Privacy Policy
Last updated: July 29, 2026
1. Data Controller
For the purposes of applicable data protection law, CryptoInfo acts as the data controller for the personal data described in this policy. Contact details are provided in the "Contact Us" section below.
2. Data We Collect
Automatically collected: Standard server logs such as IP address, browser type, pages visited and timestamps. Used for security monitoring and performance analysis.
Visitor accounts
If you create a free CryptoInfo account, we store:
- - Your email address (used for login and account communications).
- - The name you provide.
- - Your password — stored as an irreversible cryptographic hash (bcrypt), never in plain text and never visible to anyone at CryptoInfo.
- - Your preferred language, used to display the site and send you emails in that language.
We do not store your IP address on your account. Your IP may appear in general server access logs (see above) for security purposes only.
Newsletter
If you subscribe to our newsletter, we store your email address, preferred language, IP address (used as evidence that consent was given, per GDPR Art. 7(1)) and subscription status (pending, confirmed, unsubscribed). We use a double opt-in process: after signing up, you must click a confirmation link sent to your inbox before you receive any newsletter email. No marketing email is ever sent to an unconfirmed address.
Watchlist
If you're logged in, the cryptocurrencies you choose to track ("star") are stored against your account, along with their display order. This data is only visible to you, and is permanently deleted if you delete your account.
3. How We Use Your Data
- - To provide and improve CryptoInfo — including your account, watchlist and newsletter subscription.
- - To detect and prevent abuse (rate limiting, fraud prevention).
- - We do not sell personal data.
- - We do not use personal data for advertising profiling.
4. Legal Basis for Processing
- - Account & Watchlist — performance of a contract (GDPR Art. 6(1)(b)): we process this data to provide the account-based features you request.
- - Newsletter — consent (GDPR Art. 6(1)(a)), given via double opt-in and withdrawable at any time.
- - Server logs — legitimate interest (GDPR Art. 6(1)(f)): keeping the site secure and operational.
- - Analytics cookies — consent (GDPR Art. 6(1)(a)), given via the cookie banner.
5. Data Retention
- - Server logs: purged after 30 days where operationally possible.
- - Visitor accounts: kept for as long as your account exists. You can delete it at any time, instantly, from your Account page.
- - Watchlist: deleted automatically and immediately when your account is deleted.
- - Newsletter subscription: kept until you unsubscribe — one click, always available, in every email and on your Account page.
6. Data Security
Passwords are never stored in plain text — they are hashed using bcrypt, a one-way cryptographic function. All pages are served over HTTPS. Confirmation and password-reset links use cryptographically random, single-use tokens.
7. Cookies
Essential cookies (always active, no consent required) — needed by Laravel to run the site:
cryptoinfo_session- session managementXSRF-TOKEN- CSRF protection
Optional analytics cookies — Google Analytics 4 and Microsoft Clarity, used to understand how visitors use the site (pages viewed, clicks, general navigation patterns). These are only set after you explicitly accept them in our cookie banner; nothing from Google or Microsoft is loaded before that. You can accept, reject or change your choice at any time via the "Cookies" link in the footer — your decision is stored in your browser (localStorage) and can be withdrawn just as easily as it was given.
We do not use advertising or third-party marketing cookies, and analytics data is never used to build advertising profiles.
8. Third-Party Services
We use third-party services for market data, assets, email delivery, and — only with your consent — analytics:
- - Google Fonts Google Fonts for font delivery.
- - CoinGecko CoinGecko for cryptocurrency market data.
- - Alternative.me Alternative.me for market sentiment data.
- - A transactional email provider, to deliver account, verification and newsletter emails.
- - Google Analytics 4 Google Analytics 4 (optional, consent-gated) for audience analytics.
- - Microsoft Clarity Microsoft Clarity (optional, consent-gated) for usage/heatmap analytics.
CryptoInfo also participates in affiliate programs (Binance, Bybit, OKX — see our Terms for the affiliate disclosure). Clicking an affiliate link is recorded as an anonymous event (which link, which page) if you've accepted analytics cookies; it does not identify you personally.
9. Your Rights
If you are in the EEA, UK, or another jurisdiction with similar protections, you have the following rights over your personal data:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can correct your name, email and language directly from your Account page at any time, instantly.
- Right to erasure — You can permanently delete your account and all associated data (including your watchlist) at any time, instantly, from your Account page. You can also unsubscribe from the newsletter with one click, at any time.
- Right to data portability — You can request an export of your personal data in a structured, machine-readable format.
- Right to object — You can object to processing based on legitimate interest, and withdraw consent (newsletter, analytics cookies) at any time without affecting the lawfulness of processing carried out before withdrawal.
How to exercise your rights
Rectification and erasure are self-service (see above). For access, portability, or objection requests, contact us using the details below — we will respond within one month, as required by GDPR Art. 12(3).
10. Contact Us
For any question about this Privacy Policy or to exercise your data rights, contact us at: contact@cryptoinfo.business.