Stefa Pay Inc. - Privacy Notice
Version 1.1 · Effective date: 6 October 2026 · Last updated: 6 October 2026
1. Introduction
This Privacy Notice ("Notice") explains how Stefa Pay Inc. ("Stefa Pay", "we", "us" or "our") collects, uses, discloses and protects personal data when businesses, their representatives and individual clients interact with us, our website at s-pay.io and the services offered through it (together, the "Services").
Stefa Pay is committed to protecting personal data in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada and applicable provincial privacy laws.
2. Data Controller and Privacy Officer
The organisation responsible for personal data described in this Notice is:
- Stefa Pay Inc., a company incorporated in the Province of Ontario, Canada (Ontario Corporation Number 1001533856).
- Registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a money services business under number N300001170.
- Registered with the Bank of Canada as a payment service provider under the Retail Payment Activities Act (RPAA).
- Registered office: 1110 Finch Avenue West, Unit 220, North York, Ontario, M3J 2T2, Canada.
Our Privacy Officer, Anna Lukyanova, is responsible for compliance with this Notice and can be reached at privacy@s-pay.io (see Section 18).
3. Scope
This Notice applies to personal data of:
- representatives, directors, officers, authorised users and beneficial owners of our corporate (B2B) clients, and our individual clients (aged 18 or over);
- prospective clients and their representatives;
- website visitors and people who contact us.
Stefa Pay provides services to businesses and to individuals aged 18 or over. The Services are designed for business use.
4. Definitions
- Personal data / personal information - information about an identifiable individual.
- Processing - any operation performed on personal data (collection, use, storage, disclosure, deletion).
- KYC/AML data - information collected to meet know-your-client, anti-money-laundering and counter-terrorist-financing obligations.
- Partner banks / providers - regulated banking, payment and virtual-currency providers through which client funds and settlements move.
5. Personal Data We Collect
Depending on your relationship with us, we may collect:
- Identification data: name, date of birth, nationality, government-issued identifiers and identity documents of directors, authorised users and beneficial owners.
- Contact data: business and personal email, phone, address.
- Corporate records: certificate of incorporation, corporate structure, registers of directors and shareholders, authorised signatories.
- KYC/AML compliance data: beneficial ownership and control information, source of funds and source of wealth documentation, occupation, expected activity, sanctions and politically-exposed-person (PEP) screening results, adverse-media results and risk-assessment outcomes.
- Financial and transaction data: account and IBAN details, currencies used (USD, EUR, USDT), payment instructions, and settlement information processed through our partner banks and providers.
- Technical and usage data: IP address and browser type, recorded in the ordinary server logs of our hosting and network provider when a page is loaded. The Site sets no cookies and uses no analytics or advertising (see our Cookie Policy).
- Communication records: correspondence, support tickets and onboarding records.
We do not intentionally collect special categories of data beyond what is required for identity verification and compliance.
Website data. The Site is hosted and delivered through Cloudflare, Inc. (United States, global network), which handles your IP address and browser type in ordinary logs when you load a page. If you contact us through the Site, the contact link opens your own email program; the message is written and sent by you, and the Site itself does not store it. Once we receive your email, we handle it as described in this Notice.
6. Sources of Data
We collect personal data:
- directly from you and your business during onboarding and use of the Services;
- from authorised representatives of your business;
- from third parties such as identity-verification, sanctions-screening and credit/fraud-prevention providers;
- from public and regulatory registers.
7. Purposes and Legal Basis for Processing
We process personal data to:
- provide the Services, open accounts and issue IBANs, and arrange payments through partner banks;
- meet our legal obligations under the PCMLTFA (FINTRAC), the RPAA (Bank of Canada), sanctions legislation and other applicable law;
- perform KYC/KYB, due diligence, sanctions and PEP screening, and ongoing transaction monitoring;
- prevent, detect and investigate fraud, money laundering and other unlawful activity;
- operate, secure and improve our website and Services;
- communicate with you and provide support;
- where permitted, send service communications.
Our legal bases include performance of a contract, compliance with legal obligations, our legitimate business interests, and consent where required.
Under PIPEDA we obtain consent in the form appropriate to the circumstances: express consent at onboarding and in forms, and implied consent where it is reasonable in context. You may withdraw consent at any time, subject to legal and contractual limits (for example, we must keep certain records to meet our legal obligations); withdrawing consent may mean we can no longer provide some Services.
