KYC, AML, and Sanctions Compliance Policy
Effective August 6, 2026
1. Introduction
1.1. The European Union (the "EU"), the United Nations (the "UN"), the United States of America (the "US"), United Kingdom (the "UK") and other official sanction authorities have imposed certain sanctions targeting several countries, entities and individuals, with the aim to prevent terrorism, money laundering, narcotics trafficking etc. (the "Sanctions"). There are two types of Sanctions: those that target entire nations (the "Sanctioned Countries") and those that target specific named individuals, entities or organisations (the "Blocked Individuals / Entities").
1.2. This Policy is developed, within the context of the law, to ensure compliance with the Sanctions and for the prevention and suppression of money laundering activities and terrorist financing. Money laundering is generally defined as engaging in acts designed to conceal or disguise the true origin of criminally derived proceeds so that the unlawful proceeds appear to have derived from legitimate origins or constitute legitimate assets. Terrorism financing means the provision or collection of funds, by any means, directly or indirectly, with the intention that they be used or in the knowledge that they are to be used, in full or in part, in order to carry out any terrorist act.
1.3. Spoildotme Ltd ("SpoilMe" or "Company"), with registered address at Griva Digeni 51, Athineon court, office 202, 8047, Paphos, Cyprus, operates a wishlist platform, through which Creators publish wishlists and Supporters send monetary contributions toward specific named items or experiences on those wishlists.
1.4. This Policy reflects both (a) the requirements of applicable Cyprus and EU legislation, including the Prevention and Suppression of Money Laundering Activities Law 188(I)/2007) (as amended) and Directive (EU) 2015/849 of the European Parliament and of the Council (as amended by Directive (EU) 2018/843), and (b) the contractual obligations imposed on SpoilMe by its payment processor(s), including Stripe.
1.5. SpoilMe is not a licensed payment institution. All payment processing, cardholder identity verification, and core AML/KYC screening of fund recipients is performed by Stripe. This Policy documents (a) SpoilMe's reliance on Stripe's regulated controls, and (b) the supplementary platform-level controls SpoilMe operates.
1.6. The purpose of this Policy is to:
- set out the responsibilities of Employees in respect of observing and complying with this Policy;
- provide information and guidelines on the money laundering and sanctions risks arising in relation to Company's activities, its due diligence procedures and how to recognise and deal with such issues if they arise;
- prevent, manage and mitigate the risk of Company to become involved in actual or potential money laundering and/or terrorist financing activities and/or any sanction restrictions;
- inform the Employees about the consequences of failing to comply with this Policy.
1.7. All Employees are obliged to comply with this Policy during the conduct of their daily duties and when representing the Company.
1.8. This Policy does not form part of any contract of employment or other contract to provide services, and we may review and amend it from time to time. In the event of significant changes to this Policy, we will make reasonable efforts to notify you accordingly.
1.9. The information in this Policy is provided in good faith, however, the Company makes no representation or warranty regarding its accuracy, adequacy, validity or completeness.
1.10. The Company applies a risk-based approach: higher-risk Third-Parties (including Creators), business relationships, products, geographies, and payment flows are subject to enhanced due diligence, enhanced monitoring, stricter approval requirements and more frequent reviews.
1.11. This Policy is reviewed by the Compliance Officer at least annually, and additionally upon any material change in law, payment processors’ requirements, Company’s business model, or risk profile.
