RDVCC

Los documentos legales están disponibles solo en inglés.

KYC Policy

Last updated: 2026-10-04

1. Who sets this policy, and our position on KYC

This KYC policy is set and enforced by AGGS TECHNOLOGY SERVICES CO., LIMITED ("the Company"), which is incorporated in the Hong Kong Special Administrative Region.

KYC (Know Your Customer) is the compliance baseline of international cross-border payment services. The virtual card brand "RDVCC Virtual Credit Card" (the "Platform") operated by the Company works with upstream licensed card issuers, who require every cardholder to complete an in-person document verification before a card is opened and require the Platform to retain the verification records for compliance review.

The Platform follows the "minimum necessary" principle: we collect only what the issuer's compliance requirements demand; verification data is kept strictly confidential, never used for marketing and never sold to any third party.

2. Identity verification data we collect

  • Document data: document type, document number, name, date of birth, nationality and issuing country, expiry date, and the address printed on the document;
  • Document images: photos of the front and back of the document;
  • Face data: the face photo taken during verification, used to match against the document photo and to complete the liveness check;
  • Verification context: the country of the IP address at the time of verification and the risk flags returned by the verification provider; your registration email was already verified by a one-time code at sign-up.

We do not collect contacts, precise location, microphone data or anything else unrelated to identity verification.

3. Who performs verification, and how data is stored and used

  • Verification provider: identity verification is performed by Didit, the third-party verification provider integrated by the Platform. When you photograph your document and face on the verification page, the data is captured and checked by that provider under its own privacy policy; when the check completes, the provider returns the decision and the extracted document data to the Platform. Users verified before September 2026 through the providers we used previously have had their records migrated into the Platform under the same standards;
  • Encryption and image storage: document numbers and full addresses are stored with AES-256-GCM field-level encryption; in the database the address is kept in plain text only down to province level. Document and face images are stored on the Company's servers and backed up to an overseas object-storage service to guard against data loss; both locations are private and not reachable from the public internet;
  • Access minimisation: only authorised administrators can view the data; viewing plain-text document data or images requires an administrator's one-time code, and every view is written to the audit log;
  • Limited use: used only to decide card eligibility, detect the same document across multiple accounts, control risk and fraud, handle support disputes, satisfy issuer compliance reviews and respond to lawful requests from competent authorities; when a card is opened, cardholder identity data is provided to the card issuer as its compliance rules require; never used for marketing and never shared with any other third party.

4. Verification flow

  1. Create an account (email + email one-time code + password); registration and top-ups do not require verification;
  2. Before your first card is opened, the system asks you to complete identity verification;
  3. Have a valid ID ready, photograph the front and back as guided and complete the face check — about 3 minutes in total, done only once;
  4. In most cases the result is immediate; a small share goes to manual review, usually completed within one business day, with the result sent by email. If it fails, you can verify again.

Please complete verification in your phone's own browser or Chrome; in-app browsers such as WeChat or QQ cannot use the camera. Users who registered before 22 September 2026 and already have real transactions will be asked to verify step by step; their existing cards keep working until then.

5. Retention period

As required by cross-border payment compliance, identity verification records (including document and face images) are retained for at least 5 years after the account ends and deleted afterwards.

6. Your rights

  • See your verification status, name, document type and verification time under Account → My Info;
  • If your document details change (name change, new document, etc.), contact support to verify again;
  • Verification records are subject to the compliance retention period above and are deleted automatically when it expires; if you close the account, the retention period is not shortened;
  • close your account (see the Privacy Policy).

7. Boundaries of use and your responsibility

The Platform provides virtual cards issued by card issuers, funded by a USDT top-up. We make no assessment or promise about whether this arrangement is lawful in your own jurisdiction; it is your responsibility to confirm and comply with the foreign-exchange, tax and payment rules that apply where you live.

  • the Platform targets personal overseas spending (subscriptions, cross-border shopping, streaming, SaaS and similar);
  • for large cross-border transfers (a single amount ≥ $10,000) we suggest a bank foreign-exchange channel — the Platform is not suited to that;
  • cashing out / routing funds back to a bank card ✗ is strictly prohibited; we terminate service on discovery;
  • when we receive a lawful investigation request from an authorised agency, we provide the necessary data as required by law.

If you are unsure whether this applies to your own situation, we suggest consulting your bank or a qualified professional adviser.

8. Contact

For KYC questions: [email protected] or support.