Safeguarding and Record-Keeping

Payoro Finance Ltd., Doing Business As (DBA) “Frontnode”, is registered as a Money Services Business (MSB) in Canada, Incorporation number BC1439769, with FINTRAC registration number M23010441. Payoro Finance Ltd. is registered with Bank of Canada under the RPAA.

1. Purpose

Frontnode is committed to protecting customer assets and maintaining complete and accurate records of customer transactions.

This policy explains:

  • how customer fiat funds are safeguarded;
  • how customers’ virtual currencies and other crypto-assets are segregated;
  • how Frontnode maintains transaction records; and
  • which records customers and cardholders should retain.

2. Safeguarding of Customer Fiat Funds

Customer fiat funds received or held in connection with Frontnode’s services are safeguarded with an approved financial institution established in the European Union.

Safeguarding means that customer funds are identified and maintained separately from Frontnode’s own operational funds. Customer funds are not treated as Frontnode’s property and are not intended to be used to finance Frontnode’s business operations, operating expenses or obligations to other creditors.

Frontnode applies appropriate financial and operational controls to protect safeguarded funds, including:

  • separation of customer funds from Frontnode’s operational funds;
  • maintenance of internal records identifying the amount attributable to each customer;
  • regular reconciliation of customer balances against the corresponding safeguarded funds;
  • controlled access to accounts in which customer funds are held;
  • review and approval procedures for transfers and withdrawals;
  • monitoring and investigation of discrepancies; and
  • retention of records sufficient to establish each customer’s entitlement.

Safeguarding is designed to protect customer funds and reduce the risk of their being used for purposes unrelated to the customer’s transactions. It does not constitute an investment arrangement, and safeguarded balances do not represent an investment product offered by Frontnode.

Safeguarding should not be understood as eliminating every possible financial, operational, banking or counterparty risk. Unless expressly stated otherwise, customer funds are not covered by a deposit guarantee scheme merely because they are held with a financial institution.

3. Segregation of Virtual Currencies

Virtual currencies and other crypto-assets held for customers are segregated from crypto-assets belonging to Frontnode.

Frontnode maintains separate systems, wallets, accounts and internal ledger records, as applicable, to identify and account for customer crypto-assets. These arrangements are designed to ensure that customer assets can be distinguished from Frontnode’s own assets and that each customer’s entitlement can be established from Frontnode’s records.

Frontnode’s controls for customer crypto-assets include:

  • segregation of customer assets from Frontnode’s proprietary crypto-assets;
  • accurate recording of deposits, purchases, transfers, conversions and withdrawals;
  • maintenance of an individual customer ledger;
  • regular reconciliation of internal customer balances against the relevant wallet and blockchain balances;
  • restricted and role-based access to wallet infrastructure;
  • approval controls for transfers and withdrawals;
  • transaction monitoring and blockchain analysis, where appropriate;
  • security measures for the storage and management of cryptographic keys;
  • monitoring for unauthorized access, fraud and suspicious activity; and
  • incident management and escalation procedures.

Where customer assets are held in an omnibus or pooled wallet, Frontnode maintains internal ledger records showing the type and amount of virtual currency attributable to each customer. Operational pooling does not change Frontnode’s obligation to maintain accurate records of each customer’s entitlement or the segregation of customer assets from Frontnode’s own assets.

Unless expressly agreed with the customer and permitted by applicable law, Frontnode does not use customer virtual currencies for its own account, pledge them as security, lend them to third parties or use them for staking, yield generation or other investment activities.

4. Reconciliation and Internal Controls

Frontnode performs reconciliations at appropriate intervals to compare:

  • customer balances recorded in Frontnode’s systems;
  • balances held in safeguarded fiat accounts;
  • balances held in customer crypto-asset wallets;
  • relevant blockchain transaction records; and
  • deposits, withdrawals, conversions, fees and other account movements.

Any material discrepancy is investigated and escalated in accordance with Frontnode’s internal procedures. Where necessary, corrective entries, restrictions or other protective measures may be applied.

Frontnode also maintains access controls, audit trails and approval procedures intended to prevent unauthorized transactions and preserve the integrity of customer records.

5. Risks Relating to Virtual Currencies

Although Frontnode applies safeguarding, segregation and security measures, virtual currencies involve risks that do not ordinarily apply to traditional fiat currencies.

These risks may include:

  • significant price volatility;
  • irreversible blockchain transactions;
  • delays or congestion on blockchain networks;
  • protocol failures, forks and changes to network rules;
  • cyberattacks, fraud and unauthorized access;
  • loss or compromise of cryptographic credentials;
  • disruptions affecting wallet, banking or technology providers;
  • regulatory restrictions or changes; and
  • reduced liquidity or availability of particular assets.

Segregation reduces the risk of customer assets being confused with Frontnode’s own assets. It does not protect customers against changes in market value, blockchain failures or all losses resulting from events outside Frontnode’s reasonable control.

Customers remain responsible for verifying wallet addresses, blockchain networks, payment details and transaction information before authorizing a transaction.

6. Transaction Records

Frontnode maintains records relating to customer accounts and transactions in accordance with applicable legal, regulatory, accounting, anti-money laundering and operational requirements.

Depending on the service used, these records may include:

  • account and customer identification information;
  • transaction confirmations and receipts;
  • payment card transaction records;
  • deposits and withdrawals;
  • virtual currency purchases, sales, transfers and conversions;
  • wallet addresses and blockchain transaction identifiers;
  • dates, times, amounts, currencies and applicable exchange rates;
  • fees and charges;
  • instructions, authorizations and authentication records;
  • communications relating to transactions, disputes or complaints;
  • refunds, reversals and chargebacks; and
  • relevant terms, policies and disclosures accepted by the customer.

Frontnode retains relevant records for a minimum of five years following the relevant transaction or the end of the customer relationship, as applicable. Certain records may be retained for a longer period where required or permitted by applicable law, regulatory requirements, legal proceedings, dispute resolution, fraud prevention or the establishment, exercise or defence of legal claims.

Records are protected using appropriate technical and organizational measures. Access is limited to authorized personnel and service providers with a legitimate business, compliance or legal need.

7. Recommendation to Customers and Cardholders

Frontnode strongly recommends that every customer and cardholder retain a personal copy of:

  • all transaction confirmations and receipts;
  • card payment records;
  • deposit and withdrawal confirmations;
  • virtual currency transaction records;
  • blockchain transaction identifiers;
  • correspondence relating to a transaction;
  • applicable fees and exchange-rate information;
  • refund, cancellation and chargeback records;
  • the Merchant’s terms and conditions;
  • the Merchant’s privacy, refund, cancellation and delivery policies; and
  • any other Merchant policies or rules applicable at the time of the transaction.

Customers should retain these records in a secure and accessible form. Merchant policies may change over time, so customers are encouraged to save or download the version that applied when the transaction was made.

Frontnode’s retention of records does not replace the customer’s responsibility to maintain personal copies. Records retained by Frontnode may be subject to legal retention periods, technical limitations, privacy requirements or restrictions on disclosure.

8. Access to Records

Customers may be able to access transaction information through their Frontnode account. Customers may also contact Frontnode to request available records relating to their account or transactions.

Frontnode may require the customer to complete identity or security verification before records are released. Access may be limited where disclosure would:

  • adversely affect the rights or privacy of another person;
  • compromise security or fraud-prevention measures;
  • interfere with an investigation;
  • disclose confidential or legally privileged information; or
  • be prohibited by applicable law or a competent authority.

9. Reporting Errors or Unauthorized Transactions

Customers should review transaction records promptly and notify Frontnode without undue delay if they identify:

  • an unauthorized or unrecognized transaction;
  • an incorrect transaction amount;
  • a missing deposit or withdrawal;
  • an incorrect wallet address or blockchain network;
  • an unexpected fee or exchange rate;
  • a duplicated transaction; or
  • any other discrepancy.

Prompt notification may improve Frontnode’s ability to investigate the matter and, where possible, prevent or limit further loss. Virtual currency transactions recorded on a blockchain may be irreversible, and Frontnode cannot guarantee that transferred assets can be recovered.

10. Updates to This Policy

Frontnode may update this policy to reflect changes in its services, safeguarding arrangements, legal requirements or operational procedures.

The current version will be published on Frontnode’s website. Customers are encouraged to review this policy periodically.