2. Definitions
2.1. For the purpose of this Policy the below definitions shall apply:
| “AML” or “Anti Money Laundering”: | Shall refer to measures aiming to prevent the Company’s involvement in money laundering as specified by this Policy. |
| “Blocked Individuals/Entities”: | Shall refer to those individuals, entities and/or organisations, who/which have been targeted by the sanctions authorities; |
| “Compliance Officer”: | Shall refer to the relevant person and/or department appointed by the Company to oversee KYC, AML, CFT, sanctions compliance, internal escalation, external reporting, policy maintenance, training and oversight under this Policy. |
| “Creator” | Shall refer to the user of SpoilMe platform and related services, who has registered an account to create a wish list of items for their Supporters to be sent monetary contributions towards such items. |
| “Employees”: | Shall refer to the employees, officers, directors, contractors and any other personnel acting on behalf of SpoilMe who are involved in onboarding, managing, supporting and monitoring the Third-Parties; |
| “MOKAS”: | Shall refer to the Financial Intelligence Unit for Combating Money Laundering in Cyprus, the national center for receiving, requesting, analyzing and disseminating disclosures of suspicious transactions reports and other relevant information concerning suspected money laundering and terrorist financing, as further detailed at http://www.law.gov.cy/law/mokas/mokas.nsf/index_en/index_en?OpenDocument; |
| “KYC”: | Shall refer to the Know Your Customer and Customer Due Diligence measures, including identification, verification, screening, risk assessment, ongoing monitoring, and record keeping, as further detailed this Policy; |
| “PEP” | Shall refer to a politically exposed person, as well as their close associates and family members. |
| “Policy”: | Shall refer to this KYC, AML and Sanctions Compliance Policy of SPOILME; |
| “Sanctions”: | Shall refer to restrictive measures, administered or enforced by the European Union, U.K. Office of Financial Sanctions Implementation (OFSI), U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC), the United Nations Security Council, or any other relevant sanctions authority, which affect in any way SPOILME, as referred in section 1.1; |
| “Sanctioned Countries”: | Shall refer to the countries which have been targeted under Sanctions; |
| “SpoilMe” or “Company”: | Shall refer to SPOILDOTME LTD, a limited liability company registered in Cyprus, registered office is at Griva Digeni, 51, ATHINEON COURT, Flat/Office 202, 8047, Paphos, Cyprus, registered number HE 446803 and any of its subsidiaries, official representatives, officers and/or authorised employees. |
| “Supporter” | Shall refer to the user of SpoilMe platform and related services, who has registered an account to send a monetary contribution toward a specific item on a Creator's wishlist. |
| “Third-Party”: | Shall refer to any third party, either individual, entrepreneur, company and/or organisation that has entered into any type of business relationship with SPOILME or is under negotiation with SPOILME with the purpose to conduct business, including Creators and Supporters; |
3. Compliance Officer
The Compliance Officer is responsible to:
3.1. Initiate updates to this Policy to ensure its compliance with the relevant applicable laws, regulations and guidelines;
3.2. Ensure that SPOILME has adequate Third-Party KYC procedures for the prevention and suppression of money laundering and terrorism financing;
3.3. Ensure that SPOILME complies with the applicable Sanctions;
3.4. Ensure that SPOILME has adequate guidelines for monitoring and reporting suspicious activities;
3.5. Receive and process reports of suspicious activities and possible breach of Sanctions and ensure that potential suspicious activity is assessed without delay and, where required by law or appropriate in the circumstances, reported to MOKAS or other competent authorities;
3.6. Oversee the First-Payment Review process and make final approve/reject decisions;
3.7. Oversee customer risk classification, approvals, escalations and enhanced due diligence decisions;
3.8. Maintain records of screening, onboarding, risk assessments, approvals, escalations and suspicious activity decisions;
3.9. Establish an on-going Employee training to ensure that Employees are kept informed of this Policy, of new developments, including information on current money laundering and terrorist financing techniques, methods and trends and the Sanctions restrictions.
3.10. Ensure that this Policy is reviewed at least annually and when there is a material change in law, business model, geography, payment flow, product or risk profile.
4. Third Parties
4.1. Third-Parties are independent contractors. The agreements entered between Third-Parties and SPOILME do not create any employee-employer relationship, partnership or joint venture between them.
4.2. SPOILME, at its own discretion selects and/or agrees to proceed with negotiation with the Third-Parties. It is at SPOILME’s sole discretion whether it will proceed with the conclusion of the relevant agreement following the completion of the due diligence in accordance with this Policy.
4.3. SPOILME may classify Third-Parties as Low Risk, Medium Risk or High Risk. High Risk relationships shall be subject to enhanced KYC, enhanced approvals, and enhanced monitoring. High Risk relationships may be rejected or terminated at any moment at the decision of the Compliance Officer. Where applicable, High Risk Third-Parties may be subject to restrictions on payment processing channels.
