Legal

Privacy Policy

Meridian Money Transfer Pvt. Ltd. provides regulated financial services. This policy explains, in detail, what personal data we collect, why, how we use and share it, how long we keep it, how we protect it, and the rights available to you.

Last updated: 1 January 2025 · Effective date: 1 January 2025

1. Introduction and Scope

This Policy applies to all personal data we process in connection with our website, our mobile and web applications, our customer accounts, and any other product or service that links to this Policy (collectively, the "Services"). It applies whether you are a prospective customer completing an application, a verified account holder, a representative of a business customer, or a visitor to our website.

This Policy does not apply to information processed by third parties that we do not control, even if you access their services through a link on our Services. We encourage you to review the privacy policies of any third party before you provide them with personal data.

Where we use capitalized terms that are not defined in this Policy, they have the meaning given to them in our Terms of Service.

2. Information We Collect

We collect only what we reasonably need to open your account, run a safe and compliant financial service, and meet our legal obligations. We collect information directly from you, automatically through your use of the Services, and from third parties as described below.

2.1 Identity and contact information

  • Full legal name, date of birth, and nationality
  • Residential address and, where applicable, mailing address
  • Phone number and email address
  • Government-issued identification number (e.g., passport, driver's licence, or national ID number)
  • Signature, where required for account or transaction authorization

2.2 Verification and onboarding documents

  • Government-issued photo identification (passport, driver's licence, national ID card)
  • Proof of address (utility bill, bank statement, or government correspondence)
  • A selfie or short video used for biometric liveness matching against your ID
  • Additional documentation we may request for enhanced due diligence, such as source-of-funds or source-of-wealth evidence
  • For business or joint accounts: incorporation documents, beneficial ownership information, and the identity information listed above for each authorized signatory or beneficial owner

2.3 Financial and transaction data

  • Account balances and holdings
  • The amount, currency, counterparty, timing, and status of each transfer, conversion, deposit, withdrawal, or payout
  • Linked payment methods, including masked card or bank account details

2.4 Device, usage, and technical information

  • IP address, approximate location derived from it, and time zone setting
  • Browser type and version, operating system, and device identifiers
  • Log data, including pages viewed, features used, session duration, and referring/exit pages
  • Interaction data collected through cookies and similar technologies (see Section 8)

2.5 Communications

  • Records of correspondence when you contact us or we contact you, including support tickets, emails, and call recordings where permitted by law and disclosed to you at the time
  • Survey responses and feedback you choose to provide

2.6 Information from third parties

We may also receive personal data about you from:

  • Identity verification and fraud-prevention providers, who confirm or supplement the information you give us
  • Credit reference and sanctions/watchlist screening agencies, as required for KYC and AML compliance
  • Partner banks and payment processors that facilitate your transactions
  • Publicly available sources, such as corporate registries, where relevant to verifying a business customer
  • Other users, for example if someone sends you a payment and provides your contact details to complete it

2.7 Sensitive information

We generally do not seek to collect sensitive categories of personal data (such as health information, biometric data used for identification beyond liveness matching, or information about racial or ethnic origin, religious beliefs, or political opinions). Where biometric data is used for identity verification, we treat it as sensitive and apply enhanced safeguards, and we only use it for the verification purpose disclosed to you at the time of collection.

3. Why We Collect and Use Your Information

We rely on different legal bases depending on the purpose of processing and the law that applies to you. The table below summarizes our principal purposes and the corresponding legal basis we typically rely on.

PurposeExamplesTypical legal basis
Account opening and identity verificationCollecting and checking ID documents, running KYC/AML checksLegal obligation; performance of a contract
Providing the core serviceMoving, holding, and converting your money; processing transfersPerformance of a contract
Compliance with financial regulationSanctions screening, suspicious activity monitoring and reporting, record-keepingLegal obligation
Fraud and financial-crime preventionDevice fingerprinting, anomaly detection, blocking suspicious transactionsLegitimate interests; legal obligation
Communicating with youAccount notices, security alerts, service updates, responses to enquiriesPerformance of a contract; legitimate interests
Improving and securing our ServicesDiagnosing technical issues, testing new features, protecting against attacksLegitimate interests
Marketing (where applicable)Sending product news or offers you can opt out ofConsent, or legitimate interests where permitted
Legal claims and enforcementResponding to disputes, audits, or requests from regulators, tax authorities, and law enforcementLegal obligation; legitimate interests

Where we rely on your consent, you may withdraw it at any time by contacting us using the details in Section 14, without affecting the lawfulness of processing carried out before you withdrew it.

4. Automated Decision-Making and Profiling

As a regulated financial service, we use automated systems to help us meet our anti-money-laundering and fraud-prevention obligations. This includes transaction monitoring rules and risk-scoring models that flag unusual account activity for review, and identity-verification tools that compare a submitted photo ID against a live selfie.

These systems support, rather than replace, human decision-making on matters that significantly affect you, such as suspending an account or declining a transaction. Where an automated result leads to an adverse outcome for you, you may contact us to request a human review, as described in Section 9.

5. How We Share Your Information

We share personal data only where necessary to run the Services or to meet a legal obligation. We do not sell your personal data to third parties, and we never will.