8. Data Sharing and Disclosure
We may disclose personal data to:
- banking and payment partners and, where applicable, an approved virtual-currency/settlement provider, to execute and settle payments;
- compliance, identity-verification and fraud-prevention providers;
- regulatory and government authorities, including FINTRAC, the Bank of Canada, the Office of the Privacy Commissioner of Canada (OPC), law-enforcement and tax authorities, where required or permitted by law;
- professional advisors (legal, audit, accounting);
- technology and infrastructure providers that support our Services under confidentiality and security obligations;
- acquirers or successors in the context of a corporate transaction, subject to appropriate protections.
We do not sell personal data.
9. International Data Transfers
Because our clients, partners and providers operate across borders, personal data may be processed outside Canada. Where we transfer personal data internationally, we require recipients to protect the data by contract or other lawful means.
Information processed or stored in another country may be accessible to courts, law-enforcement and other authorities there under that country's laws.
10. Data Retention
We retain personal data only as long as necessary for the purposes described or as required by law. In particular, records related to AML/CTF compliance are retained for a minimum of five (5) years from the date of the transaction or the end of the business relationship, in line with FINTRAC requirements. Other records are retained according to our internal retention schedule. In particular:
- Enquiries sent to us by email that do not lead to a client relationship are kept for two (2) years from our last reply, then deleted or anonymised.
- Website and hosting logs (IP address, browser type) are kept by our hosting provider, Cloudflare, Inc., for the short period set by its own policy; we do not export or keep separate copies of them.
- Records of security breaches affecting personal information are kept for at least twenty-four (24) months, as required by PIPEDA.
11. Security Measures
We apply administrative, technical and physical safeguards appropriate to the sensitivity of the data, including access controls, encryption in transit, monitoring and staff confidentiality obligations. No system is completely secure; we work continuously to protect personal data and to respond to incidents.
12. Automated Processing
We use automated tools for identity verification, sanctions/PEP screening and transaction monitoring. These tools support, but do not solely determine, decisions with legal or similarly significant effects; material decisions involve human review. You may contact us to discuss any such decision.
13. Rights of Data Subjects
Subject to applicable law, you may request to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- withdraw consent where processing is based on consent;
- request deletion or restriction where permitted (note that AML and other legal obligations may require us to retain certain data);
- object to certain processing;
- request portability where applicable.
To exercise these rights, contact our Privacy Officer (Section 18). We may need to verify your identity before responding.
We respond to access requests within 30 days, as required by PIPEDA. We may extend that period only as the law allows, and we will tell you if we do. We charge no fee beyond a reasonable cost, which we notify to you in advance. If we refuse a request we will explain why. You may challenge our compliance with this Notice: first with our Privacy Officer and then with the Office of the Privacy Commissioner of Canada (see Section 17).
14. Cookies and Tracking Technologies
The Site sets no cookies and uses no analytics, advertising or tracking technologies. Your browser stores only a small item that remembers your cookie choice and, if you consent to Functionality, items that remember your chosen language; these stay on your device. Our hosting and network provider records your IP address and browser type in ordinary server logs. Details are set out in our separate Cookie Policy, accessible from the website footer.
15. Children's Data
The Services are not directed at individuals under the age of 18. We do not knowingly collect personal data of children.
16. Privacy Breaches and Governance
We maintain a privacy breach response procedure. If a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada (OPC) as required, and maintain a record of breaches in accordance with PIPEDA. We keep records of all breaches of security safeguards for 24 months.
17. Complaints and Supervisory Authorities
If you have a concern about how we handle personal data, please contact our Privacy Officer first. You also have the right to complain to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or the relevant provincial or foreign supervisory authority.
18. Contact Information
- Privacy Officer: Anna Lukyanova, Stefa Pay Inc.
- Email: privacy@s-pay.io (general: info@s-pay.io)
- Phone: +1 450 485 9061
- Address: 1110 Finch Avenue West, Unit 220, North York, Ontario, M3J 2T2, Canada
19. Updates to This Notice
We may update this Notice from time to time. The "Last updated" date above shows when it was last revised. Material changes will be communicated through the website or directly where appropriate.