AML/CFT Policy
Last Updated: August 14, 2026
NO PURCHASE NECESSARY TO ENTER, PLAY, OR WIN. This Policy does not create any right, benefit, or expectation of privacy for any user, and does not limit Bitsky’s rights under the Terms and Conditions. “Bitsky,” “Company,” “we,” “us,” or “our” means Bitsky LLC. “Platform” means Bitsky.bet.
1. Purpose and Application
This Policy governs Bitsky’s controls to detect, prevent, and report money laundering, terrorist financing, and related financial crime in connection with Gold Coin purchases, Sweep Coin redemption, and Prize payment. It applies to every Bitsky employee and contractor with access to user funds, verification data, or compliance systems, and binds Bitsky’s third-party payment, cryptocurrency, and identity-verification processors by contract. It supplements, and does not replace, the Terms and Conditions, Privacy Policy, and Cashout & Redemption / Platform Rules.
2. Legal Basis and Reliance
Bitsky is a sweepstakes-promoted social gaming platform, not a licensed money transmitter. Bitsky’s program is built on two layers:
a) Direct obligations. Bitsky directly performs identity verification, sanctions screening, and transaction monitoring as described below, regardless of its licensing status, because these are conditions of its banking and processing relationships and because they reflect sound practice under FinCEN guidance, OFAC regulations, and applicable state law.
b) Reliance on regulated partners. Where a payment or cryptocurrency processor is itself a licensed/registered money services business, Bitsky relies in part on that processor’s BSA/AML program for functions the processor performs directly (e.g., final transaction settlement, SAR filing on transactions it processes). Bitsky confirms, at onboarding and annually thereafter, that each such processor maintains a compliance program consistent with 31 U.S.C. § 5318(h) or equivalent, and retains that confirmation as a compliance record under Section 9.
3. Risk Assessment
Bitsky’s Compliance Officer (Section 8) maintains a written risk assessment, reviewed at least annually and after any material change to products, geographies, or payment methods, that documents:
• Customer risk factors (verification status, jurisdiction, account age, prior compliance history);
• Product/channel risk factors (fiat vs. cryptocurrency redemption, redemption velocity); and
• The resulting risk rating methodology used to route accounts to standard or enhanced due diligence under Section 5.
The current risk assessment is maintained as a compliance record, not published externally.
4. Customer Identification Program (CIP)
Before a user may purchase Gold Coins or redeem a Prize, Bitsky collects and verifies:
• Full legal name, current residential address, and date of birth;
• A government-issued photo ID, verified for authenticity and facial match via Bitsky’s identity-verification provider; and
• A Social Security Number or Taxpayer Identification Number, where required for tax reporting under Section 4.C of the Terms and Conditions or for Prize redemption.
Verification failures are handled as follows: a user has seven (7) calendar days from a document request to cure a deficiency (consistent with the Terms and Conditions insertion on age/identity verification timelines); after that period, Bitsky may decline, suspend, or close the account and, where applicable, withhold or forfeit Prize balances as described in Section 7.
5. Customer Due Diligence and Enhanced Due Diligence
5.1 Standard due diligence applies to all verified accounts and consists of the CIP information above plus a baseline expectation of normal activity derived from a user’s first 30 days of gameplay. [This 30-day figure is a suggested operational default, not sourced from any existing Bitsky document - no prior policy defines an “activity baseline” period - and should be confirmed or adjusted by compliance/legal before adoption.]
5.2 Enhanced due diligence (EDD) is automatically triggered by any of the following, and requires manual compliance review before a redemption is released:
• A single redemption request of $7,500 or more - the Emerald-tier ceiling under Section 1.3(a) of the Cashout & Redemption Policy, above which redemption limit increases already require discretionary management review - or aggregate redemptions reaching a user’s applicable tier limit under that same Section (Iron–Gold: $2,500; Platinum–Sapphire: $5,000; Emerald: $7,500) within a rolling 30-day period;
• Any redemption request subject to the Florida $5,000 per-outcome cap described in Section 1.3(b) of the Cashout & Redemption Policy where the underlying win before reduction exceeded that cap;
• Any cryptocurrency redemption request, regardless of amount;
• A deposit-to-redemption ratio or timing pattern matching a Section 6 red flag;
• A confirmed or suspected sanctions or PEP match under Section 6; or
• Any account with a prior compliance flag, dispute, or SAR referral.
