Privacy Policy
To exchange crypto here you do not create an account, and we do not ask for your name, your email, your phone number, your date of birth, or a photograph of your passport. What we necessarily hold is the technical record of your order: the addresses involved, the assets, the amounts, and the times. We keep that because it is how we complete your order, prove what happened if you dispute it, and meet our legal obligations. We do not sell it, and we do not use it for advertising.
1. Who is responsible for your data
The controller of your personal data is the operator of buysellcrypto.exchange, trading as BuySellCrypto Exchange.
Data protection contact: privacy@buysellcrypto.exchange. We have not appointed a data protection officer, and are not required to appoint one. Rights requests and privacy questions are handled at that address.
This policy covers buysellcrypto.exchange and every order created through it. It should be read with our Terms of Service and Cookie Notice.
2. What we collect
Some cryptoasset data is personal data when it can be linked to you, so we treat all of the following as personal data.
2.1 Order data, collected because you gave it to us
| Data | Where it comes from |
|---|---|
| Sending asset, network, and amount | You, in the exchange form |
| Receiving asset, network, and estimated amount | You, in the exchange form |
| Your receiving (payout) address, and memo or destination tag | You |
| Your refund address, if you provide one | You |
| Promotional code, if you enter one | You |
| Rate type selected (floating or fixed) | You |
| Order ID, order status, and the deposit address assigned to your order | Generated by us |
| Creation, update, and completion timestamps | Generated by us |
| Deposit and payout transaction hashes, and on-chain data associated with them | Public blockchains |
2.2 Technical data, collected automatically
- IP address, and the approximate country derived from it.
- Date and time of requests, the pages and endpoints requested, HTTP status, and referrer.
- Browser type and version, operating system, device type, and screen size.
- Language preference.
This is standard server-log data generated by our hosting provider for every website request. We use it to operate the site, diagnose faults, enforce rate limits, detect abuse, and apply the geographic restrictions described in our Restricted Jurisdictions list.
2.3 Support and chat data
- Email support. If you email us, we hold your email address, your message, any attachments, and our replies.
- Site chat. The messages you type into the chat window on our site are sent to our chat provider so a reply can be produced. Do not type your private key, seed phrase, or any information you would not want recorded into that window, or into any chat window anywhere. Chat transcripts are retained as described in section 7.
2.4 Compliance data, only if section 12 of the Terms applies
If an order triggers the review conditions in section 12 of our Terms or our AML & Acceptable Use Statement, we may ask you for additional information such as the source of the funds, or identity or address documents. We ask for this only when a specific condition is met, we tell you why at the time, and we hold it under the retention rule in section 7. We do not request it for standard orders.
We also run deposit and destination addresses against blockchain-analytics and sanctions-screening sources. The result of that screening is held against the order record.
3. What we do not collect
Stated plainly, because it is the reason many people use this service:
- No account. There is no registration, no username, and no password.
- No name, date of birth, phone number, or postal address for a standard order.
- No email address required to create or complete an order. You only give us one if you choose to contact support.
- No identity documents, selfies, or biometric data for a standard order.
- No payment-card, bank-account, or other financial-instrument data. We do not handle fiat currency.
- No advertising or cross-site tracking cookies, no advertising identifiers, and no data sold or shared with data brokers, ad networks, or affiliate trackers.
- No profiling that produces legal effects for you, and no automated decision-making of that kind. Address screening flags an order for a human to look at; it does not decide anything about you by itself.
4. Why we use it, and our legal basis
Where the UK GDPR or EU GDPR applies to you, our legal bases are as follows.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating, executing, and paying out your order | Order data (2.1) | Performance of a contract |
| Refunding an order we cannot complete | Order data, refund address | Performance of a contract |
| Answering your support request | Support and chat data (2.3) | Performance of a contract; legitimate interests |
| Operating, securing, and debugging the site; rate limiting; preventing abuse | Technical data (2.2) | Legitimate interests in a secure, functioning service |
| Sanctions and blockchain-analytics screening | Addresses, amounts, IP-derived country | Legal obligation; legitimate interests in preventing financial crime |
| Applying geographic restrictions | IP-derived country | Legal obligation; legitimate interests |
| Retaining records of transactions | Order data, compliance data | Legal obligation |
| Handling a dispute, complaint, or legal claim | Whatever is relevant to it | Legitimate interests; establishment or defence of legal claims |
| Responding to a lawful request from an authority | Whatever is lawfully required | Legal obligation |
| Non-essential cookies, if and when we use any | See Cookie Notice | Consent |
Where we rely on legitimate interests, we have considered your interests and rights and concluded ours do not override them. You may ask us for that assessment.
