Monra Privacy Policy

Version: 2026-09-22

This Policy explains how Monra, Inc., a Delaware corporation, handles personal information for its websites, application, wallets, payment tools and support. Contact us at hello@monra.global.

1. Whose information this covers and who is responsible

This Policy covers users, business representatives and beneficial owners, recipients, clients, invoice contacts, payment-link participants, visitors and people contacting support, including people whose information another user supplies.

Monra determines how information is used to administer accounts, operate its application, maintain its transaction records, provide support and protect the service. For those activities, Monra is the controller under applicable data-protection law. A business supplying information about its clients or employees has its own responsibilities; any processing Monra performs solely on that business's instructions is governed by the applicable processing arrangement.

Bridge and its applicable affiliates and financial partners determine how information is used for their regulated financial services, verification, compliance and transaction decisions. They act as controllers for those activities. Bridge's European notice also describes processing performed on a partner's instructions; roles depend on the particular activity and applicable agreement, not just the provider's name.

Coinbase Developer Platform (CDP) supplies authentication and wallet infrastructure. Its developer terms provide for Coinbase to act as processor for specified end-user data under applicable data-protection laws. Coinbase and other providers may also have their own controller activities. Their notices are linked in Provider Terms and Disclosures.

2. Information we handle

Depending on the features used, information includes:

  • Account and business information: names, email, country, account type, business name, MonraTag, account identifiers and information about representatives, ownership or authority supplied to us.
  • Verification information: Bridge customer identifiers, verification status, requested steps, endorsements, restrictions, rejection categories and related customer/compliance information received from Bridge. Identity documents are normally supplied through Bridge-hosted verification; Monra also receives customer and transaction data through provider messages and webhooks.
  • Wallet and transaction information: wallet addresses, networks, balances, public transactions, transaction hashes, amounts, assets, currencies, bank and virtual-account details, counterparties, payment references, fees, rates, receipts, source-of-funds information supplied to us, returns and errors.
  • Invoice, recipient and payment-link information: names, contact details, addresses, tax identifiers, bank/wallet details, line items, descriptions, notes, payment terms and status supplied by users or counterparties.
  • Support information: messages, attachments, complaints, requests and correspondence.
  • Device and security information: IP addresses, browser/device information, authentication and security events, PIN/MFA status, logs, errors and browser storage used by the service.
  • Agreement and authorisation information: records of notices and acknowledgments, provider agreement identifiers, and wallet-delegation and key-export records. The fields depend on the particular acceptance or authorisation flow.

Monra does not receive the raw CDP wallet private key displayed in Coinbase's isolated key-export experience. Funded payment links use a different key: Monra generates and stores an encrypted link-specific claim key and uses it to authorise claims. That key is associated with the funded-link transaction; it is not the user's CDP wallet private key.

3. Where information comes from

We obtain information from you, your organisation, other users and transaction participants; through authentication, infrastructure and support providers; from Bridge and its partners; from public blockchains; and through your device and use of Monra.

Creating a Monra account sends account details, including name or business name, email and account type, to Bridge to initiate its customer/verification process. Wallet addresses are registered with Alchemy for transaction monitoring. This can happen before you open or complete Bridge verification, including if you initially use only wallet features. We also send transaction instructions, relevant beneficiary details and wallet-ownership attestations where required.

Bridge independently collects information for its services, potentially including identity documents, financial records, source-of-funds information, device/location signals and public-record information. Its collection is described in its own notice; Monra does not claim to receive everything Bridge collects.

5. Automated checks and review

Monra automatically checks matters such as verification status, provider endorsements, balances, transaction parameters and security conditions. A failed check can prevent a feature or transaction. Bridge makes its own underlying verification and compliance decisions. Coinbase applies screening within its wallet services; this does not mean Bridge verifies every Monra user or processes every on-chain transfer.

Bridge may use automated systems for verification, sanctions, fraud, transaction authorisation and anti-money-laundering controls. Where applicable law gives rights concerning a solely automated decision with legal or similarly significant effects, you may request an explanation, human review and an opportunity to contest it. Contact hello@monra.global for all review requests, including those concerning Bridge decisions. Monra will coordinate the request with the relevant provider and communicate with you, but cannot override provider decisions.

6. Recipients and sharing

We disclose information as needed for the purposes above to:

  • Bridge and its relevant affiliates/financial partners: verification, financial services, compliance, transaction processing and support.
  • Coinbase CDP: authentication and user-controlled wallet infrastructure.
  • AWS, including SES: hosting, databases, storage, encryption services, logging, queues and email delivery.
  • Alchemy: blockchain access and wallet/transaction monitoring.
  • Crisp: customer-support messaging.
  • Google: authentication and address-related features when used.
  • Banks, payment networks and transaction counterparties: payment instructions, recipient details, receipts, compliance and dispute information. Network rules may require transaction, directory and fraud-related data to be shared with network operators.
  • Professional advisers, authorities and others where necessary: legal/accounting advice, lawful requests, protection of rights or investigation of misconduct.
  • Parties to a proposed corporate transaction: due diligence or a merger, financing or sale, subject to appropriate confidentiality and applicable law.

