometric/liveness data and liveness check | Sumsub (sub-processor of VIRTUABROKER CORP. / Card Provider) | Identity verification |
| Source of funds information | VIRTUABROKER CORP. / Card Provider | AML enhanced due diligence |
| Sumsub verification token | Sumsub → VIRTUABROKER CORP. → Card Provider | KYC re-use — avoids duplicate identity verification across providers |
Important: KYC/KYB processing is performed by VIRTUABROKER CORP. and the Card Provider using Sumsub (sumsub.com) as their identity verification sub-processor. Sumsub processes identity documents, biometric data, and liveness checks on behalf of these providers under its own privacy obligations. Pine receives only verification status outcomes (pass/fail) and, where applicable, a Sumsub verification token used solely to avoid duplicate KYC across providers — Pine does not receive or store raw identity documents or biometric data. Sumsub’s Privacy Notice is available at sumsub.com/privacy-notice.
2.3. Financial and Transaction Data
| Data | Purpose |
|---|---|
| Wallet addresses and transaction hashes | Displaying portfolio and history |
| On-ramp/off-ramp transaction details (amount, currency, pairs) | Order processing via VirtuaBroker |
| Exchange orders, deposits, withdrawal records | Order management and support |
| Card transaction history | Displayed in-app (sourced from Card Provider) |
| Vault deposit/withdrawal data (Morpho) | Displaying investment positions |
| Token balances and asset portfolio | Portfolio display via Alchemy |
| Saved payment methods and beneficiary information | Facilitating repeat transactions, reducing manual entry, payment destination management |
2.3.1. Saved Payment Methods and Beneficiary Data
Where supported by the Platform, Users may optionally save payment methods, payout destinations, or beneficiary information for convenience and faster transaction flows.
This information may include:
- beneficiary or recipient full name;
- bank account details, IBAN, account identifiers, or payment destination information;
- phone numbers linked to payment destinations;
- country or jurisdiction information;
- national identification numbers or tax identifiers where voluntarily provided by the User or required for a specific payment flow.
This functionality is optional. Users may update or delete saved payment methods through the Platform where available.
2.4. Technical and Device Data
| Data | Purpose |
|---|---|
| IP address | Security, rate limiting, fraud prevention |
| Device type, browser, operating system | Compatibility and security |
| Session data, access logs | Security monitoring, debugging |
| Chain ID / network selections | Multi-chain functionality |
2.5. Communications Data
| Data | Purpose |
|---|---|
| Email content (support correspondence) | Customer support |
| In-app notification data | Service communications via Novu |
| User-submitted feedback | Platform improvement |
2.6. Encrypted Personal Data
Sensitive personal, financial, and beneficiary profile data stored in our database is encrypted at rest using AES-256 encryption. Decryption requires a server-side key managed by Pine under strict access controls.
3. How We Collect Personal Data
- Directly from you: when you register, complete KYC, or contact support;
- Automatically: via cookies, logs, and telemetry when you use the Platform (see Part III – Cookie Policy);
- From Third-Party Providers: Privy (authentication and wallet identity), VIRTUABROKER CORP. (KYC outcomes, order data), Alchemy / Moralis (transaction and portfolio data), CoinMarketCap (token prices);
- From public blockchain data: wallet addresses, transaction hashes, and on-chain data are publicly available on the respective blockchains and are not exclusively within Pine's control.
