Privacy Policy

What personal data we collect, why we process it and who we share it with.

DRAFT — for legal review, not yet approved by counselUpdated: 3 min read

Effective date: 13 September 2026 (draft)

1. What we collect

Identity data you provide during verification (name, date of birth, government ID, proof of address and similar) and data our identity verification partner generates from it; contact details (email, phone); transaction data (top-ups, conversions, card spending, withdrawals); device and usage data (app and website interaction, approximate location from IP address, device identifiers).

2. Why we collect it

To verify your identity and meet legal KYC/AML obligations; to provide the card, wallet and conversion service; to detect and prevent fraud and abuse; to meet regulatory reporting obligations; to improve the product; and to send service and security notices.

3. Who we share it with

Our licensed issuing partner(s) and identity verification partner(s), strictly for the purposes above; infrastructure and hosting providers acting on our instructions; and regulators and law enforcement where legally required. We do not sell your personal data.

4. Card data

We do not store your full card number (PAN) or CVV. Issuance and tokenization happen at our licensed issuing partner; we hold only the references needed to operate the service.

5. Retention

We retain identity and transaction data for as long as required by applicable KYC/AML and financial record-keeping law, and delete or anonymize it afterwards unless a longer period is legally required.

6. Your rights

Subject to applicable law (for example, GDPR where it applies), you may request access to, correction of or deletion of your data, and may object to certain processing. Deletion may be limited by the legal retention obligations described above.

7. International transfers

Your data may be processed in countries other than your own, including by partners operating in other regions. We use appropriate safeguards where required by law.

8. Security

We use technical and organizational measures appropriate to the sensitivity of the data, including tokenization of card data and access controls. No system is 100% secure; we will notify you and the relevant authorities of a qualifying breach as required by law.

9. Cookies and tracking

magic.website does not use tracking cookies or advertising trackers. The browser’s local storage holds only three technical values: the selected language, a flag that the language hint was dismissed, and your choice in the cookie banner. They are not shared with third parties and are removed when you clear the site’s data in your browser. Our hosting provider (Cloudflare) may set strictly necessary cookies to protect against automated requests; they are not used for profiling.

Analytics cookies (to measure traffic and site performance) are enabled only after you click “Accept all” in the banner. As of the effective date of this Policy, no analytics tools are connected; when they are, this section will name the provider, retention period and how to withdraw consent. To change your choice, clear the site’s data in your browser — the banner will appear again.

10. Contact

For questions about the processing of your personal data, exercising your rights or withdrawing consent, write to privacy@magic.website. For general questions, write to support@magic.website or use the Support button in the app.