Last updated: 9 September 2026
Template draft. This page is an English template prepared for launch readiness. Legal entity name, registered address, governing law, regulator references and card program partner names must be confirmed by legal counsel before the site goes live.
1. Who we are
Wirego ("we", "us") operates the website www.vccpt.com and provides card issuing, card management, dashboard and API services through supported card programs. [Legal entity name, registration number and registered address to be confirmed.] Questions about this policy can be sent to [email protected].
2. Data we collect
2.1 Contact form
When you submit the contact form we collect the information you provide: nickname, work email, Telegram or WhatsApp contact, company name, country or region, estimated monthly spend, industry or use case, required card type and any message you write. We also record the page you were on, the referring site, campaign parameters (UTM values and advertising click identifiers), your language and device type, the time the form was opened and submitted, and the country derived from your IP address. Your IP address itself is stored only as a salted hash used for abuse prevention.
2.2 Website analytics
We record first-party usage events such as page views, sections viewed, buttons clicked and form interactions, linked to a random session identifier that is not tied to your identity. If you accept analytics cookies we also use Google Analytics 4 with IP anonymisation and Consent Mode; see the Cookie Policy.
2.3 Account and verification data
If you open an account, our card program partners and we may collect identity and business verification information as described in the KYC / AML Policy. That processing is governed by the account terms you accept at onboarding.
2.4 Data we ask you not to send
Do not submit card numbers, CVV codes, passwords, wallet private keys, seed phrases or full identity document numbers through the contact form. Submissions that appear to contain such data are rejected automatically and are not stored.
3. How we use data
- To review your request, assess whether our card programs fit your use case and respond to you, normally within 48 hours.
- To route your enquiry to a sales representative. Lead notifications are delivered to our team through Telegram; the message contains the details you submitted.
- To understand how the website is used and improve its content and conversion flow.
- To prevent spam, abuse and fraud, and to comply with legal obligations.
Legal bases (where GDPR or similar laws apply): performance of pre-contractual steps at your request, our legitimate interests in operating and securing the website and responding to enquiries, your consent for analytics cookies, and compliance with legal obligations.
4. Sharing
We share data with service providers that host and operate the website and our internal tools, currently including Cloudflare (hosting, database and edge network), Telegram (internal lead notifications) and Google (analytics, only with consent). We share verification and transaction data with card program partners, banking partners and regulators where required. We do not sell personal data.
5. International transfers
Our providers may process data outside your country. Where required we rely on appropriate safeguards such as standard contractual clauses.
6. Retention
Contact form records are retained for up to 24 months after your last interaction, or longer where needed to establish, exercise or defend legal claims. Website analytics events are retained for 14 months. Verification records are retained for the period required by applicable anti-money laundering law, typically five years after the end of the relationship.
7. Your rights
Depending on where you live you may have the right to access, correct, delete or restrict the use of your personal data, to object to processing, to data portability, and to withdraw consent. To exercise these rights contact [email protected]. You may also lodge a complaint with your local data protection authority.
8. Security
We use encryption in transit, access controls, hashed IP storage and audit logging for our lead records. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
9. Children
Our services are intended for businesses and adults. We do not knowingly collect data from anyone under 18.
10. Changes
We may update this policy from time to time. The date at the top of the page shows the latest version.