Public blockchain transactions can be viewed by anyone. People possessing an invoice or payment link may be able to view its contents. Avoid including unnecessary sensitive information.

Monra does not sell personal information or share it for cross-context behavioural advertising. This describes Monra, not Bridge's separate activities. Bridge's US and rest-of-world notices describe its own marketing and advertising practices.

7. Processing locations and international transfers

Monra is a US corporation. Its production infrastructure and databases are hosted on AWS in London, United Kingdom. Personnel access personal information from Serbia, Lithuania and France. Providers may process information in other countries under their own service arrangements; AWS London does not mean all processing occurs only in the UK.

Data-protection rules differ between countries. Where a transfer is restricted by applicable law, it requires a valid transfer basis. Depending on the recipient and route, this can be an applicable adequacy decision or contractual safeguards such as EU standard contractual clauses and applicable UK transfer safeguards. AWS and Coinbase publish data-processing and transfer provisions for their services; those do not, by themselves, cover every Monra data-access or provider arrangement.

Contact hello@monra.global for information about the safeguards applicable to your information or to request a copy of relevant safeguards, subject to lawful redactions.

8. Retention and deletion

Retention depends on the purpose and applicable requirements, rather than one period for every record:

  • Account/profile records are needed while an account is active and may be needed afterwards to handle closure, disputes or applicable legal duties.
  • Transaction, invoice, agreement and compliance-related records may need to be kept for accounting, tax, provider-contract or legal-claim purposes.
  • Support and security records may be needed to resolve requests, investigate incidents and protect legal rights.
  • Temporary signup and browser information serves the relevant authentication, security or operational purpose.

A deletion request is assessed against these purposes, legal holds and applicable requirements. Deleting an account does not mean every related record is immediately erased, including residual backup copies. We do not promise a fixed automatic deletion date for all systems.

Monra cannot erase public blockchain history. Bridge and other independent controllers apply their own retention requirements; a request to Monra does not automatically delete their records.

9. Cookies, browser storage and support

Monra and its providers use browser storage for authentication, security, signup continuity, wallet operations, pending transactions, preferences and support. Not all storage labelled functional is necessarily exempt from consent requirements.

Crisp loads after your authenticated Monra profile loads, not only when you open chat. It receives your email, display name, account type, country, environment and a support-session identifier to connect your support conversation.

Monra does not use advertising pixels, session-replay tools or non-essential analytics integrations. Browser settings can block or remove storage, but some features may then stop working. Where consent is legally required for a storage purpose, it must be obtained before that storage is used; this Policy is not that consent.

10. Security

Monra uses application access controls, provider security features, encryption or hashing for appropriate data and security logging. No system is completely secure, and this is not a guarantee that every data field is encrypted or that loss or unauthorised access cannot occur. Protect your devices, login details, MFA methods and exported keys, and report suspected compromise promptly.

11. Your rights

Depending on applicable law, you may have rights to access, correct, delete or obtain a portable copy of information; restrict or object to processing; withdraw consent; obtain safeguards for qualifying automated decisions; opt out of sale, targeted advertising or qualifying profiling; limit certain sensitive-data uses; appeal a denial; and complain to a regulator.

Email hello@monra.global with your request. We may reasonably verify identity and authority, including for an authorised agent. Do not send passwords, private keys or unnecessary identity documents. We will explain applicable limitations and respond within the period required by law. You may request an appeal by replying with “Privacy Appeal.” We do not discriminate against you for exercising applicable rights.

EEA/UK individuals may complain to the competent supervisory authority, including where they live, work or believe an infringement occurred. Send requests relating to provider processing to Monra; we will coordinate them with the relevant controller. That controller remains responsible for its processing and response. This support arrangement does not restrict your statutory rights.

If another Monra user supplied your information, you may contact us about Monra's processing and that user about their own use of your information.

12. Age, changes and contact

Monra accounts are for people aged 18 or older. Contact us if you believe an underage person has improperly supplied account information.

We may update this Policy and will give prominent or advance notice where required. Changes that legally require consent will be addressed separately rather than inferred from continued use.

Monra, Inc.
Registered-agent and correspondence address:
131 Continental Dr, Suite 305
Newark, DE 19713
United States

Support and privacy: hello@monra.global