English
Spanish
Buy cryptoCompareCard
Crypto
Buy CryptoCompare
Card
How It Works2% CashbackCompare Cards
EarnLoginJoin the Beta
EN 🇬🇧
English
Spanish

Privacy Policy

Effective Date: October 28th, 2025
Version: 2.0
Previous version: Privacy Policy version 1.0

Important Notice: This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our websites, use our mobile apps, communicate with us, or otherwise interact with any services, pages, features, or content that link to this Policy (collectively, the “Services”).

We designed this notice to be concise and readable. If you have any questions, contact us at privacy@bleap.finance.

Glossary

Capitalised terms shall have the meanings assigned to them in these Terms, unless the context requires otherwise.

“Personal data”
means any information relating to an identified or identifiable natural person. 

‍“Controller” means the entity that determines the purposes and means of processing personal data. 

‍“Processor” means a service provider that processes personal data on our behalf and according to our instructions. 

‍“EEA/UK” means the European Economic Area and the United Kingdom. 

‍“KYC/AML” means know‑your‑customer and anti‑money‑laundering compliance checks. 

1. Scope and Definitions

1.1 Contracting entity and scope

This Policy applies to the Services operated by Bleap Ltd,  company incorporated in England and Wales with company number 14918472 and registered office at 9th Floor, 107 Cheapside, London, United Kingdom, EC2V 6DN, and all its subsidiaries (the “Bleap Group”) and covers visitors, applicants, individual customers, and representatives of institutional customers who interact with us online or offline.

If you are reading a translated version, the English version controls to the extent of any conflict, unless local law provides otherwise. 

2. Who We Are and How to Contact Us 

2.1 Controller

The controller of your personal data is: Bleap Ltd, a company incorporated in England and Wales with company number 14918472 and registered office at 9th Floor, 107 Cheapside, London, United Kingdom, EC2V 6DN. 

Email: privacy@bleap.finance 
Postal address: Bleap Ltd, 9th Floor, 107 Cheapside, London, United Kingdom, EC2V 6DN
Data Protection Officer: dpo@bleap.finance 

The Bleap Group is established in the UK via Bleap Ltd and in the EEA via Bleap Finance Sp. z o.o. (Poland).

2.2 Regional operating/controller entities

Current primary entities are:
‍

Where you reside Operating Entity Contact Address
European Economic Area (EEA) Bleap Finance Sp. z o.o. ul. Domaniewska 37, lok. 2.43, 02-672 Warszawa, Poland
United Kingdom Bleap Ltd 9th Floor, 107 Cheapside, London, EC2V 6DN, United Kingdom
Rest of world Bleap Ltd 9th Floor, 107 Cheapside, London, EC2V 6DN, United Kingdom

2.3 Joint controllership

The Bleap Group may share personal data within the group to operate, support, and improve the Services, consistent with this Policy and applicable law. In limited cases (for example, group-wide login, risk, or compliance functions), entities may act as joint controllers. Where joint controllership applies, your primary contact is the operating entity serving you; Bleap Ltd coordinates group compliance and can help route requests.

Where we jointly determine purposes and means, for example, group-wide identity verification or risk functions, Bleap Ltd and Bleap Finance Sp. z o.o. act as joint controllers. We have Art. 26 arrangement allocating responsibilities, including a primary contact point for data-subject rights. Your primary contact remains the operating entity serving you, and you may exercise your rights under Section 11 with either entity.

3. Categories of Personal Data 

We collect personal data in three main ways: (i) you provide it, (ii) we collect it automatically, and (iii) we receive it from other sources. 