5.1 Categories of recipients

  • Regulated partner banks and payment institutions that hold customer funds and execute payments on our behalf
  • Identity verification and fraud-prevention providers that process KYC checks and biometric matching under strict contractual controls
  • Cloud hosting, data storage, and customer support platform providers, acting as processors under contracts that limit their use of your data to providing services to us
  • Professional advisers such as auditors, accountants, and lawyers, where necessary for their engagement
  • Regulators, tax authorities, and law enforcement, where we are legally required or permitted to disclose information
  • A successor entity in the event of a merger, acquisition, or sale of assets, with the acquiring party assuming equivalent privacy commitments

5.2 Sub-processors

Our verification, hosting, and payment partners may themselves engage sub-processors to deliver parts of their service. We require our processors to impose the same data protection obligations on any sub-processor they engage, and we maintain oversight of this chain through contractual audit rights.

6. International Data Transfers

Because we work with partner banks and service providers in multiple countries, your personal data may be transferred to, and processed in, jurisdictions other than the one in which you reside. Where we transfer personal data internationally, we use recognized safeguards appropriate to the transfer, such as standard contractual clauses, adequacy decisions, or equivalent mechanisms recognized under applicable law, and we require recipients to protect your data to a standard consistent with this Policy.

7. Data Retention

We retain personal data for as long as your account is active and, after closure, for the period required to meet our legal, regulatory, and accounting obligations. In particular:

  • Identity verification and transaction records are typically retained for a minimum period after the end of our relationship with you, as set by applicable anti-money-laundering law (commonly five to seven years, depending on jurisdiction)
  • Communications and support records are retained for as long as needed to resolve your enquiry and for a reasonable period afterward for quality and dispute-resolution purposes
  • Device and usage logs are retained for a limited period sufficient for security monitoring, after which they are deleted or aggregated so they no longer identify you

Where we no longer need personal data for these purposes, we securely delete or anonymize it. Backup copies are removed in the ordinary course of our backup-rotation cycle.

8. Cookies and Tracking Technologies

Our website and applications use cookies and similar technologies (such as pixels and local storage) to keep you signed in, secure your session, remember your preferences, and help us understand how the Services are used.

CategoryPurposeCan you disable it?
Strictly necessaryKeep you signed in, maintain session security, load the ServicesNo — required for the Services to function
FunctionalRemember preferences such as language or display settingsYes, via browser settings
AnalyticsUnderstand which pages and features are used, to improve the productYes, via browser settings or our cookie preferences tool
Security and fraud preventionDevice fingerprinting and anomaly detection to protect your accountNo — disabling may prevent us from securing your account

You can control non-essential cookies through your browser settings or, where available, through a cookie preference tool on our website. Disabling strictly necessary or security cookies may prevent you from using the Services.

9. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights regarding your personal data. Where a right is not available under the law that applies to you, we will still consider requests made in this spirit wherever reasonably possible.

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct information that is inaccurate or incomplete
  • Deletion — request deletion of your data, subject to records we are required to keep for regulatory reasons (such as KYC records, which must be retained for several years by law)
  • Restriction or objection — ask us to restrict or object to certain kinds of processing, including direct marketing
  • Portability — request your data in a structured, commonly used, machine-readable format, where technically feasible
  • Withdraw consent — where we rely on your consent, withdraw it at any time
  • Lodge a complaint — with your local data protection authority or financial regulator, if you believe we have not handled your data properly

To exercise any of these rights, email support@getmeridian.online. We may need to verify your identity before actioning a request, and we will respond within the timeframe required by applicable law (and in any event within one month for most requests, extendable in complex cases).

10. How We Protect Your Data

We apply layered technical and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration:

  • Encryption in transit using TLS 1.3 and at rest using AES-256
  • Role-based access controls, so employees can access personal data only where necessary for their job, with access logged and periodically reviewed
  • Multi-factor authentication for internal systems handling customer data
  • Continuous monitoring for anomalous access patterns and regular vulnerability testing
  • Formal incident-response procedures, including notification to affected customers and regulators where required by law

More detail on the specific controls we operate is available on our Security page. No method of transmission or storage is completely secure, and while we work hard to protect your information, we cannot guarantee its absolute security.

11. Children's Privacy

Our Services are intended for adults capable of entering into a binding contract and are not directed to children. We do not knowingly collect personal data from anyone below the minimum age required to hold a financial account in their jurisdiction. If we learn that we have collected personal data from a child in violation of this Policy, we will take steps to delete it promptly.

12. Third-Party Links and Services

The Services may contain links to third-party websites or integrate third-party services (for example, identity verification providers or payment networks). This Policy does not apply to those third parties, and we encourage you to review their privacy policies before providing them with personal data.

13. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, our Services, or the law. If we make material changes, we will notify you by email or through an in-product notice before the changes take effect. The "Last updated" date at the top of this Policy indicates when it was last revised. We encourage you to review this Policy periodically.

14. Contact Us

Meridian Money Transfer Pvt. Ltd. is the entity responsible for the personal data described in this Policy.

Questions about this Policy or how we handle your data? Email support@getmeridian.online and we'll respond within five business days.

If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority or the financial services regulator responsible for our operations in your jurisdiction.