Privacy Policy
Effective date: 2026-05-04
This Privacy Policy describes how CryptHunter ("we", "us", "our") collects, uses and safeguards information when you use our website at crypt-hunter.com and the Telegram bot @CryptHunter_v1Bot (collectively, the "Service").
1. Data we collect
We collect the minimum data needed to operate the Service:
- Account data: email address, password hash, language preference, registration date.
- Subscription data: tier, status, billing periods, crypto invoice IDs and matching transaction hashes.
- Telegram data (if you link a Telegram account): your Telegram user ID and username, used only to deliver signals and grant access to private signal groups.
- Crypto payments: we record the transaction hash and your sending wallet address (visible on-chain regardless) solely to reconcile invoices.
- Technical data: IP address, browser type, request timestamps. Used for rate-limiting and abuse detection. Stored 30 days then aggregated/anonymized.
- We do not collect government IDs, photos, biometrics or financial account credentials.
2. How we use data
- Provide the Service: authenticate you, deliver signals, run subscriptions.
- Bill subscriptions, generate invoices, prevent fraud.
- Send transactional emails (verification, payment confirmations, account changes). We do not send marketing emails without explicit consent.
- Comply with applicable law and respond to legitimate legal requests.
- We do not sell or rent your data to anyone, ever. We do not share it with advertisers.
3. Third-party services
We rely on the following processors. Each handles a narrow slice of data and operates under its own privacy terms:
- Resend (United States) — transactional email delivery. Receives email and message contents. See resend.com/legal/privacy-policy.
- Hosting providers (Hetzner, Cloudflare) — store the database and serve the website. Standard infrastructure access; no application-level access to your data.
- We do not run third-party analytics like Google Analytics. We may add a privacy-friendly self-hosted analytics tool (Plausible / Umami) — if so, this policy will be updated.
4. Cookies and local storage
We use only essential storage:
- JWT access and refresh tokens stored in your browser's localStorage to keep you signed in.
- Locale preference cookie set by next-intl to remember your language choice.
- We do not use tracking cookies, advertising cookies, or third-party tracking pixels.
5. Retention
- Account data: kept while your account is active and 12 months after deletion (for tax / accounting compliance), then permanently removed.
- Billing records: kept for 7 years as required by Ukrainian tax law for sole proprietors.
- Technical logs: 30 days, then aggregated.
6. Your rights
You can:
- Request a copy of the data we hold about you.
- Correct inaccurate data via your account settings.
- Request account deletion. Email us; we'll confirm and delete within 30 days, except records we must retain by law.
- Request export of your data in a machine-readable format.
- If you are in the EU/UK, you may lodge a complaint with your local data protection authority.
7. Children
The Service is not directed at people under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the account.
8. International transfers
Our infrastructure is located in the EU (Hetzner, Germany). Some processors (Resend) operate in the United States. Resend is certified under the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. DPF, providing the legal basis for these transfers.
9. Changes
We may update this Policy. The effective date above will change. Material changes will be communicated via email or a banner on the site.
10. Contact
Questions or requests: support@crypt-hunter.com