5. Creators and Supporters
5.1. Additional rules apply under this Policy to the following categories of Third-Parties:
- Creators – users of SpoilMe platform and related services, who have registered an account to create a wish list of items for their Supporters to be purchased as gifts, subject to full identity verification and the First-Payment Review; and
- Supporters – users of SpoilMe platform and related services, who have registered an account to send a monetary contribution toward a specific item on a Creator's wishlist.
5.2. The Company’s core Sanctions/anti-abuse obligations, imposed by SpoilMe's classification as a content-creator support platform, are:
- no peer-to-peer money transfers: every payment must fund a specific, named wishlist item, not a bare cash request; and
- every fund recipient must be a genuine content creator with a verifiable public audience.
5.3. The Company may classify Creators as Low, Medium, or High Risk based on the factors below.
| Risk category | Factors considered |
|---|---|
| Identity/verification risk | Whether Stripe KYC is complete; consistency of name, bank details, and profile identity |
| Presence/legitimacy risk | Whether the Creator has a verifiable public social-media audience with a backlink to their SpoilMe page; account age; posting frequency; follower authenticity |
| Geographic risk | Country of registration/residence; whether the jurisdiction is Sanctioned or unsupported by Stripe |
| Sanctions/PEP risk | Screening result against Sanctions and Blocked Individuals/Entities lists; PEP status |
| Transactional risk | Value and velocity of contributions received; use of the $5,000 per-transaction cap; multiple cards/emails associated with the same Supporter identity |
| Content risk | Nature of wishlist items; repeated moderation rejections; attempts to solicit cash-equivalents |
5.4. High Risk Creators are subject to enhanced review, additional evidence requests, and may have payouts permanently withheld or their account rejected at the Company’s discretion. In particular, High Risk Creators are subject to:
- mandatory human review before approval (never auto-approved, even via partner invite codes);
- a request for traffic-source verification evidence where public presence cannot be confirmed directly; and
- more frequent ad-hoc re-review during the life of the relationship.
5.5. SpoilMe relies on Stripe, its payment processor, as the primary regulated layer of identity verification and payment-level AML/fraud control. SpoilMe does not independently collect or store government identity documents, to the extent identity verification of Creators is performed by Stripe through the Stripe Connect Express onboarding flow, covering government-ID-verified identity, date of birth, address, and bank/debit account details. No funds can be transferred to a Creator whose Stripe account has not reached a fully verified status, and checkout toward an unverified or under-review Creator is blocked in code. Every card payment from a Supporter is screened in real time by Stripe Radar's machine-learning fraud model, supplemented by SpoilMe's own configured Radar rules (3-D Secure step-up, block-listing of default fraud lists, blocking of card-cycling patterns, and manual review routing of elevated-risk payments). Creators from jurisdictions unsupported by Stripe Connect cannot onboard, with country eligibility checked automatically against Stripe's country specifications at account creation.
5.6. A Creator's first payment automatically triggers an account review: payouts are frozen and further checkout toward that Creator is disabled until the review is resolved. SpoilMe's automated system checks the Creator's public online presence and identity consistency to confirm they are a genuine content creator, and requests further evidence (e.g., proof of how they share their wishlist) if this cannot be verified directly. The Compliance Officer makes the final approve or reject decision based on this evidence, and the outcome is logged. If approved, payouts and checkout resume normally. If rejected, payouts remain frozen, the held payment is refunded, and the Creator may not re-register. Creators referred through a vetted partner may be fast-tracked, except where classified as High Risk.
6. Politically Exposed Persons (PEPs)
6.1. A PEP is an individual entrusted with a prominent public function (e.g., heads of state or government, ministers, members of parliament, senior judges, senior military officers, senior state-owned enterprise executives, or senior officials of international organizations), other than middle-ranking or junior officials, together with their immediate family members and known close associates.
6.2. PEP status does not itself indicate wrongdoing but places a Creator or Supporter in a higher risk category requiring enhanced review.
