gembreak
Recently Pulled
Breitling Avenger Automatic 42MM Blue Dial Men's WatchCrystal$4,784
Omega Seamaster Diver 300M 18K Rose Gold 42MM Green TitaniumSapphire$12,236
Cartier Rotonde 42MM 18K Rose Gold Alligator Strp Men's WatchEmerald$23,184
Breitling Navitimer Automatic 41MM Cream Dial 18K Rose Gold Men'sTopaz$39,468
Audemars Piguet Royal Oak Chronograph 26331or Rose Gold Brown DialRuby$86,400
Richard Mille RM 11-03 Flyback Chrono Rose GoldDiamond$332,640
Breitling Avenger Automatic 42MM Blue Dial Men's WatchCrystal$4,784
Omega Seamaster Diver 300M 18K Rose Gold 42MM Green TitaniumSapphire$12,236
Cartier Rotonde 42MM 18K Rose Gold Alligator Strp Men's WatchEmerald$23,184
Breitling Navitimer Automatic 41MM Cream Dial 18K Rose Gold Men'sTopaz$39,468
Audemars Piguet Royal Oak Chronograph 26331or Rose Gold Brown DialRuby$86,400
Richard Mille RM 11-03 Flyback Chrono Rose GoldDiamond$332,640
Breitling Avenger Automatic 42MM Blue Dial Men's WatchCrystal$4,784
Omega Seamaster Diver 300M 18K Rose Gold 42MM Green TitaniumSapphire$12,236
Cartier Rotonde 42MM 18K Rose Gold Alligator Strp Men's WatchEmerald$23,184
Breitling Navitimer Automatic 41MM Cream Dial 18K Rose Gold Men'sTopaz$39,468
Audemars Piguet Royal Oak Chronograph 26331or Rose Gold Brown DialRuby$86,400
Richard Mille RM 11-03 Flyback Chrono Rose GoldDiamond$332,640
Back to boxes

Legal

Anti-Money Laundering Policy

Last updated: August 16, 2026

Policy owner

Nexus Sky Corp, operating as gembreak

3422 Old Capitol Trail, Suite 4087, Wilmington, DE 19808, United States

AML Compliance Officer: Avery Andon, Founder

admin@gembreak.com

Nexus Sky Corp ("the Company") operates gembreak, a platform on which customers buy platform credits by card, open watch boxes, and either keep, sell back, or take delivery of the watch they receive. This policy sets out the controls the Company maintains to prevent its Services from being used for money laundering, terrorist financing, sanctions evasion, or other financial crime. It applies to every director, officer, employee, and contractor of the Company, and to every customer account.

1. Regulatory framework

The Company is a merchant selling digital credits and physical goods. It does not accept deposits, transmit funds between customers, exchange or custody virtual currency, or otherwise act as a money services business, and it is not registered as one. Card processing is performed by our payment service provider, a regulated third-party payment company, and settlement reaches the Company through that provider.

The Company maintains a risk-based AML program proportionate to its size and to the risk profile assessed in section 4, informed by the US Bank Secrecy Act, the sanctions programs administered by the US Treasury Office of Foreign Assets Control (OFAC), and the anti-money-laundering rules of the card networks. Where our payment service provider or an acquiring bank imposes stricter requirements, those requirements apply.

2. Funds flow and payout controls

The Company pays money out to customers, and the controls on that path are the most important in this policy. Money does not move freely through the Services: what a customer can withdraw is deliberately narrower than what they hold.

  • Credits may be bought only by payment card, through our payment service provider. The Company does not accept cash, wire transfers, money orders, cryptocurrency, or third-party payment instruments.
  • Purchased credits can never be withdrawn. Credits bought with a card may only be spent on the Services or refunded to the card that paid for them. There is no route by which money entering as a card payment leaves as a payout.
  • Only sell-back proceeds are withdrawable. Withdrawable value is created solely by selling a watch back to the Company, and the platform tracks that balance separately from the total. This is enforced in the database, not by staff discretion.
  • Payouts go only to the customer, and only after identity verification. A withdrawal is paid to an account held in the verified account holder's own name, and no first payout is released until identity has been verified through the regulated identity verification provider integrated with our payment service provider. The Company does not pay a third party, an account in another name, or an instrument that has not been verified as the customer's.
  • Credits cannot be transferred, gifted, or otherwise moved between accounts.
  • Funds are held on request. Requesting a withdrawal debits the balance immediately, only one request may be open at a time, and every request is reviewed before it is paid.

The effect is that a customer cannot use the Services to convert a card payment into a bank transfer. To withdraw anything at all, they must buy credits, open a box, receive a watch, and sell that watch back — leaving a complete record at each step and accepting the sell-back rate. That is a poor laundering route and an expensive one, which is the point.

