Privacy Policy

Last Updated: May 19, 2026 · Version 2.0

Controller: Cause Vision s.r.o. (Prague, Czech Republic, ID: 17539013).

This Privacy Policy explains how Cause Vision ("Cause", "we") collects, uses, shares, retains, and protects personal data when you use the Cause Wallet web application, mobile applications, the CauseCard programme, and related services. We are committed to processing personal data lawfully, fairly, and transparently.

1. Controller and contact

The data controller responsible for your personal data is Cause Vision s.r.o., registered in Prague, Czech Republic under ID 17539013. We can be contacted at:

For EU and UK residents, you may also contact your local supervisory authority. The Czech supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, "UOOU").

2. Categories of personal data we collect

Identity data
Full legal name, date of birth, nationality, government-issued ID number, photograph/selfie (from KYC).
Contact data
Email address, phone number, postal address (for KYC and card delivery).
Account data
Username, password hash, two-factor secrets, security questions, authenticated devices.
Financial data
Wallet addresses, transaction history, on-chain transfers, fiat top-ups, card transactions, balances.
Verification data
ID document images, selfie/liveness video, proof of address, Sumsub applicant ID and verification outcome.
Source-of-funds data
Self-declared occupation, expected transaction volume, beneficial-ownership disclosures, supporting documents where requested.
Technical data
IP address, browser type and version, device identifier, OS, time zone, login timestamps, cookies.
Usage data
Pages viewed, features used, in-app behaviour, error logs, performance telemetry.
Communications
Messages exchanged with our support team or AI assistant, surveys, complaints.
Marketing preferences
Whether you've opted in or out of marketing channels and which categories.

3. How we use your personal data

We use personal data for the following purposes, each with a stated legal basis under the EU/UK GDPR:
PurposeCategories usedLegal basis (GDPR Art. 6)
Provide and operate the Services (account, transactions, balances)Identity, Account, Financial, TechnicalContract performance (Art. 6(1)(b))
Verify your identity and meet AML/CTF obligationsIdentity, Verification, Source-of-fundsLegal obligation (Art. 6(1)(c))
Sanctions screening and politically-exposed-person checksIdentity, Source-of-fundsLegal obligation (Art. 6(1)(c))
Detect, prevent, and investigate fraudAll categoriesLegitimate interest (Art. 6(1)(f))
Communicate operational notices (e.g. login alerts, security)Contact, Account, TechnicalContract performance / Legal obligation
Customer support and complaints handlingContact, Account, CommunicationsContract performance
Improve the Services, debug, and monitor performanceTechnical, UsageLegitimate interest
Tax reporting (CRS, FATCA, DAC8, CARF where applicable)Identity, FinancialLegal obligation
Marketing (only where you've opted in)Contact, Marketing preferencesConsent (Art. 6(1)(a))
Comply with court orders, regulator requests, or law-enforcement subpoenasAnyLegal obligation

You may withdraw any consent you have given at any time without affecting the lawfulness of processing carried out before withdrawal.

4. Automated decision-making

We use automated processes for parts of identity verification (operated by our KYC provider Sumsub), transaction-monitoring alerts, fraud-risk scoring, and sanctions screening. These processes may significantly affect you (for example, by delaying or blocking a transaction or by closing your account).

Where required by Article 22 GDPR you have the right to obtain human intervention, express your point of view, and contest the decision. Contact us at info@cause.vision to do so.

5. Who we share personal data with

We share personal data only as necessary, and only with recipients bound by appropriate contractual safeguards:
Sumsub (Sum and Substance Ltd)
Identity verification provider. Receives your ID documents and selfie to perform KYC. Returns a verification result and applicant ID.
Rain Cards
CauseCard issuer. Receives Identity, Contact, and Account data necessary to issue and operate the card. Rain is an independent controller for cardholder data.
Alchemy Pay
Fiat on/off-ramp processor. Receives Identity, Contact, and transaction data necessary to settle fiat top-ups and withdrawals.
Visa and acquiring banks
Card transaction processing — receive masked card number, merchant, amount, and FX data.
Cloud infrastructure providers
AWS (compute, storage), Vercel (web hosting), Cloudflare (CDN and bot mitigation). Processors acting on our instructions.
Analytics & telemetry
Aggregated, pseudonymised usage analytics. We do not sell personal data to analytics providers.
Tax authorities and regulators
Where required by FATCA, CRS, DAC8, CARF, AML laws, or by valid legal process.
Law enforcement
Where legally required (court order, subpoena, regulator demand). We assess the validity and scope of every request.
Affiliates and successors
Within the Cause group; on a sale/merger, to the acquiring entity, subject to equivalent or better protection.

We do not sell personal data to advertisers and we do not engage in cross-context behavioural advertising for the Services.