3.1 Data you provide to us 

  • Basic customer information: name, email, phone, address, date of birth, nationality, country of residence, and similar identifiers. 
    ‍
  • Supplemental identification information: government ID data (e.g., passport/ID/driver’s license numbers and images), residency information, proof‑of‑address documents. 
    ‍
  • Electronic identification/verification (EIDV) information: selfie photos or short videos used to verify likeness against your ID; may include biometric templates generated by our ID verification vendors where permitted by law. Where required, we will obtain your explicit consent. 
    ‍
  • Financial information: bank account details, payment card PAN (tokenized where possible), tax identification numbers, income/asset attestations where needed for regulated offerings. Institutional information (if you represent a business): company name, registration number, business address, and personal details for beneficial owners and control persons as legally required. 
    ‍
  • Wallet information: crypto or digital asset wallet addresses you supply for transactions. 
    ‍
  • Account information: login identifiers, security credentials, and settings/preferences. 
    ‍
  • Transaction information: counterparties, amounts, payment method, currencies, timestamps, transaction identifiers. 
    ‍
  • Communications and support: messages, recordings (where lawful and with notice), survey responses, bug reports, or other content you submit.

3.2 Data we collect automatically 

  • Device and app data: device identifiers, OS/browser type and version, app version, network information, language. 
  • Usage data: pages viewed, clicks, feature use, session timestamps, referral/UTM data. 
  • Diagnostic and troubleshooting: crash logs, performance metrics, error reports. 
  • Approximate location inferred from IP, unless you grant precise location permissions. 
  • Cookies and similar technologies (see Section 9).

3.3 Data from other sources 

  • Identity and sanctions screening providers: results of KYC/AML checks, sanctions/PEP status, document authenticity. 
  • Public and commercial databases: government or supervisory lists, company registers, watchlists. 
  • Blockchain data: publicly available on‑chain transaction metadata (hashes, timestamps, wallet addresses, and related signals). 
  • Analytics and marketing partners: aggregated usage insights and campaign metrics. 
  • Affiliates and integration partners: information necessary to enable features or account connections. 

We do not intentionally collect special categories of data (e.g., health, religion) outside of EIDV biometrics for identity verification where permitted and necessary. We do not intend to collect information from children (see Section 12).

4. Purposes and Legal Bases for Processing

We only process personal data where we have a lawful basis. The table below summarises the main purposes, typical data categories, and the legal basis we rely on. Where data is needed to comply with law or to perform a contract, failure to provide it may mean we cannot offer certain Services. 
‍

Data categories Purpose Legal basis
Basic, ID, EIDV, Financial, Wallet, Account, Transaction, Communications Provide and operate the Services (account creation, transactions, customer support) Contract (Art. 6(1)(b) GDPR)
Basic, Account, Transaction Service communications (e.g., security or transactional notices) Legitimate interests and/or Legal obligation
Basic, ID, EIDV, Financial, Institutional, Wallet, Transaction, public/watchlist data KYC/AML, sanctions and fraud screening, eligibility checks Legal obligation (Art. 6(1)(c) GDPR)
Basic, Account, Device, Usage, Transaction Security, fraud prevention, and platform integrity (including logs and monitoring) Legitimate interests (protecting users and our Services)
Device, Usage, Diagnostics, limited Basic Analytics, product research, and improvement Legitimate interests (improving Services); you may object
Basic, Usage, Marketing interactions Marketing communications and non-essential cookies Consent (you can withdraw at any time)
Any relevant Regulatory compliance, tax and corporate governance, responding to lawful requests Legal obligation
Any relevant Record-keeping and dispute resolution Legitimate interests


We have conducted Legitimate Interests Assessments and you may object to processing based on our legitimate interests (see Section 11).

If you do not provide mandatory KYC data, we cannot provide regulated services.

4.1 Special-category data (biometrics for EIDV) 

Where permitted by law, we may generate a biometric template from your selfie (and, if applicable, a short liveness video) to compare with your identity document solely to verify your identity and to prevent fraud.

We apply strict safeguards, role-based access, encryption, separate storage of biometric templates, purpose limitation, and minimal retention (biometric templates are not used for any other purpose and are deleted once any legally required retention window ends; see Section 7). We do not use biometric data for profiling or marketing. Our legal basis for other KYC data remains Art. 6(1)(c) GDPR (AML/CTF obligations).

We use Sumsub as our processor for identity verification. Where any international access occurs, we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA), supported by transfer impact assessments (TIAs) and supplementary measures; copies of the relevant safeguards are available on request. Sumsub acts only on our documented instructions and may not use biometric data for its own purposes.

