Legal

Privacy
Policy

This Privacy Policy explains how Bodalong Technology Inc collects, uses, discloses, protects and retains personal information in connection with the Bodalong platform, this website and our cross-border value infrastructure services.

Legal Entity
Bodalong Technology IncOperator of the Platform
Entity Details
Colorado Profit CorporationEntity ID #20251947308
Principal Office
1312 17th Street, Suite 716Denver, CO 80202, United States
Privacy Contact
contact@bodalong.techLast updated: August 18, 2026

01Introduction

Bodalong Technology Inc ("Bodalong", the "Company", "we", "us" or "our") is a profit corporation organized under the laws of the State of Colorado, United States. We build and operate infrastructure that helps businesses collect, convert and settle value across borders.

Because of the nature of our services, we are required to collect and verify certain information about our clients, their beneficial owners and their transactions. We treat that responsibility as a matter of trust: this Policy describes, in plain terms, what we collect, why we collect it, and the choices available to you.

This Policy applies to personal information processed through our website, platform, APIs and related services (together, the "Services"). By using the Services, you acknowledge the practices described here.

02Information We Collect

We collect information in three ways: directly from you, automatically through your use of the Services, and from third parties that help us verify identity and manage risk.

  • Identity and verification data — legal name, date of birth, nationality, government-issued identification numbers and document images, photographs or likenesses used for verification, and information about directors, officers and beneficial owners of business clients.
  • Business and contact data — entity name, registration numbers, registered and operating addresses, tax identifiers, contact names, email addresses and telephone numbers.
  • Financial and transaction data — bank account details, wallet addresses, payment instructions, transaction amounts, currencies, counterparties and settlement history.
  • Technical data — IP address, device and browser characteristics, log records, access times, pages viewed and interactions with the Services.
  • Communications — records of correspondence with our team, including support requests, onboarding materials and feedback.
  • Screening results — outcomes of sanctions, watchlist, politically-exposed-person (PEP) and adverse-media checks performed by our screening partners.

03How We Use Your Information

We use personal information only for defined, legitimate purposes connected to the Services:

  • Onboarding and verification — to establish accounts, verify identity and business status, and meet know-your-customer requirements.
  • Providing the Services — to quote, route, convert and settle transactions, operate accounts, and reconcile activity.
  • Compliance and risk management — to conduct anti-money-laundering, counter-terrorist-financing, sanctions and fraud screening; to monitor transactions; and to investigate and report suspicious activity where the law requires.
  • Operation and improvement — to maintain security, troubleshoot, analyze usage and improve the performance and design of the Services.
  • Communication — to respond to inquiries, deliver service notices, and, where permitted, share product updates you can opt out of at any time.
  • Legal and enforcement — to establish, exercise or defend legal claims and to comply with lawful requests from authorities.

04Legal Basis for Processing

Depending on the context, we rely on one or more of the following grounds:

  • Performance of a contract — processing necessary to open and operate your account and to execute your transactions.
  • Legal obligation — processing required by applicable laws, including identity verification, record-keeping and reporting duties under United States federal and state law.
  • Legitimate interests — processing that supports the security, integrity and improvement of the Services, balanced against your rights.
  • Consent — where required, for example for certain optional communications or cookie categories; consent can be withdrawn at any time.
Where our activities become subject to the Bank Secrecy Act and related FinCEN rules, we collect, verify and retain customer information as those laws require.

05Information Sharing and Disclosure

We do not sell personal information. We share it only in the following limited circumstances:

  • Banking and settlement partners — financial institutions and payment networks that execute or clear your transactions, to the extent needed to complete them.
  • Verification and screening providers — identity-verification, sanctions-screening and fraud-prevention services acting under contractual confidentiality obligations.
  • Service providers — hosting, analytics, communications and support vendors that process data on our instructions and for no independent purpose.
  • Regulators and authorities — where disclosure is required by law, subpoena or similar lawful process, or is necessary to protect rights, safety and the integrity of the financial system.
  • Corporate transactions — in connection with a merger, acquisition or reorganization, subject to continued protection consistent with this Policy.

06Data Security

We apply administrative, technical and physical safeguards designed for a financial-infrastructure environment, including encryption in transit and at rest, role-based access control, multi-factor authentication for internal systems, network monitoring, and vendor security review.

No method of transmission or storage is completely secure. If we become aware of an incident affecting your personal information, we will investigate promptly and provide notice where the law requires it.

07Data Retention

We retain personal information for as long as your relationship with us continues and thereafter for the periods required by law — including identity-verification and transaction records that must be preserved under applicable financial record-keeping rules.

When information is no longer required, we delete it or render it irreversibly anonymous, unless continued retention is necessary for legal, regulatory or legitimate dispute-resolution purposes.

08Your Rights

Depending on your state or country of residence, you may have some or all of the following rights, including under the Colorado Privacy Act and other U.S. state privacy laws:

  • Access and portability — to confirm whether we process your personal information and to obtain a copy in a portable format.
  • Correction — to ask us to correct inaccurate or incomplete information.
  • Deletion — to request deletion, subject to records we must keep by law.
  • Opt-out — to opt out of the sale of personal information, targeted advertising, or certain profiling (note: we do not sell personal information).
  • Appeal — to appeal a decision we make on a rights request, as provided by applicable state law.

To exercise any of these rights, contact us at contact@bodalong.tech. We may need to verify your identity before acting, and we will respond within the timeframes required by applicable law.

09International Data Transfers

We are headquartered in the United States and may process information in the United States and in other countries where our service providers operate. Where personal information is transferred across borders, we use contractual and organizational measures designed to keep it protected to a standard consistent with this Policy.

The cross-border nature of our Services also means transaction-related information is necessarily transmitted to the jurisdictions involved in executing and settling your transfers.

10Cookies and Tracking

We use a limited set of cookies and similar technologies on our website:

  • Strictly necessary cookies — required for security, load balancing and core site functionality.
  • Preference cookies — remember choices such as language or region.
  • Analytics cookies — help us understand aggregate usage so we can improve the site; no advertising profiles are built.

Most browsers let you refuse or delete cookies through their settings. Blocking necessary cookies may affect how the site functions.

11Third-Party Links

The Services may contain links to websites or services operated by third parties. Those destinations have their own privacy practices, which we do not control and for which we are not responsible. We encourage you to review the privacy policy of every third-party service you use.

12Children's Privacy

The Services are designed for businesses and are not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us personal information, contact us and we will delete it promptly.

13Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology or legal obligations. The current version is always posted on this page with its revision date. Where a change is material, we will provide additional notice through the Services or by email before it takes effect.

14Contact Us

Questions, requests or concerns about this Policy or our handling of personal information can be directed to our privacy contact:

Bodalong Technology Inc
1312 17th Street, Suite 716
Denver, CO 80202, United States
Email: contact@bodalong.tech

We aim to acknowledge every privacy inquiry within five business days and to resolve it within the timeframes set by applicable law.