Privacy policy

What we collect, why we collect it, and how long we keep it.

Last updated

This policy explains what we collect when you use SpotEx.trade, why we collect it, who sees it and how long we keep it.

The controller of your personal data is Spotex EQ, [THE OFFICE HAS NOT YET BEEN ESTABLISHED]. For questions about this policy, or to exercise any of the rights below, write to legal@spotex.trade.

How we approach your data

We collect as little as we can. The safest way to look after something is not to hold it, so where we can do without a piece of information about you, we do.

  • An account needs an email address, a username and a name. That is what we ask for.
  • We do not ask for identity documents, a photograph, a selfie, a date of birth or a national identification number, and we do not carry out identity verification.
  • Please do not send us identity documents. We do not want them, we have nowhere to keep them, and we will delete anything of that kind that reaches us.
  • We do not use advertising trackers, third-party analytics or social media pixels. That is why there is no cookie banner to click through here.
  • We do not sell your personal data and we do not share it for advertising. There is no arrangement under which anyone pays us for information about you.
  • Everything else we hold is either what the exchange cannot work without — your balances, orders and transactions — or what keeps your account safe.

Where we rely on your consent we ask for it in plain words, separately from anything else, and you can take it back at any time without losing access to your account.

This describes how we operate. It is not a promise about what the law will require of us. Exchanges that hold customer assets are required to verify their customers in many places, and that may come to apply to us. If it does, or if we decide to introduce verification, we will tell you what will be collected and who will process it before it takes effect — and if you would rather not, you will be able to withdraw your balance and close your account first.

What we collect

Things you give us:

  • Your email address, username, first name and last name, when you register.
  • Anything you write to support, including attachments.
  • Withdrawal addresses you save, and the labels you give them.
  • The reason you give us if you freeze your account.

Things we record because the exchange could not work otherwise:

  • Your balances, deposits, withdrawals, orders and trades, with their times and amounts.
  • Blockchain addresses we issue to you, and the transaction identifiers of deposits and withdrawals — these are public on the chain by their nature.
  • Your fee tier and trading volume, and whether another customer referred you.

Things we record to keep your account safe:

  • The IP address and browser user-agent of each sign-in, and of the sessions and devices on your account.
  • A record of security events: sign-ins from a new device, password changes, authenticator changes, API keys created and revoked, withdrawals requested and approved.
  • Whether you have an authenticator enrolled, and your recovery codes in hashed form.
  • API key identifiers, the addresses a key is restricted to, and when each key was last used.

That is the whole of it. Two things worth saying about what is on that list but is never readable by us:

  • We never see your password. It is stored as a hash that cannot be reversed, so we cannot tell you what it is and nobody who obtains the database can either.
  • We never store your API secret. It is shown to you once, and we keep only what is needed to check that a request was signed with it.

Why we are allowed to use it

  • To provide the exchange under our agreement with you — your account, balances, orders, deposits and withdrawals.
  • To meet our legal obligations, including record-keeping, and anti-money-laundering and sanctions obligations where they apply to us.
  • For our legitimate interest in keeping the exchange and its customers safe: detecting fraud, preventing account takeover, spotting market manipulation, and keeping the service running.
  • With your consent, where we ask for it. You can withdraw consent at any time.

Verifying who you are

We do not carry out identity verification, and we hold no identity documents — see "How we approach your data" above for what that means and what would happen if it changed.

We do confirm two things, and neither involves a document. We confirm that the email address on the account is one you can receive mail at, because it is how we reach you about your money. And when you ask us to do something that cannot be undone — lift a freeze, act on a data request — we may ask you to prove the account is yours, using what is already on it rather than anything new.

Who else sees your data

We share the minimum necessary with the companies that help us run the exchange:

  • Custody and blockchain providers, to issue deposit addresses and to send withdrawals. They see the addresses and amounts involved.
  • Our email provider, to deliver account and security email. They see your email address and the content of those messages.
  • Our hosting and database providers, who store the data on our behalf.

Each of them acts on our instructions under a written contract, and may not use your data for their own purposes.

We also share data where we must: with a law-enforcement agency, a regulator, a tax authority or a court, where we are legally required to, and with professional advisers where necessary. If we are ever involved in a merger or sale of the business, your data may pass to the buyer under the same terms.

We do not sell your personal data, and we do not share it for advertising.

Where your data is

We and our providers may store and process data in the United States. Where data leaves the State of California, United States, we rely on standard contractual clauses with each provider, or another safeguard the law recognises to protect it.

How long we keep it

  • Account and identity data: while your account is open, and for 5 years afterwards.
  • Transaction records — deposits, withdrawals, orders, trades, balance changes: for 5 years, because we are required to keep financial records and because this system's record of your money is those tables themselves.
  • Security and audit events: for 5 years.
  • Support correspondence: for 3 years.
  • Session and device records: until the session ends or you revoke the device, plus a short period in the security log.

Closing your account does not delete the records above before those periods end. That is a legal obligation, not a preference.

Your rights

Depending on where you live, you have some or all of these rights:

  • To know what we hold about you, and to get a copy of it.
  • To have inaccurate data corrected.
  • To have data deleted, where we are not required to keep it.
  • To restrict or object to how we use it, including objecting to processing based on our legitimate interests.
  • To receive the data you gave us in a portable form.
  • To withdraw consent where we relied on it.
  • To complain to your data protection authority. In the State of California, United States that is the California Privacy Protection Agency.

To exercise any of them, write to legal@spotex.trade from the address on your account. We will respond within 45 days. We may need to confirm it is really you before we act — which, for an account that holds money, is a protection for you.

Where deletion would conflict with a record we must keep, we will delete what we can, stop using the rest, and tell you what we kept and why.

Cookies

We use cookies only to make the site work:

  • A session cookie, so you stay signed in. It is required.
  • A device cookie, so we can recognise a browser you have used before and ask you for less. It is also how we can tell you about a sign-in from a device nobody has used.
  • A preference cookie remembering whether you chose the light or dark theme.

There are no advertising or analytics cookies, so there is no consent banner to click through.

How we protect it

Passwords are hashed with a memory-hard algorithm. Session tokens are stored only as hashes. Provider credentials and API key secrets are encrypted at rest. Access to production data is limited to staff who need it, and administrative actions are recorded in an audit log. We use TLS for everything in transit, and a strict content security policy so that a script we did not write cannot run on our pages.

No system is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will tell you and the relevant authority, as the law requires.

Children

The exchange is not for anyone under 18, and we do not knowingly collect data about children. If you believe a child has given us data, write to legal@spotex.trade and we will delete it.

Changes

We may update this policy. We will publish the new version with the date it was updated, and where the change is material we will tell you by email before it takes effect.

Contact

Spotex EQ [THE OFFICE HAS NOT YET BEEN ESTABLISHED] legal@spotex.trade

We do not have a public office. The address above is our address of record for formal and legal notices; it is not somewhere you can visit. Write to us by email — it reaches us faster and we answer every request from there.