4. Legal Basis for Processing
We process personal data on the following legal bases, in accordance with applicable data protection law (including the GDPR where applicable):
| Processing Activity | Legal Basis | | ---------------------------------------------------------- | ----------------------------------------------- | --- | ------------------------------------------------ | ----------------------------------------------- | | Account creation and management | Performance of a contract | | Authentication via Privy | Performance of a contract | | Smart account creation (Pimlico) | Performance of a contract | | KYC / AML compliance checks | Legal obligation | | Sanctions screening | Legal obligation / legitimate interest | | Transaction processing (on-ramp/off-ramp via VirtuaBroker) | Performance of a contract | | Card programme access (Card Provider) | Performance of a contract | | Portfolio and transaction history display | Performance of a contract / legitimate interest | | Security monitoring, rate limiting, fraud prevention | Legitimate interest | | Notifications and service communications (Novu) | Performance of a contract / legitimate interest | | Marketing communications | Consent (where required) | | Improving the Platform | Legitimate interest | | Reporting to authorities | Legal obligation | | Saved payment methods and beneficiary management | Performance of a contract / Legitimate interest |
5. Third-Party Service Providers and Data Sharing
We may share personal data with the following categories of recipients:
5.1. Technology and Infrastructure Partners
| Provider | Role | Data Shared | Privacy Reference |
|---|---|---|---|
| Privy (privy.io) | Authentication & embedded wallet provider | Email, wallet address, authentication ID | privy.io/privacy |
| Pimlico | ERC-4337 bundler and paymaster | Wallet address, UserOperation data | pimlico.io/privacy |
| Relay (relay.link) | Token swaps and cross-chain bridge | Wallet address, chain ID, transaction data | relay.link |
| Alchemy | Blockchain RPC and portfolio data | Wallet address, chain ID | alchemy.com/privacy-policy |
| Moralis | Transaction history indexing | Wallet address, chain ID | moralis.io/privacy-policy |
| CoinMarketCap | Token price data | API queries (no personal data) | coinmarketcap.com/privacy |
| Novu | Notification infrastructure | User ID, email, notification preferences | novu.co/privacy |
| Sumsub (sumsub.com) | Identity verification sub-processor (used by VIRTUABROKER CORP. and Card Provider for KYC/KYB) | Identity documents, biometric data, liveness check results, verification token | sumsub.com/privacy-notice |
| Redis (infrastructure) | Caching layer | Session tokens, cached data | N/A (infrastructure) |
| PostgreSQL (infrastructure) | Database | All stored user and account data | N/A (infrastructure) |
5.2. Financial and Compliance Partners
| Provider | Role | Data Shared |
|---|---|---|
| VIRTUABROKER CORP. (VirtuaBroker) | Fiat on/off-ramp, KYC, openbanking exchange | Email, wallet address, transaction data, KYC documentation |
| Card Provider (confidential) | Virtual/physical card programmes | Email, wallet address, KYC data, card usage data |
| Morpho Protocol | DeFi lending vault infrastructure | Wallet address (on-chain, publicly visible) |
5.3. Regulatory and Legal Authorities
We may disclose personal data to competent administrative, judicial, fiscal, or regulatory authorities when required by applicable law, court order, or regulatory mandate.
5.4. Corporate Transfers
In the event of a merger, acquisition, or corporate restructuring, personal data may be transferred to a successor entity, subject to appropriate confidentiality commitments.
6. International Data Transfers
Some of our Third-Party Providers are located outside your country of residence or outside the European Economic Area (EEA). Where personal data is transferred internationally, we ensure that appropriate safeguards are in place, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- adequacy decisions by relevant data protection authorities;
- compliance with the provider's applicable data transfer frameworks.
You may contact us at support@pinewallet.io to obtain information about the safeguards applicable to specific transfers.
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy:
| Data Category | Retention Period |
|---|---|
| Account registration data | Duration of active account + applicable legal retention period |
| KYC / AML data | As required by applicable AML/CFT law (typically 5–10 years post-relationship) |
| Transaction and financial records | As required by applicable financial regulations |
| Communication logs / support tickets | 3 years from last interaction, or as required by law |
| Security logs (IP, access logs) | 90 days to 12 months, depending on applicable law |
| Marketing consent records | Until consent is withdrawn + reasonable dispute period |
| Encrypted user profile data | Duration of active account; deleted upon verified account closure request |
| Saved payment methods and beneficiary information | Duration of active account, until removed by the User, or for longer periods where required for fraud prevention, compliance, dispute handling, or legal obligations |
After the applicable retention period, data is deleted or anonymised in a manner that prevents re-identification.
8. Your Rights as a Data Subject
Depending on your country of residence and applicable law, you may have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure ("Right to be Forgotten") | Request deletion of your data where no legal obligation to retain exists |
| Restriction | Request that we limit processing of your data in certain circumstances |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interest or for direct marketing |
| Withdraw Consent | Withdraw consent at any time where processing is consent-based |
| Automated Decisions | Not be subject to solely automated decision-making that significantly affects you |
How to exercise your rights: Submit a request to support@pinewallet.io. We may need to verify your identity before processing your request. We will respond within the timeframe required by applicable law (e.g., 30 days under GDPR).
Supervisory authority: If you are a resident of the European Union or EEA and believe we are not processing your data in accordance with the GDPR, you have the right to lodge a complaint with your local data protection supervisory authority.
9. Children
The Platform and Pine's services are not directed to persons under 18 years of age (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected such data, we will take reasonable steps to delete it promptly.
