AML Policy
Last updated: 8 October 2026
This Anti-Money Laundering and Sanctions Policy (the “Policy”) describes how Flexrix Pay (“we”, “us”) prevents the Service from being used for money laundering, terrorist financing, proliferation financing or sanctions evasion. It forms part of our Terms of Use; capitalised terms have the meaning given there.
Flexrix Pay is privacy-first. We do not collect identity documents or carry out identity verification (KYC) of merchants or their customers. Instead, our controls work on what the blockchain shows and on clear rules about who may use the Service and for what — and we apply them to every payment and every payout, automatically.
1. Our commitment
We do not tolerate money laundering, terrorist financing, proliferation financing or sanctions evasion. We do not knowingly provide the Service to sanctioned persons, to persons in Restricted Jurisdictions or for prohibited activities, and we will refuse, hold or end any relationship or transaction that we believe is connected to them.
2. Scope and framework
This Policy applies to every account, every payment received through the Service and every payout sent from it, and to everyone who works on the Service.
It is designed with reference to the Recommendations of the Financial Action Task Force (FATF), including those on virtual assets, and to the sanctions regimes of the United Nations Security Council, the European Union, the United Kingdom and the United States (OFAC).
3. Responsibility
The operator of Flexrix Pay is responsible for this Policy, for deciding cases that our automated controls escalate, and for keeping the controls up to date. Compliance questions can be sent to [email protected].
4. Risk-based approach
We assess the risk of money laundering and sanctions evasion presented by the networks and assets we support, the ways the Service can be used, the jurisdictions our merchants are located in, and the patterns we see on the blockchain. We design our controls around those risks and review them when we add a network, an asset or a feature.
5. Account opening
To open an account, a merchant verifies an email address, states the country of residence and the account type, and declares that it is not a US person, is not located in or resident of a Restricted Jurisdiction, and accepts our Terms of Use and this Policy. Two-factor authentication is mandatory for every user.
Sign-up is not available from Restricted Jurisdictions. The countries that are blocked automatically are the United States and its territories, Cuba, Iran, North Korea, Russia and Belarus; the full list of Restricted Jurisdictions is in section 3 of the Terms of Use.
We do not request identity documents, selfies, proof of address, company documents or beneficial-ownership information.
6. Prohibited and restricted activities
The activities listed as prohibited in section 15 of the Terms of Use are not allowed on the Service, and the restricted activities listed there require our prior written approval. Accounts used for prohibited activities are closed.
7. Screening of incoming payments
Every incoming payment is screened before it is credited:
- the sending address is checked against the digital-currency addresses on the OFAC Specially Designated Nationals (SDN) list, which we refresh regularly; a refresh is rejected if it would suddenly shrink the list, so that a faulty download cannot silently weaken screening;
- for USDT and USDC, the addresses involved are checked against the token issuer’s blacklist, read both from our mirror of the issuer’s on-chain events and directly from the token contract at the latest block;
- if a check cannot be completed, the payment waits until it can — it is never credited unchecked.
A payment that matches is not credited. It is held for manual review. Depending on the outcome and on the law, we credit it, return it to the sender, keep it frozen, or report it to the competent authority.
8. Screening of payouts
Every payout destination is checked against the same sanctions list and, for USDT and USDC, against the issuer blacklist. Payouts to matching addresses are blocked automatically.
Merchants can add further controls: approval above an amount, approval by two different people, daily limits, an allowlist of destinations with a waiting period before new addresses can be used, and automatic transfers only to their own allowlisted wallet. Payouts made in the dashboard require a fresh authenticator code.
9. Monitoring
Every movement of funds is recorded in a double-entry ledger that is reconciled against the blockchain several times an hour. We look for activity that suggests misuse of the Service, such as funds moving in and straight out again with no apparent business purpose, payments split to stay under limits, repeated exposure to high-risk addresses, payments from addresses linked to prohibited activities, and attempts to reach the Service from Restricted Jurisdictions.
10. Holding, freezing and ending relationships
Where our controls or our review indicate a risk, we may hold a payment, block a payout, limit or suspend an account, freeze funds or close the account, as described in sections 16 and 25 of the Terms of Use. Funds frozen under a legal requirement remain frozen until the competent authority allows their release.
11. Reporting and cooperation
Where the law requires it, we report suspicious activity and sanctions matches to the competent authorities, and we respond to lawful requests from law enforcement and courts. We disclose only what the law requires.
12. No tipping-off
Where the law prohibits it, we will not tell anyone that a report has been made or that an analysis is under way, and we may not be able to explain why a payment is held or an account is restricted.
13. Records
We keep records of accounts, payments, payouts, screening results, reviews and decisions for at least five years after the end of the business relationship, or longer where the law requires. Changes made in the dashboard are written to an audit log that cannot be altered.
14. People and access
Only people who need it for their role have access to our systems and data, and each of them is briefed on this Policy before getting access and whenever it changes. Keys that control funds are held in an isolated signing service that enforces its own rules on destinations and limits.
15. Merchants’ responsibilities
Merchants must comply with the anti-money-laundering, sanctions and other laws that apply to their own business, including any customer checks those laws require of them; must not use the Service to accept or send payments on behalf of third parties without our approval; and must not try to evade our controls.
16. Review
We review this Policy at least once a year and whenever the law, sanctions or our Service change materially. The date at the top of this page shows when it was last updated.