crypt.pe — AML and KYC Notice
Effective Date: 30 May 2026 Last Updated: 12 September 2026 Operator: 3-102-969985 S.R.L. (Sociedad de Responsabilidad Limitada), registered with the National Registry (Registro Nacional) of Costa Rica. Domicile: Escazú, San José, Costa Rica.
This notice explains our position on anti-money-laundering (AML) and know-your-customer (KYC) practices. It is written deliberately so that you, the user, understand both what we do and what we do not do.
1. Our position in one paragraph
Based on the operator's current assessment, crypt.pe provides non-custodial software and does not take possession or control of customer funds or private keys. We do not hold funds, do not move funds, and do not perform the virtual-asset activities — exchange, transfer, custody, administration, or control of virtual assets — that define a virtual asset service provider (VASP) under Article 15 quáter of Costa Rican Law No. 7786 (as added by Legislative Decree No. 10961, published in La Gaceta on 19 June 2026) or under FATF guidance. On that basis, our current assessment is that our activity falls outside the SUGEF registration regime applicable to VASPs in Costa Rica, and we do not currently perform KYC or customer due diligence (CDD) on our users. Regulatory classification depends on the activities actually performed and may change as legislation, regulations and regulatory guidance develop. We actively monitor the implementing regulations that CONASSIF and SUGEF will issue under the new regime; the operator will implement registration, verification, reporting or other controls where required by applicable law, and will give affected users reasonable notice.
2. What this means in practice
- We do not verify your legal identity, ask for government-issued ID, photographs, proof of address, source-of-wealth documentation, or beneficial-ownership information at sign-up.
- We do not screen each individual cryptocurrency transaction against sanctions lists in real time.
- We do not issue tax statements (e.g., 1099, P60, AIS) on behalf of users; that is your responsibility in your jurisdiction.
- We do not report transactions to financial-intelligence units except where compelled by valid legal process in our jurisdiction.
What we do instead — platform-layer safeguards
Not performing KYC does not mean doing nothing. Because crypt.pe controls the software layer (pages, invoices, API keys, webhooks) even though it never controls funds, we apply proportionate safeguards where we actually have reach:
- Address screening at onboarding. Wallet addresses added to an account can be checked against public sanctions lists and reputable on-chain analytics flags before they are accepted; flagged addresses can be refused or removed.
- Abuse-pattern monitoring. We monitor platform-level signals — mass account creation, disposable-email clusters, impersonation of known brands on payment pages, phishing-style page content — and suspend accounts that match them.
- Takedown responsiveness. Payment pages used for fraud, phishing, or sale of illegal goods are removed on discovery or on substantiated report (see Section 7).
- Auditability by design. Every payment facilitated through the Service is a public on-chain transaction. Unlike an opaque internal ledger, the complete flow of funds is permanently visible to any investigator, analytics firm, or court with no cooperation needed from us.
These measures target what a software layer can genuinely influence. They are not, and are not represented to be, a substitute for the regulated AML programme of a custodial financial institution — precisely because we do not perform the custodial activities that would require one.
3. What we expressly do not permit
Even though we do not perform KYC, using the Service for any of the following is strictly prohibited:
- Money laundering — using the Service to layer, integrate, or otherwise disguise the source of unlawful proceeds.
- Terrorist financing — receiving or facilitating payments for, or on behalf of, organisations or individuals designated as terrorists by your jurisdiction or by competent international bodies.
- Sanctions evasion — receiving payments from, or sending payments on behalf of, individuals, entities, or jurisdictions subject to sanctions imposed by the United Nations, the European Union, the United Kingdom, the United States (including OFAC SDN), or the Republic of Costa Rica.
- Fraud, theft, extortion, ransomware, or any other criminal activity under the laws of your jurisdiction or ours.
- Receiving payments for goods or services that are illegal in either your jurisdiction or in the Republic of Costa Rica.
- Operating an unlicensed money-services business, unregistered exchange, or unauthorised securities offering through crypt.pe links.
- Mixing, tumbling, chain-hopping, or laundering services, or any activity primarily designed to obfuscate the origin of cryptocurrency.
