Privacy Policy
Last updated: 4 August 2024
This page explains what personal data we collect, why we need it, who we share it with, and what you can ask us to do with it.
1. Who is responsible for your data
The data controller is [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. For any privacy question or request, contact [PRIVACY EMAIL].
2. What we collect
Account data. Your email address, display name, an optional profile picture, and a referral code. Your password is handled by our authentication provider and is stored only as a cryptographic hash — we never see it.
Identity verification data. If you submit KYC, we collect the identity documents and photographs you upload, along with the details on them. These are needed to meet anti-money-laundering obligations and to release withdrawals.
Financial and activity data. Your wallet balances, deposits, withdrawals, trades, orders and referral earnings — the record of what you did on the platform.
Payment data. Card payments are handled by Stripe. We receive a confirmation and a payment reference; we never receive or store your full card number. For payouts we store the account details you enter, and an identifier for your Stripe Connect account where applicable.
Support messages. Messages and any files you send us through the in-app support chat.
Technical data. Your IP address is used at sign-up to limit mass account creation, and standard server logs record requests. We do not run advertising or cross-site tracking, and we do not sell data to anyone.
3. Why we use it, and on what basis
- To provide the service — running your account, executing and settling trades, processing deposits and withdrawals. Basis: performance of our contract with you.
- To meet legal obligations — identity verification, anti-money-laundering checks, record-keeping, responding to lawful requests. Basis: legal obligation.
- To keep the platform safe — rate limiting, fraud and abuse prevention, an audit record of administrative actions. Basis: our legitimate interest in a secure service.
- To support you — answering your messages and investigating issues you report. Basis: performance of our contract and legitimate interest.
4. Who we share it with
We share data only with the providers that make the service work, and only as far as needed:
- Supabase — database, authentication and encrypted file storage.
- Stripe — card payments and payouts. Stripe is an independent controller for the payment data it collects; see Stripe’s own privacy policy.
- Our hosting provider — serving the application and its logs.
- Public market data sources — we read public price feeds. No personal data of yours is sent to them.
- Authorities — where we are legally required to disclose, or to establish or defend a legal claim.
5. How it is protected
- All traffic is encrypted in transit (HTTPS), and the application sends strict security headers including a Content Security Policy.
- Identity documents are held in private storage. They are never publicly addressable — access is via short-lived links that expire after one hour.
- Database access is row-level restricted so one user cannot read another user’s records.
- Administrative actions on accounts and balances are written to an append-only audit log.
6. How long we keep it
Account, transaction and verification records are retained for as long as your account is open and afterwards for the period our anti-money-laundering and accounting obligations require — typically [e.g. 5 years] from the end of the relationship. Support messages are kept for [e.g. 2 years]. After that, data is deleted or anonymised.
7. Your rights
Depending on where you live, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete your data — though we must keep records the law requires us to keep;
- restrict or object to a particular use;
- provide your data in a portable format.
Write to [PRIVACY EMAIL] and we will respond within [e.g. 30 days]. If you are not satisfied, you may complain to your local data protection authority.
8. Cookies and local storage
We use browser storage for one purpose: keeping you signed in and remembering interface preferences such as your theme and whether balances are hidden. There are no advertising cookies and no third-party analytics trackers.
9. Children
The platform is not for anyone under 18. We do not knowingly collect data from children, and we delete any such account we discover.
10. Changes
If this policy changes materially we will update the date above and notify registered users.
© 2026 CoinX1. All rights reserved.