Privacy Policy

1. Controller and contact

kiosk.cash is the data controller for the processing described here. Our registered entity, address and company number are shown in the footer of our website and on your order confirmation. Privacy questions and rights requests: privacy@kiosk.cash. If we have appointed a Data Protection Officer, their contact details are published on the same page.

2. Data we collect

You give us: the payout method you choose; your refund wallet address; the delivery address and phone number if you request cash delivery; your account name, IBAN and BIC if you request a bank transfer; your name and email if you supply them; and identity documents where our AML rules require them.

Created by the service: your order ID, the collection PIN (stored only as a one-way hash, never in readable form), amounts, exchange rate, fee, the deposit address issued to you, order status history, and which member of staff or which courier handled each step.

Collected automatically: IP address, browser and device information, timestamps, and security logs including failed PIN and failed login attempts.

At the counter: where a payout requires identification, staff record the document type and number and the name shown on it. Some kiosks operate CCTV under separate signage.

3. Why we process it, and on what legal basis

To perform your order (Article 6(1)(b) GDPR): pricing, issuing a deposit address, tracking payment, arranging your payout and handling refunds.

To meet legal obligations (Article 6(1)(c)): anti-money-laundering identification and record-keeping, sanctions screening, tax and accounting records, and responding to lawful requests from authorities.

For our legitimate interests (Article 6(1)(f)): preventing fraud and theft, securing the platform and our cash, investigating disputes, and improving the service. We balance these against your rights and use the least intrusive option that works.

With your consent (Article 6(1)(a)): optional email updates. You may withdraw consent at any time without affecting processing already carried out.

Identity documents are handled under Article 9 conditions only where applicable law requires or permits it for AML purposes.

4. Automated decisions

Some checks run automatically: a KYC document may be required above a euro threshold, an order may be held after repeated incorrect PIN entries, and orders may be blocked where cash is insufficient or a limit is exceeded. These do not produce legal effects on you without human involvement, and a member of staff reviews any held order. You may ask for a human review of any automated outcome.

5. Who we share it with

We do not sell personal data and we do not use it for advertising. We share it with: our own kiosk staff and couriers, limited to the countries and orders they are assigned to; our hosting and infrastructure providers, acting as processors under contract; banks and payment providers where you choose a bank payout; our price data provider, which receives no personal data; professional advisers under a duty of confidentiality; and supervisory authorities, financial intelligence units, law enforcement or courts where we are legally required to disclose.

If we are legally required to report a transaction, we may be prohibited from telling you.

6. International transfers

We aim to keep personal data within the European Economic Area. Where a provider processes data outside the EEA, we rely on an adequacy decision or on Standard Contractual Clauses with additional safeguards. Details are available on request.

7. How long we keep it

Identification records and transaction records are kept for the period required by the anti-money-laundering law applying to each branch, generally five years after the transaction or the end of the relationship, and longer only where an authority requires it. Accounting records follow national tax periods. Security and access logs are kept for a shorter operational period. Order records that never resulted in a transaction are kept for a limited period for fraud prevention, then deleted or anonymised. CCTV retention is set out on the notice displayed at each kiosk.

8. Security

Access to the staff and admin systems requires a passkey. Staff can only reach orders in the countries assigned to them. Collection PINs and staff credentials are stored as one-way hashes. Identity documents are stored outside the public web directory and access to them is logged. Data is served over HTTPS. No system is perfectly secure, and we will notify you and the relevant supervisory authority of a personal data breach where the law requires it.

9. Your rights

Where the GDPR applies you may request access to your data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Some rights are limited: we cannot delete records that AML law requires us to retain, and we cannot alter a completed blockchain transaction. We will respond within one month, extendable by two further months for complex requests.

You may complain to your local supervisory authority, or to the authority in the country where the branch you dealt with is established.

10. Cookies and tracking

We use a session cookie that is strictly necessary to keep you signed in and to remember that you have entered your order PIN. We do not use advertising or cross-site tracking cookies. Local browser storage is used only to keep your order visible while you are on the page.

11. Children

The service is not available to anyone under 18 and we do not knowingly collect data from children. If you believe we hold such data, contact us and we will delete it.

12. Changes

We may update this policy. The date below shows the current version, and material changes will be notified on the site before they take effect.