6.3. Where a Creator or Supporter is identified as a PEP, the Compliance Officer must:
- require senior approval before allowing continued payouts or contributions;
- seek to establish the source of funds where the transaction pattern is inconsistent with the individual's known public role; and
- apply enhanced monitoring for at least 12 months after the individual ceases to hold the relevant public function.
7. Monitoring and Reporting
7.1. As part of the ongoing relationship with the Third-Party, an ongoing KYC, AML and Sanctions compliance monitoring will be carried out on a risk-based approach by the Compliance Officer.
7.2. There are several issues, which require Compliance Officer to investigate whether a Third Party or a transaction violates this Policy (“Red Flags”). Red Flags indicators during the business relationship with Third-Parties are:
7.2.1. Unusual change of company structure, change of business activities, change of bank account details, unusual transactions, or activities potentially linked to money laundering or any other illegal activities;
7.2.2. Transactions and/or activities that are not consistent with the initially declared purpose or nature of the relationship between the parties;
7.2.3. The type of transaction is not accepted, in accordance with the respective Sanctions:
7.2.4. Third-Party’s shareholders and/or beneficial owner and/or director and/or officer have a name similar to the name of a Blocked Individual/Entity;
7.2.5. Third-Party, its shareholders, beneficial owners, directors or officers are related to a political exposed person (“PEP”);
7.2.6. Change of ownership of the Third-Party to a jurisdiction subject to Sanctions;
7.2.7. Change of destination of funds to a Sanctioned Country;
7.2.8. Third-Party is unwilling to provide KYC documents and/or further supportive identification documents;
7.2.9. Unusual requests for invoicing, favourable payment terms and cash payment;
7.2.10. Publications that claim the involvement of the Third-Party to money laundering and terrorist financing or any other illegal action which can affect SPOILME;
7.3. The list mentioned in section 7.2 is not exhaustive and any suspicion that Third-Party is directly or indirectly involved with money laundering and/or is subject to Sanctions should alert Employees and/or Compliance Officer to further investigate the activities in accordance with this Policy.
7.4. Any suspicion of money laundering transactions or activities or suspicion for applicable Sanctions should be reported by the Employees to Compliance Officer immediately. The Compliance Officer should validate and consider the received report and discuss the circumstances of the case with the reporting Employee. During that period the business engagement and/or transaction with the Third-Party should be on hold until further instruction and guidance from the Compliance Officer. After further research of supportive documents and written explanations regarding the transaction and/or the unusual activity, Compliance Officer should briefly set out the reason for regarding the transaction or activity to be reported as suspicious or, if he/she decides against reporting, his/her reasons for that decision.
7.5. Compliance Officer upon knowledge or reasonable suspicion that a Third-Party is engaged in money laundering will promptly report to MOKAS and/or to the police and/or any relevant authorised authority appointed for the prevention of money laundering and terrorism financing. In the event of applicable Sanctions, Compliance Officer will determine the risk of such cooperation and take appropriate measures.
8. SpoilMe Platform Transaction Monitoring and Content Controls
8.1. In addition to monitoring and reporting procedures described in Section 7, the following applies to the transactions and content monitoring and control with respect to SpoilMe platform.
8.2. Amount limits. Contributions are limited to a minimum of USD 5 and a maximum of USD 5,000 per transaction (aggregate cart total), enforced server-side and independently recomputed on every checkout — client-submitted values cannot override this control.
8.3. Payment screening. Every Supporter payment is scored by Stripe Radar's ML model and SpoilMe's custom rules, including 3-D Secure step-up authentication, blocking of payments matching default fraud lists, blocking of card-cycling patterns (more than five distinct cards on one email within a week), and manual-review routing of elevated-risk payments.
8.4. Destination charges. All Supporter payments are created as PaymentIntents on the SpoilMe platform account; only the Creator's net share is transferred onward. This gives SpoilMe full visibility and control over every transaction before any funds reach a Creator.
8.5. Wishlist content moderation (anti-disguised-transfer control). Every wish is reviewed by a multi-model AI pipeline on creation and on every edit, applying asymmetric confidence thresholds. The central test applied is whether the wish converts a contribution into a specific, named item; bare cash requests, gift cards, crypto, prepaid cards, disguised P2P transfer requests (e.g., payment-app handles, IBANs, wallet addresses), and redirects to external tipping platforms are rejected regardless of framing.
