Privacy Notice
Effective date: 17 November 2025
This Privacy Notice (“Privacy Notice”) explains how Push Virtual Assets LLC (“Push,” “we,” “our,” or “us”) and its affiliates collect, use, share, and protect your personal data when you use our website (https://www.push.co/) (the “Site”) or our Push mobile application (together, the “Platform”). It also describes your rights under U.S. law.
It’s important to us that you understand how your information is used. We encourage you to read this Privacy Notice in full, but here are some key points at a glance:
- Transparency: Our goal is to make your crypto experience simple and secure. If you do not agree with how your personal information is collected, used, or shared as described in this Privacy Notice, or if you are under 18, please stop using our Services.
- Purpose: We collect and use your information to deliver and enhance our Services, improve your experience, protect the security and integrity of our Platform, and comply with legal obligations.
- Sharing: We may share your information with companies within the Aave Labs group, as well as trusted service providers and partners, to provide our Services and meet regulatory requirements.
Company Details
Entity name: Push Virtual Assets LLC.
Status: Data Controller.
Registered Address: 16192 Coastal Highway Lewes, DE, 19958, United States.
E-mail: privacy-support@push.co.
Who Is in Scope of This Privacy Notice?
This Privacy Notice applies to a range of individuals who interact with Push, including:
- Customers: Individuals who register for and use our Services through the Platform. This includes account holders, verified users, and anyone who initiates or completes transactions, whether directly or through integrated features.
- Prospective Customers: Individuals who have not yet registered an account but interact with us during onboarding, request information about our Services, join a waitlist, or otherwise express interest in becoming a user of the Platform.
- Website and App Users: Visitors to our public-facing website or users of the Platform who may browse, explore, or engage with available features without registering as Customers.
Exclusions
This Privacy Notice does not apply to all individuals who may interact with Push. Specifically:
- Employees, contractors, and other staff: Information collected in the context of employment or recruitment is governed by a separate internal privacy policy.
- Vendors, service providers, and corporate partners: Data collected and processed in the course of business-to-business relationships - such as contract management, due diligence, or partnership activities - is managed under separate agreements and policies.
Application of This Privacy Notice
For the purposes of this Privacy Notice, and only where required by applicable U.S. state privacy laws, the terms “personal information” and “sensitive personal information” (sometimes also referred to as “personal data” and “sensitive personal data”) carry the meanings assigned to them under those laws. This includes the California Privacy Rights Act of 2020 (CPRA), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), and the Utah Consumer Privacy Act (“UCPA”).
Much of the personal information we collect, use, and share is regulated by the Gramm–Leach–Bliley Act (“GLBA”) and other federal laws. Information covered by these laws is exempt from the CPRA. While we are not required to include GLBA-covered information in the disclosures below, we may choose to do so for transparency.
We may also collect, use, and share personal information in other contexts that fall within the scope of California privacy law. The table below provides an overview of the categories of personal information we may collect, use, or disclose. Not every category applies to every individual - the information we process depends on your relationship and interactions with us.
In addition to the rights available to California residents, individuals in Virginia, Colorado, Connecticut, and Utah may also have rights under their state privacy laws. These may include the right to access, correct, delete, or obtain a copy of your personal information, as well as the right to opt out of targeted advertising, sales of personal data, or profiling that produces legal or similarly significant effects.
If you reside in one of these states, you can exercise your rights by contacting us at privacy-support@push.co. Where required, we will also provide an appeals process if we deny your request.
Sensitive Information Disclosure
We collect certain categories of sensitive personal information, as defined under applicable U.S. state privacy laws. This may include government identifiers (such as Social Security numbers, driver’s license numbers, state ID numbers, or passport numbers), account log-in details combined with security credentials or passwords, and biometric information used for identity verification. We collect and use this information only as necessary to process transactions, comply with legal and regulatory obligations (including KYC/AML requirements), protect the security and integrity of our Platform, and manage our business operations. We do not use sensitive personal information for purposes beyond those permitted by law. We do not sell or share this information for cross-context behavioral advertising or use it for automated decision-making with legal or significant effects, except where required for fraud prevention or regulatory compliance and subject to human review.
What Data Do We Collect About You?
We collect different types of personal information depending on how you interact with Push. These include information you provide directly, information we collect automatically when you use the Platform, and information we obtain from third parties.
Information You Provide
This is information you voluntarily give us when creating an account, using our Services, or otherwise interacting with us, such as:
- Personal identifiers: Name, address, phone number, email address, and date of birth.
- Account and financial details: Login credentials, linked wallet addresses, linked bank accounts or payment methods.
- Identity documentation: Government-issued identification (e.g., driver’s license, passport, state ID), photographs, or biometric likeness (e.g., facial image or video) used to verify your identity.
- Supporting documents: Other documentary evidence provided during onboarding or customer support (e.g., proof of address, business documentation for entity accounts).
- Transaction information: Records of transactions, including assets, amounts, dates, and times.
- Communications: Records of your interactions with our support team, surveys, or feedback you submit.
- Preferences and settings: Selections you make in the Push SDK or within your account, including notification preferences or app configuration.
Information Automatically Collected
When you use our Platform, we automatically collect certain technical and usage information, including:
- IP address, device/browser type, and OS.
- Usage and diagnostics data.
- Geolocation data.
Information From Third Parties
We may also collect information about you from trusted third parties, including:
- Identity verification and sanctions-screening vendors.
- Payment processors.
- Blockchain data.
- Public records and databases.
- Integration partners.
Special Categories of Data
Certain types of information we collect are considered “sensitive” or “special categories of personal data” under U.S. state privacy laws, including:
- Government identifiers: Such as Social Security numbers, driver’s license numbers, state identification card numbers, or passport numbers.
- Biometric information: Such as facial images or videos collected for identity verification and fraud prevention.
- Financial account information: Account log-in details in combination with security codes, passwords, or other credentials that allow access to your financial accounts.
We collect and use these categories of data only for limited, lawful purposes - for example, to comply with KYC/AML obligations, verify your identity, prevent fraud, protect the security of our Platform, and manage our business operations. We do not use this information for purposes beyond those permitted by applicable law, and we do not sell or share sensitive personal information for cross-context behavioral advertising.
Anonymized and Aggregated Data
In addition to the categories of personal data described above, Push may also process anonymized information, to the extent reasonably possible. Anonymous information is information that cannot be traced back to a person and, as such, is not considered personal data. Types of data we may anonymize, depending on the processing purpose, include transaction data, click-stream data, performance metrics and fraud indicators. We use anonymous data for different purposes including to monitor and mitigate fraud and other risks and to improve the performance of the Platform.
Push may also create and process anonymized or aggregated information. This means information that has been stripped of personal identifiers and cannot reasonably be linked back to an individual. Depending on the purpose, this may include transaction trends, usage patterns, performance metrics, or fraud-related indicators. We use anonymized information to help monitor and reduce fraud and other risks, to analyze and enhance Platform performance, and to support the ongoing development of our Services.
How Do We Use Your Personal Data?
We use personal data to operate our business, deliver the Services you request, and comply with our legal and regulatory obligations. In particular, we may use your data for the following purposes:
- Service delivery and account management: To provide, operate, and improve our Services; create and maintain your account; process transactions; and ensure the functionality and performance of the Platform.
- Identity verification and compliance: To verify your identity, conduct know-your-customer (“KYC”) and anti-money laundering (“AML”) checks, monitor for suspicious or illegal activity, and fulfill regulatory and licensing obligations under U.S. federal and state law.
- Security and fraud prevention: To detect, investigate, and prevent fraud, unauthorized transactions, abuse of our Services, or other harmful or illegal activity; and to safeguard the security and integrity of the Platform.
- Customer support and engagement: To respond to inquiries, provide technical or account support, and manage communications with you.
- Personalization and improvement: To enhance and tailor the customer experience, gather feedback, conduct surveys, and perform research and analytics to improve our Services.
- Communications and marketing: To send you service-related updates and information, and - with your consent where required by law - to provide promotional content or marketing communications.
- Legal and regulatory obligations: To comply with court orders, subpoenas, regulatory examinations, investigations, and other legal processes.
- Technology and innovation: We may use artificial intelligence and automated tools to support onboarding, fraud detection, and security monitoring. These tools assist human decision-making and are not used to make automated decisions that have legal or similarly significant effects without human review.
- Other compatible purposes: We may also use personal information for purposes that are reasonably related to, or compatible with, the reasons described above, consistent with applicable laws and your expectations.
We may use artificial intelligence tools to support fraud prevention and onboarding. Automated decisions with significant effects are subject to human review.
Legal Bases for Processing
Push processes personal information only where we have a lawful basis to do so. Depending on the circumstances, this may include:
Legal Obligations
We process certain information because it is required under U.S. federal and state laws and regulations. This includes, but is not limited to, the Bank Secrecy Act, state money transmission statutes, Office of Foreign Assets Control (“OFAC”) requirements, and Financial Crimes Enforcement Network (“FinCEN”) regulations. These obligations require us to verify identities, monitor transactions, keep records for defined periods, and report suspicious activity.
Contractual Necessity
We process data to perform our contract with you, including creating and maintaining your account, enabling transactions, providing customer support, and delivering the core Services you have requested. Without this processing, we would be unable to provide you with access to the Platform.
Legitimate Interests
In some cases, we process data where we have a legitimate business interest in doing so, provided that your privacy rights are not overridden. These interests include maintaining the security and integrity of the Platform, preventing fraud and abuse, improving and developing our Services, and enhancing the customer experience.
Consent
In limited situations, we will seek your consent before processing your personal information. For example, we may require your explicit consent to collect and use biometric data for identity verification in certain states, or to send you marketing communications where consent is required under applicable law. You can withdraw your consent at any time by contacting us.
To Whom Do We Disclose Personal Data?
We share personal information only as necessary and in accordance with this Privacy Notice. Depending on the circumstances, your data may be disclosed to:
Regulators and Authorities
To comply with applicable U.S. federal and state laws, regulatory obligations, supervisory examinations, court orders, subpoenas, or other legal processes.
Vendors and Service Providers
Trusted third parties who support our operations, such as identity verification providers, sanctions-screening partners, payment processors, IT and security service providers, analytics platforms, and other technical or professional services that enable us to provide the Platform.
Affiliates
Companies within our corporate group, including our parent entity, subsidiaries, sister companies, joint ventures, or other entities under common ownership or control, to the extent necessary to deliver Services, ensure platform security, or support business operations.
Business Transfers
In connection with, or during negotiations of, any merger, acquisition, restructuring, reorganization, or sale of assets, where information may be transferred as part of the business transaction.
With Your Direction or Consent
To other third parties where you have instructed us to do so, or where you have otherwise provided your consent.
We do not sell your personal information or share it for purposes of cross-context behavioral advertising.
Cookies, Analytics and Advertising
Cookies are small text files placed on your device (for example, your computer, smartphone, or tablet) when you use our Platform. They help us recognize your device, remember your preferences, and improve your overall experience. In addition to cookies, we may use similar technologies such as SDKs, pixels, beacons, and local storage to collect and store information automatically when you interact with our Services.
When you visit or use the Platform, we may generate and store any of the following types of cookies:
- Strictly Necessary Cookies: These cookies are essential for the operation of the Platform and to enable you to use its features, such as logging in, maintaining sessions, and accessing secure areas. They also include security cookies used to protect your account and prevent fraudulent activity. Because these cookies are strictly necessary, they cannot be disabled. You may block or delete them via your browser settings, but some parts of the Platform may not function properly as a result.
- Functionality Cookies: If you consent, these cookies remember your choices - such as username, language, or region - to provide a more personalized experience. They may also store your preferences for interface customization (like font size or layout) or remember where you left off in a session. These cookies are not used for tracking your activity on third-party websites.
- Performance Cookies: If you consent, these cookies collect information about how you use the Platform - for example, which pages you visit most frequently and whether you receive error messages. This data helps us understand how the Platform performs and allows us to improve its reliability, speed, and usability. We may also use this information to assess the effectiveness of media campaigns and user journeys.
- Analytics and Customization Cookies: If you consent, we use analytics tools (including from trusted third parties) to understand how visitors engage with our Platform. These cookies may collect information such as your IP address, browser type, device information, time spent on the Platform, and the links or features you interact with. We use this information to analyze usage patterns, optimize the Platform’s design, and improve user experience.
- Advertising and Marketing Cookies: If you consent, these cookies and similar technologies help us deliver Push promotions or third-party advertisements that are more relevant to you. They may also limit how often you see a particular advertisement and help measure campaign performance. Where required by law, we will obtain your consent before placing these cookies and will provide mechanisms for you to opt out of targeted advertising and analytics cookies.
Other Tracking Technologies
We also use other technologies similar to cookies, such as web beacons (also known as “clear GIFs” or “pixel tags”), which are transparent images embedded in web pages, emails, or apps. These help us measure engagement, such as whether an email has been opened or a specific page viewed.
We may also use customized links or tracking parameters to understand which hyperlinks you click and associate that information with your account to improve our communications and personalize your experience.
For simplicity, references to “cookies” in this section include these related tracking technologies.
Consent and Managing Cookies
We will seek your consent to place cookies and similar technologies on your device where required by law, except for cookies that are strictly necessary to deliver the Services you request.
You can withdraw your consent or adjust your cookie preferences at any time. Most browsers allow you to view, delete, or block cookies and to clear stored data. To learn how to do this, visit www.allaboutcookies.org, which provides detailed instructions for all major browsers. Please note that if you disable or delete cookies, some features of the Platform may not function as intended.
Third-Party Access and Analytics Providers
Some cookies and analytics technologies are provided by third parties who process data on our behalf - such as analytics vendors, ad networks, or social media partners. These third parties may have access to cookie data to perform their services but are not permitted to use it for their own purposes. We maintain contractual and technical controls to protect your information and limit use to authorized activities.
International Data Transfers
Data is primarily processed in the U.S. Where transferred abroad, we use safeguards such as contractual clauses consistent with U.S. law.