3. Governance and responsibility

The Company has designated Avery Andon, Founder, as its AML Compliance Officer, with personal responsibility and authority for this program and direct access to senior management. The AML Compliance Officer is reachable at admin@gembreak.com and:

  • Owns and maintains this policy and reviews it at least annually.
  • Performs the enhanced and senior reviews described in section 5 and the screening described in section 6.
  • Reviews escalated accounts and transactions and decides whether to restrict, suspend, or terminate an account.
  • Determines whether a report to a regulator or law-enforcement agency is required and makes any such report.
  • Responds to information requests from our payment service provider, acquiring banks, card networks, regulators, and law enforcement.
  • Commissions the independent testing described in section 11 and acts on its findings.

Where the AML Compliance Officer is unavailable, or where a matter concerns the AML Compliance Officer personally, it is escalated to senior management. Senior management approves this policy and is accountable for providing the resources needed to operate it. A change in the individual holding this role is recorded in the next revision of this policy.

4. Risk assessment

The Company assesses its inherent financial-crime risk as moderate. Paying money out to customers is the principal driver of that rating, mitigated by the restriction in section 2 that only sell-back proceeds may be withdrawn. The Company reviews that assessment at least annually and whenever the business model, payment flow, or product range materially changes. The principal risks identified, and the controls applied to each, are:

  • Stolen or unauthorized card use. Cardholder data is captured and tokenized by our payment service provider. Card-fraud and authentication controls are provided by that provider as part of its service, and the Company acts on the outcomes reported to it.
  • Refund and chargeback laundering. Refunds are returned only to the original card, never to an alternative instrument, in cash, or in excess of the original charge.
  • Resale of high-value goods. Watches are shipped only to the account holder at the address held on the account, every shipment passes a manual operations review before dispatch, and shipments above the thresholds in section 5 require documentary verification.
  • Structuring and multi-accounting. One verified phone number may be associated with only one account, which the platform enforces, and cumulative activity is measured against the thresholds in section 5.
  • Sanctions and PEP exposure. Addressed by the customer representations, screening, and access restrictions in section 6, together with the compliance controls provided by our payment service provider. Sanctions and PEP screening is repeated before a payout is released.
  • Cash-out laundering. Purchased credits are not withdrawable, so card funds cannot be routed to a bank account. Withdrawals draw only on sell-back proceeds, and each one is reviewed before release.
  • Money mules and third-party payouts. Payouts are made only to an account in the verified account holder's own name. A payout instruction naming anyone else is refused and escalated under section 8.
  • Account takeover before payout. Identity verification under section 5 is required before a first payout, and a change of payout details re-triggers it.

5. Customer identification and tiered due diligence

The Company applies identification measures in three tiers. Each tier is cumulative: a customer who meets a higher tier's trigger must satisfy that tier's requirements in addition to the ones below it. Where a trigger is met, the relevant activity is paused until the review is complete.

Tier 1 — Standard, applied to every customer

  • A verified email address and an authenticated session.
  • Confirmation that the customer is aged 18 or over, and the sanctions representations in section 6.
  • True, accurate, and complete registration information.
  • Verified possession of a US or Canadian mobile number by one-time code, before any purchase or opening. This is enforced by the platform and cannot be bypassed; a number may be linked to only one account, and changing it requires a support review.
  • Cardholder name, billing address, and address-verification results captured by our payment service provider at the time of payment and available to the Company for review.

Tier 2 — Enhanced due diligence

Triggered when any of the following occurs:

  • Any first withdrawal, at any amount. No payout is released until the account holder has completed enhanced verification. There is no de minimis exemption.
  • A change to the payout account, or a payout instruction that does not match the verified account holder.
  • Cumulative credit purchases reach $5,000 in any rolling 30-day period.
  • A shipment is requested for a watch with a recorded value of $10,000 or more.
  • Any red-flag indicator in section 7 is identified.
  • The billing name or billing country does not match the account holder or the shipping destination.
  • The Company is notified by our payment service provider of elevated risk on the account, or a chargeback or fraud claim is raised.

Enhanced review requires government-issued photo identification and proof of address in the name of the account holder. This verification is not performed by the Company by eye: it is carried out through the regulated identity verification provider integrated with our payment service provider, which performs document authentication, biometric liveness and selfie matching, and data checks against the details held for the account. The Company receives the verification outcome and the underlying result rather than adjudicating the documents itself.

