Draft template — not reviewed by a lawyer
This document was drafted from what the software actually does. It has not been reviewed by a qualified lawyer, it is not legal advice, and it is not fit to govern a live financial service. It must be reviewed and completed by counsel qualified in the relevant jurisdiction before Crypto Gate accepts real customer funds.
Passages in [SQUARE BRACKETS] are unfilled placeholders. Nothing in them has been invented — a plausible but wrong company name, address, governing law or retention period would be far more dangerous than a visible blank.
Privacy policy
Last updated
What Crypto Gate collects, why, who else sees it, and what you can ask us to do about it.
1. Who we are
Crypto Gate, of , , operates Crypto Gate and decides how and why the personal data described here is processed.
This policy covers the Crypto Gate website, dashboard, mobile app and API. It does not cover a merchant's own site or checkout — if you paid a merchant who uses Crypto Gate, that merchant's privacy policy governs the order itself.
[PLACEHOLDER — DATA PROTECTION REGISTRATION AND CONTACT. Any supervisory authority registration, and the name and address of a data protection officer or representative if one is required. We hold no registration number we can state here and will not invent one.]
2. What we collect
The list below is what the software actually records — not a generic list. If something is not here, we are not collecting it.
Information you give us
- Name — as entered on your account.
- Email address — used to sign in, to send one-time codes, and to reach you about your account.
- Bio — an optional free-text field on your profile. Whatever you put in it, we store.
- Profile photo, if you upload one.
- Password — stored only as a one-way hash. We never store, and cannot read, your actual password.
- Anything you send to support, including messages in live chat.
Information collected automatically when you use the service
- IP address of each request that signs in or acts on your account.
- Approximate location derived from that IP — country, region and city only. This is a lookup against a third-party database, not GPS, and it is often imprecise.
- Browser and operating system, derived from the user-agent string (for example “Chrome on macOS”), together with the raw user-agent string.
- Device identifiers — a random identifier generated for your browser or app install, stored by us hashed, never in the clear. See section 5.
- Sign-in history — successes and failures both, with the timestamp, IP, approximate location and device description. Failures are recorded deliberately, so that someone trying your password is visible to you and to us.
- Two-factor and one-time-code events — that a code was issued and whether it was accepted. Codes themselves are stored hashed.
Financial and account records
- Transaction records — payment requests you created, deposits received, withdrawals and payouts made, swaps performed, with amounts, assets, timestamps and status.
- On-chain data — deposit addresses issued to you, destination addresses you paid out to, and transaction hashes.
- Ledger entries — the double-entry record behind every balance movement.
- API key metadata — a key's label, when it was created, when it was last used and by which IP. The secret itself is stored only as a hash.
- Webhook endpoint URLs you configure and the delivery attempts made to them.
We do not collect payment card details, because the service does not accept cards. No card data ever reaches our systems.
3. Why we collect it
- To run your account and the service — authenticating you, showing your balance, creating payment requests, sending payouts.
- To keep the account secure — recognising a device, deciding when to demand an emailed code, alerting you to a sign-in from somewhere new, rate-limiting and detecting credential-stuffing attempts.
- To keep an accurate financial record — the ledger has to be complete and auditable to be worth anything.
- To support you — answering your questions and investigating problems.
- To detect and prevent abuse — fraud, money laundering, sanctions breaches and other prohibited use, as described in the acceptable use policy.
- To meet legal obligations — including responding to lawful requests and retaining records we are required to retain.
We do not sell your personal data. We do not share it with advertisers, data brokers, or ad networks, and we do not run advertising or third-party analytics trackers on the product.
4. Legal basis
Broadly, we process your data because we need it to perform our contract with you (running the account), because we have a legitimate interest in keeping the service secure and preventing abuse, and because some records we are required by law to keep.
[PLACEHOLDER — LAWFUL BASIS MAPPING. Counsel to confirm which data protection regimes apply given where Crypto Gate is established and where its customers are, and to map each processing purpose above to a specific lawful basis under each. We describe our intent to handle data lawfully and minimally; we do not claim compliance with any named regime as a settled fact until this review is done.]
5. Device recognition and sign-in
This deserves its own section because it is the least obvious thing we do, and it involves an identifier that behaves like a credential.
When you sign in from a browser or app install we have not seen before, we email you a one-time code before any session exists. Getting that prompt on every single sign-in would be miserable, so once you have proved yourself we remember the device.
How that works:
- A random identifier is generated for your browser and stored in a cookie named
cg_device. The mobile app holds the equivalent value in secure storage and sends it as a request header instead. - We store only a SHA-256 hash of that identifier against your account, never the value itself. If our device table were ever stolen, it could not be used to skip the emailed code — which is exactly why it is hashed.
- Alongside the hash we keep a label (“Chrome on macOS”), the last IP, the last approximate location and when it was last used, so you can look at your device list and recognise your own machines.
- Trust expires after 90 days, and the cookie is set to expire on the same schedule. An abandoned laptop stops being a way in.
- The identifier is only ever a hint about which device you are on. It never authenticates you by itself — your password still has to be correct first.
You can clear the cookie at any time (see the cookie policy) or remove a device from your account. Either way the next sign-in from that device asks for an emailed code again.
6. Who else sees your data
These are the third parties the service actually calls, and exactly what each one receives. Nothing else about you is routinely sent anywhere.
