Legal

Privacy Policy

Last updated: August 2, 2026

This policy explains what information we collect from you, why we collect it, how we protect it, and the rights you have over it. Written to be read, not scrolled past.

1. What we collect

  • Account data, email address, display name, and a hashed password (or OAuth identifier if you sign in with Google).
  • Verification data, for deposits above $10,000 we collect a government ID, a selfie, and residential address to satisfy anti-money-laundering rules.
  • Financial activity, plan choices, deposits, withdrawals, referral earnings, and simulated trade history within our platform.
  • Device metadata, IP, browser, and coarse location, used strictly to detect fraud and secure your account.

2. How we use it

  • To run your account: authenticate you, execute your instructions, settle weekly payouts, and support you when things go sideways.
  • To satisfy the law: KYC/AML checks, sanctions screening, and regulatory reporting where mandated.
  • To keep the platform safe: detect fraud, prevent account takeovers, and monitor on-chain anomalies with Chainalysis.
  • To improve the product: aggregated, anonymised analytics, never sold, never combined with third-party data for advertising.

3. Who we share it with

  • Regulated identity providers (Sumsub), KYC verification.
  • Financial infrastructure (Fireblocks, Chainalysis, Circle), custody, monitoring, on/off-ramp.
  • Cloud infrastructure (AWS, Cloudflare, Lovable Cloud), hosting and delivery.
  • Law enforcement, only under a valid, jurisdiction-appropriate order, and only the narrow data set required.
  • We do not sell your data. Ever.

4. Retention

  • KYC records: 5 years after account closure (regulatory minimum).
  • Transaction history: 7 years (financial-record retention).
  • Marketing analytics: anonymised at 90 days, aggregated indefinitely.
  • Support tickets: 2 years for quality assurance, then deleted.

5. Your rights

  • Access, correct, export, or delete your data by mailing privacy@stablecoinflip.com. We respond within 30 days.
  • You may object to processing that goes beyond running your account, subject to our regulatory obligations.
  • EU / UK / Swiss residents have full GDPR rights. California residents have full CCPA rights. Both are honoured globally as a matter of policy.

6. Security

  • TLS in transit; AES-256 at rest. Passwords stored with Argon2id. MPC-protected custody.
  • SOC 2 Type II controls, annual penetration testing by Trail of Bits and Cure53.
  • Report a vulnerability to security@stablecoinflip.com, we run a bug bounty on Immunefi.

7. Cookies

  • We use strictly-necessary cookies for authentication and CSRF protection. That's it. No advertising cookies. No third-party trackers.

8. Changes

  • We'll email you at least 30 days before any material change. The current version and its effective date are always at the top of this page.
Questions? privacy@stablecoinflip.com, a human answers within one business day.