Security of Personal Data
Push takes appropriate administrative, technical, and physical measures to safeguard your personal information. That said, no system for transmitting or storing data electronically can be guaranteed to be completely secure. While we work to protect your information against unauthorized access, use, or disclosure, we cannot guarantee absolute security. If required by law to notify you of a security incident involving your personal information, we may do so electronically, in writing, or by telephone, as permitted.
Protecting your information is also a shared responsibility. When creating an account, choose a strong and unique password, keep it confidential, and notify us immediately if you suspect any unauthorized access to or use of your account.
We implement administrative, technical, and physical safeguards including:
- Encryption.
- Access controls and personnel training.
- Firewalls and intrusion detection.
- Incident response planning.
- Regular audits.
Data Retention
When determining how we handle and protect personal information, we take into account factors such as the type and sensitivity of the data, the potential risks of unauthorized access or disclosure, the purposes for which the data was collected and whether those purposes can be met in other ways, as well as our obligations under applicable law. We retain personal data only as long as necessary for:
- Service provision.
- Compliance with legal obligations (e.g., AML recordkeeping for seven years).
- Dispute resolution and enforcement.
Biometric data is retained per state law (e.g., one year in Texas, three years in Illinois, up to 7 years otherwise).
Based on these considerations, we delete personal information once it is no longer required for the purposes described in this Privacy Notice, such as when your account is closed or when you submit a valid deletion request. However, we may retain certain information where necessary to comply with legal, regulatory, or recordkeeping obligations (for example, anti-money laundering requirements, tax laws, or contractual commitments).
Third-party applications / websites
The Platform may include links to websites, applications, or services operated by third parties that are not owned or controlled by Push. These third parties may have their own privacy notices or policies, which we encourage you to review. Push is not responsible for the privacy practices, security, or content of any third-party sites or services.
Your Rights
We respect your privacy and provide you with certain rights over your personal information. The rights available to you may vary depending on your state of residence and applicable law, but they generally include:
- Right to Know: Request details about the categories and specific pieces of personal data we collect, use, disclose, or share.
- Right of Access: Obtain a copy of the personal information we hold about you.
- Right to Deletion: Request that we delete your personal data, subject to legal, regulatory, or business recordkeeping obligations (for example, AML record retention requirements).
- Right to Correction: Request correction of inaccurate or incomplete personal information.
- Right to Data Portability: Receive certain personal information in a structured, commonly used, and machine-readable format, and, where feasible, have it transmitted to another controller.
- Right to Opt Out: Opt out of certain uses of your personal data, such as sharing for targeted advertising, the sale of personal data (if applicable), or profiling that produces legal or similarly significant effects.
- Right to Limit Use of Sensitive Personal Information: Where required by law, limit our use of sensitive personal data (such as government identifiers, biometric information, or account log-in credentials) to only those purposes permitted by applicable statutes.
- Right to Non-Discrimination: You will not be denied services, charged different prices, or provided with a different level of service simply because you exercised your privacy rights.
To exercise these rights, contact: privacy-support@push.co. To protect your information, we may need to verify your identity before fulfilling your request, including by requesting additional information or documentation.
State-Specific Rights
In addition to the general rights described above, some states — including California, Virginia, Colorado, Connecticut, and Utah — provide residents with additional privacy protections. Depending on where you live, these may include the right to opt out of targeted advertising, the right to opt out of profiling that produces legal or similarly significant effects, and in California, a broader set of rights and disclosures under the California Privacy Rights Act (“CPRA”). These state-specific rights are intended to give you greater control over how your personal information is used and shared. More detail on the rights available in each state can be found in Annex B of this Privacy Notice.
Children’s Privacy
Our Platform is not intended for individuals under 18, and we do not knowingly collect personal information from anyone in this age group. If you are under 18, please do not submit any personal information through the Platform. If we become aware that a user is under 18, we will require the closure of their account, restrict access to our Services, and delete their information as soon as reasonably possible. If you are aware of someone under 18 using our Services, please contact us so we can take appropriate action.
Changes to your personal data
Please keep us informed if your personal data changes or if you become aware that any personal data that we hold is not accurate.
Changes to This Privacy Notice
We may update this Privacy Notice. Updates will be posted on our website with a revised date. Where material changes are implemented, we will notify you by email or in-app. Please check the Privacy Notice regularly so that you are aware of any changes.
Contact Us
For questions, complaints, or to exercise rights, contact:
Email: privacy-support@push.co
You may also have the right to complain to your state attorney general or other regulator.
Annex A – Consent to Processing of Personal and Biometric Data
By providing your consent, you authorize Push and its identity verification providers, SumSub or Persona, to collect and process biometric information (such as facial likeness) for purposes including identity verification, fraud prevention, compliance with anti-money laundering and counter-terrorist financing (AML/CFT) requirements, and other legal obligations. For further details, please refer to SumSub’s Privacy Policy and Persona’s Privacy Policy.