MOTO FINANCE INC. PRIVACY POLICY

Last updated: September 13, 2026

This Privacy Policy explains how Moto Finance Inc. (“Moto Finance,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you visit our websites, apply for membership, use the Moto application, or use the Moto Card, Moto Membership, and our other services. It also explains your rights and how to exercise them.

1. Introduction

1.1 Scope

Moto Finance Inc. is a corporation incorporated in the State of Delaware, United States. We are the controller of the personal data we process in connection with our websites at https://moto-card.com and https://legal.moto-card.com (the “Site”), the Moto mobile application (the “App”), our membership application process, and the Moto Card, Moto Membership (including Moto Lite and Moto Members), Points, referrals, Relationship Manager and concierge services, Moto Lens, payment and transfer features and related services (together, the “Services”). Where this Privacy Policy says that we act as a processor for one of our partners, that partner is the controller for that processing.

This Privacy Policy is drawn up in accordance with Articles 12, 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), the GDPR as it forms part of the law of the United Kingdom (“UK GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and the other data protection laws that apply to our Services. It explains what personal data we collect, where we get it, why we use it and on what legal basis, who we share it with, where we process it, how long we keep it, and the rights you have.

This Privacy Policy is a notice. It tells you how we handle your personal data; it is not a contract and it does not ask you to agree to anything. Other Moto Finance documents, such as the Moto Finance Platform Agreement and the Card Terms that apply to you, refer to it as the Moto Finance Privacy Policy (the “Privacy Policy”).

1.2 Summary

  • We collect what we need to run a regulated card and money service. That includes verifying your identity, which is required by law.
  • We do not sell your personal data, and we do not use it for advertising. The App contains no advertising trackers and does not track you across other companies’ apps or websites.
  • Face ID, Touch ID and your App PIN stay on your device. We never receive them.
  • We must keep some records, such as identity verification and transaction records, for at least five years after you leave. We delete or anonymize other data when we no longer need it, as described in section 9.
  • You can close your account in the App and exercise your rights at any time by contacting us at contact@moto-card.com.

2. Who We Are and How to Contact Us

The controller of your personal data is:

Moto Finance Inc.
1111B S Governors Ave., STE 29768
Dover, DE 19904
United States

Email: contact@moto-card.com
Phone: +1 (978) 584-4083

2.1 Where we act for Lightspark Payments Europe AS

Lightspark Payments Europe AS (registry code 16298772), Pärnu mnt 110, Tallinn, Estonia, provides virtual asset services and EUR virtual IBAN services to members resident in the European Economic Area (“EEA”). Lightspark Payments Europe AS processes your personal data as an independent controller under its own privacy policy. To the extent we process your personal data on the instructions of Lightspark Payments Europe AS in connection with these services, we act as its processor; for any additional data or purposes, we act as controller.

3. The Personal Data We Collect

What we collect depends on how you use the Services. We collect personal data from you, from your device, and from other sources.

3.1 Data you give us

  • Sign-in data: your email address and the one-time codes we send to it. If you create a passkey, your device or password manager keeps the private key and we receive only the public key.
  • Membership application data: your legal name, date of birth, telephone number, residential and billing address, the city you are based in, your occupation, source of funds, gross annual income, expected monthly volume and the purpose of your account, your answers to our membership questions (for example, why you are interested in Moto and how often you travel), and, if you choose to give them, your Instagram and X handles. If someone completes the application for you, or you ask us to share your application status with someone, we also record that person’s email address.
  • Identity verification data: images of your identity document and the information on it (such as your name, date of birth, nationality, document number and expiry date), a selfie and a short liveness video, the biometric data derived from them (see section 5), and your proof of address. Our identity verification provider collects this data inside the App on our behalf.
  • Payment and transfer data: the people and accounts you pay or save as recipients, including their names, email and postal addresses, bank account details (such as account and routing numbers, IBAN and BIC, UK account number and sort code, or SWIFT details and bank name and address) and crypto wallet addresses and networks; the amount, memo and destination of each transfer; and the security codes you enter to confirm a transfer.
  • Card data: the card nickname, spending controls and delivery address you choose, your card delivery details, and your decisions on card payment approvals.
  • Relationship Manager, concierge and booking data: the messages, photos and files you send to your Relationship Manager, the requests you make, the intro calls you book (date, time and your time zone), and booking details such as guest names, travel dates and booking references. See section 14.
  • Support data: the conversations, attachments and details you share when you contact our support team.
  • Membership data: your plan, the terms you accepted and when, and, if you change or cancel your plan or close your account, the reasons and comments you give.
  • Profile and preferences: changes you make to your display name and address, your notification preferences, and your display settings (such as your display currency and whether balances are hidden).

3.2 Data we collect from your device

  • Device and app data: your device type and model, operating system, app version, language, time zone, the name of your device as set in its settings, and the push notification token your device issues.
  • IP address: your IP address reaches us and our providers whenever the App or Site connects to them.
  • Location data: if you allow location access while you use the App, we use your device’s precise location to suggest your address as you type it and to show Moto Lens recommendations near you. If you have not allowed location access, we may use an approximate location derived from your IP address to suggest addresses near you. Our identity verification provider may also check your location while you verify your identity. The App never uses location in the background.
  • Product analytics: a random identifier created when the App is installed, the screens you view (including internal references carried by a screen, such as the identifier of an account, card or transaction you are looking at), the elements you tap, and when the App is opened and closed. The App does not send your name or email address with these events.
  • Crash and diagnostic data: when the App encounters an error, details of the error, your device and operating system, your IP address, the screens you visited shortly before it, and the address of any request that failed.
  • Data kept on your device: the App keeps your signed-in session in encrypted storage on your device, protected by a key derived from your App PIN (see section 10). Your preferences, some account details the App displays (such as your first name), and, if you start a membership application and do not finish it, your saved answers are kept in the App’s standard local storage on your device, which is not separately encrypted. Your saved answers let you continue your application later.

Camera, photos and microphone. The App uses your camera and photo library when you take or choose a photo or file to send to your Relationship Manager or to support. During identity verification, our identity verification provider’s screens in the App use your camera to capture your identity document, your selfie and your liveness video, and you can upload a document from your photo library (see section 3.1).

3.3 Data we receive from other sources

SourceData we receive
Our identity verification providerVerification results, data extracted from your documents, and screening results against sanctions, politically exposed person (“PEP”), and adverse media lists.
Sanctions, PEP and adverse media listsWhether your name appears on them. These lists come from governments and publicly available sources.
Our wallet screening providerRisk scores and classifications for wallet addresses and blockchain transactions linked to your account.
Our card program partners and the card networkCard authorizations, settlements, refunds and disputes, including the merchant’s name, category and country.
Our payment and ramp providersYour account status with them, your deposit account details, and incoming and outgoing payments, including the name and account details of the person who sent you a payment.
Public blockchainsWallet addresses and transaction data, which are publicly visible.
Our wallet infrastructure providerYour wallet address and the status of transactions.
Our sign-in providerSign-in events and session data.
Our address lookup providerAddress suggestions and the details of the address you select.
People who invite youIf you joined through a member’s referral link, the fact that they referred you.
People who apply for youIf someone else completes your application, the data they give us.
Travel and benefit partnersConfirmations and details of bookings and benefits you request.

3.4 Data about people who are not members

Some of the data we process is about people other than you:

  • Your recipients: when you save a recipient or send a payment, we process that person’s name, contact details and bank or wallet details so that we and our payment providers can make the payment and meet our anti-money laundering obligations.
  • People who pay you: when someone sends money or crypto-assets to your account, we receive their name and account details or wallet address with the payment, and we screen incoming wallet addresses.
  • Guests: when you make a booking for others, we process their names and the booking details.
  • People you invite: if someone joins through your referral link, we may show you that they joined and whether they have completed the steps needed for the referral to count.

3.5 What you have to provide

Providing identity verification data is a legal requirement: without it, we are legally prevented from opening an account or providing the Services. Providing account, financial and contact data is a contractual requirement: without it we cannot deliver the Services you request. Allowing location, camera, photo library, calendar and notification access is optional; if you do not allow it, only the feature that needs it is unavailable. Social media handles and marketing preferences are voluntary.

We use your personal data for the following purposes. For people in the EEA, the United Kingdom and Switzerland, we rely on the legal bases shown under Article 6 GDPR and UK GDPR.

