Privacy Policy
Privacy Policy
How Money Port collects, uses, shares, and protects personal information.
Money Port Privacy Policy
Last updated: September 10, 2026
Money Port ("Money Port," "we," "us," "our") operates a peer-to-peer AUD ⇌ MNT currency exchange platform (the "Platform"). This Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to everyone who registers for or uses the Platform.
Because Money Port facilitates cross-border fiat exchange between Australia and Mongolia, and performs identity verification as part of KYC/AML obligations, this Policy is written to meet a high bar — treat it as a starting point for legal review, not a substitute for one, particularly around Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and Mongolia's Law on Protection of Personal Information.
1. Information We Collect
Account information: name, email address, phone number, and a hashed password.
Identity verification (KYC) information: date of birth, residential address, nationality, employment details, source-of-funds declarations, government-issued ID (front and back), and a selfie image, submitted through our KYC form.
Financial information: linked bank account details, AUD balance, deposit and withdrawal requests, and trade history (rates offered, amounts, payment methods, and counterparties).
Trade and communication data: listings you create or respond to, in-app chat messages between trading counterparties, payment proof and escrow-confirmation uploads, and any support communications.
Technical and usage data: IP address, device and browser type, log-in timestamps, session data, and general usage patterns on the Platform.
Information from third parties: where relevant, verification results from identity or fraud-check providers, and confirmation data from payment or banking partners.
We do not knowingly collect sensitive categories of information (e.g., health, religion, biometric templates beyond the identity-document photo/selfie itself) beyond what is strictly required for identity verification.
2. Why We Collect and Use It
- To create and administer your account, and authenticate you when you log in.
- To perform KYC/AML/CTF verification, as legally required for a financial exchange service.
- To enable P2P listings and trades, including matching, escrow handling, and dispute resolution.
- To process AUD deposits and withdrawals and maintain accurate balances.
- To detect, investigate, and prevent fraud, money laundering, terrorism financing, and abuse of the Platform.
- To communicate with you: verification emails, trade notifications, security alerts, and support responses.
- To comply with legal and regulatory obligations, including responding to lawful requests from regulators, tax authorities, or law enforcement.
- To improve the Platform's reliability, usability, and security.
We do not sell your personal information, and we do not use your KYC or financial data for advertising purposes.
3. Legal Basis for Processing
Where applicable data protection law requires a stated legal basis, we rely on: performance of our contract with you (Terms of Service), compliance with legal obligations (AML/CTF, tax, and financial-services law), our legitimate interests in operating a secure marketplace and preventing fraud, and, where relevant, your consent (e.g., for optional communications).
4. Who We Share Information With
- Service providers acting on our behalf, under contractual confidentiality and security obligations, including: Cloudinary (document and proof-image storage), Resend (transactional email delivery), our database/hosting infrastructure provider, and any identity-verification or fraud-screening vendor we engage.
- Your trading counterparty, limited to what is necessary to complete a trade (e.g., name matching for payment verification, payment proof) — never your full KYC documents.
- Regulators, tax authorities, and law enforcement, where legally required, including under AML/CTF reporting obligations.
- Professional advisors (legal, audit) where necessary, under confidentiality obligations.
- A successor entity, if Money Port is involved in a merger, acquisition, or asset sale, subject to equivalent privacy protections.
We do not share your personal information with third parties for their own marketing purposes.
5. International Data Transfers
Because Money Port operates between Australia and Mongolia, your information may be processed or stored in either jurisdiction, or in the jurisdiction where our infrastructure or service providers operate. Where we transfer personal information internationally, we take reasonable steps to ensure the recipient is subject to an equivalent standard of protection, through contractual safeguards where required.
6. Data Retention
We retain personal and KYC information for as long as your account is active, and afterward for the period required by applicable AML/CTF and financial record-keeping law (commonly several years after account closure or the relevant transaction — confirm the exact period with legal counsel for both the Australian and Mongolian requirements that apply to you). Trade and transaction records are retained for audit, dispute, and regulatory purposes. Once retention obligations expire, we securely delete or anonymize the data.
7. How We Protect Your Information
- Passwords are hashed (bcrypt) and never stored in plain text.
- Authentication uses signed JWT sessions via NextAuth.
- KYC documents are stored with restricted, access-controlled storage (Cloudinary), separate from general application data.
- Role-based access control limits who internally can view KYC submissions, balances, and disputes — admin actions are logged.
- Data in transit is encrypted (HTTPS/TLS).
- Access to production data is limited to personnel who need it to perform their role.
No system is completely secure, and we cannot guarantee absolute security, but we continuously review and improve these safeguards.
8. Your Rights
Subject to applicable law (including the Australian Privacy Principles and Mongolia's data protection law), you have the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate or outdated information.
- Request deletion of your information, where we are not legally required to retain it (e.g., for AML/tax purposes).
- Object to or request restriction of certain processing.
- Withdraw consent for optional processing (this does not affect processing required for KYC/legal compliance).
- Lodge a complaint with us, or with the relevant supervisory authority (in Australia, the Office of the Australian Information Commissioner — OAIC).
To exercise these rights, contact us at [insert privacy contact email]. We may need to verify your identity before actioning a request.
9. Cookies and Similar Technologies
We use essential cookies/session tokens required for authentication and core functionality. [If you add analytics, marketing, or preference cookies, list them here with purpose and duration, and add a cookie-consent banner for non-essential categories.]
10. Children
The Platform is not directed at, and is not available to, individuals under 18. We do not knowingly collect information from minors. If we learn we have done so, we will delete it.
11. Data Breach Notification
If a data breach occurs that is likely to result in serious harm, we will assess and, where required by law (including Australia's Notifiable Data Breaches scheme), notify affected individuals and the relevant regulator without undue delay.
12. Changes to This Policy
We may update this Policy as our services, legal obligations, or practices change. We will post the updated version with a new "Last updated" date, and for material changes we will provide additional notice (e.g., email or in-app notification).
13. Contact Us
For any privacy question, request, or complaint, contact: [insert privacy contact email / registered business address].
Note: this is a strong starting draft, not a compliance guarantee. Before publishing, have it reviewed against your actual retention periods, your specific AML/KYC provider (if any beyond manual admin review), your Australian financial-services registration status (e.g., AUSTRAC registration as a remittance/exchange provider is very likely required for this business model), and Mongolia's data protection and financial regulations.