Legal · updated 8 October 2026
Privacy Policy
This Privacy Policy explains which personal data Sam White Ltd. (“we”) processes when you use the OnRamp website and application, why, and which rights you have. It is based on the EU General Data Protection Regulation (GDPR), which applies in Malta.
An important distinction runs through this policy: data you enter into the Software is processed by us as controller of the Software; data you provide to a Service Partner for identity verification or the execution of a transaction is processed by that Service Partner as its own controller, under its own privacy policy.
1. Controller
- Controller for the Software
- Sam White Ltd.
- Address
- 19, St. Mark Street, Valletta VLT 1362, Malta
- Contact for privacy requests
- Via the support function inside the application after sign-in
We have not appointed a data protection officer because we are not legally required to. Privacy requests are handled through the support ticket system so that we can verify that a request really comes from the account holder.
2. Data we process in the Software
- Account
- E-mail address, password (hashed), e-mail verification status, role, account status, timestamps
- Profile
- First and last name, phone number, postal address, country; optionally company name, registration number, VAT ID and company address
- Payout methods
- Bank account details (holder, IBAN/account number, BIC/routing number, bank name) and wallet addresses with network and your ownership confirmation
- Requests
- Direction, amounts, currency, asset, network, rate, fee, status, your personal payment reference, the payout method used, timestamps
- Support
- Tickets and messages you send us
- E-mails
- Which e-mails we sent you, whether they were delivered, opened or clicked (provided by our e-mail service)
- Security
- Session data, blocked-account flags and fingerprints (e.g. hashed e-mail, phone, IBAN, wallet) used to prevent duplicate or fraudulent accounts
- Partner programme
- Referral code, who referred you, commissions (if you are a partner)
- Usage analytics
- Pages visited, device type, browser, approximate location (country/region), referrer, interaction events – stored under a random identifier, without cookies and without your IP address
We do not process identity documents, selfies, proof-of-address documents or source-of-funds documents. Those are collected directly by Service Partners (see section 4).
3. Purposes and legal bases
- Providing the Software, your account and your requests – performance of a contract (Art. 6(1)(b) GDPR).
- Handing your request and the related details to the responsible Service Partner – performance of a contract (Art. 6(1)(b)) and our legitimate interest in operating the platform (Art. 6(1)(f)).
- Preventing fraud, duplicate accounts and misuse (alias detection, blocklist, session security) – legitimate interest (Art. 6(1)(f)).
- Transactional e-mails about your account and requests – performance of a contract (Art. 6(1)(b)).
- Marketing e-mails to existing customers – legitimate interest (Art. 6(1)(f)); you can object at any time via the unsubscribe link or your account settings.
- Cookieless usage analytics to improve the Software – legitimate interest (Art. 6(1)(f)).
- Keeping records required by law and defending legal claims – legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)).
4. Service Partners and identity verification (KYC)
Identity verification, anti-money-laundering checks and the execution of payments and exchanges are not performed by Sam White Ltd.. They are performed by independent, licensed Service Partners, each of which is a separate controller of the data it collects from you.
To execute a request, the Software transmits to the responsible Service Partner the data required for it: your name and contact details, the bank account or wallet involved, the amounts, currency, asset, network and reference of the request, and the status of your e-mail verification.
Where a Service Partner is legally obliged to verify your identity, it (or its specialised verification provider) will collect the necessary data directly from you – typically identity documents, a selfie or video, proof of address, date of birth, nationality and, where required, information about the origin of funds. This data goes directly to the Service Partner; it does not pass through or get stored in our Software. The Service Partner may share the verification result (approved / pending / rejected) with the Software so that we can show you the status.
Service Partners are obliged to retain verification and transaction records for the periods prescribed by anti-money-laundering law (commonly five to ten years) and may be required to report to supervisory authorities or financial intelligence units. We have no influence on these processes. Please read the privacy policy of the Service Partner handling your request; it is referenced in the request details and in the partner's own interface.
5. Other recipients
- Hosting and database providers in the EU/US (Vercel Inc., Neon Inc.) – processors acting on our instructions under data-processing agreements.
- E-mail delivery provider (Resend Inc., US) – processor for sending and tracking transactional and marketing e-mails.
- Market-data provider (CoinGecko) – receives no personal data; we only fetch public prices.
- Messaging service used for internal admin alerts about new requests (Telegram) – receives the request reference and amounts only.
- Authorities, courts or legal advisers where we are legally obliged or entitled to disclose data.
Where providers are located outside the EEA, transfers are based on EU Standard Contractual Clauses or an adequacy decision (such as the EU-US Data Privacy Framework).
6. Cookies and analytics
The Software uses only strictly necessary cookies: a session cookie that keeps you signed in and, where you arrived via a partner link, a short-lived referral cookie. No advertising or third-party tracking cookies are set.
Our usage analytics are first-party and cookieless. A random identifier is stored in your browser's local storage, your IP address is not stored, and bots are excluded. You can disable analytics in your browser by blocking local storage or using a content blocker; the Software continues to work.
7. Retention
- Account and profile data: for the life of your account and up to 10 years thereafter where needed to comply with legal obligations or defend claims.
- Request data: at least as long as required for commercial and anti-money-laundering record-keeping (typically 5–10 years).
- Support tickets: 3 years after closure.
- E-mail logs: 2 years.
- Usage analytics: 13 months.
- Blocklist fingerprints: until the block is lifted.
8. Your rights
You have the right to access your data, to rectification, to erasure (where no retention duty applies), to restriction of processing, to data portability and to object to processing based on legitimate interest, including direct marketing. You can exercise these rights through the support function in the application. You also have the right to lodge a complaint with a supervisory authority – in Malta the Information and Data Protection Commissioner (idpc.org.mt) – or the authority of your place of residence.
For data processed by a Service Partner (in particular verification documents and transaction records) you must address the respective Service Partner directly; we can only help you identify which partner handled your request.
9. Security
All traffic is encrypted (TLS). Passwords are stored as salted hashes. Access to production data is restricted to authorised staff. Bank and wallet details are stored only as entered by you and are shown back to you in the application; we recommend enabling the security features of your e-mail account, since it protects access to your account.
10. Changes
We may update this policy. The current version with its date is always published here. Last updated: 8 October 2026.
