Bancoli - Privacy Policy
This Privacy Policy describes how Oli Technologies LLC (d/b/a Bancoli) ("Bancoli," "we," "us," or "our") collects, uses, stores, shares, and protects your information when you use the Bancoli platform (accessible at app.bancoli.com and related applications).
Bancoli GLBA Initial Privacy Notice: Bancoli is a financial technology company. For platform-held nonpublic personal information (NPI) Bancoli collects or processes in connection with covered financial products or services, this Privacy Policy serves as Bancoli's initial privacy notice and describes Bancoli's collection, use, sharing, and retention practices. Your information is also shared with OliBank International Inc, an affiliated chartered bank under common ownership, which serves as the settlement principal for the program and performs its own bank-capacity compliance, accounting, oversight, and regulatory-response functions. OliBank's collection, use, and protection of NPI is governed by the OliBank Privacy Policy & GLBA Privacy Notice. In a conflict concerning NPI held by OliBank, the OliBank notice controls.
1. Information We Collect
1.1. Information You Provide Directly
| Data Category | Examples |
|---|---|
| Business identity data | Legal entity name, DBA, tax ID (EIN/TIN/VAT), state/country of incorporation, business address, business description |
| Personal identity data | Authorized representative's full legal name, date of birth, place of birth (where present on the identity document), nationality, country of citizenship, residential address (solopreneurs), government-issued photo ID, and personal Tax ID (for U.S. sole proprietors, the SSN or ITIN) |
| Beneficial ownership data | Names, dates of birth, nationalities, tax-residence countries, residential jurisdiction evidence, and ownership percentages of individuals identified under Bancoli's risk-based beneficial-ownership threshold (generally those holding ≥ 25% of the business entity, lowered under enhanced due diligence), plus at least one individual with significant responsibility to control, manage, or direct the entity |
| Business profile data | Countries of operations (businesses), industry selection, PEP self-declaration, business description |
| Financial data | Settlement bank account details (account number, routing number, IBAN), billing information |
| Digital wallet data | Blockchain wallet addresses, on-chain transaction identifiers |
| Contact data | Email address, phone number, mailing address |
| Account credentials | Username, password (stored in hashed form), two-factor authentication preferences |
| Enhanced due diligence (EDD) data (collected only when an enhanced-review trigger applies) | For Politically Exposed Persons (PEPs): Source of Wealth (SOW) and Source of Funds (SOF) documentation. For volume-threshold or other EDD reviews: financial statements or tax returns (up to the prior 12 months), certified corporate structure charts, and business-plan support. Additional documentation may be requested by the Responsible BSA Officer. |
1.2. Information We Collect Automatically
During onboarding and ongoing use, we automatically collect the following data to satisfy regulatory requirements under the Bank Secrecy Act (BSA), FinCEN regulations, and applicable examination frameworks:
| Data Category | Collection Method | Purpose |
|---|---|---|
| IP geolocation | Recorded at application, login, and each session | Jurisdiction verification; sanctions screening; client initiative verification |
| Device fingerprinting | Browser/device characteristics captured passively | Fraud detection; account takeover prevention; dormancy reactivation verification |
| URL risk scoring | Automated content analysis of your declared business website | Business category verification; prohibited business screening |
| Source of origination | HTTP referrer, search query parameters, direct URL entry | Client initiative verification |
| Transaction metadata | Timestamps, amounts, payer identifiers, velocity patterns | BSA/AML monitoring; structuring detection; ACH return tracking |
1.3. Biometric Verification Data
During identity verification, Bancoli uses contracted identity-verification providers, to perform automated liveness checks. These checks may involve biometric facial geometry processing by the provider. Bancoli does not natively store raw biometric facial-geometry templates on its own servers; Bancoli's internal records are limited to verification results, confidence scores, session identifiers, provider audit metadata, and evidence needed for BSA/AML compliance. This data is used exclusively for:
- (a) Verifying that the authorized representative is a live person (anti-spoofing);
- (b) Matching the live capture against the submitted government-issued photo ID;
- (c) Re-verification upon dormancy reactivation: if your account has been inactive for more than two (2) years, reactivation requires a new liveness check and ID re-upload (which involves collection of biometric facial geometry). Accounts inactive for more than three hundred sixty-five (365) days and not more than two (2) years require multi-factor authentication (2FA) for reactivation, which does not involve biometric data collection.
Biometric verification notice and GLBA/BIPA position:
By proceeding with the liveness check, you consent to the collection, capture, transmission, processing, storage, and use of biometric verification data by Bancoli and its contracted identity-verification service providers for identity verification, fraud prevention, BSA/AML compliance, sanctions compliance, account reactivation, and program-assurance purposes.
