Privacy Policy
Last Updated: September 28, 2026
Grain Inc. (“Grain,” “we,” “us,” or “our”) takes your privacy seriously. This Privacy Policy describes our practices for collecting, using, storing, protecting, and sharing (collectively, “processing”) your personal information, as well as the rights and choices you may have regarding your personal information. Please read it carefully.
1. What This Privacy Policy Covers
This Privacy Policy covers all Grain customers, including consumer and business customers, and all activities under the Managed Account Program (“MAP”), including consumer deposit accounts, business deposit accounts, digital-asset, stablecoin, stablecoin checkout, wallet, and foreign-exchange (“FX”) services. It applies when you visit or interact with our websites, applications, and any other products and services that link to this Privacy Policy (collectively, the “Services”), or otherwise interact with us, including via email, social media, or other channels.
Whether you are a consumer using a consumer deposit account, an authorized user of a business deposit account, a beneficial owner, director, or authorized representative of a business customer, or another individual transacting through our infrastructure, this Privacy Policy governs the personal information Grain collects and processes about you. Grain may process personal information to provide and administer the MAP and the Services, including for identity verification (Know Your Customer or “KYC” checks), anti-money laundering (“AML”) compliance, sanctions screening, transaction monitoring, fraud prevention, account administration, and other purposes described in this Privacy Policy.
Consumer and business deposit accounts offered through the MAP are held at Erebor Bank, N.A., Member FDIC, subject to applicable account terms, disclosures, and FDIC insurance limits. The applicable account or service terms describe the features available to you.
This Privacy Policy does not apply to personal information collected in the context of employment or recruiting, including information relating to job applicants, employees, or contractors, which is governed by separate policies.
We may provide supplemental notices when required by applicable law or when a particular feature requires additional information, but this Privacy Policy is the single Grain privacy policy for our consumer and business Services.
2. Types of Information We Collect and Categories of Sources
The types of personal information we collect about you depend on your interactions with us and our Services. Below are examples of the types of personal information we collect and the categories of sources.
2.1. Information You Provide Directly
This includes when you use, or apply to use, our Services or otherwise engage or communicate with us, such as:
- Name and contact information, such as full name, email address, SSN, postal address, phone number, and other information used to open or administer a consumer or business account.
- Account information, such as username and password, account settings and preferences, and other similar account-related information.
- Professional information, such as company name, title, and role.
- Corporate ownership and control information, such as names, contact details, and ownership percentages of beneficial owners, directors, and control persons of our corporate clients.
- Government-issued identifiers and identification documents, such as national identification numbers (e.g., Social Security number, taxpayer identification number, or passport number) and government-issued identification documents (e.g., driver’s license, passport, or national identity card).
- Identity verification and compliance information, such as date of birth, physical address, source of funds or wealth documentation, and information relating to Politically Exposed Person (“PEP”) status, sanctions screening, and other KYC and AML requirements.
- Communications and user content, such as information contained in your communications with us (including by phone, email, or otherwise) and any other information you submit to us.
- Payment and account information, such as payment details, billing address, bank account or payment-card information, deposit-account number, balances, transaction history, and direct-deposit or other funding information.
Some of the personal information we collect may be considered sensitive personal information under the data protection laws of certain jurisdictions. Depending on the Services you use and the applicable legal requirements, this may include:
- Biometric data: As part of our identity verification process, we may require you to provide a selfie, photograph, or video of yourself. We may use a third-party identity verification provider to compare your image with the photograph contained in your government-issued identification document. In connection with this process, the provider may extract or generate information about your facial geometry for purposes of verifying your identity. This information may constitute biometric data under the laws of certain states or countries. For more information about our collection and use of biometric data in connection with identity verification, please see our Biometric Data Privacy Notice.
- Personal information that reveals political opinions: As part of our identity verification, compliance, and sanctions screening process, we may collect information about whether you are a PEP. In some jurisdictions, PEP status may be considered information that reveals political opinions or otherwise constitutes sensitive personal information.
We process sensitive personal information only as permitted by applicable law, including where you have provided your consent or where processing is otherwise permitted or required by law, such as to comply with anti-money laundering, sanctions, fraud prevention, or other regulatory obligations.
We generally collect the personal information necessary to provide our Services and fulfill the purposes described in this Privacy Policy. Certain personal information may be required to access or use particular features of our Services. If you do not provide, or do not permit us to collect or process, such information where permitted by applicable law, we may be unable to provide our Services to you.