By using the Service you confirm that none of your activity falls within any of the categories above.
4. Our rights — including the right to suspend
We reserve the right, in our sole reasonable discretion and without prior notice, to:
- suspend or terminate any account that we reasonably suspect is being used for any prohibited activity listed in Section 3;
- disable profile pages, API keys, and webhook deliveries;
- block specific wallet addresses from being added to user accounts (for example, addresses that appear on public sanctions lists or are flagged as belonging to known illicit-finance clusters by reputable on-chain analytics providers);
- report suspected illicit activity to the competent authorities of the Republic of Costa Rica — including the Financial Intelligence Unit (Unidad de Inteligencia Financiera, UIF) of the Costa Rican Drug Institute (Instituto Costarricense sobre Drogas, ICD) — or other relevant jurisdictions where we are legally compelled or reasonably believe it is appropriate to do so;
- preserve and disclose account records and on-chain data in response to a lawful order from a court, regulator, or law-enforcement agency with jurisdiction over us;
- cooperate with on-chain analytics partners, law-enforcement, and victims of theft in the lawful tracing of funds, recognising at all times that we do not have custody and cannot freeze or return funds.
Because the Service is non-custodial, account suspension prevents future use of the Service but does not affect cryptocurrency already received on-chain. We have no ability to freeze, return, or seize funds.
5. Sender-side responsibility
When you accept a payment through crypt.pe, you are accepting it directly from the sender's wallet, on-chain, without our involvement in the flow of funds. The sender's identity, the source of their funds, and the legality of their transaction in their own jurisdiction are matters between the sender and the authorities that apply to them.
If you are operating a business at scale and accept payments from many counterparties, you should evaluate whether you have independent KYC/AML obligations under the laws applicable to you. The Service does not perform that function for you.
Practical guidance for merchants
While the Service imposes no KYC on you, good practice protects your own business:
- Keep records. Every payment through crypt.pe produces an on-chain transaction hash and a receipt; export the CSV regularly and retain it with your normal accounting records for the period required by applicable law, documented company policy and professional advice.
- Know your obligations, not ours. A freelancer invoicing clients occupies a very different regulatory position from a platform aggregating payments for third parties. If you resell payment collection to others, seek local legal advice — you may be the party that needs registration, not us.
- Watch for red flags. Overpayments followed by refund requests to a different address, payers insisting on unusual chains for no reason, or requests to split one payment across many wallets are classic laundering patterns. Decline them; you are never obliged to accept a payment.
- Verify refund addresses. Refunds should be sent only to a supported refund address verified with the payer through a channel you trust. Do not automatically treat the original sending address as a valid refund address: centralized exchanges and custodial wallets often send withdrawals from shared operational wallets, so returning assets to such an address might not credit the original customer. Require additional verification where necessary to prevent fraud, sanctions violations or misdirected payments.
6. Future changes
The Company actively monitors regulatory developments, including:
- the implementing regulations of Article 15 quáter of Law No. 7786 (Costa Rica's VASP registration regime), to be issued by CONASSIF and administered by SUGEF;
- the applicable AML/CFT framework of the Republic of Costa Rica (Law No. 7786, as amended by Laws No. 8204 and No. 9449);
- FATF Travel Rule guidance for virtual assets;
- EU MiCA implementation in the European Union;
- equivalent rules in other major jurisdictions.
If our activity becomes regulated such that KYC or other compliance steps are required, we will:
- update this Notice;
- notify affected users with reasonable advance notice;
- introduce the minimum necessary identity-verification flow; and
- continue to remain non-custodial.
7. Reporting suspected abuse
If you believe an account on crypt.pe is being used for any of the prohibited activities listed in Section 3, please report it to us at legal@crypt.pe with the subject "abuse report" and any supporting information. We treat such reports seriously and confidentially.
8. Governing law
This Notice is governed by the laws of the Republic of Costa Rica. The competent courts of San José, Costa Rica have jurisdiction over any dispute arising from it.
9. Contact
© 2026 3-102-969985 S.R.L. · Escazú, San José, Costa Rica.