4.2 Automated decision‑making and profiling (KYC/AML and fraud)

We use automated tools to assess risks (e.g., sanctions hits, document fraud, transaction patterns). These tools may affect access to certain features or trigger holds or enhanced checks. You have the right to request human review, express your viewpoint, and contest a decision where required by law.

4.3 Criminal-offence data

AML/fraud screening may involve processing data relating to criminal convictions or offences (or inferring risk of offences) under Art. 10 GDPR . We process such data only where authorised by EU or applicable Member-State law, with appropriate safeguards, and solely for AML/CTF, sanctions compliance, fraud prevention, and related legal obligations.

5. Recipients and How We Share Information

We share personal data only as described below and with appropriate safeguards. We do not sell your personal data.

  • Service providers (processors): cloud hosting, data storage, security monitoring, content delivery, customer support, communications (email/SMS), analytics, ID/document verification (including biometric processing where applicable), fraud/AML monitoring, payments and banking partners, and professional advisors (legal, audit, tax). Processors may use data only on our instructions and must protect it appropriately.
    ‍
  • Affiliates: to operate, support, and improve the Services, consistent with this Policy.
    ‍
  • Partners and integrations: when you connect your account or direct us to share data with a third party.
    ‍
  • Authorities and third parties for legal reasons: to comply with law, enforce terms, protect rights, investigate fraud or security issues, or respond to valid legal requests.
    ‍
  • Corporate transactions: in connection with a merger, acquisition, restructuring, or asset sale. Where feasible, we will require the recipient to respect this Policy.

6. International Data Transfers

We operate globally. If we transfer personal data outside your country (including from the EEA/UK to countries without an adequacy decision), we use approved safeguards:

  • EU Standard Contractual Clauses (SCCs) and, where applicable, the UK IDTA/Addendum;
  • Transfer risk assessments and supplementary measures (e.g., encryption in transit and at rest, access controls);
  • Other lawful derogations where appropriate (e.g., performance of a contract).

7. Retention

We retain personal data only as long as necessary for the purposes set out above, to meet legal, accounting, or reporting requirements, and to defend or establish legal claims. Typical periods (subject to applicable law):

  • Account records: Life of account + up to 5 years
  • KYC/AML records: 5 years after the relationship ends (or longer if required by AML law)
  • Transaction and payment records: 6–10 years (statutory/accounting)
  • Security logs and telemetry:12–24 months
  • Customer support records: 24 months (unless needed longer for disputes)
  • Marketing data: Until you opt out or after 24 months of inactivity

When retention ends, we will delete or irreversibly anonymise the data, unless a longer period is required by law or needed for legal claims.

8. Security

We implement administrative, technical, and physical safeguards appropriate to the nature of the data and risks, including encryption in transit and at rest, access controls, segregation of environments, monitoring and logging, employee training, and incident response. No system is perfectly secure; however, we maintain and regularly review our security programme. Where required by law, we will notify you and regulators of data breaches. We also conduct vendor due diligence and restrict employee access to personal data on a need-to-know basis.

You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any suspected unauthorised access or use.

9. Cookies and Similar Technologies

We use essential cookies to make the Services work and non-essential cookies (e.g., analytics, advertising) with your consent. You can manage or withdraw cookie consent at any time via Cookie Settings in our banner, or through your browser settings.

Our website cookie settings applies opt-in for all non-essential cookies in the EEA/UK, remembers your granular choices for at least 6 months, and provides an always-available Cookie Settings link in the footer to change or withdraw consent at any time.

Where used, SDKs, local storage, and similar identifiers are treated in line with this section and our Cookie Policy. See our Cookie Policy for the current list of cookies, vendors, purposes, and retention periods. We currently do not respond to “Do Not Track” signals. In supported regions, we honour Global Privacy Control (GPC) signals for opt-outs related to targeted advertising where applicable.