2.2. Information Collected Automatically
When you visit or interact with our Services, we (and our service providers) may use technologies such as cookies, web beacons, server logs, and other similar tracking technologies (collectively, “tracking technologies”) that automatically or passively collect certain information about your device and usage. This includes:
- Location information, such as general location inferred from an internet protocol (IP) address.
- Device and network information, such as device identifiers, IP address, operating system and version, browser type and settings, hardware identifiers, and other similar device and network information.
- Usage information, including details about your interactions with and use of our Services, such as pages viewed or accessed (including pages viewed before and after interacting with our websites), the length and duration of your visits, the date and time of access, mouse movements, clicks, scrolls, and other interactions with our Services, as well as other similar information about your use of our Services.
For more information about the tracking technologies we use and why, as well as to update your preferences, please see our Cookie Preferences Center by clicking the “Cookie Settings” link in the footer of our website.
2.3. Blockchain, Digital-Asset, Wallet, FX, and Transaction Data
When digital-asset, stablecoin, stablecoin checkout, wallet, FX, or other transactions are initiated, received, settled, or otherwise processed through our Services, we collect and/or log certain information, some of which may be collected directly from blockchain networks, wallet providers, financial institutions, or other transaction counterparties. This includes:
- Wallet addresses and wallet-account information.
- Transaction metadata, such as transaction IDs, wallet addresses, timestamps, confirmations, network fee information, asset type and amount, stablecoin information, FX currencies and rates, and other transaction details.
- Digital-asset and stablecoin information, such as the type, amount, issuer or source, destination, custody or settlement information, and related blockchain or transaction records.
- FX and payment information, such as currencies exchanged, exchange rates, settlement details, payment instructions, and information about the financial institutions or providers involved in a transaction.
2.4. From Third-Party Partners and Other Sources
We may receive information from third-party service providers and partners, including information shared by our clients in connection with their use of our Services. We also collect information about you from other sources, such as:
- Identity verification and compliance services, credit bureaus, sanctions screening databases, and public databases (including government registers and corporate filings).
- Social media platforms and other publicly or generally available sources.
- Our corporate clients, who may provide us with the personal information of their beneficial owners, directors, authorized representatives, or end-customers to facilitate compliance checks required for transaction processing.
3. How We Use Information
We collect and use personal information for the purposes described below. In certain regions, we are required to have a legal basis for processing your personal information. Generally, our legal bases for processing include consent, contractual necessity, compliance with a legal obligation, and our “legitimate interests” or the legitimate interests of others. The ways we plan to use your personal information, along with the corresponding legal bases, are described below.
- Providing the Services. Operating and supporting our consumer and business Services, opening and administering accounts, including consumer deposit accounts in the Managed Account Program, processing deposits, withdrawals, payments, digital-asset and stablecoin transactions, stablecoin checkout activity, wallet activity, and foreign exchange (“FX”), and communicating with you. Legal Basis: To fulfill our contractual obligations to you and/or our business or financial partners, and our legitimate interest in operating our business.
- Identity Verification, Compliance, and Sanctions Screening. Verifying your identity, conducting background checks, screening against global sanctions lists, evaluating PEP status, and conducting KYC, AML, and counter-terrorist financing (“CTF”) checks. As part of our identity verification process, we may require you to provide a selfie, photograph, or video of yourself, which may be compared with the photograph contained in your government-issued identification document. For more information about our collection and use of biometric data in connection with identity verification, please see our Biometric Data Privacy Notice. We process this information to comply with applicable legal and regulatory requirements and our obligations to banking and other financial services partners, including requirements under the Bank Secrecy Act and applicable regulatory requirements. Legal Basis: To comply with legal obligations to which Grain is subject, or as necessary for our legitimate interests in maintaining essential banking partnerships, preventing financial crime, and operating a compliant and trusted financial platform. Where required by applicable law, we rely on your consent for biometric data.
- Transaction Monitoring and Fraud Prevention. Monitoring and analyzing transaction activity, patterns, device information, and user behavior to detect, investigate, prevent, and mitigate fraud, suspicious activity, money laundering, sanctions evasion, or other unauthorized or illegal activities on our platform. Legal Basis: Our legitimate interest in protecting the safety, security, and integrity of our platform, our banking and payment partners, and our users.
- Improving the Services. Monitoring and analyzing how our Services are accessed and used, evaluating and improving them, understanding our consumer and business users, and developing new consumer and commercial offerings. Legal Basis: Our legitimate interest in enhancing and developing our Services and, where required by applicable law, your consent (for tracking technologies).