  • To assess your membership application, open and maintain your account, and provide the Services, including the Moto Card, your balances and wallet, payments and transfers, statements, Membership, Points, referrals and benefits. Membership applications are reviewed by a member of our team. Legal basis: performance of a contract with you, or steps taken at your request before entering into one.
  • To sign you in and keep your account secure, including sending sign-in codes, supporting passkeys, and asking you to confirm payments, card details and other sensitive changes with Face ID or your App PIN. Legal basis: performance of a contract with you, and our legitimate interest in protecting your account.
  • To verify your identity, screen you against sanctions, PEP and adverse media lists, screen wallet addresses and transactions, monitor transactions, send and receive the information that must accompany crypto-asset transfers, and keep the records the law requires. Legal basis: compliance with legal obligations to which we are subject under the law of the EU, its member states or the United Kingdom; where the obligation arises under other law (such as U.S. anti-money laundering and sanctions law) or is imposed on us by our regulated partners, our legitimate interest in preventing financial crime, complying with that law and meeting our partners’ requirements.
  • To process card payments, deposits, withdrawals and transfers, and to collect Membership fees, which are debited from your Moto balance after advance notice. Legal basis: performance of a contract with you.
  • To decide which Services are available where you live. Your residence determines which Card Terms apply to you, which payment provider serves you and which features you can use. Legal basis: compliance with legal obligations, and our legitimate interest in offering each Service only where we and our partners are permitted to.
  • To provide your Relationship Manager and concierge services, including your chat, intro calls and their reminders, requests, approvals and bookings. Legal basis: performance of a contract with you.
  • To suggest your address and show Moto Lens recommendations near you using your device’s location. Legal basis: your consent, which you give by allowing location access and can withdraw at any time in your device settings. Where we use an approximate location derived from your IP address to suggest addresses, our legitimate interest in making address entry quicker and more accurate.
  • To send you notifications about your money, card, verification, Membership, concierge and our products. Legal basis: performance of a contract with you for notifications about your account; your consent, given through your device’s notification permission, for push notifications.
  • To provide customer support and handle complaints and disputes. Legal basis: performance of a contract with you, and our legitimate interest in resolving issues and defending legal claims.
  • To send you service communications, such as changes to our terms, fees and this Privacy Policy. Legal basis: performance of a contract with you, and compliance with legal obligations.
  • To send you marketing communications about Moto Finance products, services and events. Legal basis: your consent where the law requires it; otherwise our legitimate interest in promoting our Services to existing members. You can opt out at any time.
  • To manage our member relationships, including tracking applications, assigning Relationship Managers, scheduling intro calls and managing Memberships in our customer relationship management system. Legal basis: performance of a contract with you, and our legitimate interest in running our membership business efficiently.
  • To understand how the App is used and improve it. Legal basis: our legitimate interest in operating and improving the Services.
  • To detect and fix errors and keep the Services running, using crash reports, diagnostics and system logs. Legal basis: our legitimate interest in providing a reliable and secure service.
  • To run our referral program, including, where available, showing members the progress of the people they invited, and awarding referral rewards. Legal basis: performance of our contract with the referring member, and our legitimate interest in running the program.
  • To detect, prevent and investigate fraud, unauthorized use, abuse of Points, referral or trial features, and security incidents. Legal basis: our legitimate interest in protecting the Services, our members and ourselves, and compliance with legal obligations.
  • To establish, exercise or defend legal claims, and to respond to courts, regulators, financial intelligence units, tax authorities and law enforcement. Legal basis: compliance with legal obligations, and our legitimate interest in protecting our rights.
  • In connection with a merger, financing, sale of assets or acquisition of all or part of our business. Legal basis: our legitimate interest in carrying out such a transaction.

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests, rights and freedoms. You can ask us for more information about that assessment using the contact details in section 2. You can object to processing based on legitimate interests (see section 11.2).

5. Biometric and Other Sensitive Data

5.1 Identity verification and liveness

To confirm that you are who you say you are, our identity verification provider(s), Persona & Sumsub, compare the photo on your identity document with a selfie and run a liveness check to confirm that a real person is present. This involves processing biometric data derived from your face, which is a special category of personal data under Article 9 GDPR and “biometric information” or “biometric identifiers” under several U.S. state laws.