The AML Compliance Officer then reviews that outcome against the account and transaction history, confirms the verified name matches the cardholder name held by our payment service provider and the destination of any payout, records the decision in writing, and either clears the account, restricts it, or escalates it to Tier 3. A failed or inconclusive verification is never overridden to release a payout.

Tier 3 — Senior review

Triggered when any of the following occurs:

  • Cumulative credit purchases reach $25,000 in any rolling 12-month period.
  • A shipment is requested for a watch with a recorded value of $50,000 or more.
  • Cumulative withdrawals reach $10,000 in any rolling 12-month period.
  • A politically exposed person or adverse-media match is identified under section 6.
  • A Tier 2 review cannot be satisfactorily resolved, or the documents provided appear altered or inconsistent.

Senior review requires everything in Tier 2, plus documentary evidence of the source of the funds used, a politically exposed person and adverse-media check under section 6, and a written decision by the AML Compliance Officer approved by senior management before further activity is permitted. An account cleared at Tier 3 is placed under ongoing monitoring and reviewed at least annually while the relationship continues.

A customer who declines or fails to satisfy a verification request has the relevant activity refused: no payout is released, no shipment is dispatched, the account may be restricted or terminated, and any remaining balance attributable to a card purchase is refunded to the original payment card rather than paid out by any other route. The Company does not knowingly open or maintain anonymous accounts, accounts in fictitious names, or accounts opened on behalf of an undisclosed third party. All records created under this section are retained under section 9.

6. Sanctions, politically exposed persons, and restricted jurisdictions

The Company does not knowingly do business with any person, entity, or government targeted by applicable sanctions.

Under our Terms of Service, every customer represents on each use of the Services that they are not located in, resident in, or a citizen of a comprehensively sanctioned territory, are not listed on or owned or controlled by a party listed on the OFAC list of Specially Designated Nationals and Blocked Persons or any other applicable restricted-party list, and are not otherwise the target of sanctions, export restrictions, or trade sanctions. A customer whose circumstances change must stop using the Services and notify us.

Customers are screened against the OFAC list of Specially Designated Nationals and Blocked Persons before any payout is released, and a confirmed match is blocked and frozen rather than paid. Access is restricted from comprehensively sanctioned jurisdictions and from any territory where the Services may not lawfully be offered, on the basis of registration data, phone number, billing country, payout destination, and shipping destination. The Company additionally relies on the sanctions and compliance controls provided by our payment service provider as part of its card processing service, and on that provider declining or reporting transactions that fail its checks.

Politically exposed persons

A politically exposed person (PEP) is an individual who holds or has held a prominent public function, together with their immediate family members and known close associates. The Company treats a PEP relationship as higher risk because of the greater possibility that funds derive from corruption or bribery.

When we check. A PEP check is performed before a first payout is released, whenever an account enters Tier 3 senior review under section 5, whenever a Tier 2 review raises a question about the customer's public role, and at any time the Company otherwise becomes aware that a customer may hold or have held a prominent public function. Accounts cleared as PEPs are rechecked at each annual review while the relationship continues.

How we check. The AML Compliance Officer checks the customer's full name, together with date of birth and country of residence where held, against publicly available politically exposed person, sanctions, and adverse-media sources, and against any screening tools made available by our payment service provider. Immediate family members and known close associates identified during the review are checked on the same basis. The search performed, the sources used, the date, and the conclusion are recorded in writing and retained under section 9.

What happens on a match. A possible match is escalated to the AML Compliance Officer, who determines whether it is a true match. A confirmed PEP relationship requires documentary evidence of the source of funds and written senior approval before any further activity, purchase, or shipment is permitted, and the account is placed under ongoing monitoring. A PEP who is also a sanctions target is handled under the paragraph below rather than approved.

Where the Company becomes aware, through a notification from our payment service provider, a customer disclosure, an internal review, or any other source, that a customer may be a sanctions target, the account is blocked, funds are frozen where required, no explanation of the reason is given to the customer, and the matter is referred to the AML Compliance Officer for investigation and any onward reporting. Attempts to evade these restrictions, including by proxy, VPN, or false registration data, are grounds for immediate termination.

7. Transaction records and red flags

Purchases, openings, sell-backs, shipment requests, and account changes are logged. Every credit balance increase is recorded against the settled payment reported by our payment service provider and cannot be created by any other route, which gives a complete and reconcilable audit trail from card charge to credit. Staff review this activity on a risk basis: when a due-diligence threshold in section 5 is reached, when our payment service provider notifies the Company of elevated risk, when a chargeback or fraud claim is raised, and where any other signal warrants it.

