Verification at an exchange service: what the order asks for and what the service has the right to ask for

An exchange order does not ask for documents: there are two required fields — a Telegram handle and a wallet address. The service does have the right to ask for a passport or a bank statement and it is written into its policy, but there is no threshold at which this is done automatically on any of the 66 directions as of 19.09.2026. We go through how a power differs from a procedure and where the document goes if it is asked for.

An exchange order does not ask for documents today. It has two required fields: a Telegram handle and a wallet address. On the three directions with a payout to a foreign card, a first name, a surname, an email and a card number are added — and all four are optional. There is no passport, no selfie, no photo of a card and no question about the source of funds in the form, and there is no field for uploading a file in it either.

At the same time the service does have the right to ask for documents, and it is written into its AML/KYC policy: a national ID card, an international passport, a bank statement — on suspicion, on a change of data or as part of ongoing checks. This is a power, not a procedure: there is no working threshold at which a document is demanded automatically on any of the 66 directions.

There is one practical conclusion. If a document is asked for, it will happen not in the form but in correspondence with an operator in the messenger — no upload screen exists in the interface. How long such a document is kept afterwards, neither the privacy policy nor the AML/KYC policy says: there is no period anywhere.

What the order actually asks for

We are an exchange service, and what follows is about our own form. All 66 directions were captured on 19.09.2026, and there are exactly five sets of fields.

What you give and what you get

Required fields

Optional fields

cash → USDT on the TRON network

Telegram handle, wallet address

cash → USDT or USDC on the Ethereum network

Telegram handle, wallet address

cryptocurrency → cash

Telegram handle

cryptocurrency → Alipay

Telegram handle

cryptocurrency → foreign card

Telegram handle

first name, surname, email, card number

The table reads like this: on most directions there are two required fields, and when you give cryptocurrency and get cash there is one, the Telegram handle. An operator will contact you through it. The four fields on the three directions with a payout to a foreign card can be left empty.

The second thing worth knowing for anyone who is afraid of “registration with a passport”: no account is needed for an order at all. Neither an email nor a captcha goes into the request that creates it. You can come back to an order through the pair “number plus secret” in the page address, and the list of orders is kept in the browser, not in a personal account.

What the service has kept the right to demand

An exchange service asks for its own things, a bank for its own: the requirements grow out of different rules and do not coincide. Why a bank asks is covered separately; here it is only the rules of the service itself.

The identity check on a customer is called KYC, and in the policy it is described like this. Clause 5.1: the service may demand reliable independent documents — a national ID card, an international passport and a bank statement are named. Clause 5.3: the identity check is allowed on an ongoing basis and documents may be asked for again, even if the check has already been passed once.

Clause 5.7 adds requirements for checking the source of funds. Clause 10 describes what happens on suspicion: the exchange is suspended, identity documents are asked for, and a report is passed to law enforcement through the responsible officer.

There are requirements for the order itself as well, clauses 4.1–4.3: the sender and the recipient of the payment are one person, transfers in favour of third parties are forbidden, the data has to be accurate, and creating an order through anonymous connections — proxy, VPN, Tor — is forbidden by the rules.

The main point: the policy describes what the service has the right to do, not what it does on every order. Between these two things there is an empty space today — there is no procedure in the form that asks for a document.

What is not in the policy: a check of the address itself

The power concerns the person: identity, behaviour in transactions, sanctions lists, risk assessment — those are clauses 7–9. About wallet scoring, “dirty” coins and the origin of a particular transaction there is not a word in the policy.

That is a separate topic, and it is covered in the article on checking USDT. Here we will add one fact: at the end of the policy there is a published list of venues that fall under AML checks. We are not carrying the names over from it — what matters is that such a list exists and is open.

And the second half of that fact. The engine's AML module is switched off on all 66 directions as of 19.09.2026 — just like verification. The list is published, but no mechanism that would check an order against it is visible in the public API.

What will happen if the check is switched on

The mechanism is in the code and it works — it is simply not engaged. It is built like this.

  • There are three requirements and they are independent: on the currency given, on the currency received, and on the person.
  • The threshold is inclusive: an amount exactly at the threshold already requires a check, not “above the threshold”. As of 19.09.2026 the thresholds on all 66 directions are set to zero: the field is there, it holds zero, and the check flag itself is off.
  • The warning is shown before payment: it comes together with the direction's data, not as an error after the form is filled in.
  • Until the check is passed, the payment details are not shown and the order does not move into awaiting payment. There is nowhere to pay — that is the stop.
  • A direction can have its own list of required documents. As of 19.09.2026 not one of the 66 directions has this field.

And the main thing: no document upload screen exists in the interface. No file picker, no form submission with an attachment — not in the exchange form, not on the order page, not in the profile. The interface can only show the line “Documents under review” for a status that has come from the engine's side.

Hence the conclusion. If a document is asked for, it will go to an operator in the messenger. Not into a secure form and not into an account — into correspondence. So the right question to ask yourself is not “which documents will they ask me for” but “to whom and through which channel am I handing them over”.

“Card verification by photo”: the practice is real, but it does not apply to this form

You have most likely come across the practice. You are asked to photograph the front of the card so that the number and the holder's name can be read, with a monitor showing the open site visible in the background. It is done once for each new card, and the practice is widespread in the industry.

