01Introduction
At Wyrr Payments LLC (“Company”, “we”, or “us”), protecting the privacy and security of personal data is a top priority. Wyrr Payments LLC is registered with the Financial Crimes Enforcement Network (FinCEN) as a Money Services Business (MSB Registration Number: 31000276660825), engaged in money transmission and dealing in foreign exchange. We are committed to upholding the standards and obligations set forth by the Bank Secrecy Act (BSA), its implementing regulations at 31 CFR Chapter X, and applicable state money transmitter licensing laws in the jurisdictions where we operate. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal data in the course of our Money Services Business operations.
02Scope and Definitions
This policy applies to all personal data collected during the course of our business operations, including activities conducted in the District of Columbia, Georgia, Illinois, Maryland, Massachusetts, New Jersey, New York, Rhode Island, Texas, and Virginia. “Personal Data” means any information about an identified or identifiable individual—including names, contact details, financial transactions, and compliance data—that is processed by our organization.
03Data Collection
We collect personal data from various sources in order to meet our regulatory and operational responsibilities. The data collected includes, but is not limited to:
- Identification Data: Full name, residential address, date of birth, government-issued identification numbers and documents
- Transaction Data: Transaction amounts, sources and destinations of funds, payment methods and associated details
- Compliance Data: Customer Identification Program (CIP) and Customer Due Diligence (CDD) records, beneficial ownership information, adverse media, watchlist, and sanctions (OFAC) screening results, Suspicious Activity Report (SAR) and Currency Transaction Report (CTR) supporting records
- Communication Records: Phone calls, emails, and written correspondence for service inquiries or complaints
04Purpose of Data Processing
The personal data we process is exclusively used for legitimate and necessary purposes including:
- Regulatory Compliance: Filing Currency Transaction Reports (CTRs), Suspicious Activity Reports (SARs), and other reports required under the Bank Secrecy Act, and adhering to all legal obligations under the BSA, FinCEN regulations, OFAC sanctions programs, and applicable state money transmitter laws
- Identity Verification & Due Diligence: Confirming the identity of customers and beneficial owners under our Customer Identification Program, and undertaking risk-based due diligence to mitigate money laundering, terrorist financing, and fraud risks
- Transaction Processing & Customer Support: Facilitating and monitoring money transmission and foreign exchange transactions, and providing effective customer service and follow-up
- Security & Risk Management: Implementing measures to detect and prevent fraud and financial crime, and ensuring ongoing transaction monitoring to maintain robust security protocols
05Data Sharing and Disclosure
We may disclose personal data under the following circumstances:
- Regulatory Reporting: To FinCEN, including CTRs, SARs, and MSB registration information, and to other authorized federal and state regulatory bodies as legally required; to the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) in connection with sanctions screening and reporting obligations; and to state financial regulators and money transmitter licensing authorities in the states where we conduct MSB activities
- Third-Party Service Providers: To trusted partners who assist with compliance, transaction processing, or customer service, provided they adhere to strict confidentiality and data protection standards
- Legal Requirements: In response to valid legal process such as subpoenas, court orders, grand jury subpoenas, or regulatory inquiries
- Inter-Institutional Cooperation: With other financial institutions under BSA information-sharing provisions (e.g., Section 314(b) of the USA PATRIOT Act) for the purpose of identifying and reporting money laundering or terrorist financing
06Data Protection and Security Measures
We have implemented a range of technical, administrative, and physical safeguards to protect your personal data, consistent with our BSA/AML compliance program, including:
- Encryption: Secure encryption for data during transmission and storage
- Access Controls: Role-based access ensuring that only authorized personnel can access sensitive information
- Regular Audits: Independent testing and periodic security and compliance audits, as required by our BSA/AML compliance program, to maintain up-to-date protocols
- Incident Response: Defined procedures to promptly address and mitigate any data breach or security incident
07Data Retention and Disposal
Your personal data is retained in accordance with the recordkeeping requirements of the Bank Secrecy Act and its implementing regulations, which generally require retention of transaction records, CIP records, and CTR/SAR-related documentation for a minimum of five (5) years, as well as any additional periods required by state licensing law or other applicable legal or operational requirements. Once the applicable retention period has expired and the data is no longer needed, it will be securely disposed of using approved methods for both physical and electronic records.
08Rights of the Data Subject
We respect the rights of individuals regarding their data. You have the right to:
- Access: Request details about the personal data we hold
- Correction: Ask for corrections if the data is inaccurate or incomplete
- Deletion & Restriction: Where applicable, request the deletion or restriction of the processing of your data, subject to our regulatory recordkeeping obligations under the BSA and other applicable law
Please note that certain rights may be limited where retention or disclosure of data is required by the Bank Secrecy Act, FinCEN regulations, OFAC requirements, or other applicable law. Any requests or inquiries regarding your personal data should be directed to our Compliance Office using the contact details below.
09Amendments to This Policy
We reserve the right to update this Privacy Policy as necessary to reflect changes in our practices, technology, or regulatory requirements. When amendments are made, we will publish an updated version with a clear indication of the revised effective date.
For questions about this Privacy Policy or to exercise your rights concerning your personal data, please contact our Compliance Office: