Privacy Policy

Effective date: September 7, 2026

This Privacy Policy explains how The Crypto Hub ("Company," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our website, software, and related services (the "Services"). We are a Delaware-based SaaS business.

It is written in plain English on purpose. Where it describes something the software does, it describes what the software actually does today.

1. Scope

This Privacy Policy applies to information we collect through our website, application dashboards, support channels, newsletters, and other interactions with the Services.

It does not apply to third-party websites, exchanges, APIs, or services that you access from our platform. Those parties have their own privacy policies.

2. Information We Collect

We may collect the following categories of personal information:

  • Identifiers: name, username, email address, account ID, and similar identifiers.
  • Account and profile data: login credentials, profile preferences, subscription plan, and account settings.
  • Transaction and portfolio data: exchange-linked balance snapshots, historical position data, watchlists, and related portfolio analytics you choose to connect.
  • Billing and commercial data: subscription status, invoices, and payment metadata (processed by payment providers; we do not store full payment card numbers).
  • Identity verification data: where you complete identity verification, images of your identity document and of your face, and the details in your anti-money-laundering profile. See section 9.
  • Device and usage data: IP address, browser type and user-agent string, screen and viewport size, pages viewed, referring site, feature usage, and timestamps.
  • Approximate location: a country, and — where you have consented to analytics cookies — a city and region, derived from your IP address. We never collect GPS coordinates, and we do not store coordinates of any kind. See section 8.
  • Phone number: where you supply one for alerts, two-factor authentication, or support.
  • Communications: support tickets, email communications, and feedback.
  • Cookies and tracking data: authentication cookies, security cookies, your cookie consent choice, and analytics and advertising tools as described in section 7.

3. Sources of Information

  • Directly from you (registration, support, forms, communications).
  • Automatically from your device and usage of the Services.
  • From integrations you authorize (for example, exchange APIs or data providers).
  • From service providers that support billing, hosting, analytics, identity verification, and security.

4. How We Use Information

  • Provide, maintain, secure, and improve the Services.
  • Create and manage user accounts and authentication sessions.
  • Process subscriptions, billing, and account administration.
  • Verify identity and meet anti-money-laundering and sanctions obligations.
  • Generate analytics, reports, and platform functionality you request.
  • Respond to support requests and communicate service notices.
  • Detect, prevent, and investigate fraud, abuse, automated sign-ups, and security incidents.
  • Comply with legal obligations and enforce our legal terms.
  • Send marketing communications where permitted by law (with opt-out options).
  • Measure advertising campaigns, where you have consented to advertising cookies.

5. Legal Bases (Where Applicable)

Where required by applicable law (including GDPR/UK GDPR), we process personal information under one or more legal bases:

  • Performance of a contract with you — running your account, syncing the exchanges you connect, billing your subscription.
  • Legitimate interests — keeping the platform secure, preventing fraud and automated sign-ups, and counting anonymous page views (see section 7 for exactly what that count contains).
  • Consent — analytics and advertising cookies, city-level location, and marketing where consent is required. You can withdraw it at any time; see section 7.
  • Compliance with legal obligations — identity verification, anti-money-laundering and sanctions screening, tax and accounting records.
  • Substantial public interest / legal obligation for the biometric element of identity verification, where applicable law requires an explicit basis for special-category data. Where consent is the required basis, we ask for it at the point of verification.

6. Service Providers We Use

These are the third parties that receive personal information from us, and what each one receives. They act as our processors except where noted.

  • Google (Firebase App Hosting, Google Cloud): hosting and infrastructure. Handles all traffic to the Services.
  • Neon: the managed PostgreSQL database, and the authentication service behind sign-in (which records the IP address and user agent of each sign-in).
  • Google Analytics 4 and Google Ads (gtag.js): web analytics and advertising measurement. Loaded on every page, but under Google Consent Mode: until you accept analytics and advertising cookies, every storage signal is denied, so no cookie is written or read and no identifier is created — only a cookieless ping used to estimate traffic in aggregate. Google acts as an independent controller for some of this processing.
  • ipwho.is: the only IP geolocation service we use. Your IP address is sent to it in exactly two cases: to resolve an approximate city, if you accepted analytics cookies; and at sign-in, only where the offline table on our own servers cannot resolve your country (in practice, IPv6 addresses), so that we can record the country of the sign-in for account security. Nothing else sends your address to a geolocation service.
  • Veriff: identity verification. Receives your identity document images, a facial image, and the identifiers needed to link the check to your account.
  • Twilio: SMS, WhatsApp, and voice. Receives your phone number and message content when we send you an alert or a verification code, or when support calls you.
  • Payment providers: Breeze (card payments), NOWPayments and DepiPay (cryptocurrency payments), and Stripe (subscription billing, where enabled). Each receives the billing details needed to take a payment. We never receive or store full card numbers.
  • Microsoft 365 (SMTP): outbound email. Receives your email address and the message.
  • Cloudflare R2: file storage for support ticket attachments and uploads.
  • Google reCAPTCHA Enterprise: bot protection on sign-up and other sensitive forms. Receives request metadata including your IP address.
  • Google Gemini: generates written summaries inside the product. Account-level samples sent for analysis are stripped of exact IP addresses and city names first.
  • Market and blockchain data providers (CoinGecko, CoinGlass, Moralis) and the exchanges you connect. These receive market queries and, for exchanges, the API credentials you supplied — not your identity data.