Our partners process this data on our behalf. Sumsub processes and stores the images, the liveness video, and the biometric comparison; our systems keep the verification result and references to it. We use this data only to verify your identity, to prevent fraud and to meet our anti-money laundering obligations. We do not use it to identify you in any other context, and we do not sell, lease or trade it.

5.2 Face ID and device biometrics

When you use Face ID, Touch ID or another device biometric to unlock the App or confirm an action, the check happens entirely on your device. We never receive, store, or have access to your fingerprint or face data; the App only learns whether the check succeeded.

5.3 Other sensitive data

We also process other data that the law treats as sensitive: your government identification numbers, your nationality or citizenship, your financial account and card details, and your precise location if you allow it. We use this data only for the purposes described in this Privacy Policy.

6. Automated Decisions and Profiling

We use automated processes, including tools provided by our service providers, to meet our legal obligations and to operate the Services safely. Some of these produce decisions without human involvement that can significantly affect you:

  • Identity verification. Our identity verification provider checks that your identity document is genuine and unaltered, that your selfie matches the photo on it, and that a real person was present during the liveness check. The result sets your verification status automatically. You need a successful verification to use most of the Services; if a check fails, you may be asked to try again, or your verification may be rejected.

  • Sanctions, PEP and adverse media screening. When your application is approved, and while you remain a member, your name and details are screened against sanctions, PEP and adverse media lists. If the screening does not return a clear result, your application or account is automatically placed on hold or rejected. You can ask us to review that decision using the details in section 2, and a member of our team will do so.

  • Availability by residence. The country of the residential address in your application determines, automatically, which Card Terms apply to you, which payment provider serves you, and which features are available to you. For example, crypto-asset deposits and withdrawals are not available to residents of the United Kingdom, Guernsey, Jersey or the Isle of Man.

  • Card payments. Each card payment is approved or declined automatically based on your available balance, the status of your card, the controls you have set, and the checks carried out by our card program partners.

Where a decision based solely on automated processing has legal or similarly significant effects on you, we rely on it because it is necessary to enter into or perform our contract with you, or because anti-money laundering laws authorize it. You have the right to obtain human review of the decision, to express your point of view, and to contest the decision. To do so, contact us using the details in section 2 and tell us which decision you want reviewed. A member of our team who can change the outcome will review it.

7. Data sharing

By using the Moto app, you are also accepting the respective privacy and data sharing terms of our partners, including Lightspark, Rain, and Iron.

8. How Long We Keep Your Data

We keep personal data only for as long as necessary for the purposes set out in this Privacy Policy, and then delete or anonymize it.

9. Closing your account

You can close your account in the App at any time under Settings, Personal details, Close account. The App takes you through a short checklist, including withdrawing any remaining balance, and asks for the reason you are leaving.

When you ask us to close your account, we freeze your cards and sign you out of the App. For 30 days you can change your mind and cancel the request. After that your account is closed, and for a further 14 days you can ask us to reactivate it. At the end of that period we delete your profile and account settings, your saved preferences and notification settings, your device and session data, and your support conversations. We keep the records that the law requires us to keep, such as identity verification documents, transaction history and anti-money laundering records, for the periods in section 9. We lock them and restrict access, use them only to respond to regulatory or legal requests, and permanently delete them at the end of the retention period.

If you cannot use the App, you can ask us to close your account by contacting us using the details in section 2.

10. How We Protect Your Data

We use technical and organizational measures designed to protect your personal data from accidental loss and from unauthorized access, use, alteration, and disclosure, including:

  • Encryption. Data is encrypted in transit between the App, our platform and our providers, and at rest in our databases.
  • Your session. The App keeps your signed-in session in encrypted storage on your device, protected by a key derived from your App PIN and available only on that device. Unlocking the App requires your App PIN or your device’s biometrics.
  • Card details. Your card number, security code and PIN are sent to the App encrypted by our card program partner, in a form that only your App can decrypt, and are shown only after you confirm with Face ID or your App PIN. Our platform passes them on without being able to read them, and the App does not store them.
  • Confirmations. Payments, card details and other sensitive changes require confirmation with Face ID or your App PIN.
  • Access controls. Access to our systems is restricted to staff who need it and protected by strong authentication. Decisions to release funds held for compliance review require two members of our team.
  • Logging. Our system logs are designed to remove email addresses, access tokens and card numbers before they are stored.

