Skip to main content
YYembiPay
How it worksComplianceCorridorsDevelopers
Talk to us Get access

Legal

Privacy Policy

Effective September 23, 2026. Version 2.0, replacing the version effective September 8, 2026. This policy describes how YembiPay handles information about organizations, their operators, the recipients and originators they submit, and visitors to this website. It is not a substitute for a signed partner data-processing agreement, which is available on request.

Review status: draft published for partner and regulator reading. Independent legal review is a gated launch item and remains open; see the legal hub for status.

In short

  • YembiPay is a business service. It processes information to onboard organizations, screen and execute settlements, produce evidence, and meet legal duties.
  • YembiPay decides how to process information about organizations, operators, screening, evidence, and website visitors. For recipient and originator details that a partner submits, YembiPay acts on the partner's instructions, and requests about that data go to the partner.
  • YembiPay does not sell information, does not use advertising technology, and runs no third-party analytics on this website. The only cookies are two essential session cookies.
  • Screening is automated; a person reviews blocks before any relationship is ended, and you can ask for human review.
  • Settlement, screening, and audit records are kept for at least seven years. Transaction hashes and wallet addresses on a public blockchain are permanent and cannot be deleted.

Who this policy covers

  • Organizations and their operators. The businesses that use YembiPay and the people who act for them. YembiPay determines the purposes and means of processing this information.
  • Recipients and originators. The people and businesses a partner submits as the parties to a settlement. The partner determines why this information is collected; YembiPay processes it under the partner's instructions to execute, screen, and evidence the settlement, and independently retains screening results and evidence to meet its own legal duties.
  • Website visitors and form submitters. Anyone who reads this site or submits a contact form.

Information we process

  • Organization and verification. Legal entity details, registration numbers, addresses, ownership structure, beneficial owner and director identity, source-of-funds declarations, and identity documents.
  • Operator identity and contact. Names, work email addresses, roles, and authentication events.
  • Credentials and security metadata. Hashed API keys and their scopes, webhook endpoints and hashed secrets, session identifiers, and security decisions.
  • Settlement and recipient records. Amounts, corridors, currencies, quote identifiers, wallet addresses, beneficiary and originator names and account or wallet details, and settlement states.
  • Screening and compliance evidence. Sanctions list versions and match evidence, issuer address-list results, monitoring events, risk scores, Travel Rule data, certificates, and the audit trail.
  • Support and form submissions. What a person deliberately sends through a contact form or a support channel.
  • Technical request data. IP address, user agent, timestamps, request identifiers, and error diagnostics.

Sources. You and your operators; partners submitting on behalf of their customers; the identity verification provider; sanctions lists and public registries; public blockchain networks; and, where you connect a bank account, the financial data provider described below.

Financial account connections

When an organization registers a bank account with YembiPay, we may ask an authorized operator to connect that account through a third-party financial data provider, currently Stripe Financial Connections. Through this connection we retrieve the account holder name and address, account status, and account type to confirm that the registered account belongs to the organization we have onboarded and screened.

We do not retrieve transaction history through this connection, use it for credit or underwriting decisions, or initiate debits or credits through it. Connections require operator authorization and can be revoked at any time by contacting privacy@yembipay.com. Data retrieved through financial account connections is stored in the United States.

How we use information

  • Onboard and verify organizations, and enforce tenant, organization, and role boundaries.
  • Screen, price, execute, reconcile, and evidence settlements, and report their states to the organization.
  • Apply sanctions, identity, and anti-money-laundering controls; detect and investigate fraud, abuse, and security incidents; and meet reporting and record-keeping duties.
  • Operate, secure, support, and improve the service, using aggregated or de-identified data for measurement wherever possible.
  • Respond to partnership, corridor, support, or developer requests that a person deliberately submits.
  • Deliver notices, certificates, and system events that the service requires.

YembiPay does not use information for advertising, does not sell or rent it, and does not profile people for marketing.

Automated screening and decisions

Sanctions screening, issuer address-list checks, monitoring rules, and the resulting risk score are automated and run on every settlement. An automated result can hold or reject a settlement. Before an organization's access is ended on the basis of screening, a person reviews the outcome. An organization can ask for human review of an automated outcome by writing to privacy@yembipay.com. Where law prohibits YembiPay from explaining a match or a report, it will say so rather than give a misleading reason.

Sharing

YembiPay shares information only for a defined operational or legal purpose, under agreements and access controls. The providers that process partner data, their purposes, and their locations are listed on the Sub-processors page. Beyond those providers, information may be shared with: counterparty institutions, to carry Travel Rule data with a settlement; participating banks and rail operators, to execute a payout; regulators, financial intelligence units, and law enforcement, under the procedures in Legal and Law-Enforcement Requests; professional advisers under confidentiality; and a successor entity in a merger, acquisition, or insolvency, under this policy.