Bancoli complies with applicable biometric privacy laws. The consent, transparency, retention, and destruction controls in this section apply regardless of your jurisdiction.
- Purpose: Identity verification and fraud prevention only.
- Retention: Raw biometric identifiers and provider-held liveness artifacts are retained by the identity-verification provider under the DPA destruction schedule — destroyed on verification-purpose satisfaction and no later than the earlier of three (3) years after the last program interaction or one (1) year after account closure or final application decline, with an absolute five (5)-year ceiling. That schedule is a MAXIMUM, not a minimum. Liveness verification results, confidence scores, and session metadata (Class C) and ID/selfie images (Class B) are non-biometric program records retained on the seven (7)-year floor. Longer retention applies only for legal hold, active investigation, regulator request, litigation preservation duty, or other applicable law.
- No sale or profit: Bancoli does not sell, lease, trade, or otherwise profit from biometric data.
- Third-party sharing: Biometric data may be shared only with contracted identity verification providers, bound to identical retention and security requirements.
2. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Identity verification (KYB/KYC) | Regulatory obligation (BSA/AML program obligations; MSB AML program under 31 CFR 1022.210). Beneficial-ownership/CDD concepts are adopted as risk-based controls where applicable, not because Bancoli is a covered financial institution under the Bank CDD Rule. |
| Sanctions and PEP screening | Regulatory obligation (OFAC, EU/UN sanctions lists) |
| Transaction monitoring | Regulatory obligation (BSA/AML, structuring detection) |
| Digital asset conversion and settlement | Contract performance |
| Client initiative verification | Legitimate interest (regulatory compliance) |
| Settlement reconciliation | Regulatory obligation |
| Fraud prevention | Legitimate interest |
| Service delivery | Contract performance |
| Regulatory reporting | Regulatory obligation (SAR, CTR filing) |
| Marketing communications | Legitimate interest (subject to opt-out) |
3. Automated Decision-Making
3.1. During onboarding, your corporate data is automatically transmitted to third-party verification services to satisfy Customer Due Diligence (CDD) requirements. This process is automated.
3.2. Your account is assigned an automated risk score based on multiple weighted factors, including jurisdiction risk, ownership and verification quality, and volume/velocity profile. This composite score determines your approval pathway. Post-activation, your actual transaction volume and velocity patterns are monitored continuously and may influence your risk classification.
3.3. Ongoing transaction activity is continuously monitored by automated systems for velocity anomalies, structuring patterns, sanctions matches, ACH return rates, and dormancy-burst patterns.
4. Information Sharing
A current list of the service providers and program counterparties in each category is available upon request through the contact channels in this document.
4.1. Service Providers. Bancoli uses regulated financial institutions, custodians, payment infrastructure providers, and technology partners to deliver its services. We share information with these providers as necessary for:
- Program account management and fund settlement
- Cross-border payment processing and currency conversion
- Identity verification and KYB/KYC processing
- Sanctions screening
- Self-custodial wallet infrastructure
- Digital asset settlement and stablecoin minting
These providers are contractually bound to use your data only for the purposes of delivering their services to Bancoli and to maintain appropriate security and confidentiality standards.
4.2. Settlement and Digital Asset Infrastructure Providers. Your data (including name, business entity information, wallet addresses, and transaction data) may be shared with the following infrastructure providers for the purposes of settlement, digital asset conversion, wallet infrastructure, and AML compliance:
- OliBank International Inc. - affiliated chartered banking partner (an affiliate under common ownership) for separately governed bank-side oversight, QA/audit, examiner support, bank-risk review, and fiat/FX services where approved. OliBank's GLBA Privacy Notice governs all NPI shared with OliBank. OliBank Privacy Policy & GLBA Privacy Notice
- Regulated asset issuers and licensed money transmitters - perform issuance, receipt, and transmission legs under their own regulatory authority and privacy policies.
- Approved downstream FX and payout providers - approved FX and provider-payout infrastructure where a route is enabled; data shared may include client identity, transaction data, payout recipient data, and compliance data needed for provider execution.
- Third-party wallet-infrastructure providers and regulated stablecoin issuers - self-custodial wallet infrastructure and supported-stablecoin issuer dependencies for the stablecoins approved for your route; data shared may include wallet addresses and on-chain transaction identifiers. Provider privacy policies are available upon request.
- Screening providers - automated screening for sanctions, adverse media, PEP, and government-registry verification; data shared may include authorized-representative and beneficial-owner full legal name, date of birth, country of citizenship/nationality, address, beneficial-ownership data, and Tax ID.