EDD review requires: (a) confirmation of source of funds (bank statement, payroll record, or exchange withdrawal history, as applicable); (b) a manual comparison of the request against the account’s documented activity baseline; and (c) written sign-off by the Compliance Officer or a delegate before release. EDD review is completed within the same processing window already disclosed in Section 1.5 of the Cashout & Redemption Policy - up to one (1) business day generally, or up to three (3) business days where the redemption method is bank or card-based - measured from the point the request enters the verification queue; the user is notified only that the request “requires additional review,” consistent with Section 9’s confidentiality requirement.
6. Sanctions Screening and Red-Flag Monitoring
6.1 Sanctions screening. Every account is screened against the OFAC SDN List - the only list any existing Bitsky policy names (the Cashout & Redemption Policy references “OFAC screening” generally) - at registration and re-screened on an ongoing basis thereafter. [Whether additional lists (e.g., the OFAC Consolidated List, UN or EU designations) are screened, and the exact re-screening cadence, are not specified in any existing Bitsky document and depend on what Bitsky’s identity-verification and payment processors actually screen against under their own contracts - this must be confirmed against those vendor agreements, not assumed.] A confirmed match results in an immediate account freeze, escalation to the Compliance Officer, and filing of a blocked-property report with OFAC within the statutory deadline.
6.2 Automated red-flag rules. Bitsky’s transaction monitoring flags an account for review when any of the following occur:
• A redemption request that does not meet the applicable wagering multiplier already required under Sections 4.1 and 5.1 of the Cashout & Redemption Policy (i.e., the minimum one-time wager for standard packages, or the 2x-purchase-value threshold for packages purchased at a discount of more than 20%);
• Gameplay concentrated in the games identified as bonus-abuse-monitored under Section 4.2 of the Cashout & Redemption Policy (Rocket Dice XY, Plinko, Baccarat, Blackjack, Mines, or similar low-risk/minimal-risk titles) immediately preceding a redemption request;
• Three or more redemption requests in a rolling 7-day period each just under the EDD threshold in Section 5.2;
• Two or more accounts sharing a payment instrument, device fingerprint, or government ID;
• A redemption payment method or cryptocurrency address not matching the verified account holder; or
• A cryptocurrency deposit or withdrawal address flagged by Bitsky’s blockchain-analytics provider as associated with a sanctioned entity, mixer/tumbler, darknet market, or ransomware wallet.
Flagged accounts are placed in manual review within the same timeframe described in Section 1.5 of the Cashout & Redemption Policy and are not released until a compliance analyst documents a disposition (cleared, EDD, or escalated to SAR consideration under Section 9).
7. Consequences and Account Actions
Upon a Section 6 flag or a failed Section 5 EDD review, Bitsky may, without liability under the Terms and Conditions: pause or decline the specific redemption; place a hold on the account pending documentation; suspend the account; or close the account and forfeit associated Gold Coin, Sweep Coin, or Prize balances to the extent permitted by law and the Terms and Conditions. Actions taken and their basis are logged as compliance records under Section 9.
8. Compliance Officer and Governance
Bitsky’s designated AML Compliance Officer, who has authority to freeze accounts, halt redemptions, and file reports without requiring prior sign-off from any other business function, and who reports on program operation to CEO or Board. In the Compliance Officer’s absence, CEO or Board holds the same authority.
Training. Employees and contractors with access to verification data, payments, or compliance systems complete AML/CFT training at onboarding and annually thereafter, covering this Policy, applicable law, and the red flags in Section 6. Completion is logged by name and date as a compliance record.
Independent testing. This Policy and its operation are tested by a party independent of daily compliance operations (internal audit, outside counsel, or a third-party consultant) no less than annually. [Annual is a suggested default, not sourced from any existing Bitsky document - no prior policy establishes an audit cadence - and should be confirmed by compliance/legal before adoption.] Findings and remediation are tracked to closure and reported under this Section.
9. Recordkeeping, Reporting, and Confidentiality
Bitsky retains CIP, EDD, sanctions-screening, and monitoring-disposition records for five (5) years from account closure or record creation, whichever is later. Where a matter meets the threshold for a Suspicious Activity Report, Bitsky (directly or through a processor relying on Section 2.b) files consistent with 31 C.F.R. § 1022.320 or the applicable processor’s equivalent obligation, and does not disclose the existence or content of a SAR to the affected user, as required by law. Bitsky cooperates fully with law enforcement and lawful court orders, consistent with Section 3.B of the Terms and Conditions.
10. Policy Maintenance
This Policy is reviewed at least annually and upon any material change in law, product, or risk profile, with revisions approved by the Compliance Officer and reflected in the “Last Updated” date above.
11. Contact
Questions may be directed to [email protected]. Disputes relating to this Policy are subject to the arbitration and dispute-resolution provisions in Section 5 of the Terms and Conditions.