We do not sell personal information. We may also disclose information to comply with law, regulation or enforceable governmental request; in connection with a merger, acquisition, financing or sale of assets, subject to customary confidentiality obligations; and to protect the rights, property, safety and security of users, the Company, and the public.

7. Cookies, Analytics, and Your Choice

Some cookies are strictly necessary: they keep you signed in, protect your session, and remember the cookie choice you made. Those are always set, because the Services cannot work without them.

Everything else is optional and nothing optional is stored on your device until you accept it. When you first visit, a bar at the bottom of the page offers Accept and Decline. Until you accept:

  • No Google Analytics or Google Ads cookie is written or read, and no advertising identifier is sent. The gtag.js script loads, but with all four Consent Mode signals denied, so what Google receives is a cookieless ping with nothing in it that identifies you.
  • No session identifier is created for you or stored in your browser. So that visits can still be counted as people rather than page loads, our server groups each visit under a one-way key it derives from your connection and rotates daily — it cannot be reversed into your IP address and cannot be joined to another day.
  • Your IP address, city, region, referring site and user-agent string are not stored. They are discarded on the server before anything is written down.
  • Your IP address is not sent to any third-party geolocation service.

What we still record without consent is a count: which page was opened, for how long, and which country it was opened from, under the daily key described above. It carries no identifier that reaches back to you and is not linked to a person. We rely on legitimate interests for that. If you prefer that we record nothing at all, you can block requests to /api/analytics/track in your browser, and most tracker-blocking extensions already do.

When you accept, we additionally store a session identifier, your IP address, an approximate city and region, the site that referred you, and your browser's user-agent string, and we load Google Analytics and Google Ads.

Changing your mind: use the link in the footer of any page to reopen the bar and switch your answer. Declining after having accepted flips the signals sent to Google back to denied on your next page view and stops any further IP address being stored. Our Cookie Policy describes each category in more detail.

8. Location Data

We derive an approximate location from your IP address. We do not use GPS, and we never store latitude or longitude — the most precise thing we hold is a city name.

By default the country is resolved on our own servers, from an offline lookup table that ships with the application. Your IP address does not leave our infrastructure for this. Two consequences worth stating: that table covers IPv4 only, so visitors on IPv6 who have not accepted cookies have no country recorded at all; and it cannot resolve a city.

City and region are therefore only available where you have accepted analytics cookies. In that case your IP address is sent to ipwho.is to resolve it. Separately, when you sign in, we record the country the sign-in came from as an account-security signal; if the offline table cannot resolve your address — in practice an IPv6 address — that lookup also goes to ipwho.is. Those are the only two circumstances in which your IP address reaches a geolocation service, and ipwho.is is the only such service we use.

We use location to understand where our users are, to detect suspicious sign-in patterns, and to apply geographic restrictions where the law requires them.

9. Identity Verification and Anti-Money-Laundering Checks

Some features require identity verification. Verification is carried out by Veriff, an identity verification provider. You are asked to photograph an identity document (such as a passport, national ID card or driving licence) and to take a selfie. Veriff compares the two.

This is biometric processing. Comparing a facial image against a document photograph creates biometric data, which is a special category of personal data under GDPR/UK GDPR and sensitive personal information under several US state laws. We do not use it for any purpose other than confirming that you are who you say you are.

Alongside the document check, we collect and store an anti-money-laundering profile, which can include:

  • Your full legal name, date of birth, and nationality.
  • Your residential address and country of tax residency.
  • Whether you are a politically exposed person (PEP), or closely associated with one.
  • Your declared source of funds and source of wealth.
  • The outcome of sanctions and watchlist screening, and your consent to that screening.
  • The verification decision, its reason, and the images of the documents you submitted.

We process this to meet legal obligations, and we share it with Veriff and with the screening providers needed to complete the checks. We do not use it for marketing, and we do not sell it.

