Why it is legal
People assume account-free crypto purchases must be operating in some grey area. They are not, and the reason is a distinction in what the business is actually doing.
An exchange converts between currencies and takes custody of customer funds. That is a regulated financial activity with identity obligations attached in essentially every developed jurisdiction. There is no version of an exchange that does not verify customers.
A gift card reseller sells a fixed-value prepaid product. It takes a payment and delivers a code. It does not hold a balance for you, does not convert currency on your behalf, and does not maintain an ongoing financial relationship. The obligations that attach to an exchange do not automatically attach here.
This is why Bitrefill, Coinsbee and Coincards can sell you a gift card for Bitcoin with nothing more than a delivery address, while every exchange on earth wants a passport. They are not being braver. They are doing something different.
The useful test
Ask whether the business is holding money for you or selling you a product. Holding money means verification, without exception. Selling a product frequently does not, up to a point.
That distinction explains almost every KYC question in this category without needing to memorise any thresholds.
Where the thresholds start
There is no single published number, and anyone quoting one confidently is guessing. Requirements vary by jurisdiction, by product, and by each operator’s own risk appetite, which is set internally and changes.
What is consistent is when verification appears rather than at what figure.
- As order values rise. Every operator has internal limits, and they are lower than most people expect.
- When fiat enters the picture. Paying with a card or bank transfer rather than crypto changes the regulatory character of the transaction immediately.
- When a balance or hosted wallet is created. The moment a company holds value for you, it is doing something else.
- When patterns look structured. Repeated purchases just under a limit are the specific thing monitoring systems are built to detect, and they flag it reliably.
That last point deserves emphasis because it is where well-meaning people create problems for themselves. Deliberately splitting a purchase to stay beneath a threshold is a recognised pattern with a name, and it attracts more attention than the single larger transaction would have.
What it does not do
Here is where expectations need correcting, because the gap between what account-free checkout provides and what people imagine it provides is substantial.
The blockchain payment is public. Permanently. It is linked to the address you paid from, and if that address has ever touched a verified exchange account, the connection exists whether or not anybody has looked.
The delivery e-mail exists. You gave it to them so they could send the code. It sits in their records like any other customer data.
The retailer sees a redemption. When the code is used, the brand records it against whatever account redeemed it.
Registering an address attaches you. If you registered a billing address to make a prepaid card pass verification checks, the card is now associated with that address.
What you get is separation: one fewer company holding your identity documents, no permanent link between a modest everyday purchase and a verified profile, and no entry on a bank statement somebody else reads. That is real and worth having. It is not invisibility, and any service marketing it as such is describing something that either does not exist or is not legal.
Ordinary reasons people want this
It is worth stating plainly that privacy preferences are normal, because the framing around this topic often implies otherwise.
A gift bought from a shared account is visible to the person it is for. Someone living with a controlling partner may need spending that does not appear on a joint statement. A person who has already been through one data breach may reasonably decline to hand identity documents to a sixth company for the sake of a €40 purchase. Someone in a country with unstable banking may prefer not to route small transactions through it.
None of that is unusual, and none of it is suspicious. The clearest evidence is that established, long-running businesses openly serve these customers within the law — Coincards has done so since 2014 and states its privacy positioning explicitly.
When it becomes a red flag
There is a line, and it is not where most people assume. It is not about amount; it is about what is being promised.
Normal
- E-mail only for a consumer-sized purchase
- Paying from your own wallet
- Verification appearing at higher amounts
- A company with published legal details
Warning
- “No verification at any amount”
- Marketing that emphasises untraceability
- No company information anywhere on the site
- Support only through a messaging app
- Prices below face value
A legitimate operator offering minimal-data checkout for ordinary purchases is a business serving a normal preference. A service advertising that it will never ask questions regardless of size is either unregulated, not delivering what it claims, or assembling a customer list it should not have. None of those end well for the customer.
The framing we would use
Data minimisation is the sensible goal, not anonymity. Give each company the least it needs to do the job you are asking of it. For a gift card, that is an e-mail address. For an exchange holding your funds, it is a verified identity, and in that case the verification is what gives you a complaints process and somewhere to escalate.
Chasing anonymity in a regulated system generally means dealing with people who are not in that system, and that is where the losses in this category happen.