Privacy Policy
This Privacy Policy explains how Eisy Myanmar collects, uses, stores, and shares personal data when you use eisymyanmar.com and related services, including virtual cards, USDT wallets, and USDT/MMK P2P trading. We aim to process personal data in line with UK GDPR principles and good industry practice for financial platforms.
1. Who we are
Data controller: Eisy Myanmar
Privacy / support contact:
support@eisymyanmar.com
2. Personal data we collect
2.1 Account & contact data
- Name, email address, phone number (where provided), and account identifiers
- Authentication data (e.g. hashed PIN / password material; we do not store raw OTPs longer than needed)
- Device, browser, IP address, and session/security logs
2.2 Identity verification (KYC) — including Myanmar passport data
To unlock P2P trading and meet AML / partner requirements, we may collect identity documents and related data, which can include:
- Myanmar passport details (full name, passport number, nationality, date of birth, expiry, and document images)
- Other government-issued ID, selfie / liveness checks, and residential information you submit
- KYC status, review notes, and decision history
KYC documents are processed only for verification, fraud prevention, sanctions screening, regulatory / partner compliance (including card programme and marketplace risk controls), and dispute handling. Access is limited to authorised personnel and systems.
2.3 Financial & transaction data
- Wallet balances, deposits, withdrawals, fees, and ledger entries
- Virtual card issuance / reload metadata (not full card PAN where tokenised by partners)
- P2P ads, orders, escrow events, chat/messages, and payment proofs you upload
- Blockchain transaction hashes and deposit addresses associated with your account
2.4 Support communications
Messages, attachments, and related metadata you send via in-app support or email.
3. How we use personal data
- To create and administer your account and provide the Service
- To issue and manage virtual cards with programme partners (e.g. Stripe Issuing / other BIN sponsors)
- To process USDT deposits/withdrawals and P2P escrow flows
- To perform KYC, AML monitoring, fraud prevention, and sanctions screening
- To resolve disputes, chargebacks, and customer support requests
- To meet legal, accounting, audit, and regulatory obligations
- To improve security, reliability, and product performance
Legal bases may include performance of a contract, legitimate interests (secure platform operation), legal obligation, and—where required—consent (for example, optional marketing).
4. Sharing of data
We may share personal data with:
- Card & payments partners (including Stripe Issuing or other issuing/programme partners) as needed to provide cards and prevent fraud
- Infrastructure providers (hosting, databases, email/OTP delivery, storage) under appropriate contracts
- Professional advisers and auditors under confidentiality
- Authorities where required by law, court order, or to protect rights and safety
- Other users only to the limited extent necessary for P2P trades you initiate (e.g. display name / trade references)—not your passport images
We do not sell personal data.
5. International transfers
Service providers may process data outside the UK/EEA. Where we transfer personal data internationally, we use appropriate safeguards consistent with UK GDPR expectations (such as contractual protections) where required.
6. Data security
- Access controls, least-privilege administration, and audit logging for sensitive operations
- Encryption in transit (HTTPS/TLS) for the web application
- Hashed/protected credentials; separation of operational secrets from application code
- Restricted handling of KYC document uploads and payment proofs
- Monitoring for abuse, duplicate accounts, and suspicious transaction patterns
No method of transmission or storage is perfectly secure. Please protect your devices, PIN, and email account. Notify us promptly of suspected unauthorised access at support@eisymyanmar.com.
7. Retention
We retain personal data for as long as needed to provide the Service and for legitimate business, dispute, and legal/AML record-keeping periods. KYC and transaction records may be kept longer where required by law or partner programmes, after which they are deleted or anonymised where practicable.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal data, and you may withdraw consent where processing is consent-based. Contact support@eisymyanmar.com. You may also complain to the UK Information Commissioner’s Office (ICO) or your local supervisory authority.
Note: we may retain certain records where we have a legal obligation or compelling legitimate interest (for example AML retention), even if you request deletion of your account profile.
9. Children
The Service is not directed to children. We do not knowingly collect personal data from individuals who are not legally eligible to use the Service.
10. Changes
We may update this Privacy Policy from time to time. The effective version is posted on this page. Material changes may also be notified in-product or by email where appropriate.
11. Contact
Privacy questions: support@eisymyanmar.com