MV8 — app.mv8.life

Privacy notice

Last updated 4 July 2026 · Version v0.2

Draft — pending review by Australian fintech/crypto legal counsel before the app surface goes live. Section structure and topic coverage are correct; prose may be refined.

MV8 Pty Ltd (operating the Motive 8 brand, referred to as 'we', 'us' and 'our' in this notice) operates the MV8 customer, merchant, and admin app at app.mv8.life. This notice explains how we handle personal information collected through that app — account, identity, wallet, and transaction data.

MV8 Pty Ltd is the Australian company responsible for the personal information described in this notice.

A separate notice at www.mv8.life/privacy covers the public marketing site, which collects only anonymous analytics.

1. Who we are and how to reach us

MV8 Pty Ltd, operating the Motive 8 brand, is the entity responsible for your personal information under this notice.

Our AML/CTF Compliance Officer oversees customer due diligence and privacy operations. In MV8's first phase this role is held by the founder; once a dedicated officer is appointed, contact details below will be updated.

For any privacy enquiry, request, or complaint, email privacy@mv8.life. We will acknowledge within 7 days and respond within 30 days. If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.

2. What we collect

We use a tiered customer due diligence (CDD) model under our AUSTRAC AML/CTF programme. Each tier collects only what is reasonably necessary for the activity it unlocks — so most customers who only earn and redeem at participating merchants stay at Tier 1 indefinitely.

2.1 Customer identity — by CDD tier

  • Tier 1 (Basic) — at wallet creation: first name, last name, mobile phone number (verified via SMS OTP).
  • Tier 2 (Standard) — when your balance exceeds A$1,000 AUD-equivalent or when you enable gifting: date of birth and residential address, verified through Frankie One.
  • Tier 3 (Enhanced) — when your balance exceeds A$5,000 AUD-equivalent, when monitoring flags an alert, or when you are identified as a Politically Exposed Person: a government-issued ID document (drivers licence or passport), verified through Frankie One against government databases.
  • The A$1,000 and A$5,000 thresholds are indicative planning figures and will be confirmed before launch with reference to our formal ML/TF risk assessment and AUSTRAC guidance.

2.2 Wallet and transaction data

  • Your MV8 custodial wallet address on Solana, and your Hearts balance.
  • Transaction records — earn events, voucher claims, redemptions, gifts, inbound deposits, settlements — including amounts, timestamps, AUD-equivalent values at the time, and on-chain transaction hashes.
  • Smart-contract memo tags used to attribute each on-chain event to a specific MV8 flow.
  • For peer-to-peer gifting (Phase 2): originator and beneficiary identity data captured under the FATF Travel Rule.

2.3 NFC fob registration

  • The unique identifier (UID) of any MV8 NFC fob you pair with your account.
  • The merchant or point-of-sale at which the fob was first tapped, and the pairing timestamp.

2.4 Device, session, and operational data

  • IP address, approximate location derived from IP, device type, browser, and app version.
  • Authentication session tokens (issued by Supabase under their asymmetric-JWT framework).
  • Authentication events, error logs, and security telemetry — used to keep the app running and to detect abuse.
  • Information you submit through support channels — only used to respond to your enquiry.

3. Why we collect it

  • To meet our AUSTRAC AML/CTF obligations — VASP registration, customer due diligence, suspicious matter reports (SMRs), Travel Rule data, and ongoing transaction monitoring.
  • To operate your account — create and secure your custodial wallet, deliver earn events, process voucher and gift flows, settle merchant balances.
  • To detect and prevent fraud — velocity checks, balance threshold alerts, and pattern detection across the customer and merchant base.
  • To deliver regulatory reporting — material change notifications, annual compliance reports, and other communications required by AUSTRAC, ASIC, or the OAIC.
  • To send service communications — SMS OTPs for sign-in and sensitive actions, transactional notifications.
  • Where you have opted in, to compile aggregate product analytics that help us improve the app. We do not use customer PII to profile you for advertising.

4. How long we keep it

AML/CTF records — customer identity records, transaction records, KYC verification outcomes, AUSTRAC reports we submit, Travel Rule records, and merchant onboarding documentation — are retained for 7 years from the end of the customer relationship or 7 years from the transaction date, as required by Australian AML/CTF law. These records must remain retrievable for AUSTRAC inspection during that period.

Other personal information not covered by the 7-year obligation is retained no longer than necessary for the purpose for which it was collected, in line with the Australian Privacy Act.

Device, session, and operational logs are typically retained for up to 90 days for security, abuse prevention, and incident investigation.

When a retention window expires, records are either securely deleted or anonymised — PII fields are nulled in place while non-PII columns and primary keys remain so aggregate analytics stay meaningful. Anonymisation is enforced by scheduled retention jobs that log every action they take.

Where you request erasure, the AML/CTF 7-year obligation applies as a retention exception — see Section 7.

5. Who else gets it

We use a small set of vetted sub-processors to deliver the platform. Each handles only the personal information needed for the function it provides, under a written data processing agreement consistent with the Australian Privacy Principles.

5.1 Sub-processors

  • Supabase — authentication and primary database hosting; row-level security, asymmetric JWT signing, application-layer encryption for sensitive fields.
  • Vercel — application hosting and edge delivery, including server logs.
  • Frankie One — automated KYC verification for Tier 2 and Tier 3, and for merchant onboarding.
  • Twilio — SMS OTP delivery for Tier 1 phone verification and sensitive-action confirmations.
  • Helius — Solana blockchain indexing and webhook delivery, used to detect on-chain events such as inbound deposits and earn-event confirmations.

