Merchantpayd ← Back to home

Anti-Money Laundering & Counter-Terrorist Financing Policy

Last updated: 17.09.2026

Undercover Payments sp. z o.o.

Registration Number: 0001069394

Registered Address: ul. Bartycka 22B/21A, 00-716 Warszawa, Mazowieckie, Poland

Undercover Payments sp. z o.o. ("Merchantpayd," "we," "us," or "our") operates a payment platform that facilitates settlement of merchant transactions, including on-chain settlement of digital assets. We maintain an anti-money laundering (AML) and counter-terrorist financing (CTF) program consistent with the EU's Anti-Money Laundering Directive framework and applicable Polish law, including obligations relevant to providers of crypto-asset-related services under EU Regulation 2023/1114 (MiCA) where applicable to our activities.

1. Merchant Due Diligence (KYB)

Before a merchant account is fully activated, we require verification of the business and the individuals who ultimately own or control it:

  • Business verification: business registration details, incorporation documents, and a description of the business's activity.
  • Beneficial ownership: identification of the natural person(s) who ultimately own or control the business, consistent with applicable beneficial-ownership transparency requirements.
  • Supporting documentation: proof of business address, banking or processing history, and any further documents reasonably requested to complete verification.

We may decline to activate, or may suspend, an account where verification cannot be completed to our satisfaction, or where submitted documentation appears altered, inconsistent, or fraudulent.

2. End-User Identification and Verification (KYC)

In addition to conducting due diligence on our merchants, Undercover Payments performs identity verification (KYC) on natural-person end users where required in connection with payment, digital-asset and related transaction flows facilitated through our platform.

End-user KYC is conducted through Sumsub, our identity verification technology provider. The applicable level of verification is determined on a risk-based basis and may depend on factors including the end user's jurisdiction, transaction value, payment method, transaction history and assessed risk.

Depending on the applicable verification level, we may collect and verify information including:

  • full legal name;
  • date of birth;
  • residential address;
  • tax identification information, where applicable;
  • government-issued identity documents;
  • selfie and/or liveness verification;
  • purpose of the transaction;
  • occupation or source of income; and
  • source-of-funds information or additional supporting documentation where enhanced due diligence is required.

Verification requirements may increase progressively based on transaction value, jurisdiction and risk. Additional verification or documentation may therefore be required before a transaction is processed or where an end user's activity triggers enhanced due diligence.

An end user who is required to complete KYC must successfully complete the applicable verification process before being treated as KYC-verified. Where verification cannot be completed, or where information is inconsistent, fraudulent or otherwise gives rise to compliance concerns, we may reject, suspend or restrict the relevant transaction or service.

3. KYC Sharing

Where an end user has successfully completed the applicable KYC process, Undercover Payments may securely share the end user's verified KYC information with authorised processing, compliance or regulated service partners where necessary for the provision of the relevant service and permitted by applicable law.

Where supported, KYC information may be shared through Sumsub's reusable KYC functionality. Undercover Payments may generate and securely transmit a Sumsub KYC share token associated with the verified end user, enabling an authorised recipient to retrieve the permitted verified identity information directly through Sumsub.

KYC information is only shared as verified information after the applicable verification process has been successfully completed. Access is limited to authorised recipients and to information necessary for legitimate compliance, identity-verification, fraud-prevention or regulatory purposes.

The sharing of previously verified KYC information does not remove or restrict the receiving partner's own compliance obligations. A receiving partner may perform its own due diligence and may require additional information or documentation before accepting or processing a transaction.

4. Risk-Based Approach

We apply a risk-based approach to both merchant due diligence and end-user verification, as well as to onboarding and ongoing monitoring. For merchants, relevant factors may include the business's country of registration and operation, ownership and control structure, the nature of goods or services offered, expected transaction volumes and the jurisdictions in which the business operates.

For end users, relevant factors may include jurisdiction, transaction value, payment method, transaction history, verification results and other risk indicators. The level of KYC and supporting documentation required may increase where higher risk is identified.

Businesses or transactions connected to jurisdictions identified by the European Commission as high-risk third countries for AML purposes, or subject to applicable EU or UN sanctions regimes, may be subject to enhanced due diligence, additional documentation requirements, transaction restrictions or rejection where required by applicable law or our internal risk controls.

5. Sanctions and PEP Screening

We screen merchants and their beneficial owners against applicable sanctions lists (including EU and UN consolidated lists) and politically exposed person (PEP) indicators as part of onboarding, and on an ongoing basis thereafter. A confirmed sanctions match results in immediate account restriction; a PEP match triggers enhanced due diligence before an account can proceed.

6. Transaction Monitoring

We monitor transaction activity for patterns inconsistent with a merchant's stated business activity or expected volume, including unusually large or structured transactions. Where activity raises a reasonable suspicion of money laundering or terrorist financing, we may request additional information, place a hold on the transaction pending review, or restrict the account while the matter is assessed.

7. Reporting Obligations

Where we identify activity that gives rise to a reasonable suspicion of money laundering or terrorist financing, we are obliged under Polish law to report it to Poland's General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej, GIIF). We are legally prohibited from informing a client that a report has been made or that they are subject to investigation ("tipping off").

8. Record Keeping

We retain merchant identification documents, beneficial-ownership records, end-user KYC verification records, and transaction data for the period required under applicable AML law, generally for at least five years following the end of a business relationship or the completion of an occasional transaction, and longer where required by a competent authority in connection with an active investigation.

9. Compliance Oversight

We maintain internal responsibility for AML/CTF compliance, including periodic review of this policy against changes in applicable law and regulatory guidance. This policy is reviewed and updated as needed to reflect those changes.

10. Contact

Questions about this policy, or requests related to an account under compliance review, can be sent to [email protected], or by post to:

Undercover Payments sp. z o.o.
ul. Bartycka 22B/21A
00-716 Warszawa, Mazowieckie
Poland
Registration Number: 0001069394