This Privacy Policy explains how Gold Everywhere Inc. ("Gold Everywhere," "we," "us," or "our") collects, uses, shares, and protects information when you use the Gold Everywhere platform and related services (the "Platform"). We operate in two capacities. For Operators (bullion dealers, coin shops, and vault operators) who hold accounts with us, we act as a data controller. For the End Customers of those Operators, the Operator is the controller and we act as a data processor on the Operator's instructions. By using the Platform you agree to this Policy. If you do not agree, do not use the Platform.
1. Information We Collect
1.1 Account and Profile
Name, business name, email, phone, address, username, password (stored hashed, never in plain text), preferred locale, and role.
1.2 Authentication and Security
Login timestamps, IP addresses, device and browser data, approximate location derived from IP, MFA configuration, and new-device records.
1.3 Billing
Subscription and payment records. Card payments are handled by third-party processors; we do not store full card numbers. We may store partial card data (brand, last four), billing addresses, and transaction history.
1.4 Catalog, Inventory, and Orders
Product and SKU data, inventory, pricing and premiums, carts, orders, coupons, refunds, and fulfillment records.
1.5 Buy-Back Data
Sell-to-us quotes, item descriptions, quote validity, inspection results, and payout records entered by the Operator.
1.6 Vault, Safety Deposit Box, and Depositor Data
Holdings records, storage model (allocated or unallocated), box assignments, statements, audit records, and visit bookings, as entered by the Operator. We are the system of record only and do not take custody of stored metal.
1.7 CRM and Relationship Data
Contacts, accounts, communication history, notes, tags, and agent assignments managed by the Operator.
1.8 KYC and Identity Verification Data
Where an Operator enables verification: government-issued document images and extracted fields (name, date of birth, document type and number), verification status, and AML and sanctions screening results. See Sections 6 and 10.
1.9 Biometric Data
Where identity verification uses facial recognition, a facial scan may be processed to match a selfie to a document. See Section 6.
1.10 Market Data
Spot price feeds and historical chart data surfaced through the Platform. This is market information, not personal data.
1.11 Files, Analytics, AI, and Communications
Uploaded files and metadata; usage and page-view analytics; AI prompts, outputs, and usage logs where AI features are used; and email and SMS delivery records where messaging is used.
2. How We Use Information
- Operate, maintain, and improve the Platform.
- Process subscriptions and payments and maintain financial records.
- Run catalog, order, Buy-Back, booking, vault, and CRM features on behalf of Operators.
- Provide KYC, AML, and sanctions-screening tooling that Operators choose to enable.
- Send transactional and service messages such as verification, password resets, billing notices, and security alerts.
- Secure the Platform through logging, malware scanning, MFA, and rate limiting.
- Comply with legal and regulatory obligations.
- Analyze aggregated, de-identified usage to improve performance.
3. How We Share Information
We do not sell personal information. We share data only as needed to provide and secure the Platform, with the sub-processors named in Section 16: payment processors, spot-feed vendors, KYC/AML and sanctions-screening providers, email and SMS providers, AI providers, fulfillment and dropship partners, and cloud infrastructure and storage. Where an Operator connects Your Keys, data flows to that Operator's own chosen vendor. We may also disclose information when required by law, court order, subpoena, or valid legal process, or in connection with a merger, acquisition, or sale of assets, in which case we will provide notice.
4. Data Storage and Security
We use encryption in transit (TLS) and at rest. Passwords are hashed. Connected third-party keys and webhook secrets are encrypted. Access to production systems is least-privilege and logged. Uploaded files are scanned for malware. Identity documents are stored in restricted-access systems. Data is logically isolated per Operator. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. Report suspected vulnerabilities to security@goldeverywhere.com.
5. Data Retention
We retain active-account data for the life of the account. After account or site closure, data is retained for 90 days to allow recovery and export, then permanently deleted. Billing and transaction records are retained as required by tax law, typically up to 7 years. KYC and AML records are retained for the period required by applicable regulation, which may extend beyond account closure. Biometric data is retained only as long as needed to complete verification and is destroyed on the schedule described in Section 6. Operators may request earlier deletion, subject to legal holds and regulatory requirements.
6. Biometric Information
Where an Operator enables facial-recognition identity verification, a biometric identifier (a facial scan) may be collected and used solely to confirm that the person presenting an identity document is its rightful holder. We provide this notice, and Operators are responsible for obtaining the individual's written consent before any biometric capture, as required by laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington law. We do not sell, lease, or trade biometric data. Biometric identifiers are retained only for as long as needed to complete the verification and are then permanently destroyed, and in no case retained longer than required by applicable law. Raw facial-recognition templates are processed by the verification provider; we store the verification result and extracted document fields, not raw biometric templates.
7. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising). To exercise a right, contact privacy@goldeverywhere.com. We will verify your request and respond within the time required by applicable law. You may appeal a decision by replying to our response. We will not discriminate against you for exercising your rights.