Public blockchain data

The on-chain leg of a settlement writes the transaction hash, the sending and receiving wallet addresses, the token amount, and the certificate's hash to a public network. That data is public and permanent by design and cannot be altered or deleted by YembiPay or anyone else. YembiPay never writes names, account numbers, documents, or any other personal information on-chain. A wallet address can identify a person when combined with other information, so YembiPay treats addresses as personal information in its own systems.

Credentials and sensitive data

Partner API keys must not be sent through contact forms or support messages. Browser partner sessions use encrypted, HttpOnly, same-site cookies with short expiry. YembiPay designs logs and analytics to exclude credentials, raw beneficiary bank data, and other unnecessary sensitive fields. Identity documents are held by the verification provider and referenced, not copied, wherever possible.

International transfers

YembiPay's primary systems and storage are in the United States. Information about organizations, operators, recipients, and compliance activity may be accessed or processed in the United States or in a country where YembiPay or a listed provider operates. For recipients and payout activity in Jamaica, Guyana, or another supported corridor, only the information needed to complete the settlement, apply controls, and meet legal obligations is transferred. Transfers rely on contractual clauses with providers, transfer assessments where a regime requires them, and technical and organizational safeguards. Where the data protection laws of Jamaica, Guyana, Bermuda, the United Kingdom, or the European Union apply to a transfer, YembiPay applies the mechanism that law requires.

Retention

  • Contact-form and support records: as long as needed to respond and manage the relationship, normally no longer than 24 months after the last interaction.
  • Organization, settlement, recipient, screening, certificate, and audit records: at least 7 years after the relationship or the transaction ends, or longer where law, a dispute, fraud prevention, or an active investigation requires.
  • Hashed credentials: until revoked, then as part of the audit trail.
  • On-chain records: permanent, by the nature of the network.

Security and incident notification

Security controls include encryption in transit and at rest, field-level encryption of personal fields, access control, tenant isolation, secret management, redaction, hash-chained audit logs, monitoring, backup, and tested recovery. No system can guarantee absolute security. If YembiPay confirms an incident that affects an organization's data, it notifies that organization without undue delay with what is known, what has been done, and what the organization should do, and notifies regulators where the law requires. Security reports go to security@yembipay.com.

Cookies and tracking

This website sets two essential cookies, both used only for the authenticated partner session: a session cookie and a cross-site request forgery token. Both are host-only, HttpOnly, restricted to same-site requests, and short-lived. There are no analytics, advertising, or third-party cookies, no tracking pixels, and no third-party scripts on the public site, so there is nothing to opt out of and no consent banner is shown. Because no tracking occurs, browser do-not-track and global privacy control signals change nothing. If this changes, this policy will be updated and consent obtained where required. Details are on the Sub-processors and Cookies page.

Your rights

Depending on the law that applies to you, you may have the right to access, correct, delete, restrict, or object to processing of your information, to receive a copy in a portable form, to withdraw consent where processing relies on it, and to ask for human review of an automated decision. To exercise a right, write to privacy@yembipay.com. YembiPay will verify your identity, respond within 30 days, and explain any extension. If you disagree with the response, you may ask legal@yembipay.com to review it, and you may complain to the data protection authority in your jurisdiction, such as the Office of the Information Commissioner in Jamaica or the Privacy Commissioner in Bermuda. Financial, compliance, audit, and legal records may need to be retained despite a request, and on-chain records cannot be altered. If your information was submitted by a partner as a recipient or originator, that partner decides on your request and YembiPay will assist it.

Eligibility and children

YembiPay is a business service and does not knowingly collect information from anyone under 18. If it learns that it has, it deletes the information unless a legal duty requires retention.

Changes

This policy is versioned and dated. Material changes are notified to registered organizations before they take effect, as described on the legal hub. Prior versions are available on request.

Contact

Privacy questions and rights requests: privacy@yembipay.com. Security reports: security@yembipay.com. A named data protection contact will be published here on appointment.

YYembiPay

Evidence-led settlement infrastructure connecting stablecoin liquidity to Caribbean local rails.

Platform

  • Product
  • Corridors
  • Compliance
  • System status

Build

  • Developer hub
  • API reference
  • Capabilities
  • Sandbox lab
  • On-chain evidence
  • Production readiness

Company

  • About
  • Contact
  • Legal
  • Privacy
  • Terms

YembiPay is settlement software, not a bank. It holds no deposits, is not yet licensed in any jurisdiction, and live value movement remains gated.

© 2026 YembiPay. All rights reserved.

Caribbean settlement / verifiable outcomes