← Back home

Legal Overview

Prepared for wallet client legal and compliance teams · CLVRBRIDGE, LLC

1. What CLVRBRIDGE Does

CLVRBRIDGE is a non-custodial smart routing API for crypto wallets. When a wallet's end user initiates a buy, sell, or swap, our engine queries 34 liquidity providers in real time — exchanges, on/off-ramps, P2P markets, and DEX aggregators — and routes the trade to the provider offering the best effective price. We never hold, control, or transmit user funds. The trade executes directly between the wallet's end user and the winning provider. CLVRBRIDGE operates solely as a technology service provider.

2. Non-Custodial Model

Funds flow directly from the end user to the liquidity provider. CLVRBRIDGE is not a party to the transaction and does not take custody at any point.

End User── funds ──▶Winning Provider── crypto/fiat ──▶End User
CLVRBRIDGE routes the trade and never touches funds.
  • CLVRBRIDGE does not custody, hold, or control user assets.
  • CLVRBRIDGE does not have access to user private keys.
  • CLVRBRIDGE does not transmit funds — the trade settles directly between the user and the provider.
  • This structure creates zero new custody obligations for the wallet client.

3. KYC Pass-Through Flow

For providers that accept relayed KYC, CLVRBRIDGE maps the wallet's existing user verification to the provider's requirements and relays the credential. The wallet retains full KYC/AML responsibility for its end users at all times.

Wallet KYC── credential ──▶CLVRBRIDGE Relay── mapped data ──▶Provider
Wallet retains KYC responsibility. CLVRBRIDGE does not store PII. Provider verifies credential.
  • Compatible providers: KYC data is relayed via API. The end user does not re-verify.
  • Non-compatible providers: CLVRBRIDGE flags this before routing. The wallet decides whether to route and expose the user to a second KYC flow.
  • Data retention: CLVRBRIDGE does not store end-user PII after relay. All relays are logged in an immutable audit trail for compliance review.
  • Audit trail: Each relay includes a cryptographic hash for integrity verification.

4. Provider Licenses & Jurisdictions

The following is a representative sample of providers in the CLVRBRIDGE routing engine and their primary regulatory jurisdictions. This list is updated quarterly.

ProviderTypePrimary JurisdictionLicense / Registration
KrakenExchangeUnited StatesFinCEN MSB, state MTLs
GeminiExchangeUnited StatesNYDFS Trust Charter
CoinbaseExchangeUnited StatesFinCEN MSB, state MTLs
Binance.USExchangeUnited StatesFinCEN MSB
OKXExchangeGlobal (various)Multiple jurisdictional registrations
BitsoExchangeMexico / Latin AmericaLocal regulatory registrations
BybitExchangeGlobal (various)Multiple jurisdictional registrations
Crypto.comExchangeGlobal (various)Multiple jurisdictional registrations
BitgetExchangeGlobal (various)Multiple jurisdictional registrations
LunoExchangeUnited Kingdom / Africa / SEALocal regulatory registrations
Independent ReserveExchangeAustralia / New ZealandAUSTRAC registered
BTC MarketsExchangeAustraliaAUSTRAC registered
BitstampExchangeLuxembourg / EUCSSF registered, MiCA transitional
Gate.ioExchangeGlobal (various)Multiple jurisdictional registrations
CoinifyOn/Off-RampDenmark / EUDanish FSA registered
BitfinexExchangeGlobal (various)Multiple jurisdictional registrations
PoloniexExchangeGlobal (various)Multiple jurisdictional registrations
KuCoinExchangeGlobal (various)Multiple jurisdictional registrations
HTXExchangeGlobal (various)Multiple jurisdictional registrations
HodlHodlP2PGlobal (non-custodial)No license required — non-custodial P2P
LocalCoinSwapP2PGlobal (non-custodial)No license required — non-custodial P2P

Note: DEX aggregators (LI.FI, 0x, KyberSwap, Velora, CowSwap, WOOFi, QuickSwap, PancakeSwap) operate via smart contracts and do not require custodial licenses. For a complete and current list, contact admin@clvrbridge.com.

5. Provider Monitoring Process

CLVRBRIDGE conducts ongoing monitoring of all integrated providers. Providers that fail our standards are removed from the routing engine.

  • Quarterly license verification: Each provider's regulatory licenses are checked for active status.
  • Sanctions screening: Providers are checked against OFAC, EU, and UN consolidated sanctions lists.
  • Adverse regulatory actions: We track enforcement actions, fines, and license revocations via public filings and news monitoring.
  • Geographic restrictions: Provider country coverage is updated as providers expand or restrict service.
  • Removal policy: Providers that fail compliance checks are deactivated from the routing engine immediately. Wallet clients are notified of material changes.

6. Sample Data Processing Agreement Language

The following is representative language from CLVRBRIDGE's standard Data Processing Agreement (DPA). A full DPA is available upon request.

Roles of the Parties

The Wallet Client is the Data Controller with respect to end-user personal data collected during its KYC process. CLVRBRIDGE acts as a Data Processor when relaying KYC credentials to a liquidity provider at the Wallet Client's instruction. The liquidity provider is an independent Data Controller with respect to KYC data it receives and verifies.

Purpose of Processing

CLVRBRIDGE processes KYC credentials solely for the purpose of relaying them to the liquidity provider selected by the routing engine for a specific transaction. CLVRBRIDGE does not use KYC data for any other purpose.

Data Retention

CLVRBRIDGE does not retain end-user KYC data after the relay is complete. Transaction metadata (trade type, asset pair, amount, provider, timestamp) is retained for routing optimization and client dashboard functionality.

Sub-Processors

CLVRBRIDGE uses Supabase (database hosting), Render (API hosting), Stripe (billing), and Resend (transactional email).

Security Measures

CLVRBRIDGE encrypts all data in transit (TLS 1.3) and at rest (AES-256). API access is restricted via key-based authentication. Access to production systems is limited to authorized personnel with multi-factor authentication.

Audit Rights

Upon reasonable request and no more than once per calendar year, the Wallet Client may audit CLVRBRIDGE's compliance with this DPA. Audits are conducted during normal business hours and at the Wallet Client's expense.

7. Contact for Legal Questions

Legal Contact: admin@clvrbridge.com

Response time: Within 2 business days

Available documents upon request: Full Data Processing Agreement (DPA), Terms of Service, Sub-Processor List, SOC 2 report (in progress), Business Continuity Plan summary

This document is provided for informational purposes and does not constitute legal advice. Wallet clients should consult their own counsel regarding regulatory obligations.