7.1 United States State Rights
Residents of states with comprehensive privacy laws, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), among others, have the rights described above, including the right to know, access, correct, delete, and opt out of targeted advertising, sale, and certain profiling. Identity documents and biometric data are treated as sensitive data, which we process only for verification and with consent where required.
7.2 End Customers of Operators
If you are an End Customer of an Operator, please direct privacy requests to that Operator first, since they are the controller of your data. If you cannot reach the Operator, contact us and we will assist where we can.
7.3 Canada and Other Regions
As a Canadian company, we handle personal information in line with PIPEDA. Individuals outside the United States may have additional rights under their local law; contact us to exercise them.
8. Cookies and Tracking
We use essential cookies for authentication and session management and for cart identification. We use first-party, aggregated analytics. We do not run cross-site advertising trackers and do not use advertising cookies. Where an Operator enables optional analytics on its own site, that is disclosed in the Operator's own notice.
9. Children
The Platform is a business tool and is not directed to children under 16, and we do not knowingly collect their data. Operators whose sites may reach children are responsible for compliance with the Children's Online Privacy Protection Act (COPPA) and similar laws.
10. Identity Verification Data Practices
When an Operator enables verification, the individual submits documents through the verification provider's interface. The provider processes the documents and returns a result to the Platform by secure webhook. We store the verification type and status, extracted personal fields (name, date of birth, document type and number), and provider metadata. Verification results are advisory; the Operator makes the onboarding and approval decision. Individuals may request access to their verification records through the Operator or by contacting us, subject to AML record-keeping requirements.
11. AI Data Practices
Where AI features are used, prompts, business context, and existing content may be sent to the configured AI provider for processing, often using the Operator's own provider keys. AI usage is logged for billing and analytics. Please avoid submitting sensitive personal information in AI prompts. Each AI provider handles data under its own terms. Self-hosted AI processing, where used, stays on our infrastructure.
12. Automated Decision-Making
The Platform does not make legally significant decisions about individuals on its own. Identity-verification and sanctions-screening results are advisory, with the Operator as the human decision-maker. Automated controls such as rate limiting and billing-balance checks are operational, not evaluative. You may request human review of any automated decision that significantly affects you by contacting us or the Operator.
13. Data Breach Notification
If a breach of personal information occurs that is likely to create a risk to affected individuals, we will notify affected Operators without undue delay and assist them in meeting their own notification obligations to End Customers and regulators. We will provide notifications as required by applicable United States state breach-notification laws and Canadian law. Notices will describe the nature of the breach, the categories of data involved, and the steps taken.
14. Operators as Data Controllers
For the personal data of their End Customers, Operators are the data controllers and Gold Everywhere is the data processor, acting on the Operator's documented instructions. Operators are responsible for maintaining their own privacy notices, establishing a lawful basis for processing, obtaining required consents (including biometric consent), and honoring End Customer rights requests. Data is isolated by Operator. A Data Processing Agreement is available on request. Our sub-processors are listed in Section 16, and Operators should reference them in their own notices as applicable.
15. International Data Transfers
Gold Everywhere is based in Canada and serves Operators primarily in the United States. Your information may be processed in Canada, the United States, and other countries where our sub-processors operate. Where required, we rely on appropriate safeguards such as standard contractual clauses for cross-border transfers. By using the Platform, you consent to these transfers as described.
16. Sub-Processors
We use the vetted sub-processors below to deliver the Platform. A given vendor applies only where the related feature is enabled. Where an Operator connects its own keys (Your Keys), the Operator's chosen vendor processes that data directly in place of ours. We will notify Operators of material changes to this list, and a current copy is available on request.
Infrastructure and Storage
- Cloudflare: cloud hosting, CDN, DNS, web application firewall, DDoS protection, and file storage. Global.
- Vultr: redundant backup file storage. United States.
Payments
- Stripe: payment processing. United States.
- Square: payment processing and point of sale. United States.
- PayPal: payment processing. United States.
- Wise: money transfers. United Kingdom.
Email and SMS
- Postmark: transactional email delivery. United States.
- Mailgun: email delivery. United States.
- VoIP.ms: SMS messaging. Canada.
Identity Verification
- iDenfy: KYC, KYB, AML, and document verification, including facial-recognition matching. Lithuania (EU).
AI Providers
- Anthropic (Claude): AI text generation. United States.
- OpenAI: AI text and vision, and speech-to-text. United States.
- Google (Gemini): AI text generation. United States.
Images
- Shutterstock: stock image licensing. United States.
- Recraft: AI image generation. United States.
Authentication (optional social login)
- Google, Microsoft, Meta, and GitHub: OAuth sign-in, used only if you choose social login. United States.
Market Data
- Metals-API (metals-api.com): live and historical precious-metals spot pricing surfaced on the Platform.
17. Changes to This Policy
We may update this Policy. We will post the revised Policy with a new effective date and, where changes are material, notify active Operators by email. Continued use after the effective date constitutes acceptance.
18. Contact
Privacy questions and requests: privacy@goldeverywhere.com. Security reports: security@goldeverywhere.com. Gold Everywhere Inc.