Skip to main content

๐Ÿ›ก๏ธ Privacy Policy


โœ… SEC CATEGORY 1 COMPLIANT | Issuer-Sponsored Tokenized Securities pursuant to SEC Division of Corporation Finance, Division of Investment Management, and Division of Trading and Markets Joint Statement dated January 28, 2026


๐Ÿ›ก๏ธ Our Commitment to Your Privacy

At OTCM Protocol, Inc., we are serious about protecting your privacy while maintaining compliance with federal securities laws and Category 1 regulatory requirements. You don't have to take our word for it thoughโ€”you can read below to understand how we treat your Personal Data.


โœ… Your Agreement

When you use our Services, we require that you:

Requirement

Description

๐Ÿ“‹

Acknowledge

Acknowledge and agree to our Privacy Policy

๐Ÿค

Understand

Understand and consent to our Privacy Policy

โœ…

Accept

Accept that we will collect, use, and share information as outlined below

โš–๏ธ

Regulatory Consent

Consent to data collection required for Category 1 compliance, KYC/AML, and accredited investor verification


Remember that your use of our Website and Services are subject to:

  • ๐Ÿ“‹ Our Terms of Use
  • ๐Ÿ“‹ Our Terms of Service (which incorporates this Privacy Policy)
  • ๐Ÿ“‹ Our Risk Disclosure
  • ๐Ÿ“‹ Our Cookie Notice

Note: Capitalized terms in this Policy have the definitions given to them in the Terms of Use and Terms of Service, unless first defined in this Policy.


๐ŸŽฏ Why We Have A Privacy Policy (And What It Covers)

๐Ÿ’ก Purpose

Our Privacy Policy helps you understand:

Topic

Description

๐Ÿ”

Collection & Use

Our collection and use of information

โš–๏ธ

Your Rights

Your rights regarding your data

๐Ÿ›๏ธ

Regulatory Requirements

How Category 1 compliance affects data handling


๐Ÿ›ก๏ธ Coverage

Our Privacy Policy covers how we treat Personal Data that we gather when you access or use our Services.

โš–๏ธ Special Notice: Category 1 Compliance Data

OTCM Protocol operates SEC Category 1 compliant infrastructure for tokenized securities. This requires collection and retention of certain data for regulatory compliance purposes, including:

Data Category

Regulatory Purpose

๐Ÿชช

KYC Data

Know Your Customer verification required by Bank Secrecy Act

๐Ÿ’ฐ

Accreditation Data

Accredited investor verification required by SEC Rule 506(c)

๐Ÿšซ

OFAC Screening Data

Sanctions compliance required by U.S. Treasury

๐Ÿ“Š

Transaction Records

Securities transaction records required by federal securities laws

๐Ÿฆ

Custody Records

Records coordination with SEC-registered transfer agent

โš ๏ธ Important: Certain data collection is mandatory for Category 1 compliance. You cannot use ST22 Tokenized Securities services without providing required KYC and accreditation verification data.


๐Ÿข Third Party Data

If your Personal Data is lawfully given to any company that we don't own or control, or to people we don't directly oversee, then their privacy policy applies, not this Privacy Policy.

๐Ÿฆ Key Third-Party Data Sharing (Category 1 Requirements)

Third Party

Data Shared

Purpose

๐Ÿฆ

Empire Stock Transfer

Identity, ownership records

SEC-registered transfer agent for custody and shareholder registry

๐Ÿ”

KYC/AML Providers

Identity verification data

Regulatory compliance verification

๐Ÿ“Š

Accreditation Verification

Financial qualification data

SEC Rule 506(c) compliance

๐Ÿšซ

OFAC Screening Services

Identity data

Sanctions compliance

๐Ÿ›๏ธ

Regulatory Bodies

As required by law

SEC, FinCEN, and other regulatory reporting


๐Ÿ“‹ Key Areas We'll Cover

Section

Topic

๐Ÿ“ฅ

How we obtain your Personal Data

๐Ÿ“Š

The types of Personal Data we collect

๐Ÿ”ง

How we use your Personal Data

๐Ÿค

Sharing your Personal Data

โš–๏ธ

Your rights with respect to your Personal Data

๐Ÿ›๏ธ

Category 1 regulatory data requirements


๐Ÿšจ Questions or Concerns?