Indicators that prompt review include:

  • Rapid, repeated purchases, or purchases structured just below a threshold in section 5.
  • Multiple cards used on one account, one card used across multiple accounts, or repeated declines followed by a success.
  • A billing name or country that does not match the account holder or the shipping destination.
  • Buying credits with little or no corresponding use of the Services, particularly followed by a refund or chargeback request.
  • Several accounts sharing a device, address, payment instrument, or shipping destination.
  • Buying credits, opening the minimum necessary, selling back immediately, and withdrawing — particularly where the customer appears indifferent to the watch or to the sell-back rate.
  • A request to be paid to an account in another name, to an account that keeps changing, or to a jurisdiction unconnected with the account.
  • A pattern of deposit and withdrawal that looks like moving money rather than playing.
  • Several accounts withdrawing to the same payout account.
  • Reluctance to complete identity verification, or the provision of documentation that appears altered or inconsistent.
  • Any indication that a customer is a sanctions target or a politically exposed person, or adverse information suggesting predicate criminal activity.
  • Pressure to release a payout quickly, or to bypass verification.

Where a review is opened, the Company may pause the account, withhold or refuse a payout, request further information, decline or reverse a transaction, cancel a pending shipment, or terminate the relationship. Every withdrawal request is reviewed before release, and releasing one is a deliberate act rather than an automatic consequence of the request.

8. Escalation and reporting

Any employee or contractor who identifies a red flag must escalate it to the AML Compliance Officer promptly and must not attempt to resolve it independently. The AML Compliance Officer investigates, documents the findings and the decision reached, and determines whether a report is required to a regulator, financial intelligence unit, or law-enforcement agency, and whether our payment service provider must be notified.

Where the Company files or considers filing a suspicious activity report, it does not disclose that fact to the customer or to any third party other than as permitted by law. Retaliation against a person who escalates a concern in good faith is prohibited.

9. Record keeping

The Company retains, for a minimum of five years from the date of the transaction or from the end of the customer relationship, whichever is later:

  • Account registration and verification records, including phone-verification history.
  • Identity, address, and source-of-funds documentation collected under section 5, and the written outcome of each enhanced or senior review.
  • Sanctions, politically exposed person, and adverse-media check records, including the sources searched and the date.
  • Transaction records, including card charges, credits applied, openings, sell-backs, refunds, chargebacks, shipments, and every withdrawal request with the account it was paid to, who approved it, and when.
  • Internal escalations, investigation notes, decisions, any reports made, and the independent testing reports required by section 11.

These records are retained as a legal obligation and survive a customer's deletion of their account, as described in the Privacy Policy. They are made available to regulators, law enforcement, our payment service provider, and acquiring banks on lawful request.

10. Training

Every employee and contractor with access to customer accounts, payments, support, or fulfillment is briefed on this policy when they take up the role, and again whenever the policy is materially revised. The briefing covers the due-diligence tiers and triggers in section 5, the screening obligations in section 6, the red flags in section 7, the escalation route in section 8, and the prohibition on tipping off.

11. Independent testing

The operation and adequacy of this program is tested by a party independent of the person who runs it. The Company engages an external reviewer — a compliance adviser, accountant, or law firm qualified in financial-crime compliance — to perform this review at least annually, and sooner following a material change to the business or at the request of our payment service provider or an acquiring bank.

The reviewer is independent of the AML Compliance Officer, takes no part in the day-to-day operation of the program, and reports to senior management rather than to the AML Compliance Officer in respect of the review. The reviewer is given access to this policy, the risk assessment, due-diligence files, screening records, escalation and investigation records, and the transaction data needed to test whether the controls described here operate in practice rather than only on paper.

Findings are reported in writing to senior management. Remediation actions, owners, and deadlines are agreed and tracked to completion, and the report together with evidence of remediation is retained under section 9 and made available to our payment service provider or an acquiring bank on request.

12. Customer obligations

By using the Services you confirm that you are using your own payment method, that the funds you use are lawfully yours, and that you are not acting on behalf of an undisclosed third party or any sanctioned person. Providing false information, using another person's payment card, or using the Services to move or disguise the source of funds is a breach of our Terms of Service and will result in termination and, where appropriate, a report to the authorities.

13. Policy governance and contact

This policy is approved by senior management, reviewed at least annually by the AML Compliance Officer, and updated whenever the law, the card network rules, the requirements of our payment service provider or an acquiring bank, or the business model change. The version in force is the one published on this page.

Compliance enquiries, including from regulators, acquiring banks, and payment partners, should be sent to admin@gembreak.com, marked for the attention of Avery Andon.

Nexus Sky Corp, operating as gembreak
3422 Old Capitol Trail, Suite 4087, Wilmington, DE 19808, United States