Privacy policy
Last updated 4 September 2026
This policy explains what personal information Bestari Markets Ltd. ("VelaPay", "we", "us") collects through the VelaPay application and this website, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.
We are the data controller for that information. You can reach us at ucard789123@gmail.com or by writing to Unit 4, 1332 Khalsa Drive, Mississauga, Ontario L5S 0A2, Canada.
1. What we collect
| Account details | Email address, phone number, password (stored only as a cryptographic hash), and the language and region settings you choose. |
|---|---|
| Identity information | Full name, date of birth, nationality, residential address, government identity document type and number, and photographs of the front and back of that document. |
| Biometric data | A short video and derived facial imagery captured during the liveness check, used to confirm that a real person is present and that the person matches the identity document. |
| Card and transaction data | Masked card number, card status, balance, deposit records, and records of purchases made with the card, including merchant name, amount and currency. |
| Blockchain data | The deposit addresses we assign to you and the transaction hashes of USDT transfers you send to them. |
| Device and log data | Device model, operating system version, application version, IP address, and timestamps of sign-in and security events. |
2. Why we collect it
- To provide the service. Opening and operating your card, crediting deposits, and showing you your balance and transactions all require the account, card and transaction data above.
- To meet legal obligations. As a financial services business we are required to identify our customers, keep records of that identification, and monitor for and report suspicious activity. Identity information and biometric data are collected for this purpose.
- To keep accounts secure. Device and log data let us detect unauthorised access, show you which devices are signed in, and investigate incidents.
- To communicate with you. We send verification codes, security alerts and transaction notifications to the email address and phone number on your account. These are service messages, not marketing.
We do not sell personal information, we do not share it with advertisers, and we do not use it to build advertising profiles.
3. Biometric data
The liveness check is performed using Amazon Rekognition Face Liveness, operated by Amazon Web Services on our behalf. The video captured during the check is transmitted to that service, which returns a confidence score and a set of reference images.
We use this data only to confirm that the person opening the account is a real, present human being and matches the submitted identity document. We do not use it for surveillance, we do not run it against any external database of faces, and we do not use it to identify you outside the verification process.
If a verification attempt fails, the associated capture is retained only as long as needed to investigate the failure and to prevent repeated fraudulent attempts.
4. Who we share it with
We share personal information only with parties who need it to deliver the service or where the law requires it:
- Our card issuing partner. Identity information is passed to the licensed institution that issues and settles your card. They act as an independent controller of that data and apply their own privacy terms.
- Infrastructure providers. Amazon Web Services hosts our servers, stores identity documents, performs the liveness check, and delivers our service emails. Data is processed in the AWS Asia Pacific (Tokyo) region.
- Communications providers. A third-party provider delivers SMS verification codes to the phone number on your account.
- Regulators and law enforcement, where we are legally obliged to disclose information, or where disclosure is necessary to investigate fraud.
Because our infrastructure is located outside Canada, your information may be processed in, and accessed from, other jurisdictions, and may be subject to lawful access requests there.
5. How we protect it
- All traffic between the application and our servers is encrypted in transit.
- Identity documents are stored in private object storage with server-side encryption, and are never publicly accessible. Access is granted through short-lived, single-use links.
- Full card numbers and security codes are not stored on our servers. They are retrieved from the issuer only when you ask to view them, and the application blocks screenshots and clears the clipboard while they are on screen.
- Access to production data is limited to staff who need it, and sensitive operations are logged.
6. How long we keep it
Identity information, verification records and transaction records are retained for the period required by anti-money-laundering law in the jurisdictions we operate in. In Canada this is generally five years from the closure of an account or the date of a transaction, and we may be required to keep records longer where an investigation is open.
Account details and device logs are deleted or anonymised within a shorter period once they are no longer needed. Data that we are not legally required to retain is deleted when you close your account.
7. Your choices
You can ask us to:
- give you a copy of the personal information we hold about you;
- correct information that is wrong or out of date;
- delete your account and the information we are not required to retain;
- explain why a particular piece of information was collected.
You can delete your account from within the application, under account settings. You can also send a deletion request to ucard789123@gmail.com from the email address on your account. We will confirm the request and tell you what, if anything, we are legally required to keep and for how long.
Where we are required by law to retain identity and transaction records, we cannot delete those on request. This is a legal obligation, not a choice we make.
8. Children
The service is not available to anyone under 18. We do not knowingly collect information from children. If we learn that we have, we delete it and close the account.
9. Changes
If we change this policy we will update the date at the top of this page, and we will notify you in the application before any change that materially affects how we handle your information takes effect.
10. Complaints
If you are not satisfied with how we have handled your information, write to us first at ucard789123@gmail.com. If we cannot resolve it, you may complain to the Office of the Privacy Commissioner of Canada, or to the data protection authority in your own country.