5. Who we share it with
We do not sell your data and we do not share it for anyone else's marketing. We share it only with the service providers we need to run the exchange, and with authorities where the law requires it.
| Recipient | What it receives | Why |
|---|---|---|
| Vercel Inc. | Technical data (2.2); order data in transit | Hosting, content delivery, and serverless functions |
| Supabase Inc. | Order data (2.1) | The database that stores your order record |
| Telegram FZ-LLC | Order notifications, including order ID, assets, amounts, deposit address, and payout address | Relays new-order notifications to our internal processing systems |
| Google LLC (United States) | The messages you type into the site chat, and the replies | Hosts and processes the site chat |
| CoinGecko | No personal data. We request market prices from our server; your identity is not part of that request. | Reference market prices |
| Analytics and advertising | None. We collect no analytics or advertising data. | No provider in use |
| Our sanctions-screening and blockchain-analytics provider | Deposit and destination addresses, amounts | Screening under our AML policy |
| Our email hosting provider | Support correspondence | Delivering and storing support email |
| Professional advisers, auditors, and insurers | Only what is relevant | Legal, accounting, and audit obligations |
| Law enforcement, regulators, and courts | Only what is lawfully required | Legal obligation |
| A purchaser of our business | Order records | Only on a sale or reorganisation, and subject to this policy |
Our order notification flow and our site chat both involve third-party services outside our infrastructure. That means your payout address passes through Telegram's systems, and anything you type into the chat window passes through our chat provider's systems. We are telling you this so you can decide what to type. Do not put a private key, a seed phrase, or a secret into either.
6. International transfers
Our providers operate outside your country of residence, including in the United States and the United Arab Emirates. Where personal data is transferred out of the UK or EEA, we rely on:
- an adequacy decision, where the destination has one; or
- the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment; or
- another lawful transfer mechanism.
You can ask us which mechanism applies to a given provider at privacy@buysellcrypto.exchange.
7. How long we keep it
| Data | Retention period | Reason |
|---|---|---|
| Order records (2.1) | 5 years from order completion | Transaction record-keeping and defence of claims |
| Server and access logs (2.2) | 90 days | Security and fault diagnosis |
| Support email | 3 years from last contact | Continuity of support and dispute history |
| Chat transcripts | 90 days | Quality and abuse prevention |
| Compliance and screening data (2.4) | 5 years from the order | Anti-money-laundering record-keeping obligations |
| Consent record for this site's notice | Stored in your own browser until you clear it | So the banner does not reappear on every visit |
After the applicable period we delete the data or irreversibly anonymise it. We may keep it longer where a specific legal obligation, investigation, or live claim requires it, and only for as long as that lasts.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and get a copy.
- Rectify data that is inaccurate or incomplete.
- Erase data, where we have no overriding obligation to keep it. Note that transaction records subject to a statutory retention period cannot be erased before that period ends, and nothing can erase a transaction from a public blockchain.
- Restrict or object to processing based on legitimate interests.
- Receive the data you gave us in a machine-readable form, and have it ported elsewhere.
- Withdraw consent at any time, where we rely on consent. This does not affect processing already carried out.
- Complain to a data protection authority.
To exercise a right, email privacy@buysellcrypto.exchange. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
Identifying you is the hard part. Because we do not hold your name or email, we usually cannot link a request to your order without help. To make a request actionable, give us your order ID and, ideally, the deposit transaction hash. If we cannot verify that a request relates to your own data, we must refuse it. That refusal protects other customers from someone else requesting their records.
If you are in California, you additionally have the rights to know, delete, correct, and opt out of “sale” or “sharing” under the CCPA/CPRA, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined, and we do not process sensitive personal information for inferring characteristics.
9. A note about blockchains
Blockchain transactions are public and permanent. Once your deposit or payout is broadcast, that record exists on a public ledger which we do not control and cannot alter, redact, or delete. Anyone can view it, and analytics firms routinely cluster addresses and infer relationships between them.
This means that using our service does not make a transaction anonymous, private, or untraceable, and we do not claim otherwise. Not creating an account with us limits what we hold about you. It does not change what the blockchain records.
10. Security
Measures we apply:
- TLS encryption in transit for all site and API traffic.
- Encryption at rest on our database provider.
- Server-side handling of every credential and API key. No secret required to operate the exchange is exposed to your browser.
- Least-privilege access to the order database, restricted to the personnel who need it.
- Rate limiting and abuse detection on our public endpoints.
- Dependency and vulnerability monitoring.
No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify affected customers where the risk is high and we have a means of reaching them.
We will never ask you for your private key, seed phrase, or recovery words, by any channel, for any reason.
11. Cookies and local storage
We use a small number of strictly necessary storage items and, at present, no advertising or analytics cookies. The full list, and how to control them, is in our Cookie Notice.
12. Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has used the service, contact privacy@buysellcrypto.exchange and we will delete what we can.
13. Changes to this policy
We will post any change here with a new date. Where a change materially affects how we use your data, we will highlight it on the site for at least 14 days before it takes effect, and we will seek fresh consent where consent is the basis.
14. Contact and complaints
Privacy questions and rights requests: privacy@buysellcrypto.exchange
General support: support@buysellcrypto.exchange
Compliance and sanctions: compliance@buysellcrypto.exchange
If you are unhappy with our response you can complain to your data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in your country of residence. You can complain to the authority where you live, where you work, or where the issue arose.