10. On-Chain Transparency and Wallets

Public blockchains are public and immutable. Transactions (including amounts, timestamps, wallet addresses, and other metadata) may be permanently viewable by anyone. If you link a wallet to your identity, your on-chain activity may become personal data. Consider this when sharing addresses or using the Services. We may analyse public blockchain data to help detect and prevent fraud, comply with laws, and improve the Services.

We cannot remove or alter data recorded on public blockchains. Where legally required, we can delete or de-link our off-chain records that associate you with a wallet address.

11. Your Privacy Rights and Choices

Depending on your location, you may have the following rights, subject to legal limits:

  • Access to your personal data and information about our processing;
  • Rectification of inaccurate or incomplete data;
  • Erasure of your data;
  • Restriction of processing;
  • Portability of data you provided to us;
  • Objection to processing based on our legitimate interests (including direct marketing);
  • Withdraw consent at any time where processing is based on your consent;
  • Rights regarding automated decision-making, including the right to obtain human review.

We may need to verify your identity before acting on a request; we’ll only ask for what’s strictly necessary.

11.1 How to exercise your rights

Email privacy@bleap.finance. We respond within one month of receiving your request. We may extend by up to two additional months where requests are complex or numerous, and will inform you of any extension. You may lodge a complaint with your supervisory authority, including UODO (Poland), or your local EEA authority.

11.2 Marketing choices 

You can opt out of marketing emails at any time by using the unsubscribe link in our messages or by contacting us. You may still receive essential service communications.

11.3 Targeted advertising

Where applicable, you can opt out via the cookie banner settings.

12. Underage applicants and Minimum Age

Our Services are not intended for individuals under 18. We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it and take steps to close the account. If you are under 18 years of age, please do not provide any information or engage in any activity within the scope of our services.

13. Third-Party Sites and Integrations

The Services may link to third-party websites, apps, or integrations. Their privacy practices are governed by their own policies. We are not responsible for the privacy, security, or content of those third-party services. Review their policies before sharing personal data with them.

14. Changes to This Policy

We may update this Policy from time to time. If we make material changes (such as new purposes, new controller information, or changes to how you exercise your rights), we will notify you in advance via email, in-app notice, or banner.

The Effective Date at the top shows when this Policy was last updated. We maintain prior versions upon request.

Do more with your crypto

Get started
Download
Bleap
Crypto
Buy CryptoCompare Crypto
Card
How crypto card worksCashback 2%Credit Card Comparison
Navigation
HomeLoginHelp
About us
Ambassador ProgramCareers
Legal
Terms of Service - Bleap WalletTerms of Service - Bleap FinanceTerms of Service - Bleap CardholderPricing DisclosureConflict of Interest PolicyRisk DisclosurePrivacy PolicyCookie PolicyCookie Settings
Social Media
X/TwitterLinkedinTelegramBlog
InstagramTikTokYoutube

© Bleap LTD 2025. All rights reserved.

Bleap Finance Sp. z o.o is a limited liability company incorporated in Poland under company number 526782047, with its registered office at Piotrkowska, nr 116, lok. 52, Łódź, 90-006, Republic of Poland and is registered in the Polish Register on Virtual Currencies Business Activity (Cryptocurrencies Register) under number RDWW-1009.

The Bleap Mastercard cards are issued by Unlimit, authorised by the Bank of Cyprus under the electronic money institution license to issue e-money and is a member of Mastercard Scheme. Please note that electronic money products are not covered by the Deposit Insurance System of the Republic of Cyprus. We ensure that any funds received by you are held in a segregated account so that should Unlimit be insolvent your funds will be protected against claims made by our creditors.

We use strictly necessary Cookies to run our site.
With your consent, we also use Analytics, Functionality, and Advertising Cookies.
Learn more and manage.

Cookie preferences

Strictly necessary Cookies are always on. Choose how we use non-essential Cookies.

For further details, please review our Privacy Policy and Cookie Policy

Strictly necessary
Required for security, network routing, and core features.
Always active
Analytics
Helps us understand usage and reliability.
Functionality
Remembers settings and support continuity.
Advertising
Measures campaigns and caps/suppresses adverts.