Article facts
| Field | Visible value |
|---|
| Purpose | Traceability of covered crypto transfers and prevention of financial crime |
| EU legal framework | Regulation (EU) 2023/1113 and applicable EBA guidance |
| EU application date | 30 December 2024 |
| Information concerns | Originator, beneficiary, transfer, provider and sometimes self-hosted address |
| Self-hosted address checks | Can include ownership/control verification; specific EU rule applies over €1,000 in relevant cases |
| Does it make a transfer risk-free? | No |
| Last reviewed | 2026-08-21 |
Why is it called the Travel Rule?
The name reflects the principle that identifying information should “travel” with a covered transfer between regulated service providers. The goal is to help providers and authorities trace transfers and identify missing, false or suspicious information.
The requirement is not unique to Quppy. It is based on international AML/CFT standards and implemented through regional and national rules.
Which transfers can be affected?
The Travel Rule can affect crypto transfers:
- from Quppy to another crypto exchange or custodial wallet;
- from another provider to Quppy;
- between a regulated provider and a self-hosted wallet;
- involving a person other than the Quppy user;
- involving providers in different countries.
The exact obligations depend on the jurisdictions, provider roles and transfer structure. A transfer to or from a self-hosted address is not automatically exempt.
Information can include:
About the originator
- full name;
- account or wallet-related identifier;
- address, identity-document number, customer-identification number, or date and place of birth where required;
- legal-entity identifier where applicable.
About the beneficiary
- full name;
- account or wallet-related identifier;
- provider or wallet type;
- legal-entity information where applicable.
About the transfer
- crypto-asset;
- amount;
- blockchain network;
- wallet addresses;
- transaction hash;
- sending and receiving providers;
- purpose or relationship where required.
The exact fields shown in Quppy can differ by country and provider.
What is a self-hosted address?
A self-hosted address is a crypto address not administered by a crypto-asset service provider on behalf of the user. It is sometimes called a personal, unhosted or non-custodial wallet address.
Quppy Crypto itself uses a custodial model. However, users can send to or receive from compatible external wallets, including self-hosted wallets where supported.
Why can I be asked to prove ownership or control of a wallet?
For covered transfers handled under the applicable EEA service configuration and involving a self-hosted address, the provider can need to identify the relevant person and assess whether the address is owned or controlled by the stated originator or beneficiary.
Under Regulation (EU) 2023/1113, specific verification obligations apply in relevant cases for transfers exceeding EUR 1,000 to or from a self-hosted address.
An approved verification method might involve:
- a signed message where technically supported;
- a small verification transfer;
- evidence from the wallet interface;
- a provider-approved ownership declaration;
- transaction history or other risk-based evidence.
The actual method must be the one shown by Quppy or the provider. Never disclose a private key or seed phrase.
The provider can:
- request missing or corrected data;
- pause the transfer;
- reject or return the transfer where possible;
- restrict transfers to or from a provider that repeatedly omits required information;
- conduct enhanced review;
- report suspicious activity where legally required.
A blockchain transaction can be technically irreversible even when the provider cannot credit it. This is why required information should be completed before sending whenever the flow requests it.
Depending on the transfer, information can be shared with:
- the sending or receiving crypto-asset service provider;
- technology vendors used to transmit Travel Rule data;
- compliance and screening providers;
- regulators, financial intelligence units, courts or law-enforcement authorities where legally required;
- other recipients described in the applicable Privacy Notice.
Travel Rule data should not be entered into public blockchain fields unless the approved process specifically requires a non-sensitive reference.
Retention depends on the applicable law and provider. Payhound’s current Privacy Notice states that Travel Rule data is generally retained for five years, with longer retention possible where authorised or required by an authority, legislation, legal proceedings or justified legitimate interests.
The retention period that applies to a particular Quppy user depends on the provider and Privacy Notice assigned to that service.
How should I complete a Travel Rule request?
- Select whether the destination is an exchange/custodial provider or a self-hosted wallet.
- Enter the beneficiary’s accurate legal name.
- Identify the external provider when requested.
- State whether the wallet belongs to you or another person.
- Provide the requested relationship or purpose information.
- Complete any approved wallet-ownership check.
- Verify the asset, network and address before confirming.
Do not choose “my wallet” merely to avoid providing beneficiary information. False information can cause rejection, restriction or further review.
Does the Travel Rule guarantee that a transfer is safe?
No. Travel Rule data supports traceability and compliance. It does not guarantee that:
- the recipient is trustworthy;
- the address is free of risk;
- the transfer can be reversed;
- the crypto-asset will retain value;
- the external provider will credit the transfer.
Always verify the recipient and transaction details independently.