If any part of this Privacy Policy is unclear or if you believe your Personal Data is being misused, please contact us immediately so we can investigate and remedy the situation.

Contact: privacy@otcm.io


โ›“๏ธ Blockchain Transparency Notice

Please understand that our Services utilize Solana blockchain smart contract technology for Category 1 compliant tokenized securities trading.

๐Ÿ“Š What Is Public on Blockchain

Data Type

Visibility

Notes

๐Ÿ”—

Wallet Addresses

Public

Visible on Solana blockchain

๐Ÿ’ฐ

Transaction History

Public

All ST22 and OTCM token transfers visible

๐Ÿ“Š

Token Balances

Public

Holdings visible at wallet level

๐Ÿชช

Identity Data

Private

NOT stored on blockchain

๐Ÿ“‹

KYC/Accreditation

Private

Stored off-chain with compliance providers

โš ๏ธ Privacy Limitation: Blockchain transactions are permanent and public. While we do not publish your identity on-chain, sophisticated analysis may potentially link wallet addresses to identities. We take reasonable steps to protect your privacy, but blockchain transparency is inherent to the technology.


๐Ÿ“ฅ Here Is How We Gather Personal Data

๐ŸŽฏ Primary Collection Methods

For our Services, we obtain your Personal Data through multiple channels:

1. ๐Ÿ‘ค Directly From You

As a user, you will:

Action

Data Collected

โœ…

Account Creation

Name, email, contact information

๐Ÿชช

KYC Verification

Government ID, address verification, date of birth

๐Ÿ’ฐ

Accreditation Verification

Financial documentation (for ST22 securities)

๐Ÿ’ณ

Payment Information

Payment details for minting fees

๐Ÿ“Š

Service Usage

Additional data as you use our Services

2. ๐Ÿฆ From Third Parties (Category 1 Requirements)

Third Party

Data Received

Purpose

๐Ÿฆ

Empire Stock Transfer

Custody confirmations, shareholder records

Category 1 custody verification

๐Ÿ”

KYC Providers

Verification results

Identity confirmation

๐Ÿ“Š

Accreditation Services

Verification status

SEC Rule 506(c) compliance

๐Ÿšซ

OFAC Screening

Sanctions check results

Compliance verification

๐Ÿ“ˆ

Analytics Providers

Usage patterns

Service improvement

3. โ›“๏ธ From Blockchain

Data Type

Collection Method

๐Ÿ”—

Wallet Addresses

When you connect wallet to platform

๐Ÿ’ฐ

Transaction History

Public blockchain data

๐Ÿ“Š

Token Holdings

Public blockchain data


๐Ÿช We Automatically Collect Certain Information

When you use our Services, you will be shown a cookie disclosure with details on:

Information

Description

๐Ÿช

Cookie Types

What cookies/pixels/tags we use

๐ŸŽฏ

Purposes

Purposes for each type

โš™๏ธ

Management

How to control cookie preferences


๐Ÿ”ง Tracking Technologies

Our Site may use Cookies or similar methods:

Technology

Purpose

๐Ÿช

Session Cookies

Maintain login state

๐Ÿ“Š

Analytics Cookies

Understand usage patterns

๐Ÿ”

Security Cookies

Fraud prevention

๐ŸŽฏ

Preference Cookies

Remember your settings

๐ŸŽฏ Purpose of Cookies

These Cookies help us:

  • ๐Ÿ” Recognize you (your web browser, phone, etc.)
  • ๐Ÿ“Š Understand how and when you visit the Site
  • ๐Ÿ“ˆ Analyze trends to learn and improve our Services
  • ๐Ÿ” Maintain security and prevent fraud
  • โš–๏ธ Support Category 1 compliance monitoring

๐Ÿšซ "Do Not Track" Limitations

Browser Setting

Our Response

๐Ÿšซ

DNT Signal

We honor DNT signals where technically feasible

โš ๏ธ

Limitations

Some tracking required for Category 1 compliance cannot be disabled


Option

Description

๐Ÿ”ง

Browser Settings

Accept/reject Cookies through browser settings

๐Ÿ—‘๏ธ

Delete Cookies

Delete existing Cookies on your device

โš ๏ธ

Functionality Impact

Some functions may not work if you disable Cookies

๐Ÿ”„

Preference Reset

Preferences may need readjustment when you visit

๐Ÿ“š Learn More: Visit AllAboutCookies.org for comprehensive cookie information.


๐Ÿ“Š This Is The Kind of Personal Data We Collect

๐Ÿ‘ค Information That Identifies You Personally

Standard Personal Data

Data Type

Purpose

๐Ÿ“›

Full Name

Account identification, regulatory compliance

๐Ÿ“ฌ

Addresses

Mail, billing, and email addresses

๐ŸŒ

Online Identifiers

Usernames, wallet addresses

๐ŸŒ

IP Address

Security, geolocation compliance

๐Ÿ“ฑ

Phone Number

Account security, communications

Category 1 Compliance Data (Required for ST22 Securities)

Data Type

Purpose

Regulatory Basis

๐Ÿชช

Government ID

KYC verification

Bank Secrecy Act

๐Ÿ“…

Date of Birth

Identity verification, age compliance

BSA, securities laws

๐Ÿ 

Residential Address

Identity verification, jurisdiction compliance

SEC regulations

๐Ÿ’ฐ

Financial Information

Accredited investor verification

SEC Rule 506(c)

๐Ÿ“Š

Tax Identification

Tax reporting, regulatory compliance

IRS requirements

๐Ÿข

Employment Information

Accreditation verification

SEC Rule 501

๐Ÿ’Ž

Net Worth Documentation

Accreditation verification

SEC Rule 501

โš ๏ธ Mandatory Collection: Category 1 compliance requires collection of KYC and accreditation data. This data collection is not optional for ST22 Tokenized Securities services.


๐Ÿ“‹ Customer and User Records

Information that may include customer and user records identified by applicable law:

Record Type

Contents

๐Ÿ“

Account Records

Registration data, preferences

๐Ÿ’ฐ

Transaction Records

ST22 and OTCM token transactions

๐Ÿฆ

Custody Records

Empire Stock Transfer coordination

โš–๏ธ

Compliance Records

KYC/AML verification, accreditation status

๐Ÿ“ง

Communication Records

Support requests, correspondence


๐ŸŒ Internet Activity Information

Data Type

Purpose

๐Ÿ”

Browsing History

Site usage analysis (on our platform only)

๐Ÿ’ป

Interaction Data

How you use our Services

๐Ÿ“Š

Trading Activity

Transaction patterns for compliance monitoring

๐Ÿ”

Security Events

Login attempts, security alerts


๐ŸŽฏ Collection Philosophy

We collect information that we believe is necessary to:

Purpose

Description

๐Ÿ–ฅ๏ธ

Functionality

Make the Site render and work well for you

โšก

User Experience

Make your use of Services faster, easier, and more intuitive

๐Ÿš€

Improvement

Improve and expand our Services

โš–๏ธ

Compliance

Meet Category 1 regulatory requirements

๐Ÿ›ก๏ธ

Security

Protect against fraud and unauthorized access

โš ๏ธ Without this information: Services will not be possible, and Category 1 compliance cannot be maintained.


๐Ÿ”ง How We Use Your Personal Data

Nearly all Personal Data we collect is used to manage, improve, understand, personalize our Services, and maintain Category 1 compliance.

