AML Policy
Last Updated: September 07, 2026
1. General Statement
i-pay.io ("we," "our," or "us") is a facilitator of fiat-to-crypto transaction flows and does not directly engage in financial services, custody of funds, or end-user onboarding. However, we are committed to supporting international efforts to prevent money laundering, terrorist financing, and other forms of financial crime.
We do not perform end-user onboarding, KYC or fund processing ourselves. Our third-party onramp providers are fully responsible for end-user identity checks, transaction monitoring, compliance reporting and risk management under applicable regulations. We do, however, perform our own due diligence on every merchant before granting access to our Services (see section 2).
2. Merchant Due Diligence (KYB)
Before a merchant is granted access to our Services, our team reviews the business itself. We collect and verify the merchant's website, incorporation documents, details of directors, shareholders and ultimate beneficial owners (UBO), and a government-issued ID of the UBO. This review is carried out manually by i-pay.io within 24 hours of receiving complete documentation and is not outsourced or shared with third parties. Merchants that are incomplete, misleading or fall within restricted jurisdictions or prohibited use cases are declined.
2a. End-User Due Diligence
End-users making transactions through services integrated with i-pay.io are verified by the responsible onramp provider before their first transaction. Verification is tiered by transaction amount and typically includes name and address details, a government-issued ID with liveness check for larger amounts, and source-of-funds evidence for very large amounts. Verified details are reused for subsequent transactions, with additional checks triggered where thresholds are exceeded.
3. Sanctions & Restricted Jurisdictions
i-pay.io does not facilitate access to payment processing for any users or businesses located in:
-
Sanctioned countries (e.g., OFAC, EU, UN lists)
-
Regions flagged for high financial crime risk by FATF or equivalent bodies
We reserve the right to restrict access to our Services based on changes in risk exposure or the presence of unlawful content, use cases, or jurisdictions.
4. Transaction Screening & Suspicious Activity
Although i-pay.io does not process payments, we actively:
-
Monitor API usage for patterns consistent with fraud or circumvention
-
Flag suspicious behavior and notify relevant upstream partners
5. Compliance Monitoring
i-pay.io conducts internal monitoring to ensure its own infrastructure is not misused. This includes:
-
Routine log reviews
-
Abuse flagging automation
Where abuse or suspicious use is detected, we may:
-
Terminate access
-
Blacklist merchant or user IPs
6. Politically Exposed Persons (PEPs)
All identity checks related to end-users are carried out by KYC providers, who apply enhanced due diligence for individuals flagged as PEPs. i-pay.io requires that such providers maintain:
-
Additional risk scoring thresholds
-
Continuous monitoring
-
Manual review workflows for PEPs and high-risk accounts
7. Training & Awareness
Although we do not handle end-user onboarding, our internal team is trained to:
-
Recognize the signs of platform abuse and suspicious use cases
-
Understand obligations under applicable AML frameworks
-
Escalate any internal red flags to responsible parties
8. Data Retention
We do not retain end-user identification documents or transaction values. Merchant KYB documentation is stored with restricted access for the duration of the merchant relationship plus any legally required period, and is never shared with third parties. Any logs or metadata retained are processed solely for platform security and abuse prevention, in accordance with applicable privacy laws.
9. Cooperation With Authorities
We cooperate fully with regulators, law enforcement, and legal bodies on valid inquiries. Information requests should be addressed to our compliance contact with:
-
Proof of authorization
-
Specific request details
-
Valid legal basis (e.g., court order, subpoena)
All requests should be sent to: compliance@i-pay.io
10. Termination
KYB information provided during onboarding proves incomplete, inaccurate or misleading