- Personalization. Understanding your needs and personalizing your experience with our Services. Legal Basis: Our legitimate interest in offering personalized experiences.
- Marketing. Sending you marketing materials, product updates, and promotional content. Where required by law, we obtain your consent. Legal Basis: Consent, or our legitimate interest in promoting and growing our business.
- Operating and Improving Our Business. Conducting internal operations, such as troubleshooting, analytics, testing, research, and general business functions like accounting, record-keeping, and auditing. Legal Basis: Our legitimate interest in operating our business efficiently or complying with applicable legal obligations (such as tax reporting).
- Managing Our Vendor and Partner Relationships. Managing our relationships with consumer and business users, corporate vendors, financial institutions, digital-asset and wallet providers, FX providers, and other financial partners. Legal Basis: To fulfill contractual obligations or our legitimate interest in maintaining productive user and partner relationships.
- Enforcing Our Agreements and Policies. Enforcing terms, conditions, and other legal agreements governing our Services. Legal Basis: To fulfill our contractual obligations to you, or our legitimate interest in ensuring compliance with our terms.
- Protection and Legal Compliance. Protecting the interests, rights, safety, security, and property of our business, our users, and others, including by making or defending legal claims, and complying with subpoenas, warrants, court orders, or lawful requests from regulators and law enforcement. Legal Basis: To comply with a legal obligation, or our legitimate interest in protecting our legal interests.
- Other Purposes. We may process personal information for additional purposes that we notify you about at or before the time of collection, or otherwise with your consent.
5. Your Privacy Rights and Choices
5.1. Marketing Communications
You may opt out of receiving marketing communications from us by following the unsubscribe instructions in those emails. We will still send you non-promotional, transaction-related messages.
5.2. Cookies and Similar Tracking Technologies
Most web browsers accept cookies by default. If you prefer, you can typically configure your browser to remove or reject cookies. Please refer to your browser’s help documentation for instructions on doing so. You can also manage your cookie preferences at any time by clicking the “Cookie Settings” link in the footer of our website. Please note that removing or rejecting cookies may affect the availability and functionality of certain features of our website. Some browsers include a feature known as “Do Not Track” or DNT. Our website is not designed to respond to “Do Not Track” signals received from browsers.
5.3. Your Privacy Rights
In certain regions (such as the EEA, UK, Switzerland, and various U.S. states), you may have specific rights related to your personal information. These may include:
- Access and Portability. Requesting confirmation of processing and a copy of your personal information. In certain cases, requesting the personal information you have provided to us in a portable format.
- Correction. Requesting correction of inaccurate personal information.
- Deletion. Requesting deletion of your personal information, subject to certain exceptions.
- Restriction or Objection. Objecting to certain processing activities or requesting their restriction in certain circumstances.
- Withdraw Consent. Withdrawing your consent to processing under certain circumstances (if we are relying on your consent to process your personal information). If you withdraw your consent, we may not be able to provide certain products or services to you.
Please note: The privacy rights described above are not absolute and are subject to certain limitations under applicable law. For example, because Grain is subject to statutory AML and financial record-keeping laws, we are legally required to retain identity verification (KYC) records, transaction monitoring logs, and associated transaction data for mandatory minimum periods (see Section 7, “How Long We Retain Information”). Consequently, we may be unable to delete or restrict the processing of your compliance-related personal information upon request if a statutory or contractual retention mandate applies.
5.4.1. U.S. State Privacy Disclosures
5.4.1.1. Scope and Applicable Exemptions
Depending on where you live, you may have additional privacy rights under applicable state law. These rights are subject to applicable exemptions, exceptions, verification requirements, and other limitations.
Some information collected or processed in connection with financial products and services may be subject to sector-specific exemptions, including exemptions under the Gramm-Leach-Bliley Act or similar financial privacy laws. The categories of personal information Grain collects, the sources of that information, the purposes for which it is used, and the categories of parties with whom it is shared are described in Sections 2 through 4 of this Privacy Policy.
5.4.1.2. Rights Under Comprehensive State Privacy Laws
Where applicable, you may have the right to:
- Confirm whether Grain processes your personal information and request access to that information;
- Request correction of inaccurate personal information;
- Request deletion of your personal information, subject to applicable exceptions;
- Request a portable copy of certain personal information;
- Opt out of the sale or sharing of personal information, targeted advertising, or certain profiling activities;
- Limit certain uses or disclosures of sensitive personal information;
- Appeal Grain’s denial of a privacy request;
- Use an authorized agent to submit a request on your behalf, where permitted by applicable law; and
- Receive equal treatment and not be discriminated against for exercising your privacy rights.