- our contracted identity-verification provider - contracted identity-verification provider performing document verification and automated liveness checks; data shared may include government-issued photo ID data and biometric verification data (see Section 1.3). Provider-held biometric and verification data are bound to the retention and security requirements described in Sections 1.3 and 5.
4.3. Regulatory and Law Enforcement. We disclose information as required by law, regulation, subpoena, court order, or regulatory examination. We cannot disclose the existence of a SAR filing (31 U.S.C. Section 5318(g)(2)).
4.4. No Sale of Personal Information. We do not sell, rent, or lease your personal information or biometric data to any third party.
4.5. Marketing and Communications. We may use your contact information to send you promotional materials about our services. In compliance with the CAN-SPAM Act, you may opt out of receiving these marketing communications at any time by clicking the "unsubscribe" link provided in the email. Please note that even if you opt out of marketing communications, we will continue to send you mandatory transactional, account, and compliance-related notices, which cannot be opted out of.
5. Data Retention
| Data Category | Retention Period |
|---|---|
| Client onboarding payloads, including liveness verification results (Class C - 7-year floor) and ID/selfie images (Class B - 7-year floor) | 7 years from account closure, or from date of rejection for declined applications |
| Transaction and settlement records | 7 years from date of transaction |
| SAR/CTR filings and documentation | 7 years from date of filing |
| Raw biometric identifiers and provider-held liveness artifacts (provider-held) | Retained by the provider under the DPA destruction schedule: the earlier of 3 years after the last program interaction or 1 year after account closure / final application decline; absolute 5-year ceiling — a MAXIMUM, not a minimum. Longer retention applies only for legal hold, active investigation, regulator request, litigation preservation duty, or other applicable law |
| Client initiative evidence packets | 7 years from account termination |
| Wallet service account data | Duration of account + 1 year |
| OFAC blocked-property records and supporting documentation | For the period the property remains blocked, plus at least 10 years after unblocking |
| OFAC transaction records not involving blocked property | At least 10 years from the date of the transaction |
Upon expiry, records are securely destroyed using methods appropriate to the data classification and the Data Disposal and Retention-Precedence SOP. Legal holds, active investigations, regulator requests, litigation preservation duties, SAR-supporting-document retention, OFAC retention, and other applicable law override ordinary deletion or disposal schedules.
Note: Certain transaction data recorded on public blockchains (e.g., wallet addresses, transaction hashes) is immutable and cannot be deleted by Bancoli or any third party. The retention periods above apply to Bancoli's internal copies of such data (except for raw biometric facial-geometry templates, which Bancoli does not natively store).
6. Data Security
We implement technical and organizational measures including: encryption at rest (AES-256), encryption in transit (TLS 1.2+), role-based access controls, annual SOC 2 Type II attestation, annual penetration testing, and a documented incident response program.
7. Your Rights
Depending on your jurisdiction, you may request: access to your personal data, correction of inaccurate data, deletion (subject to regulatory retention and the limitations described in Section 5, including the immutability of blockchain data), data portability, or objection to processing. If your application was denied, you may request the general Program eligibility or risk reason category for the denial, subject to sanctions, SAR, provider-confidentiality, and no-tipoff restrictions. Contact privacy@bancoli.com. We will respond within 30 days.
8. International Data Transfers
Your data is processed and stored in the United States. Where data is transferred from jurisdictions with specific data transfer requirements, Bancoli relies on applicable legal frameworks (including the EU-U.S. Data Privacy Framework, Standard Contractual Clauses, or equivalent mechanisms) to ensure adequate protection.
Note for EU/UK Residents: Bancoli restricts access to certain services in EEA/UK jurisdictions. Where covered-market services are available, data may be shared with OliBank and the categories of service providers described in this section for settlement, FX and provider-payout execution, sanctions/AML controls, and recordkeeping. Those providers may act as independent controllers or processors according to their own terms and applicable law.
9. State Privacy Law Compliance
Bancoli complies with applicable United States federal, state, and territorial privacy laws. Where a comprehensive state privacy law applies to you, you may have rights of access, correction, deletion, and opt-out with respect to personal information, subject to the exemptions those laws provide for financial institutions and for information processed under the Gramm-Leach-Bliley Act and other financial-services laws. To exercise any right available to you, contact us using the information in Section 12; we will verify your request and respond as the applicable law requires.
10. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware and applicable US federal law, without regard to conflicts of law principles. Any dispute arising from or related to this Privacy Policy shall be resolved in accordance with the dispute resolution provisions of the Bancoli Terms of Use.
11. Changes to This Policy
Material changes will be communicated via email or in-app notification at least thirty (30) days prior to the effective date.
12. Contact Information
Data Controller: Oli Technologies LLC (d/b/a Bancoli) Email: privacy@bancoli.com