Last updated 23 August 2026

Privacy Policy

NELVOI is pre-launch. Sections describing account and verification data describe how the service is built and will operate; today the only personal data this site actually processes is what you send through the contact form, plus server logs and — only with your consent — analytics.

1. Introduction and Scope

1.1 Overview. This Privacy Policy (the «Policy») describes how Nelvoi Ltd, together with its subsidiaries and affiliates (collectively «NELVOI», «Company», «we», «us» or «our»), collects, uses, discloses, stores and protects personal information when you access or use our website at https://nelvoi.com (the «Site»), our applications (the «App») and all services provided or facilitated through them (collectively the «Platform» or «Services»).

1.2 Acceptance. By accessing or using the Platform, opening an Account, or otherwise providing information to us, you acknowledge that you have read and understood this Policy. If you do not agree with it, you must stop using the Platform.

1.3 Partners. Cards and accounts are provided through regulated partner institutions, and identity verification is performed by a specialist provider. Personal information shared with those parties is processed for the purposes described in this Policy and under applicable law. Where a partner acts as an independent controller of your data rather than on our instructions, that will be made clear to you at the point the data is collected.

1.4 Controller. Nelvoi Ltd is the controller of the personal information described in this Policy. The registered address and, where applicable, the identity of a representative and a data protection officer will be published here before accounts open.

2. Information We Collect

2.1 Information you provide. (a) Account information — full legal name, date of birth, email address, phone number, residential address and credentials. (b) Identity verification information — government-issued identity documents, a photograph or liveness capture, a tax identification number where required, and supporting documentation. (c) Business information for entity accounts — registered name, jurisdiction of incorporation, business address, nature of business, corporate documents, and details of authorised users. (d) Beneficial ownership information — names, dates of birth, addresses, identity documents and ownership percentages of ultimate beneficial owners. (e) Financial information — bank details, transaction history and source of funds documentation. (f) Communications — what you send us through the contact form or by email, and our replies.

2.2 Information collected automatically. Our servers keep standard logs containing IP address, request time, page requested, browser and operating system, for security and abuse prevention. If you allow analytics, Google Analytics additionally records the pages you view, an approximate region derived from a truncated IP address, and technical details of your browser. If you refuse, none of that is collected.

2.3 Information from third parties. We receive the result of an identity check from our verification provider together with the data the law requires us to keep — not a copy of everything you uploaded to them. We also receive transaction and compliance information from our issuing and banking partners, and we consult sanctions and politically-exposed-person lists, which are public or licensed data sources.

2.4 Cookies. This site sets no cookies until you answer the consent banner, and none at all if you refuse. Your answer is stored in your browser's local storage rather than a cookie. If you agree, two Google Analytics cookies are set. We do not use advertising cookies, tracking pixels, social network buttons or browser fingerprinting. The complete list, with lifetimes, is in our Cookie Policy at https://nelvoi.com/cookie-policy.

3. How We Use Information

3.1 Providing the service. To open and administer your Account, provide the Services, process and display transactions, answer your questions, and communicate with you about your Account.

3.2 Compliance and security. To verify your identity and meet know-your-customer requirements; to comply with anti-money-laundering law; to screen against sanctions and politically-exposed-person lists; to detect, prevent and investigate fraud and unauthorised access; to comply with legal obligations, court orders and regulatory requests; and to enforce our Terms and Conditions.

3.3 Improving the product. To understand how the Platform is used and to improve it. Where this relies on analytics, it happens only with your consent.

3.4 Communications. To send service messages about your Account, and to answer what you write to us. We do not run a marketing mailing list. If we ever start one, it will be opt-in and separately consented to — never a consequence of opening an Account.

4. Who We Share It With

4.1 Partners delivering the service. Issuing and banking partners, custodians and the identity verification provider, to the extent necessary to provide the Services and meet regulatory obligations.

4.2 Vendors. Providers who help us run the Platform: hosting, analytics (with your consent), customer support tooling and payment processing. They are contractually bound to protect the information and to use it only for the purpose for which it was disclosed.

4.3 Legal and regulatory. To comply with law, regulation or legal process; in response to properly constituted requests from authorities or law enforcement; to protect our rights, safety or property or those of others; and in connection with investigations of suspected fraud or breaches of our terms. We do not hand over customer data on an informal approach.

4.4 Business transfers. In connection with a merger, acquisition, reorganisation, sale of assets or insolvency, information may transfer to the acquiring or successor entity, which remains bound by this Policy or a policy no less protective.

