1. Who we are
U-transfer is operated by Ultima (“U-transfer”, “we”). This policy explains what personal data we handle when you use the U-transfer app at app.u-transfer.com and this website, why we handle it, and what you can ask us to do with it.
Questions, requests or complaints: adinglee@u-transfer.com.
2. What we collect
- Account data — your email address, your password in hashed form, and the sign-in method you used (email, or a third-party account such as Google, Telegram or X). From a third-party sign-in we receive only the account identifier and, where the provider supplies it, your verified email address and display name.
- Identity data — the name, country and phone number you provide when you open a card, and, for a physical card, the identity documents required by the card issuer. Identity documents are submitted to our card issuing partner for verification.
- Delivery data — recipient name, phone number and shipping address, collected only when you order a physical card.
- Financial data — your wallet balance, your on-chain deposit addresses and the deposits credited to them, transfers, card top-ups, card issuing fees, and the card transactions reported to us by the issuer.
- Support data — messages, and any images you attach, in the in-app chat.
- Technical data — IP address, browser or device information, and timestamps of security-relevant actions such as sign-in, email verification and card operations.
- Referral data — who invited you, and the commission generated by accounts you invited.
We do not ask for, and you should never send us, your card PIN, your password, or one-time codes sent to your email.
3. Why we use it
- To operate your account, issue and service your cards, and process deposits, transfers and top-ups.
- To meet identity verification, anti-money-laundering and sanctions obligations that apply to us and to our card issuing partners.
- To keep accounts secure — verifying email addresses, detecting fraud and abuse, and investigating incidents.
- To answer support requests and to send service messages such as verification codes, card status and announcements.
- To calculate referral commission where you take part in the referral programme.
4. Who we share it with
- Card issuing and processing partners — the licensed issuer and processors that issue your card and settle your transactions. As stated in our Terms, the identity of these partners is not disclosed.
- Email delivery provider — used to send verification codes and service notifications to your email address.
- Infrastructure providers — the hosting provider that runs our servers and database.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to investigate fraud or to protect our users.
We do not sell personal data, and we do not use it for advertising.
5. Public blockchains
Deposits reach your account through public blockchains (TRON, BSC and Polygon). Transactions on those networks are public, permanent and outside our control: we can neither delete nor alter them. The link between an on-chain address and your identity is held by us and is not published.
6. How long we keep it
Account, identity and transaction records are retained for at least five years after an account is closed, in line with the anti-money-laundering requirements set out in our Terms. Support conversations are kept for as long as they are useful for handling your case and for the same statutory period where they concern a transaction.
7. Security
Traffic to our services is encrypted in transit. Passwords are stored hashed and are never recoverable in plain text. Sensitive actions — signing in from a new context, changing your email or password, viewing full card details, applying for a physical card — require a one-time code sent to your verified email address. Administrative access to our back office requires two-factor authentication and is restricted per account.
8. Cookies and local storage
This website sets no cookies and runs no analytics or advertising scripts. The app stores your session token and interface preferences in your browser’s local storage so that you stay signed in; clearing your browser data signs you out.
9. Your rights
You may ask us to give you a copy of the personal data we hold about you, to correct it if it is wrong, or to delete it. Deletion is limited by the retention obligations described in section 6: where the law requires us to keep a record, we will keep it and restrict its use instead. You may also withdraw a consent you have given, and object to a use that is not required to operate your account.
Send any request to adinglee@u-transfer.com from the email address registered on the account. We may need to verify your identity before acting on it.
10. Data protection framework
Personal data is processed in accordance with the data protection standards in force at the DIFC, consistent with the applicable law and jurisdiction set out in our Terms & Conditions.
11. Children
U-transfer is not intended for anyone under 18. We do not knowingly open accounts for minors, and we close any account we discover to belong to one.
12. Changes
We may update this policy for legal, security or product reasons. The current version is always published on this page; continuing to use the service after publication constitutes acceptance.