Privacy Policy
Version 2026-08-24 · Effective August 24, 2026
Issued by Ohana Capital AG
Effective date
August 24, 2026

Issued by
Ohana Capital AG
1. Scope and purpose
Ohana Capital AG uses personal information to administer invited platform access, secure accounts, operate verification and account workflows, communicate with users, and meet applicable legal obligations.
This policy applies to information processed through the website, authenticated platform, customer support, recruitment and careers workflows, identity-verification processes, internal financial records, portfolio tools, and product workflows.
2. Information we collect
2.1 Information you provide
Depending on the services requested, this may include:
- Name, date of birth, contact information, country, and residential address
- Government-issued identity documents and verification images
- Tax, employment, income, source-of-funds, and suitability information
- Information entered into platform financial workflows; real payment credentials and external wallet addresses must not be submitted while external payment services are inactive
- Account preferences, support requests, and communications
- Information submitted when enabling account-security features
- Recruitment information such as a résumé, cover note, employment history, professional profile link, and application communications
2.2 Account and transaction information
We process records created through use of the platform, including:
- Orders, positions, trades, balances, portfolio values, and transaction history maintained in the platform ledger
- Funding request, transfer, withdrawal, reward, and maturity records maintained by the platform
- Verification status, legal acceptance records, and security events
- Product selections, account tier information, and support history
2.3 Device and usage information
When the platform is accessed, technical information may be collected, including:
- IP address, browser, operating system, device, and language
- Access dates, pages viewed, navigation, and feature interactions
- Session, authentication, security, reliability, and error information
- Cookie and analytics preferences
3. How information is collected
Information is collected directly from you, generated through platform activity, received from financial and identity-verification service providers, or obtained where permitted from fraud-prevention, sanctions, and public-record sources.
We do not intentionally collect information that is not reasonably connected to an account, requested service, security need, or applicable obligation.
3.1 Email delivery and engagement signals
Transactional and operational emails may include a Resend-provided 1×1 tracking pixel. When an email application or image proxy loads that remote content, we may record a provider-reported event and timestamp linked to the message for delivery and engagement operations. This is an estimated signal, not proof that a person read the email: blocked images can prevent a report, while privacy services, image proxies, security scanners, prefetching, caching, or forwarding can create or misattribute one.
3.2 Optional customer-support chat
The Crisp customer-support chat is loaded only after the customer-support chat choice is enabled in Cookie Preferences and only when the service is configured. Crisp may then process chat messages and attachments, IP address, browser and device information, a chat session cookie, and support metadata needed to operate the conversation.
For a signed-in user, the platform may send the authenticated account email together with a server-generated HMAC signature so support staff can distinguish a verified account email from an address entered by a visitor. The signing secret remains on the Ohana Capital server. Signing out clears the local Crisp session association. Do not send passwords, authenticator codes, recovery phrases, private keys, or payment credentials through chat.
4. How information is used
Information may be used to:
- Create, administer, authenticate, and protect accounts
- Verify identity and conduct risk-based KYC, sanctions, and financial-crime checks
- Process orders, funding requests, withdrawals, and product instructions
- Calculate balances, portfolio history, rewards, and maturity information
- Provide support and deliver service, security, and legal notifications
- Detect suspicious, unauthorized, abusive, or fraudulent activity
- Maintain records and respond to valid legal or regulatory requests
- Diagnose reliability issues and improve products where permitted
- Obtain and record required policy and cookie choices
- Evaluate job applications, communicate with candidates, document hiring decisions, and administer recruitment
We do not sell personal information to third parties for their own marketing.
5. Sharing and service providers
Information may be shared only where reasonably necessary with:
- Identity-verification, fraud-prevention, sanctions-screening, and security providers
- Banks, payment providers, market-data providers, and transaction counterparties
- Hosting, communications, analytics, customer-support (including Crisp when enabled), and professional service providers
- Private inference providers used by authorized CRM staff, subject to data minimization and applicable contractual safeguards
- Recruitment, document-storage, and hiring-administration providers
- Courts, authorities, law enforcement, or regulators where disclosure is legally required
- Parties involved in a corporate transaction, subject to appropriate safeguards
Service providers receive information for defined purposes and are expected to handle it under contractual and legal requirements applicable to their role.
6. Cookies and analytics
Necessary browser storage is used to maintain sessions, remember security state, and preserve essential preferences. Optional analytics and the Crisp customer-support chat are activated independently and only after the corresponding choice is made through Cookie Preferences.
Cookie choices are versioned and may be changed from the Cookie Preferences control in the website footer. Marketing storage is not enabled by the current preference flow.
7. International processing
Providers and infrastructure may process information outside the country where a user resides. Where applicable law requires safeguards for an international transfer, we use an appropriate contractual, organizational, or legal transfer mechanism.
8. Security
We use technical and organizational controls appropriate to the information and service, which may include:
- Encryption in transit and protected storage controls
- Role-based access restrictions and authenticated administrative access
- Account, financial-action, and security-event records
- Monitoring and controls intended to detect unauthorized activity
- Optional multi-factor authentication available through account settings
- Incident handling, backup, and service-recovery procedures
No internet service or storage method can guarantee absolute security. Users should use unique credentials, protect authentication devices, and promptly report suspected unauthorized access.
9. Retention
Information is retained for as long as reasonably necessary to provide services, secure accounts, resolve disputes, maintain financial and legal records, and meet applicable retention obligations. Retention periods vary by information type, account status, product, and jurisdiction. Customer-support conversations may be retained in the configured support system for service, security, and complaint handling. The separate internal CRM assistant does not retain conversation content in the platform; only limited operational metadata and confirmed business actions are recorded for security and accountability.
Website job applications are scheduled for review or deletion after 365 days unless a shorter period is requested and permitted, a longer period is required by law, or the candidate separately agrees to consideration for future roles.
When information is no longer required, it is deleted, anonymized, or isolated from active use in accordance with applicable requirements and operational constraints.
10. Rights and choices
Depending on applicable law and subject to permitted limitations, a user may be able to:
- Request access to or a copy of personal information
- Correct inaccurate or incomplete information
- Request deletion or restriction of certain processing
- Object to or withdraw consent from consent-based processing
- Request portable data in an available structured format
- Opt out of non-essential analytics and marketing communications
- Submit a complaint to an applicable data-protection authority
Identity verification may be required before a request is fulfilled. Financial, security, fraud-prevention, and legal records may need to be retained even after an account is closed or a deletion request is made.
11. Minors
The platform is not intended for anyone under 18 or below the legal age required to use the services in their jurisdiction. We do not knowingly offer accounts to children.
12. Policy changes
This policy may be updated to reflect product, legal, provider, or security changes. Material revisions are versioned and presented through the platform when renewed acceptance is required.
Questions about this document?
Contact Ohana Capital AG and include the document title and version in your message.
Contact support