Tatum — blockchain infrastructure
Generates and monitors the blockchain addresses your payments arrive at, and broadcasts your outbound transactions. Receives: blockchain addresses, transaction amounts, assets and transaction hashes. It does not receive your name, email or password. It does, necessarily, hold the association between an address and our account with it.
Postalynk — email delivery
Sends transactional email: one-time sign-in codes, security alerts, password resets and account notices. Receives: your email address, your name where it appears in the message, and the content of the email itself — which for a sign-in alert includes the time, approximate location and device description of the sign-in.
Supoora — live chat
Powers the support chat widget, where it is enabled. Receives: your account identifier, your name and your email address, plus whatever you type into the chat. It is deliberately not given your balance or your transaction history — support has no business seeing those through a third-party widget. Do not paste API keys, recovery codes or private keys into a chat window.
IP geolocation lookup
Turns an IP address into an approximate country, region and city for sign-in alerts and your device list. Receives: the IP address of the request, and nothing else — no name, no email, no account identifier. Results are cached for 24 hours to avoid repeating the lookup. This is best-effort: if it fails, the alert says “Unknown location” and your sign-in proceeds normally.
CoinGecko — price data
Supplies reference prices used to display fiat values and to cross two assets for a swap. Receives: nothing about you. We request prices for assets, not for accounts.
Others
We also use hosting and infrastructure providers that necessarily process data on our behalf, and we may disclose data to professional advisers, to law enforcement or a regulator where we are lawfully required to, and to an acquirer if the business is sold — in which case this policy continues to apply to data transferred until it is replaced.
[PLACEHOLDER — SUB-PROCESSOR LIST. A named, dated list of hosting, storage, backup and monitoring providers, with location and role, maintained and published as processors are added or changed.]
7. Where data is processed
The providers above operate internationally, so your data may be processed outside the country you are in.
[PLACEHOLDER — HOSTING LOCATION AND TRANSFER MECHANISM. The countries in which data is stored and processed, and the mechanism relied on for any cross-border transfer (for example standard contractual clauses or an adequacy decision), once counsel has confirmed which regimes apply.]
8. How long we keep it
Financial records are kept even after you close your account. Ledger entries, transaction records, deposits, withdrawals, payouts and swaps are the record of money we held on your behalf. We cannot delete them on request, and we would not want to: an incomplete ledger cannot answer a later dispute, an audit or a lawful request about funds we handled. Related identifying information is retained alongside them for the same reason.
Other categories:
- Profile data (name, email, and an optional phone number) — for as long as the account is open, then for as long as it remains attached to retained financial records.
- Sign-in history and security logs — kept long enough to investigate account compromise and abuse.
- Trusted device records — expire 90 days after last use, or immediately when you remove the device.
- Geolocation cache — 24 hours.
- Support conversations — retained by the chat provider under its own schedule as well as ours.
[PLACEHOLDER — RETENTION PERIODS. The specific number of years each category above is kept, set against the record-keeping obligations that apply in . We have deliberately not written “seven years” or any other figure here, because a retention period we invented is a promise we might break.]
9. Your rights
Whatever regime ultimately applies, we intend to honour the following in practice, and you can exercise any of them by writing to [email protected]:
- Access — a copy of the personal data we hold about you.
- Correction — most profile fields you can edit yourself; write to us for anything you cannot.
- Deletion — of data we are not required to keep. Financial and ledger records are the exception, for the reasons in section 8, and we will tell you plainly what we have kept and why rather than quietly refusing.
- Portability — your transaction history in a machine-readable form.
- Objection and restriction — you can object to processing based on our legitimate interests, though refusing security processing may mean we cannot safely keep the account open.
- Complaint — to your data protection authority, in addition to raising it with us.
We will verify your identity before acting on a request, and we will respond within [RESPONSE PERIOD]. We do not charge for a reasonable request.
[PLACEHOLDER — REGIME-SPECIFIC RIGHTS AND DISCLOSURES. Any additional statutory rights, notices or opt-outs required by the regimes that apply, along with the authority a complaint should be directed to.]
10. How we protect it
What the software does today:
- Passwords, API secrets, one-time codes and device identifiers are all stored hashed. A stolen table is not a stolen account.
- Two-factor authentication is required on every path that moves funds.
- A sign-in from an unrecognised device requires an emailed code before a session is created.
- Blocking an account ends its sessions and API access immediately, rather than at next login.
- Sign-in attempts, successful and failed, are recorded and visible to you.
- Traffic is served over TLS.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and any authority we are required to notify, without undue delay.
If you find a vulnerability, please report it to [email protected].
11. Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will investigate and delete what we can lawfully delete.
12. A note about the blockchain
Blockchain transactions are public and permanent. Addresses, amounts and timestamps are visible to anyone, forever, on every network we support. That data is not ours to delete, and no privacy right you exercise against us can remove it — it is not in our systems.
Blockchain analysis can often link addresses to each other and, with other information, to a person. Treat an address you publish as public information about you.
13. Changes
We will update this policy when what we do changes, and we will change the “last updated” date at the top by hand. Where a change materially affects how we use your data, we will tell you directly rather than relying on you re-reading this page.
14. Contact
Crypto Gate
Privacy and data requests: [email protected]
Security reports: [email protected]
General support: [email protected]
Before this document goes live
Have counsel qualified in the relevant jurisdiction review the whole of it, fill every bracketed placeholder, and confirm what licensing or registration holding customer funds requires where Crypto Gate operates and where its customers are. Until that is done this page is a draft, not a contract.
Questions about this document: [email protected]. Everything else: [email protected].