6. International data transfers

Cause Vision operates from Prague, with offices in Nairobi and Dubai, and uses cloud infrastructure that may store or process data in the EU, the UK, the United States, and other regions. Where personal data is transferred outside the European Economic Area or the UK, we rely on:

  • European Commission adequacy decisions (where available);
  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • UK International Data Transfer Agreement / UK Addendum;
  • Supplementary technical and organisational measures (encryption in transit and at rest, access controls) where required by case-law.

A copy of the relevant transfer mechanism for any specific transfer is available on request to info@cause.vision.

7. Retention

We retain personal data only for as long as necessary for the purpose collected, plus any period required by law. Indicative retention periods:
DataRetention periodBasis
KYC documents (ID, selfie, proof of address)Minimum 5 years after account closureEU 5AMLD / national AML rules
Transaction records7 years after the transactionTax, accounting, AML
Account credentials and 2FA secretsUntil account closure + 30 daysOperational
Support tickets and communications3 years after the last interactionLegitimate interest, dispute defence
Marketing-preference logsUntil you opt out + 12 monthsDemonstrate consent compliance
Server access logs and security telemetryUp to 12 monthsSecurity, abuse prevention
Anonymised analyticsIndefiniteNo longer personal data
Sanctions-screening alerts and outcomes5 years after generationAML

After applicable retention periods elapse we delete or irreversibly anonymise the data.

8. Your rights

Depending on your jurisdiction, you have the following rights in respect of your personal data. To exercise any of them, email info@cause.vision. We will respond within 30 days (or 45 days for complex requests, with notice) and we will not charge a fee except in narrow circumstances permitted by law.
  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure — deletion, subject to retention obligations (AML, tax).
  • Restriction — temporary pause on certain processing while a dispute is resolved.
  • Portability — a structured, machine-readable copy of data you have provided to us.
  • Objection — to processing based on legitimate interest or for direct marketing.
  • Withdraw consent — for any consent-based processing.
  • Human review of automated decisions — as described in Section 4.
  • Complaint to a supervisory authority — for example UOOU (Czech Republic), ICO (UK), or your local DPA in the EU.

California residents (CCPA/CPRA): you also have the right to know which categories of personal information we have collected and disclosed in the preceding 12 months, the right to opt out of "sale" or "sharing" (we do not engage in either as defined under CCPA/CPRA), the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising your rights.

9. Security

We protect personal data with administrative, technical, and physical measures appropriate to its sensitivity, including:
  • TLS/SSL encryption in transit;
  • Encryption at rest for production data stores;
  • Multi-factor authentication for staff with access to systems;
  • Principle-of-least-privilege access controls and access logging;
  • Regular vulnerability scanning, penetration testing, and dependency auditing;
  • Two-factor authentication available to all users (and required for sensitive actions);
  • Hardware-backed key storage for custodial wallets where applicable;
  • Breach response procedures with regulator notification within statutory deadlines (e.g. 72 hours under GDPR).

No system is perfectly secure. You can help by enabling 2FA, using a unique strong password, storing backup codes safely, and reporting suspicious activity at techsupport@cause.vision.

10. Cookies and similar technologies

We use cookies and similar technologies for:

  • Strictly necessary — session management, authentication, security (e.g. CSRF tokens). Not optional.
  • Preference — language, currency, theme.
  • Analytics — aggregated usage; only set with consent where required.
  • Anti-bot — Cloudflare Turnstile token.

You can control non-essential cookies via the consent banner where it is presented and via your browser settings.

11. Minors

The Services are not intended for individuals under 18. We do not knowingly collect personal data from minors. If you become aware that a minor has provided personal data to us, contact info@cause.vision and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. The current version and last-updated date are shown at the top of this page. For material changes we will notify you in advance by in-app message or email. Continued use of the Services after the effective date of a change constitutes acceptance.

13. Special-category and financial data

Identity-verification data may include biometric data (used to confirm a match between you and your ID photo) and is processed on the basis of explicit consent and substantial public interest (preventing money laundering and terrorist financing). Financial data is processed under contract performance and legal obligation. We apply enhanced safeguards for these categories including stricter access controls and shorter internal retention for raw biometric templates.

14. Complaints and supervisory authorities

If you believe we have processed your personal data unlawfully, you can raise a complaint with us at info@cause.vision. You also have the right to lodge a complaint with your local supervisory authority. Our lead supervisory authority in the EU is the Czech Office for Personal Data Protection (UOOU). UK residents may contact the Information Commissioner's Office (ICO).

See also: our Terms of Use and Risk Disclosure.

Cause Vision s.r.o., Prague, Czech Republic (ID: 17539013). Offices: Prague, Nairobi, Dubai.