To submit a request, contact us at privacy@grain.inc with the subject line “Data Subject Rights Request.” You may also use any additional request method identified on our website or in this Privacy Policy. We may require additional information to verify your identity and authority to submit the request. If we deny your request, we will explain the basis for the denial and, where required by applicable law, provide instructions for submitting an appeal.
5.4.1.3. State-Specific Financial Privacy Disclosures
The following disclosures apply to the extent required by applicable law and supplement the other privacy and information-sharing disclosures in this Privacy Policy and any applicable Regulation P notice.
- California Residents. In accordance with California law, Grain will not share nonpublic personal information collected about California residents with nonaffiliated third parties except as permitted or required by law, including with your consent or as necessary to service your accounts.
- Vermont Residents. In accordance with Vermont law, Grain will not share nonpublic personal information collected about Vermont residents with nonaffiliated third parties except as permitted or required by law, including with your consent or as necessary to service your accounts.
- Residents of Alaska, Illinois, Maryland, and North Dakota. In accordance with applicable law, Grain will not share nonpublic personal information with nonaffiliated third parties for their own marketing purposes or for joint marketing without your authorization, except as permitted or required by law.
- Residents of Massachusetts, Mississippi, and New Jersey. In accordance with applicable law, Grain will not share nonpublic personal information obtained in connection with your deposit-account or share-account relationship, as applicable, with nonaffiliated third parties for their own marketing purposes or for joint marketing without your authorization, except as permitted or required by law.
5.5. Submitting a Request
To exercise your privacy rights, please email us at privacy@grain.inc with the subject line “Data Subject Rights Request.” Before we can fulfill your request, we must verify your identity. If we cannot verify your identity, we may decline the request.
6. How We Protect Information
We use commercially reasonable administrative, physical, and technical safeguards designed to protect your personal information against unauthorized access, loss, alteration, or disclosure. However, no internet transmission or electronic storage method is 100% secure. If we are required by law to inform you of a security breach affecting your personal information, we will notify you in accordance with applicable law.
7. How Long We Retain Information
We retain personal information for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law. For instance, we may keep your information to comply with our legal or regulatory obligations, to resolve disputes, to enforce our agreements, to comply with an actual or anticipated investigation or litigation, or as otherwise permitted by law.
Specifically, to comply with AML laws, CTF frameworks, banking and financial-services requirements, and the requirements of our regulated partners, we may be legally and contractually obligated to retain identity verification (KYC) records, source of funds documentation, sanctions screening history, transaction monitoring alerts, deposit-account records, digital-asset and stablecoin records, wallet information, FX records, and other transaction records for a minimum of ten (10) years after the termination of the applicable business relationship or closure of the applicable consumer or business account, or as otherwise mandated by applicable law.
For other personal information, factors we consider in determining retention periods include the statute of limitations for potential legal claims, whether the data has been aggregated or pseudonymized, and our legitimate business needs.
8. Cross-Border Data Transfers
We and our service providers may collect, process, and store your personal information in countries outside of your home country, including the United States, where data protection laws may differ from those in your jurisdiction.
When transferring personal information to other countries we take measures to comply with data protection laws applicable to those transfers. In particular, when transferring personal information outside the EEA, UK, or Switzerland to a country with data protection laws that do not offer an equivalent level of data protection to your country, we implement appropriate safeguards in accordance with applicable data protection laws, such as Standard Contractual Clauses (EU SCCs) or the UK International Data Transfer Addendum. For more information, please contact us using the details below.
9. Other Important Information
9.1. Links to Third-Party Websites
Our websites may contain links to third-party services. We are not responsible for the privacy practices of those third parties and encourage you to read their policies.
9.2. Children’s Privacy
Our Services are not intended for or directed to individuals under the age of 18. We do not knowingly collect personal information from minors.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by revising the “Last Updated” date at the top of this Privacy Policy and posting the updated version, or by providing more direct notice (such as via email) as required by law.
11. How to Contact Us
If you have any questions, comments, or concerns about this Privacy Policy or our privacy practices, please contact us at:
Grain Inc.Attn: Grain Privacy
Email: privacy@grain.inc
If you are in the EEA or UK and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.