The transmission of information over the internet and mobile networks is never completely secure, and we cannot guarantee the security of data sent to us. If a personal data breach is likely to put your rights and freedoms at risk, we will tell you and the relevant authorities as the law requires.

11. Your Rights

11.1 If you are in the EEA, the United Kingdom or Switzerland:

Under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and other applicable laws, you have the right to:

  • Access your personal data and receive a copy of it, together with information about how we process it.
  • Correct inaccurate personal data and complete incomplete personal data.
  • Erase your personal data in the circumstances set out in Article 17 GDPR, subject to the records we are legally required to keep (see section 9).
  • Restrict our processing of your personal data in the circumstances set out in Article 18 GDPR.
  • Data portability: receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before you withdrew it.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you, except where Article 22 GDPR permits it, and to obtain human review of such a decision as described in section 6.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. In the United Kingdom, that is the Information Commissioner’s Office (https://ico.org.uk). In Switzerland, it is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch). Complaints about processing carried out by Lightspark Payments Europe AS may be addressed to it directly or to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You can also complain to us about how we handle your personal data, using the details in section 2. We will acknowledge your complaint, look into it and tell you the outcome.

11.2 Your right to object

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests, including profiling based on those interests. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. You also have the right to object at any time to the use of your personal data for direct marketing, including profiling related to it, and we will then stop using it for that purpose.

12. Your Relationship Manager and Concierge

If your Membership includes a Relationship Manager, you can chat with them in the App, book an intro call, and ask our concierge team for help with bookings and requests.

  • Who can read your chat. Your Relationship Manager and the members of our concierge team who support them can read your messages and attachments. Relationship Managers are part of Moto Finance’s team. Your chat is hosted by our service provider Stream, and it includes system messages about your bookings and approval requests.
  • How long we keep it. Your chat history is kept for the duration of your Membership, and it stays with your account if your Relationship Manager changes (see section 9).
  • What not to send. Please do not send your card number, security code, PIN, App PIN or sign-in codes in the chat. Your Relationship Manager will never ask for them.
  • Intro calls. When you book an intro call, we record the time and your time zone in our systems and in our customer relationship management system so that your Relationship Manager can prepare. The App shows you your Relationship Manager’s name and direct telephone number.
  • Bookings and requests. When you ask us to book travel, a hotel or another benefit, we share the details needed with the relevant partner (see section 7.2).

13. Children

The Services are intended only for adults. We do not accept membership applications from anyone under 18 years of age, and we do not knowingly collect personal data from children. If you are a parent or guardian and believe that a child has provided us with personal data, please contact us, and we will delete it.

14. Third-Party Websites and Services

The Site and the App contain links to third-party websites and services, such as our partners’ terms and privacy policies. Some steps in the App, such as the identity verification screens provided by Sumsub, are operated by our providers. We are not responsible for the privacy practices of third-party websites and services that are not acting on our behalf. We encourage you to read the privacy policies of these third parties before providing any information to them.

15. Laws That Apply

Our processing of personal data is governed by the GDPR and the national data protection laws of the EU and EEA member states in which our members reside, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the CCPA and other U.S. state privacy laws where they apply, the Estonian Personal Data Protection Act in respect of the services provided by Lightspark Payments Europe AS, and the Nigeria Data Protection Act 2023 in respect of users in Nigeria.

Much of the processing described in this Privacy Policy is required by financial regulation, including Directive (EU) 2015/849 on the prevention of money laundering and terrorist financing and the national laws implementing it, Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, Regulation (EU) 2023/1114 on markets in crypto-assets and Directive (EU) 2015/2366 on payment services where applicable to our service providers, and the sanctions regimes administered by the United Nations, the European Union, the United Kingdom and the United States Office of Foreign Assets Control.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, and we review it at least once a year. When we do, we post the new version on this page and update the “Last updated” date. If we make a material change, such as using your personal data for a new purpose or sharing it with a new category of recipient, we will tell you in the App or by email before the change takes effect.

17. Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your personal data, please contact us at:

Moto Finance Inc.
1111B S Governors Ave., STE 29768
Dover, DE 19904
United States

Email: contact@moto-card.com
Phone: +1 (978) 584-4083