Legal Overview
Prepared for wallet client legal and compliance teams · CLVRBRIDGE, LLC
1. What CLVRBRIDGE Does
CLVRBRIDGE is a non-custodial smart routing API for crypto wallets. When a wallet's end user initiates a buy, sell, or swap, our engine queries 34 liquidity providers in real time — exchanges, on/off-ramps, P2P markets, and DEX aggregators — and routes the trade to the provider offering the best effective price. We never hold, control, or transmit user funds. The trade executes directly between the wallet's end user and the winning provider. CLVRBRIDGE operates solely as a technology service provider.
2. Non-Custodial Model
Funds flow directly from the end user to the liquidity provider. CLVRBRIDGE is not a party to the transaction and does not take custody at any point.
- CLVRBRIDGE does not custody, hold, or control user assets.
- CLVRBRIDGE does not have access to user private keys.
- CLVRBRIDGE does not transmit funds — the trade settles directly between the user and the provider.
- This structure creates zero new custody obligations for the wallet client.
3. KYC Pass-Through Flow
For providers that accept relayed KYC, CLVRBRIDGE maps the wallet's existing user verification to the provider's requirements and relays the credential. The wallet retains full KYC/AML responsibility for its end users at all times.
- Compatible providers: KYC data is relayed via API. The end user does not re-verify.
- Non-compatible providers: CLVRBRIDGE flags this before routing. The wallet decides whether to route and expose the user to a second KYC flow.
- Data retention: CLVRBRIDGE does not store end-user PII after relay. All relays are logged in an immutable audit trail for compliance review.
- Audit trail: Each relay includes a cryptographic hash for integrity verification.
4. Provider Licenses & Jurisdictions
The following is a representative sample of providers in the CLVRBRIDGE routing engine and their primary regulatory jurisdictions. This list is updated quarterly.
| Provider | Type | Primary Jurisdiction | License / Registration |
|---|---|---|---|
| Kraken | Exchange | United States | FinCEN MSB, state MTLs |
| Gemini | Exchange | United States | NYDFS Trust Charter |
| Coinbase | Exchange | United States | FinCEN MSB, state MTLs |
| Binance.US | Exchange | United States | FinCEN MSB |
| OKX | Exchange | Global (various) | Multiple jurisdictional registrations |
| Bitso | Exchange | Mexico / Latin America | Local regulatory registrations |
| Bybit | Exchange | Global (various) | Multiple jurisdictional registrations |
| Crypto.com | Exchange | Global (various) | Multiple jurisdictional registrations |
| Bitget | Exchange | Global (various) | Multiple jurisdictional registrations |
| Luno | Exchange | United Kingdom / Africa / SEA | Local regulatory registrations |
| Independent Reserve | Exchange | Australia / New Zealand | AUSTRAC registered |
| BTC Markets | Exchange | Australia | AUSTRAC registered |
| Bitstamp | Exchange | Luxembourg / EU | CSSF registered, MiCA transitional |
| Gate.io | Exchange | Global (various) | Multiple jurisdictional registrations |
| Coinify | On/Off-Ramp | Denmark / EU | Danish FSA registered |
| Bitfinex | Exchange | Global (various) | Multiple jurisdictional registrations |
| Poloniex | Exchange | Global (various) | Multiple jurisdictional registrations |
| KuCoin | Exchange | Global (various) | Multiple jurisdictional registrations |
| HTX | Exchange | Global (various) | Multiple jurisdictional registrations |
| HodlHodl | P2P | Global (non-custodial) | No license required — non-custodial P2P |
| LocalCoinSwap | P2P | Global (non-custodial) | No license required — non-custodial P2P |
Note: DEX aggregators (LI.FI, 0x, KyberSwap, Velora, CowSwap, WOOFi, QuickSwap, PancakeSwap) operate via smart contracts and do not require custodial licenses. For a complete and current list, contact admin@clvrbridge.com.
5. Provider Monitoring Process
CLVRBRIDGE conducts ongoing monitoring of all integrated providers. Providers that fail our standards are removed from the routing engine.
- Quarterly license verification: Each provider's regulatory licenses are checked for active status.
- Sanctions screening: Providers are checked against OFAC, EU, and UN consolidated sanctions lists.
- Adverse regulatory actions: We track enforcement actions, fines, and license revocations via public filings and news monitoring.
- Geographic restrictions: Provider country coverage is updated as providers expand or restrict service.
- Removal policy: Providers that fail compliance checks are deactivated from the routing engine immediately. Wallet clients are notified of material changes.
6. Sample Data Processing Agreement Language
The following is representative language from CLVRBRIDGE's standard Data Processing Agreement (DPA). A full DPA is available upon request.
Roles of the Parties
The Wallet Client is the Data Controller with respect to end-user personal data collected during its KYC process. CLVRBRIDGE acts as a Data Processor when relaying KYC credentials to a liquidity provider at the Wallet Client's instruction. The liquidity provider is an independent Data Controller with respect to KYC data it receives and verifies.
Purpose of Processing
CLVRBRIDGE processes KYC credentials solely for the purpose of relaying them to the liquidity provider selected by the routing engine for a specific transaction. CLVRBRIDGE does not use KYC data for any other purpose.
Data Retention
CLVRBRIDGE does not retain end-user KYC data after the relay is complete. Transaction metadata (trade type, asset pair, amount, provider, timestamp) is retained for routing optimization and client dashboard functionality.
Sub-Processors
CLVRBRIDGE uses Supabase (database hosting), Render (API hosting), Stripe (billing), and Resend (transactional email).
Security Measures
CLVRBRIDGE encrypts all data in transit (TLS 1.3) and at rest (AES-256). API access is restricted via key-based authentication. Access to production systems is limited to authorized personnel with multi-factor authentication.
Audit Rights
Upon reasonable request and no more than once per calendar year, the Wallet Client may audit CLVRBRIDGE's compliance with this DPA. Audits are conducted during normal business hours and at the Wallet Client's expense.
7. Contact for Legal Questions
Legal Contact: admin@clvrbridge.com
Response time: Within 2 business days
Available documents upon request: Full Data Processing Agreement (DPA), Terms of Service, Sub-Processor List, SOC 2 report (in progress), Business Continuity Plan summary
This document is provided for informational purposes and does not constitute legal advice. Wallet clients should consult their own counsel regarding regulatory obligations.