4.5 With your consent. For any other purpose, with your explicit consent.

4.6 We do not sell your data. We do not sell or rent personal information to anyone, for any purpose. Our revenue comes from card fees, which are published on the pricing page.

5. How Long We Keep It

5.1 Retention. We keep personal information for as long as necessary to provide the Services and maintain your Account; to comply with legal and regulatory obligations, including anti-money-laundering record-keeping of at least five (5) years after an Account is closed; to resolve disputes and enforce agreements; and to meet audit requirements.

5.2 The limit on deletion. That retention obligation overrides a deletion request. A request to erase your data does not extend to records we are legally required to keep, and any provider promising otherwise is describing something it cannot deliver.

5.3 Deletion. When retention is no longer required, information is securely deleted or anonymised.

6. Security

6.1 Measures. Encryption in transit and at rest; role-based access control with logging; two-factor authentication on accounts; regular security assessment and monitoring; and staff training on data protection. Identity documents are handled by our verification provider rather than stored on our own servers.

6.2 No absolute guarantee. No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security.

6.3 Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will follow our incident response procedure and notify affected individuals and the relevant supervisory authority as and when required by applicable law, without undue delay.

7. Your Rights

7.1 General. Subject to applicable law and to the retention limits in Section 5, you may have the right to: (a) obtain a copy of the personal information we hold about you; (b) have inaccurate or incomplete information corrected; (c) request deletion; (d) receive your data in a structured, machine-readable format; (e) request restriction of processing in defined circumstances; (f) object to processing based on legitimate interests; and (g) withdraw consent where processing relies on it.

7.2 If you are in the European Economic Area or the United Kingdom. You have the rights above under the GDPR and the UK GDPR. Our legal bases for processing are: performance of a contract with you; compliance with a legal obligation, which is what verification, screening and record-keeping rest on; legitimate interests, for security and fraud prevention; and consent, which is what analytics rests on. You may complain to the data protection authority in your country of residence at any time, independently of us.

7.3 If you are a California resident. Under the CCPA and CPRA you have the right to know what personal information we collect, use and disclose; to request deletion; to correct inaccurate information; to limit the use of sensitive personal information; to opt out of the sale or sharing of personal information; and not to be discriminated against for exercising any of these rights. We do not sell or share personal information as those terms are defined in that law.

7.4 Other jurisdictions. Comparable rights exist under a growing number of data protection laws, and where one applies to you, it applies. Which supervisory authority oversees us depends on where Nelvoi Ltd is established; that will be named here before accounts open. Your right to complain to the authority in your own country does not depend on it.

7.5 How to exercise them. Write to [email protected]. We will respond within the period required by applicable law and may need to verify your identity first — a request to hand over personal data cannot be honoured without knowing who is asking.

7.6 Automated decisions. We use automated tools for identity verification, sanctions screening, fraud detection and risk scoring, because doing it by hand at scale is not possible and the law requires it to be done. Where an automated decision produces a legal or similarly significant effect on you, you may ask for human review, and we will provide information about the logic involved to the extent the law requires and disclosure would not undermine the control itself.

8. International Transfers

8.1 Where data goes. Your information may be transferred to and processed in countries other than the one you live in, including where our hosting, verification and partner institutions are located. Data protection law in those countries may differ from your own.

8.2 Safeguards. Where we transfer personal data internationally we rely on the safeguards the law provides — an adequacy decision where one exists, or standard contractual clauses approved by the relevant authority, together with the additional measures those clauses require.

9. Children

The Platform is not intended for anyone under eighteen (18) years of age, or the age of majority where they live if that is higher, and identity verification is designed to prevent it. We do not knowingly collect personal information from children. If we learn that we have, we will delete it promptly.

10. Changes to This Policy

10.1 Modifications. We may update this Policy by publishing the revised version on the Platform and changing the date at the top of this page. For changes that materially affect your rights, we will notify Account holders by email or through the Platform rather than quietly republishing the page.

10.2 Continued use. Continued use of the Platform after a change takes effect constitutes acceptance of the updated Policy.

10.3 Versions. We keep previous versions of this Policy for at least five (5) years. A previous version is available on request to [email protected].

11. Contact

Privacy and data requests: [email protected]

General support: [email protected]

Entity: Nelvoi Ltd. The registered address will be published here and in the footer of the Site before accounts open.