If you close your account, this material is deleted rather than retained — see section 11. Where a specific jurisdiction obliges us to retain verification records for a fixed period, that obligation would override the deletion described there; if that becomes the case we will say so here.

10. Automated Decision-Making

We run an automated scoring system that estimates whether a registered account belongs to a real person or to an automated sign-up. It reads signals such as the email domain, whether the email address was ever verified, whether the account ever signed in or paid, the device and referrer recorded at sign-up, and how much activity the account has generated. It produces one of three verdicts: real, suspicious, or likely bot.

This scoring can result in an account being disabled automatically. Where an account is enrolled in a clean-up campaign, it is emailed a warning first, re-scored on every pass, and removed from the campaign if it verifies, pays, completes identity verification, or otherwise starts to look real. If it reaches the end of that sequence, the account is disabled without a person reviewing it individually.

Disabling is a reversible flag, not a deletion: nothing in this process deletes an account or its data. If your account has been disabled and you believe the decision is wrong, contact us at the address in section 17. You have the right to obtain human review of the decision, to express your point of view, and to contest it. An administrator can restore the account.

An automated judgement is never asserted as a certainty. The system's strongest automatic verdict is "likely bot"; only a human reviewer can record a definitive one, and a human's verdict is never overwritten by the automation.

11. Data Retention and Deletion

We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements.

If you ask us to delete your account (from your account settings, or by contacting us), this is what happens:

  • Your account is disabled immediately. Your sessions are revoked, sign-in is refused, and any active subscription is set to cancel at the end of the period you have paid for.
  • A 30-day grace period begins, so that a request made in error can be reversed.
  • After 30 days, a scheduled process erases your data table by table. Anything that exists only because you had an account is deleted: your identity documents and anti-money-laundering profile, exchange connections and API keys, portfolio and trade history, tax records, alerts, notifications, settings, sessions, push subscriptions, and course progress.
  • A small number of records survive in anonymisedform, because a business record or an aggregate would otherwise develop a hole. Analytics rows keep the page path, event type and country, and lose your user ID, email address, IP address, city, region, referrer, user agent and event properties. Email delivery logs keep the recipient's domain and lose the rest of the address. Financial records keep the amounts and lose the identity, grouped under a one-way pseudonym so accounting still balances.
  • Administrative audit records of the deletion itself are kept. A record explaining why an account was erased has to outlive the account, or the erasure cannot be evidenced.
  • Your user row itself is emptied — name, email address, credentials, IP addresses and verification identifiers cleared, and the erasure timestamped — rather than dropped. The final removal of that empty row is a separate, deliberate administrator action.

Analytics event rows are otherwise retained for ongoing product reporting. Where you have declined cookies, those rows contain no IP address, no session identifier and no user agent to begin with.

12. Data Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, encryption of stored exchange API credentials, access controls, audit logging of administrative actions, rate limiting, and secure infrastructure practices.

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

13. International Data Transfers

Your information may be processed in the United States and other countries where our service providers operate. Where required, we use appropriate safeguards for cross-border data transfers.

14. Your Privacy Rights

Depending on where you live, you may have rights such as access, correction, deletion, portability, objection, restriction, and withdrawal of consent for certain processing. You may also have rights related to targeted advertising and to automated decision-making — see section 10 for the automated decision this platform actually makes.

You can withdraw cookie consent at any time from the Cookie settings link in the footer of any page, and you can request deletion of your account from your account settings.

To submit any other request, contact us using the details below. We may verify your identity before fulfilling requests.

15. Delaware Privacy Disclosures

In accordance with the Delaware Online Privacy and Protection Act (DOPPA), this policy identifies the categories of personal information collected, categories of third parties with whom information may be shared, the process for policy changes, and this policy's effective date.

Do Not Track:Some browsers transmit "Do Not Track" (DNT) signals. Because there is no universally accepted standard for DNT signals, our Services do not respond to DNT at this time. The cookie bar described in section 7 is the control we do offer.

16. California Privacy Notice

California residents may have rights under the California Consumer Privacy Act, as amended by the CPRA, including rights to know, delete, correct, and limit use of sensitive personal information, and rights related to sharing for cross-context behavioral advertising. The sensitive personal information we handle is the identity verification and anti-money-laundering material described in section 9.

We do not sell personal information for monetary consideration. Advertising cookies set with your consent may constitute "sharing" for cross-context behavioral advertising under California law; declining or withdrawing cookie consent stops it.

17. Children's Privacy

Our Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Material changes may also be communicated through in-product or email notices where required.

19. Contact Us

Company name: THECRYPTOHUB LLC

Mailing address: South Governors Avenue, Dover, Delaware, US

Privacy email: hello@thecryptohub.io

You can also contact us via the support channel available in your account.