10. Security Measures
Pine implements technical, administrative, and organisational security measures including:
- Encryption at rest: sensitive user data is encrypted using AES-256 encryption in the database;
- Encryption in transit: all data transmitted between users and the Platform uses TLS/HTTPS;
- Authentication: multi-factor authentication options via Privy;
- Access controls: role-based access control (RBAC) for internal systems;
- Rate limiting: API rate limiting via Redis-backed throttling (60 requests/minute per User);
- Input validation: server-side input sanitisation and validation on all API endpoints;
- Security monitoring: access logs and anomaly detection.
Notwithstanding the above, no system is completely secure. We cannot guarantee that security incidents will never occur.
11. Links to Third-Party Services
The Platform integrates with or links to third-party services. Pine is not responsible for the privacy practices of those services. We encourage you to review the privacy policies of Third-Party Providers before sharing personal data with them.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the Platform or by email. The updated Policy will be effective from the date indicated at the top. Continued use of the Platform after such changes constitutes acceptance of the updated Policy.
PART III – COOKIE POLICY
Introduction
This Cookie Policy explains how Pine Labs S.A. ("Pine", "we", "us", "our") uses cookies and similar tracking technologies on the Pine web application (the "Platform").
This Policy should be read together with our Privacy Policy (Part II) and Terms and Conditions (Part I).
Last Updated: 25 May 2026
1. What Are Cookies?
Cookies are small text files stored on your device (computer, tablet, or mobile) when you visit a website or web application. Cookies are widely used to make applications work efficiently, to improve user experience, and to provide analytics and reporting information.
Similar technologies include:
- Local Storage / Session Storage: browser-based storage used by JavaScript for persisting session state;
- Pixels / web beacons: tiny images or scripts used to track user interactions;
- Device fingerprinting: collecting device-level attributes for security and fraud detection.
2. Types of Cookies and Technologies We Use
2.1. Strictly Necessary Cookies and Technologies
These are essential for the Platform to function. They cannot be disabled without severely impairing core functionality. No consent is required for these.
| Name / Technology | Provider | Purpose | Duration |
|---|---|---|---|
| JWT authentication token | Pine (internal) | Maintains your authenticated session | 24 hours |
| Privy session token | Privy (privy.io) | Manages your embedded wallet and authentication session | Session / Privy-defined |
| CSRF protection token | Pine (internal) | Prevents cross-site request forgery attacks | Session |
| Rate-limiting identifier (Redis) | Pine (internal) | Enforces API rate limits to prevent abuse | 60 seconds rolling |
| Wallet connection state (localStorage) | Pine (internal) | Persists connected wallet and chain selection | Session |
2.2. Functional Cookies and Technologies
These cookies enable enhanced functionality and personalisation but are not strictly necessary.
| Name / Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Language/locale preference | Pine (internal) | Stores your preferred language and regional settings | Persistent (up to 1 year) |
| Profile mode preference | Pine (internal) | Remembers your selected profile mode (LITE / NORMAL) | Persistent (account lifetime) |
| Chain selection cache | Pine (internal) | Caches your last selected blockchain network | Session |
2.3. Analytics and Performance Cookies
These cookies help us understand how Users interact with the Platform so we can improve it.
| Name / Technology | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google (Google Analytics 4) | Distinguishes unique users; used for page view counting and session measurement across all GA4 properties | 2 years |
_ga_* | Google (Google Analytics 4) | Stores and counts page views for the Pine GA4 property | 2 years |
Analytics cookies are only set when you have explicitly accepted analytics cookies via the consent banner. You can withdraw consent at any time by clicking "Reject all" in the consent banner or clearing your browser cookies.
2.4. Third-Party Service Cookies
Certain Third-Party Providers integrated into the Platform may set their own cookies or use their own tracking technologies:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Privy | Embedded wallet authentication | privy.io/privacy |
| Alchemy (API calls) | Blockchain data (no client-side cookies, server-side API) | alchemy.com/privacy-policy |
| Novu (in-app notifications) | Notification delivery and preferences | novu.co/privacy |
3. Why We Use These Technologies
| Category | Purpose |
|---|---|
| Authentication and session management | To verify your identity, maintain your logged-in session, and secure your account |
| Security | To detect and prevent fraud, abuse, and unauthorised access |
| Functionality | To remember your preferences, wallet connections, and application state |
| Performance | To cache data efficiently (e.g., token prices, KYC status) and reduce API calls |
| Analytics | To understand usage patterns and improve the Platform |
4. Your Cookie Choices
4.1. Strictly necessary cookies cannot be disabled, as they are essential for the Platform to function securely.
4.2. Functional and analytics cookies can be managed through:
- your browser settings (most browsers allow you to block or delete cookies; see your browser's help documentation);
- the in-app privacy settings via the Platform's cookie consent banner (currently active on the web application);
- opt-out mechanisms provided by Third-Party Providers (see their respective privacy policies).