It has nothing to do with our form today. The service has no directions where a person pays by card: a card is there only as a way of paying out, and the card number in those orders is optional. There is nothing to pay by card with in the form — so there is nothing to confirm ownership of a card for.

It is not only our own questions section and one of the landing pages that call this check a mandatory condition. The requirement stands in the AML/KYC policy itself, clause 5.6: anyone who intends to pay by card has to pass a card check following the instructions on the site. That is a document in force, and the service refers to it in the consent form.

The discrepancy is therefore wider than a mistake in a help text: the requirement stands in the rules in force. As of 19.09.2026 verification is switched off on all 66 directions. It is the form you should go by, not the text next to it.

What happens to the document next

The policy names a responsible officer: that person collects identification information, maintains internal procedures for keeping reports and records, monitors transactions and passes information to law enforcement. There is no name, no job title and no way to contact this person on the site.

The employees' duty of confidentiality applies after they leave as well. Disclosure to state and law enforcement authorities is not considered a breach.

Now the honest part. There is no retention period in either of the two policies. The privacy policy speaks of keeping data for the whole period needed and of periods set by purposes and contract terms. A specific number of months or years is nowhere to be found, and we are not going to name one.

There is a second hole as well. In the list of data collected there are no identity documents at all: it has name, phone, email, device data, IP, cookies, enquiries. The document the policy allows to be asked for is not described in the list of what is collected.

Data can be deleted by writing to the support address. Orders remain even so — the interface explains this by saying they are monetary documents and that the law requires it. Which rule exactly requires it is not named on the site. Neither of the two policies has a revision date, so here they are recounted from pages captured on 19.09.2026.

What to ask any exchange service before a transfer

Five questions worth asking before you have sent anything. They work against any service, ours included.

  • Is the right to demand documents described before the transfer, not after? A rule that appeared after payment is no longer a rule but a condition for getting money back.
  • Through which channel is the document sent and who receives it? A form on the site, email, a messenger — these are different levels of risk, and the difference between them is bigger than the difference between lists of documents.
  • Is a retention period named? Not “for as long as it is needed”, but a period.
  • Are the legal entity and the jurisdiction named? A document is handed to someone specific, not to a site.
  • Does the service have an amount threshold of its own and where is it published? Not the one in the financial monitoring law, but its own: the amount from which the service itself asks for a document. A threshold named in correspondence is not a threshold.

We are an exchange service, and exactly one question out of the five is fully closed for us — the first. The right to demand documents is described in the rules before the transfer. The second is half closed: the channel is known — correspondence with an operator, but who receives the document is not named. The policy names a responsible officer, but there is no name, no job title and no way to contact that person on the site.

The other three. A retention period is not named. The jurisdiction is named — indirectly, through the privacy policy with its reference to the legislation of Ukraine; the legal entity is not named anywhere. There is no threshold of its own — it is neither “high” nor “low”: the threshold fields are set to zero, and the check itself is off, so there is nothing to trigger.

A licence has nothing to do with it

Licences for this kind of activity are not issued in Ukraine: the law “On Virtual Assets” № 2074-IX had not come into force as of 19.09.2026, and there is no state register of service providers. Asking an exchange service for a licence number is pointless — there is nobody to issue one yet.

What is actually in force: registration with the State Financial Monitoring Service as a primary financial monitoring entity and customer due diligence for transactions with virtual assets from 30 thousand hryvnias — Article 11, Part 4 of Law № 361-IX, version of 26.06.2026. The supervisory body is the Ministry of Digital Transformation. The version and the status of Law № 2074-IX were checked on 19.09.2026.

The caveat about these 30 thousand is required. It is the statutory threshold for the exchange service's obligation as a financial monitoring entity, not the service's own threshold and not “the amount from which the site asks for a passport”. No such amount of its own exists at all.

And it has an exception aimed at services exactly like ours: the exemption from the check below 30 thousand does not apply on suspicion, nor when the money comes from the payer in cash. Cash is in three of our five sets of fields.

The argument “licensed versus anonymous” is covered in a separate article — here we only lean on it.

We are an exchange service and we work with USDT on the TRON and Ethereum networks. The right to ask for documents is described in our rules before the transfer, it does not appear after it. If you need the direction itself — exchanging USDT on the TRON network.

Short answers

Can I exchange without verification?

Today the order does not require a single document: as of 19.09.2026 the check is switched off on all 66 directions. But “without verification” does not mean “they will never ask”: the right to ask for documents is written into the rules and applies on suspicion and when the source of funds is checked. We cannot promise that no document will be asked for.

Where do I send a document if it has been asked for after all?

There is no upload screen on the site, so there is one channel — correspondence with an operator in the messenger. Before you send anything, check that you are writing to the contact given on the service's site, not to whoever wrote to you first.

How long is a document I have sent kept?

There is no answer. Neither the privacy policy nor the AML/KYC policy names a period, and in the list of data collected identity documents are not described at all. We are not going to name a period “by general practice”: that would be a guess, not a rule of the service.

Is registration needed to create an order?

No. No account is needed for an order: neither an email nor a captcha goes into the request that creates it. You can come back to a created order through the pair “number plus secret” in the page address, and the list of orders is kept in your browser.

Author: MW ExchangeUpdated
01

Read next