๐ŸŽฏ We Use Personal Data To:

Service Delivery

Use

Description

โœ…

Purpose Fulfillment

Accomplish a purpose when you provide Personal Data

๐Ÿ› ๏ธ

Service Provision

Provide our Services and respond to your requests

๐Ÿ’ฐ

Transaction Processing

Process ST22 and OTCM token transactions

๐Ÿฆ

Custody Coordination

Coordinate with Empire Stock Transfer

Category 1 Compliance (Required)

Use

Regulatory Basis

๐Ÿชช

KYC Verification

Bank Secrecy Act, AML requirements

๐Ÿ’ฐ

Accreditation Verification

SEC Rule 506(c)

๐Ÿšซ

OFAC Screening

U.S. Treasury sanctions requirements

๐Ÿ“Š

Transaction Monitoring

Securities law compliance

๐Ÿ›๏ธ

Regulatory Reporting

SEC, FinCEN reporting obligations

๐Ÿ“‹

Record Keeping

Securities transaction record requirements

Communication

Use

Description

๐Ÿ“ง

Service Communications

Communicate about Services based on your preferences

โœ…

Confirmations

Send transaction confirmations

๐Ÿ“จ

Updates

Email you about your use of the Services

๐Ÿšจ

Security Alerts

Notify you of security-related events

Support & Personalization

Use

Description

๐Ÿค

Support

Offer and provide support for the Services

๐ŸŽจ

Personalization

Personalize the content on our Site

๐Ÿ“‹

Requests

Fulfill requests and respond to questions

Improvement & Development

Use

Description

๐Ÿ”ฌ

Research

Test, research, analyze and develop the Service

๐Ÿš€

New Features

Offer new Services and make the Site better

Security & Compliance

Use

Description

๐Ÿ›ก๏ธ

Fraud Prevention

Deter and stop illegal, fraudulent, and other damaging actions

๐Ÿ”

Security

Maintain safety, security and integrity of the Site and Services

โš–๏ธ

Policy Enforcement

Ensure compliance with obligations and enforce company policies

๐Ÿ›๏ธ

Legal Compliance

Interact with governmental and law enforcement as required by law


๐Ÿ”„ New Uses

We may need to use your previously-collected Personal Data for new purposes consistent with our Services and their evolution. When this happens, we will inform you before we start (except where required by law or Category 1 compliance).


๐Ÿ“ง Communication Preferences

Don't want to receive marketing communications from us?

Method

Instructions

๐Ÿ“ฑ

Email Opt-Out

Use the opt-out link provided in emails

๐Ÿ“ง

Contact Us

Email your preference to: privacy@otcm.io

โš ๏ธ Note: You cannot opt out of transactional or compliance-related communications required for Category 1 operations.


๐Ÿค How We Share Your Personal Data

๐Ÿ’ฐ Not for Monetary Gain

We are NOT in the business of sharing your Personal Data for monetary gain.

We do need to perform and improve our Services and maintain Category 1 compliance, which requires sharing your Personal Data with:


๐Ÿ›๏ธ Regulatory and Compliance Sharing (Required)

Recipient

Data Shared

Purpose

๐Ÿฆ

Empire Stock Transfer

Identity, ownership records

SEC-registered transfer agent custody

๐Ÿ›๏ธ

SEC

As required by law

Securities law compliance

๐Ÿ’ต

FinCEN

SAR/CTR filings as required

Bank Secrecy Act compliance

๐Ÿšซ

OFAC

Screening data

Sanctions compliance

๐Ÿ‘ฎ

Law Enforcement

As required by law

Legal obligations

โš ๏ธ Mandatory Sharing: Category 1 compliance requires sharing certain data with regulatory bodies and Empire Stock Transfer. This sharing is not optional.