4.3. Please note that disabling certain cookies may impair your ability to use some features of the Platform, including wallet connections, notifications, and preference persistence.
5. Mobile Application Considerations
The Pine mobile application (built with Capacitor/Ionic on Android) does not use browser cookies in the traditional sense. However, similar data persistence is achieved through:
- Android SharedPreferences and secure storage for session tokens;
- Application local storage for user preferences and wallet state;
- In-app HTTP sessions using HTTPS with server-side session management.
All mobile-side data storage follows the same principles as described in this Policy.
6. Do Not Track
Some browsers include a "Do Not Track" (DNT) feature that signals your preference not to be tracked. The Platform currently does not respond to DNT signals. The Platform relies on its own consent management mechanism — the cookie consent banner — to collect and manage your tracking preferences. We encourage you to use the consent banner to control your cookie settings.
7. Updates to This Cookie Policy
We may update this Cookie Policy to reflect changes in the technologies we use or applicable regulations. We will notify you of material changes through the Platform. The updated Policy is effective from the date indicated at the top.
8. Contact
For any questions about this Cookie Policy or our use of tracking technologies, contact us at: support@pinewallet.io
Appendix A – Third-Party Providers Summary
| Provider | Service Category | Regulatory Notes |
|---|---|---|
| Privy (privy.io) | Authentication, embedded wallet | Non-custodial; GDPR compliant |
| Sumsub (sumsub.com) | Identity verification sub-processor (KYC/KYB) | Used by VIRTUABROKER CORP. and Card Provider; GDPR compliant; processes identity documents and biometrics |
| VIRTUABROKER CORP. (VirtuaBroker) | Fiat on/off-ramp, KYC, openbanking | Regulated exchange partner; own KYC/AML obligations; technology infrastructure model; underlying fiat/custody services provided by VirtuaBroker's regulated third-party partners |
| Card Provider ([CONFIDENTIAL]) | Virtual/physical card programme | Operates under issuer's financial licence |
| Alchemy | Blockchain RPC, portfolio data, transaction data | Enterprise API; SOC 2 compliant |
| Moralis | Transaction history indexing | Enterprise API |
| Morpho | DeFi lending vaults (ERC-4626 / ERC-4337) | Decentralised protocol; no regulatory licence |
| Pimlico | ERC-4337 bundler and paymaster | Infrastructure provider |
| Relay (relay.link) | Token swaps and cross-chain bridge | Third-party protocol; charges service fee per swap/bridge transaction |
| Novu | Notification infrastructure | GDPR compliant |
| CoinMarketCap | Token pricing data | Data provider |
Appendix B – Supported Blockchain Networks and Risk Disclosures
| Network | Chain ID | Notes |
|---|---|---|
| Ethereum Mainnet | 1 | High liquidity; highest security assumptions |
| Polygon (PoS) | 137 | Layer 2 / sidechain; additional bridge risk |
| BNB Smart Chain | 56 | Third-party chain; own validator set |
| Arbitrum One | 42161 | Optimistic rollup; fraud proof window |
| Base | 8453 | Optimistic rollup (Coinbase); fraud proof window |
Use of any network involves smart contract, validator, bridge, and consensus risks that are beyond Pine's control.
Appendix C – DeFi Vault Risk Disclosure
By accessing the Invest (vaults) section of Pine, you confirm that you have read and understood the following:
- No guarantees: Yield rates are variable, not guaranteed, and can be zero or negative.
- Smart contract risk: Morpho protocol smart contracts may contain bugs or be exploited.
- Liquidity risk: You may not be able to withdraw funds immediately in all market conditions.
- Regulatory risk: DeFi protocols are not licensed financial products in most jurisdictions. Regulations may change.
- Loss of capital: You may lose part or all of your deposited assets.
This disclosure does not constitute investment advice. Consult a qualified financial advisor before participating in any DeFi product.
END OF LEGAL DOCUMENTS
For questions, legal notices, or data subject requests:
- Legal: contact@pinewallet.io
- Privacy / DPO: support@pinewallet.io
- Security: support@pinewallet.io
- Support: support@pinewallet.io