
Crossmint and GDPR
CertReports found no public GDPR evidence for Crossmint as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 24 Aug 2023
- Expires or valid through
- 30 Jun 2027
- Scope
- Crossmint, Inc., together with its subsidiaries Crossmint Atlas, Inc., Crossmint Horizon Inc., and Crossmint Financial Services US, Inc., relies on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF to receive personal data from the EEA, the United Kingdom, and Switzerland in connection with the services described in our Master Services Agreement and Privacy Policy. Crossmint processes personal data as a controller, as a processor on behalf of enterprise customers in white-label and B2B configurations, and, for identity verification and certain regulated activities, as an independent controller alongside specialised third-party providers. Purposes of processing. Personal data received in reliance on the DPF is processed to: Deliver our contracted services, including wallets (custodial and non-custodial), on-ramp and off-ramp, digital asset orchestration and transfers, stablecoin custody, primary and secondary sales of NFTs and certain non-currency fungible tokens, and Worldstore checkout. Perform KYC and KYB onboarding, including through Persona Identities, Inc. Comply with applicable AML, sanctions, tax, and financial-services laws, including the US Bank Secrecy Act, state money transmission laws, MiCA, GDPR, PSD2, and the FATF Travel Rule. Conduct fraud prevention, transaction monitoring, and security, including automated risk scoring and participation in fraud-intelligence networks. Process payments in line with card network rules. Provide customer support and AI-assisted internal operations, under governance controls that exclude training of general-purpose models. Conduct research, development, and product improvement, primarily using anonymised or aggregated data. Send direct marketing communications, with consent. Manage recruitment and the employment relationship. Categories of personal data. Crossmint processes: Contact and personal identification data (including date of birth, nationality, gender, signature, photographs). Government-issued identification. Biometric data collected for identity verification through Persona (retained for no more than three years). Wallet and transaction data. Source-of-funds and source-of-wealth information. Device and network data, including indicators used for fraud and AML purposes. Online activity, cookie, and local-storage data. Customer service and communications data. Marketing preferences. Employment-application data and HR data of employees of Crossmint Europe, S.L. Categories of recipients. Personal data may be disclosed to: Crossmint group affiliates, including Crossmint Europe, S.L., Crossmint Horizon Inc., Crossmint Atlas, Inc., and Crossmint Financial Services US, Inc. Persona Identities, Inc., acting both as processor and as independent controller for fraud-prevention and identity-graph services. Regulated transaction counterparties, including a U.S. Money Services Business registered with FinCEN and licensed in the relevant states for the US Ramp and Transfer Services pending Crossmint Financial Services US, Inc. obtaining its own licences. Fraud, AML, blockchain analytics, and transaction-monitoring providers. Payment service providers, card processors, and acquiring banks. Customer support and AI-powered operational tools. Project creators, third-party sellers, and fulfillment providers, strictly as necessary to deliver user-initiated transactions. Cloud hosting, security, auditing, and analytics providers. Government authorities and regulators in the jurisdictions where Crossmint operates. Professional advisors and business transferees. Crossmint contractually requires third-party recipients to provide the same level of protection to personal data transferred under the DPF as the DPF Principles require, and remains accountable for onward transfers consistent with the Accountability for Onward Transfer Principle.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Crossmint, Inc.: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 7b0b9d9c8f |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Crossmint GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Crypto and web3 category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Crypto and web3 vendor has GDPR evidence in the index yet.