Legal / Anti-Money Laundering and Counter-Terrorist Financing Policy

Anti-Money Laundering Policy

Applies worldwide

Version 1.0 Last updated: 10 October 2026

Please note: OnFire has zero tolerance for money laundering, terrorist financing and sanctions evasion. We work only with regulated partners for payments and cards, and we will report suspicious activity to the authorities where the law requires or permits it.

About This Policy

This Anti-Money Laundering and Counter-Terrorist Financing ("AML/CTF") Policy sets out how OnFire prevents its Services from being used to launder money, finance terrorism, evade sanctions or commit other financial crime. It applies to all users, sellers, hosts, drivers, couriers, business users, employees and contractors of OnFire. It should be read together with our Know Your Customer (KYC) Policy and our Terms of Service.

1. Our Role and Our Regulated Partners

OnFire is a platform and marketplace. It is not a bank, an electronic money institution or a money transmitter, and it does not itself hold customer funds as a regulated institution. Regulated financial services on OnFire are provided by licensed partners, including:

  • Stripe, for payment processing, and for payouts to sellers, hosts, drivers and other users through Stripe Connect
  • Card issuing partners, such as Wallester AS, an electronic money institution authorised in Estonia, and Stripe Issuing, which issue OnFire payment cards

These partners are obliged entities under anti-money laundering law and run their own AML/CTF programmes. OnFire supports those programmes, and on top of them applies its own controls, described in this policy, to the activity it can see on its platform, such as marketplace listings, bookings, transactions between users and account behaviour.

Where any crypto-asset feature is made available, it will be provided through, or in partnership with, a provider authorised for that activity in the relevant jurisdiction, and this policy applies to it in full.

3. Governance and Responsibility

OnFire’s senior management is responsible for this policy and approves it. A designated Compliance Officer oversees its day-to-day operation, including risk assessment, investigations, decisions on suspicious activity, liaison with our partners and with authorities, and staff training. The Compliance Officer has the independence, authority and resources needed for the role and reports directly to senior management.

This policy is reviewed at least once a year, and whenever there is a material change in the law, our products, our partners or our risk exposure.

4. Our Risk-Based Approach

We assess the money laundering and terrorist financing risks our Services are exposed to, and apply controls proportionate to that risk. Our assessment considers:

  • Customer risk: who the user or business is, its ownership, and whether it is a politically exposed person
  • Product risk: for example, payment cards, payouts, peer-to-peer transfers and high-value marketplace listings carry more risk than messaging
  • Geographic risk: where the user lives and transacts, including countries identified as high-risk by the European Commission or FATF
  • Transaction risk: amounts, frequency, velocity and patterns of activity
  • Channel risk: for example, accounts opened and used entirely remotely

The result determines the level of verification, the limits that apply, and how closely an account is monitored.

5. Customer Due Diligence

Before enabling money features or payouts, we and our partners identify and verify users and businesses, including the ultimate beneficial owners of businesses, and understand the purpose and intended nature of the relationship. Enhanced due diligence applies to higher-risk customers, including politically exposed persons and customers connected to high-risk countries. The full process is described in our Know Your Customer (KYC) Policy.

We do not open or maintain anonymous accounts, or accounts in obviously fictitious names, for any feature that moves money.

6. Sanctions Screening

We and our partners screen users, businesses and their beneficial owners against the sanctions lists of the European Union, the United Nations, the United Kingdom and the United States (OFAC), when they are onboarded and on an ongoing basis as lists change. We do not provide money features to, and do not allow payments to or from, sanctioned persons or entities, persons owned or controlled by them, or residents of comprehensively sanctioned countries or regions.

Where we find a confirmed match, we freeze or block the relevant funds and transactions as required by law, and report to the competent authority.

7. Transaction and Activity Monitoring

We monitor activity on the platform, and share relevant signals with our partners, to detect behaviour that may indicate financial crime. Examples include:

  • Splitting payments into smaller amounts to avoid limits or checks (structuring)
  • Money moving in and straight out again with no apparent purpose
  • Activity that does not match what we know about the user or business
  • Listings, bookings or orders that are fake, overpriced or never fulfilled, or a buyer and seller who appear to be the same person or acting together
  • Unusual refund, chargeback or cancellation patterns
  • Many accounts linked to the same device, payment method or identity
  • Transactions connected to high-risk or sanctioned countries

Alerts are reviewed by trained staff. We may ask you for information about a transaction, its purpose or the source of the funds.

8. Prohibited Activity

You must not use OnFire to:

  • Launder the proceeds of crime, or hide where money comes from
  • Finance terrorism or the proliferation of weapons of mass destruction
  • Evade sanctions, or deal with sanctioned persons or countries
  • Commit fraud, including payment fraud, identity fraud, scams and fake listings
  • Move money on behalf of someone else, or act as an unlicensed money transmitter
  • Buy, sell or facilitate anything prohibited by our Acceptable Use Policy or Supported Business Types

9. Reporting Suspicious Activity

Where we know, suspect or have reasonable grounds to suspect that activity involves money laundering, terrorist financing or sanctions evasion, we escalate it to the Compliance Officer, inform the relevant partner, and, where the law requires or permits, report it to the competent authority. In Ireland, that is the Financial Intelligence Unit (FIU Ireland) of An Garda Síochána and the Revenue Commissioners; in the United States, the appropriate federal authorities.

The law prohibits us from telling anyone, including the person concerned, that a report has been made or that an investigation is under way ("tipping off"). This is why we may be unable to explain some account decisions.

10. Actions We May Take

To meet our legal obligations and protect the platform, we may, without prior notice where the law requires:

  • Ask for further information or documents
  • Refuse, delay or reverse a transaction, booking or order
  • Hold or delay payouts, or restrict money features
  • Lower or apply limits to an account
  • Suspend or close an account
  • Freeze funds where required by sanctions law
  • Share information with our regulated partners and with law enforcement and regulatory authorities

Requests from authorities are handled under our Law Enforcement Requests policy.

11. Record Keeping

We keep customer due diligence records and transaction records for five years after a business relationship ends or a transaction is completed, or longer where the law or an ongoing investigation requires. Records are kept securely, with restricted access, and are processed in line with the Privacy Policy.

12. Training and Awareness

Employees and contractors whose work touches payments, payouts, marketplace trust and safety or customer support receive AML/CTF and sanctions training when they join and at least once a year, so they can recognise and escalate suspicious activity. Breaches of this policy by staff may lead to disciplinary action.

13. Raising a Concern

If you suspect that someone is using OnFire for money laundering, terrorist financing, fraud or sanctions evasion, report it to [email protected], or use the report option on the listing, profile or message. Reports are treated confidentially. Do not confront the person or tell them you have reported them.

14. Who We Are and How to Contact Us

This policy is issued by the OnFire company that provides the Services to you: OnFire Messenger Ltd., registered in Ireland under company number 796932, for users in the European Economic Area, and OnFire Messenger Inc., a Delaware corporation, for users in the United States.

OnFire Messenger Ltd.
Registered Office: 77 Camden Street Lower, Dublin, D02 XE80, Ireland

OnFire Messenger Inc.
254 Chapman Rd, Ste 209, Newark, DE 19702, United States

Questions about this policy, or about a verification or account review: [email protected]. Questions about how we handle your personal data: [email protected]. Everything else: [email protected].

Changes to this policy. We review this policy at least once a year and whenever the law, our products or our partners change. Material changes will be announced in the OnFire App or by email before they take effect, unless a change is required immediately by law.

This Anti-Money Laundering and Counter-Terrorist Financing Policy was last updated on 10 October 2026.

Version 1.0 — last updated 30 September 2026.