Privacy Policy

Last updated: February 12, 2026

Data Controller: Bank of Bali · Contact: hello@bankofbali.com

Bank of Bali is built on a privacy-first foundation. This Policy explains what personal data we collect, why we collect it, how long we keep it, and the rights you have under the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and similar laws. We never sell, rent or share your data with advertisers.

1. Who we are

Bank of Bali (the "Service") is operated by Bank of Bali ("we", "us", "our"), acting as the Data Controller for the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR.

Our Data Protection contact is: hello@bankofbali.com. Privacy and data-subject requests can be sent to the same address with the subject line "Privacy Request".

2. Data we collect

We intentionally minimise data collection. The categories we process are:

  • Account data — email, hashed password (bcrypt), preferred language, theme, optional display name.
  • Wallet metadata — public Monero address(es), encrypted local wallet filename. We never see your seed phrase or private keys; they live on your device and on a wallet file encrypted with a password we cannot decrypt.
  • Session data — httpOnly secure cookies (access & refresh JWT tokens), expiring automatically.
  • Security telemetry — IP address, coarse geolocation (country/city) and User-Agent at login, used solely for fraud-detection (VPN/proxy flags, impossible-travel).
  • Transactional metadata — swap orders, on-ramp/OTC requests, merchant invoices. On-chain transactions (Monero) are inherently private and stored only as transaction IDs.
  • Support correspondence — emails you send to hello@, support@, press@ bankofbali.com.

We do not collect: government IDs (unless you voluntarily complete enhanced due-diligence for OTC volumes over $1,000), biometrics, contact lists, browsing history, or advertising identifiers.

3. Lawful basis (GDPR Art. 6)

We rely on the following legal grounds:

  • Contract (Art. 6(1)(b)) — to provide the wallet, swaps, OTC and merchant services you sign up for.
  • Legitimate interest (Art. 6(1)(f)) — fraud prevention, security logging, abuse-protection, and product analytics that do not identify individuals.
  • Legal obligation (Art. 6(1)(c)) — AML/CTF record-keeping where applicable, and responding to lawful requests from competent authorities.
  • Consent (Art. 6(1)(a)) — non-essential cookies (analytics), marketing emails, and any KYC documents you voluntarily submit. You can withdraw consent at any time via the cookie banner or by emailing us.

4. How we use it

  • Operate the Service and maintain a secure non-custodial wallet experience.
  • Route swaps and fiat-on-ramp requests to the partner you choose (e.g. ChangeNOW, Guardarian).
  • Detect fraud, brute-force, and money-laundering risk via our internal AI Fraud and Security teams.
  • Send transactional emails (welcome, password reset, security alerts).
  • Improve the Service through aggregated, non-identifying analytics (only with your consent).

5. Recipients & sharing

We share data only with the following categories of recipients, under written processor agreements:

  • Hosting & infrastructure — our managed Kubernetes provider and MongoDB host.
  • Swap providers — ChangeNOW and similar liquidity aggregators receive the minimum data needed to execute your trade (assets, amounts, payout address).
  • Fiat on-ramp / KYC providers — Guardarian and similar, when you choose a fiat-funded purchase.
  • Email delivery — Zoho Mail (transactional emails only).
  • Analytics — PostHog (EU/US), loaded only if you accept analytics cookies.
  • Carbon-offset — Toucan/Klima public APIs (no personal data sent; only on-chain retire amounts).
  • Authorities — only when compelled by a valid legal order in the operating jurisdiction.

We do not sell personal data (CCPA §1798.120). We do not share data for cross-context behavioural advertising.

6. International transfers

Bank of Bali operates globally. Personal data may be processed in the EU, the UK, the United States and Indonesia. Where data leaves the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs 2021) or an adequacy decision. You may request a copy of the applicable safeguards by contacting us.

7. Retention periods

  • Account & wallet metadata — for as long as your account is active, plus 30 days after deletion request.
  • Security & login telemetry — 12 months (rolling window).
  • Transactional records (swaps, OTC, payouts) — 5 years (AML record-keeping requirement).
  • Support correspondence — 24 months from last contact.
  • Marketing consent — until you unsubscribe.

8. Your rights (GDPR / UK GDPR / CCPA)

Subject to applicable law, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate data.
  • Erasure ("right to be forgotten") — note that AML laws may require us to retain certain records for 5 years.
  • Restrict or object to processing based on legitimate interest.
  • Data portability — a machine-readable export of your account data.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with your local supervisory authority (e.g. CNIL, ICO, AEPD, or your national DPA).
  • Opt-out of "sale" / "sharing" (CCPA/CPRA) — we do not sell or share data; this is enforced by default.

To exercise any right, email hello@bankofbali.com. We respond within 30 days (extendable by 60 days for complex requests, GDPR Art. 12(3)).

9. Cookies & tracking

We use the strict minimum of cookies. See our dedicated Cookie Policy for the full list, lifetimes and how to opt out. Analytics scripts (PostHog) load only after you click "Accept analytics" on the cookie banner.

10. Children

Bank of Bali is not directed at persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us and we will delete it.

11. Security

We apply industry-standard controls: TLS 1.3 in transit, bcrypt password hashing, encrypted wallet files, JWT httpOnly secure cookies, brute-force lockouts, optional TOTP 2FA, VPN/proxy fingerprinting, and 24/7 automated fraud monitoring. No system is 100% secure — store your 25-word seed phrase offline; we cannot recover it for you.

12. Breach notifications

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and inform affected users without undue delay.

13. Changes to this policy

We will post any material change here and update the "Last updated" date. For substantive changes, we will email account holders at least 14 days before they take effect.

14. Contact & complaints

Privacy questions, requests and complaints: hello@bankofbali.com.

EU/UK users also have the right to lodge a complaint with their national data-protection authority.

© 2026 Bank of Bali · All rights reserved.