๐Ÿข Service Providers

Provider Type

Purpose

๐Ÿ’ณ

Payment Processors

Process payments for minting fees

๐Ÿ›ก๏ธ

Security Providers

Maintain platform security

๐Ÿ’ป

Technology/Hosting

Infrastructure services

๐Ÿ“Š

Analytics Providers

Usage analysis

๐Ÿ”

KYC/AML Providers

Identity verification

๐Ÿ’ฐ

Accreditation Verification

SEC Rule 506(c) compliance


๐Ÿ” Compliance & Security

Recipient

Purpose

๐Ÿ“‹

Auditors

Maintain compliance and security

๐Ÿšจ

Security Services

Detect security issues and fraud

๐Ÿ›ก๏ธ

Fraud Prevention

Protect against illegal or improper activity


๐Ÿ”ฌ Research & Development

Recipient

Purpose

๐Ÿงช

Internal Research

Technological development

๐Ÿ›

Debug Services

Repair errors on the Site or Services


๐Ÿ“ž Customer Service

Recipient

Purpose

๐Ÿค

Customer Care

Customer support services

๐Ÿ“ฆ

Order Processing

Transaction fulfillment


๐ŸŒ Public & Transaction Information

Others may access your Personal Data if you:

Action

Consequence

๐Ÿ“ข

Post Publicly

Information becomes public

๐Ÿ’ฐ

Complete Transactions

Transaction data recorded on blockchain (public)

๐Ÿค

Access Third Parties

Their privacy policies control

โš ๏ธ Blockchain Transparency: ST22 and OTCM token transactions are recorded on the Solana blockchain and are publicly visible. While your identity is not directly published, wallet addresses and transaction history are public.


๐Ÿข Corporate Changes

Your Personal Data may be transferred through:

Event

Handling

๐Ÿค

Merger/Acquisition

Data transfers to acquiring entity

๐Ÿ’”

Bankruptcy

Data may be transferred as asset

๐Ÿ’ฐ

Asset Sale

Data may be included in sale

We will notify you of any such transfer and your options.


๐Ÿ›ก๏ธ Data Security and Retention

๐Ÿ” Security Measures

We employ safeguards designed to protect Personal Data:

Safeguard Type

Examples

๐Ÿ”ง

Technical

Encryption, access controls, monitoring

๐Ÿข

Organizational

Employee training, access policies

๐Ÿ—๏ธ

Physical

Secure facilities, device security


โš ๏ธ Security Disclaimer

๐Ÿšจ NO SYSTEM IS 100% SECURE

Despite our security measures, we cannot guarantee absolute security.
You are responsible for:
โ€ข Maintaining security of your wallet and private keys
โ€ข Using strong, unique passwords
โ€ข Protecting your devices from unauthorized access
โ€ข Reporting any suspected security breaches immediately

๐Ÿ“… Data Retention

Category 1 Compliance Retention Requirements

Data Type

Retention Period

Regulatory Basis

๐Ÿชช

KYC Records

5 years after account closure

Bank Secrecy Act

๐Ÿ’ฐ

Transaction Records

7 years

Securities laws, IRS requirements

๐Ÿ“Š

Accreditation Records

5 years

SEC Rule 506(c)

๐Ÿšซ

OFAC Screening

5 years

Treasury requirements

๐Ÿ“ง

Communications

3 years

Business records

โš ๏ธ Regulatory Retention: We are required by law to retain certain records for specified periods. Deletion requests cannot override regulatory retention requirements.


๐ŸŒ Personal Data Use/Storage

๐Ÿ—บ๏ธ Global Processing

Your Personal Data may be used, hosted, or otherwise processed outside of your home jurisdiction in jurisdiction(s) that may not provide equivalent levels of protection, including the United States.