5.2 Regulators, law enforcement, and the courts

  • AUSTRAC — for suspicious matter reports (SMRs), threshold transaction reports (TTRs) where applicable, annual compliance reports, and information requests under the AML/CTF Act. Where we file an SMR, we are prohibited by law from notifying the affected customer (the tipping-off offence).
  • Law enforcement and other regulators — only on a valid production order, search warrant, subpoena, or equivalent lawful authority.
  • Courts — under court order or other compulsion of law.

5.3 What we do not do

  • We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
  • We do not run third-party advertising, behavioural targeting, or cross-site tracking inside the app.
  • We do not use your personal information to train external AI models.

6. Cross-border disclosure

Some of our sub-processors process personal information outside Australia — primarily in the United States and, depending on routing, in the European Union. Where this is the case, we take reasonable steps to ensure the overseas recipient handles your personal information consistently with the Australian Privacy Principles, through a combination of contractual obligations and the provider's own security and privacy certifications.

Frankie One processes data in Australia. Supabase, Vercel, Twilio, and Helius primarily process data in the United States. Helius and Vercel edge endpoints may be located worldwide. The list of locations may change as sub-processors evolve their infrastructure; this notice will be updated when material changes occur.

7. Your rights under the Privacy Act

You have the right to ask us to access or correct any personal information we hold about you, and to complain about how we have handled your information. You can exercise these rights either by emailing privacy@mv8.life or by using the data export and erasure controls in the app (see Section 8).

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to fix inaccurate or out-of-date information.
  • Erasure — request that we delete your data. Erasure is constrained by the AML/CTF 7-year retention obligation: we will erase what we can immediately, and the response will itemise exactly which records are being retained until a specified future date, when each class is re-evaluated.
  • Withdraw consent — for non-essential cookies and analytics, at any time, in Settings → Privacy → Cookies and consent (see Section 9).
  • Complaint — to us in the first instance; if you are not satisfied, you can refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.

8. Data Subject Rights endpoints

In addition to the email pathway in Section 7, you can exercise the access and erasure rights directly inside the app. The UI lives under Settings → Privacy and calls the following endpoints, which are authenticated by your active session.

  • GET /api/v1/customers/{id}/data-export — returns a single JSON bundle of all of your customer-scoped data: profile, transactions, vouchers, NFC fobs, gifting history, and audit-log entries that reference your customer ID.
  • POST /api/v1/customers/{id}/erasure-request — initiates erasure. The response lists exactly what we erase immediately and what we retain under the AML/CTF 7-year obligation, together with the date when each retained class is re-evaluated. This action requires you to re-authenticate via SMS OTP.
  • Every data export and erasure request is itself recorded in our audit log under the event types dsr.export_requested, dsr.erasure_requested, and dsr.erasure_executed. Audit-log entries for these events are themselves retained for 7 years.

9. Cookies and consent

Unlike the public marketing site at www.mv8.life — which uses only anonymous analytics and runs without cookies or a consent banner — the authenticated app surface holds your account, wallet, and transaction data. Cookies and similar technologies are needed for parts of it to work, so the app runs a full consent flow with granular controls. You can revisit the flow at any time in Settings → Privacy → Cookies and consent.

  • Essential — strictly necessary for authentication, session management, security (CSRF protection), and fraud prevention. These cannot be turned off; without them, the app cannot operate.
  • Functional — optional preferences such as language, theme, and remembered UI state. You can turn these on or off.
  • Analytics — optional anonymised product analytics that help us improve the app. You can opt in or out.
  • No pre-ticked boxes. No dark patterns. The consent UX uses the same calm brand voice as the rest of the app, and your choice is recorded with a timestamp and the version of this notice in force at the time.

10. Data breach notification

If we become aware of an eligible data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC as soon as practicable, as required under the Notifiable Data Breaches scheme. We also operate an internal target to detect, classify, and escalate suspected breaches within 72 hours of first signal, which feeds into the 'as soon as practicable' standard.

11. Security

We protect your personal information through a defence-in-depth security programme: server-side enforcement of access controls, row-level security in Postgres, encrypted storage at rest, an application-layer cipher for the most sensitive fields, asymmetric JWT signing with quarterly key rotation, and hardware multi-factor authentication for staff who can access PII.

The full set of controls — covering smart-contract security, off-chain services, data protection, identity, key management, and incident response — is documented in our internal MV8 Security Architecture & Controls. We do not restate the details here to keep this notice focused on what affects you directly.

12. How we notify changes

For material changes — for example, a new sub-processor, a new category of personal information, or a change in retention — we will show an in-app notice and, where appropriate, send you a message at next sign-in. For minor or non-material changes, we will update the 'last updated' date at the top of this page.

We preserve a copy of the version of this notice in force at the time of each consent action and material transaction, so the basis on which information was collected is always traceable.

13. Effective date and version

Effective date: 16 June 2026. Version v0.1. This is a draft pending review by Australian fintech/crypto legal counsel before the app surface goes live. The companion privacy notice for the public marketing site at www.mv8.life/privacy covers handling on that surface and is maintained separately.