8.6. Prohibited content categories additionally include illegal substances, weapons/violence, sexual content or services offered in exchange for gifts, and other illegal goods; rejected wishes generate a permanent audit record and repeat submissions of previously rejected content are automatically re-rejected.
8.7. Red flags requiring escalation to the Compliance Officer include, without limitation:
- unusual change in a Creator's payout destination, business activity, or bank details;
- contribution patterns inconsistent with a Creator's declared audience size or wishlist activity;
- a Creator's name, or that of a beneficial owner, matching a Sanctions or Blocked Individuals/Entities list;
- PEP association identified for a Creator or Supporter;
- repeated attempts to solicit cash-equivalents or disguised transfers via wishlist content or messaging;
- negative media coverage linking a Creator to money laundering, terrorist financing, or illegal activity; and
- reused card fingerprints across multiple purported identities (card-testing/fraud-ring signature).
9. Sanctions and Blocked-Party Screening
9.1. Third-Parties, including Creators, their beneficial owners, and known controllers must not be the subject of applicable Sanctions or Blocked Individuals/Entities lists, and must not be resident, registered, or located in a Sanctioned country, as a condition of receiving payouts.
9.2. With respect to SpoilMe platform payments, sanctions screening occurs at two levels: (a) Stripe's network-level Sanctions and compliance screening embedded in its onboarding and payment infrastructure, and (b) SpoilMe's own review of Creator identity and public information during the first payment review.
9.3. Where a Third-Party is found to be subject to Sanctions, all transactions with such Third-Party shall be stopped immediately, and Compliance Officer must determine appropriate next steps, which may include reporting to the relevant authority. If a Creator or Supporter is found to be subject to Sanctions, the Compliance Officer must immediately suspend the relevant account, hold any associated funds, and determine appropriate next steps, which may include refund to the originating Supporter and reporting to the relevant authority.
10. Suspicious Activity and Reporting to MOKAS
10.1. Any Employee who identifies a red flag under Sections 7 and 8 or otherwise suspects money laundering, terrorist financing, or a Sanctions breach must report it to the Compliance Officer immediately. Pending review, the related account or transaction must be held — no further payments processed and no payout released.
10.2. The Compliance Officer must assess the report without delay, document the reasoning for the decision reached (whether to escalate or not), and where knowledge or reasonable suspicion of money laundering or terrorist financing is confirmed, report promptly to MOKAS or another competent authority.
10.3. Tipping-off prohibition. No Employee may inform a Third-Party, Creator, Supporter, or any other party that a report has been made, is being considered, or has been requested by MOKAS or another authority.
10.4. Safe harbor. An Employee or the Compliance Officer who reports a suspicion in good faith in accordance with this Policy is not liable for any resulting loss to a Third-Party, Creator or Supporter, including loss arising from delay, refusal, or cancellation of a transaction.
11. Record Keeping and Access
11.1. Records relating to Third-Party reviews, risk classifications, approval/rejection decisions, traffic-source evidence, and suspicious activity reports are retained by SpoilMe:
- for one year from the review date if no ongoing relationship is established; and
- for the duration of the relationship and for six years following its termination.
11.2. Access to KYC-related records is restricted to the Compliance Officer and specifically authorized Employees. Records are not shared with third parties absent legal obligation or prior written consent from the relevant Third-Party, except when required by law enforcement or regulatory authorities.
11.3. Identity documents collected during Stripe's onboarding flow are held by Stripe, not by SpoilMe; SpoilMe's own records consist of review decisions, AI assessment outputs, traffic-source submissions, and audit logs.
12. Training
12.1. Training of Employees who have communication with Third-Parties and/or access to their KYC in AML procedures and Sanctions awareness will take place from time to time, but at least once a year. Such training will focus on discussions of KYC policies and procedures, international updates and amendments to local legislation or regulations with regards to AML and relevant Sanctions imposed by the relevant authorities.