Processing Location

Safeguards

๐Ÿ‡บ๐Ÿ‡ธ

United States

Primary processing location

๐ŸŒ

Other Jurisdictions

Standard contractual clauses where applicable


๐Ÿ‘ถ Personal Data of Children

๐Ÿšซ Age Restrictions

Requirement

Description

โŒ

No Minors

We do not offer our Services to children

๐Ÿšซ

No Collection

We do not knowingly collect Personal Data from anyone under 18

โš–๏ธ

Accredited Investors

ST22 securities require accredited investor status (adults only)

๐Ÿ—‘๏ธ Data Deletion Policy

If we discover Personal Data from a child under 18:

Action

Timeline

๐Ÿšจ

Deletion

We will delete it as quickly as possible

๐Ÿ“ง

Contact

If you believe a child under 18 has given us Personal Data, contact us at privacy@otcm.io


โš–๏ธ Privacy Rights In Certain Jurisdictions

๐Ÿ›๏ธ Consumer Data Protection Laws

Certain jurisdictions have enacted laws to protect and empower consumers with respect to their data and Personal Data.

๐Ÿ‡บ๐Ÿ‡ธ California Residents (CCPA/CPRA)

California residents have specific rights:

Right

Description

๐Ÿ”

Right to Know

Request disclosure of Personal Data collected

๐Ÿ—‘๏ธ

Right to Delete

Request deletion of Personal Data (subject to exceptions)

๐Ÿšซ

Right to Opt-Out

Opt-out of sale/sharing of Personal Data

โœ๏ธ

Right to Correct

Request correction of inaccurate Personal Data

โš–๏ธ

Non-Discrimination

Not be discriminated against for exercising rights

โš ๏ธ Limitations: Category 1 regulatory retention requirements may limit deletion rights.

๐ŸŒ Other Jurisdictions

You may have additional rights based on your residency. Contact privacy@otcm.io for jurisdiction-specific information.


๐Ÿ”„ Changes to this Privacy Policy

๐Ÿ“ Updates May Occur

From time to time, we may need to change how we use your Personal Data due to:

Reason

Description

โš–๏ธ

Legal Changes

Applicable laws and regulations

๐Ÿ›๏ธ

Regulatory Updates

Category 1 compliance requirements

๐Ÿš€

Service Evolution

Better performance of our Services


๐Ÿ“ข Notification Process

If changes happen, we will:

Action

Method

๐Ÿ”„

Update Policy

Update this Privacy Policy

๐Ÿšจ

Alert You

Place notice on the Site and/or send email

๐Ÿ“…

Effective Date

Clearly indicate when changes take effect


โœ… Continued Use = Agreement

We use Personal Data according to the Privacy Policy effective at the time that information is collected. Continued use after policy updates constitutes acceptance.


๐Ÿ“ž Contact Information

๐Ÿค Questions or Comments?

If you have any questions or comments about:

Topic

Contact

๐Ÿ”’

Your Personal Data

privacy@otcm.io

๐Ÿ›ก๏ธ

Your Privacy

privacy@otcm.io

๐Ÿ“‹

Our Privacy Policy

privacy@otcm.io

โš–๏ธ

Your Rights

privacy@otcm.io

๐Ÿ›๏ธ

Category 1 Compliance

compliance@otcm.io

Mailing Address:

OTCM Protocol, Inc.
Attn: Privacy Officer
[Address]
Wyoming, United States

๐Ÿ“‹ Document Information

Field

Value

๐Ÿ“„

Document Version

3.0

๐Ÿ“…

Effective Date

January 2026

๐Ÿ“

Jurisdiction

Wyoming, United States

โš–๏ธ

Governing Law

Wyoming State Law and Federal Law

๐Ÿ›๏ธ

Regulatory Framework

SEC Category 1 (Issuer-Sponsored Tokenized Securities)


๐Ÿ›ก๏ธ Your Privacy Matters โ€” We're committed to protecting your personal information while maintaining Category 1 compliance and providing you with the best possible service experience.


ยฉ 2026 OTCM Protocol, Inc. | All Rights Reserved

ST22 Tokenized Securities are securities under federal securities laws. Category 1 compliance requires collection and retention of certain personal data as described in this Privacy Policy.