Privacy Policy

Privacy Policy

Last updated: October 1, 2025

This Privacy Policy explains how CryptoProfitCalc (“CryptoProfitCalc,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you use CryptoProfitCalc.com (the “Site”) and our related tools, calculators, and services (the “Services”). By accessing or using the Services, you acknowledge this Policy. If you do not agree, please discontinue use.

1) Who We Are & How to Contact Us

If we appoint an EU/UK representative or a Data Protection Officer, we will publish their details here.

2) Information We Collect

A. Information You Provide Directly

  • Account details (if offered): name, username, email, hashed password, authentication logs.
  • Calculator inputs you type or upload (e.g., holdings, buy price, fees, tax region). Default: processed transiently; not stored unless you choose to save scenarios, create an account, or enable sync/back-up.
  • Support communications: messages, attachments, bug reports, feedback.
  • Marketing subscriptions (opt-in): email address, preferences.
  • Payment metadata (for premium features): plan, timestamps, transaction IDs; we do not receive full card numbers.

B. Information Collected Automatically

  • Device & usage data: IP address, approximate location (country/region), browser & OS, language, referring/exit pages, URLs visited, time on page, clicks/scrolls, performance diagnostics, cookie or local-storage identifiers.
  • Logs: server, error, and security logs.

C. Information from Third Parties (If You Connect Them)

  • Single sign-on (e.g., Google/Apple): basic profile data you authorize.
  • Exchange/wallet integrations (optional): API keys or CSV/JSON files; processed only to deliver the calculations you request. Do not grant withdrawal permissions.
  • Referrals/affiliates: referral codes or attribution IDs from partner links.

4) How We Use Information

  • Provide, operate, and maintain the calculators and features you request.
  • Generate results and (if you opt in) persist saved scenarios.
  • Process subscriptions or payments through our payment processor.
  • Send service updates, security alerts, and respond to support requests.
  • Personalize content (e.g., theme, currency, tax region, last-used settings).
  • Monitor performance, fix bugs, prevent abuse and fraud.
  • Conduct analytics to improve accuracy, usability, and reliability.
  • Comply with law, enforce Terms, and protect rights, property, and safety.

We do not sell personal information.

5) Cookies & Similar Technologies

We use cookies, local storage, and similar technologies for:

  • Strictly necessary (login, security, load balancing).
  • Preferences (theme, currency, default region).
  • Analytics (aggregated usage statistics and performance).
  • Marketing/attribution (limited affiliate or campaign tags, if used).

Where required, we display a cookie banner to obtain consent for non-essential cookies. You can adjust browser settings and/or our cookie settings (if available). Some features may not function without certain cookies.

Do Not Track: we do not currently respond to DNT signals due to the absence of a common industry standard.

6) Analytics, Measurement & Third-Party Tools

We may use privacy-forward analytics or mainstream tools to understand aggregated usage and improve the Site. Where available, we enable IP truncation or similar minimization features. If we embed third-party content (e.g., fonts/CDNs), those providers may receive your IP address and user-agent to serve content securely. We do not attempt to identify you from analytics data.

7) Payments & Subscriptions

Payments for premium features (if any) are processed by third-party processors (e.g., Stripe/Paddle). We do not store full card numbers on our servers. The processor acts as an independent controller or processor for your payment data. Consult the processor’s privacy notices for details.

8) API Keys, Uploads & Saved Scenarios

  • API keys (optional): stored encrypted at rest; used only to fetch data you authorize. You can revoke keys at any time both on your exchange and within our product (if offered). Do not enable withdrawals.
  • CSV/JSON uploads: processed to compute results; retained only if you choose to save scenarios or for a short time to complete processing.
  • Saved scenarios: tied to your account so you can revisit results; you can delete scenarios at any time.

9) How We Share Information

  • Service providers (processors): hosting, storage, analytics, error monitoring, email, support, payment processing, security—bound by contract to protect data and use it only per our instructions.
  • Legal/compliance: to respond to lawful requests or protect rights, property, and safety.
  • Business transfers: data may transfer in a merger, acquisition, or asset sale under appropriate safeguards.
  • With your consent: e.g., when you connect third-party accounts.

We do not sell personal information or share it for targeted advertising where prohibited by law.

10) International Data Transfers

We may process data in countries other than where you reside. When transferring personal data outside the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses (SCCs) and implement supplementary safeguards where appropriate.

11) Data Security

We implement administrative, technical, and physical safeguards, including TLS encryption in transit, encryption at rest for sensitive secrets (e.g., API keys), access controls, and monitoring. No method is 100% secure; please use strong passwords and enable multi-factor authentication if accounts are available.

12) Data Retention

  • Account data: retained while your account is active and up to 24 months after closure (longer where required by law).
  • Saved scenarios: retained until you delete them or your account.
  • Support tickets: up to 24 months after resolution.
  • Logs & analytics: typically 12–18 months in aggregated or pseudonymized form.
  • Payment records: per tax/accounting laws (generally 7–10 years).

We may anonymize data for statistical purposes; anonymized data is not subject to deletion rights.

13) Your Privacy Rights

Your rights vary by jurisdiction (e.g., GDPR/UK GDPR in the EEA/UK; CCPA/CPRA in California) and may include:

  • Access to your personal data.
  • Rectification of inaccurate data.
  • Deletion (subject to legal exceptions).
  • Restriction of processing in certain cases.
  • Portability of data in a structured, commonly used format.
  • Objection to processing based on legitimate interests and to direct marketing.
  • Withdraw consent where processing is based on consent.

To exercise rights, email privacy@cryptoprofitcalc.com or support@cryptoprofitcalc.com. We may ask for verification before responding.

California Residents (CCPA/CPRA)

  • We do not sell personal information.
  • You may request access, correction, or deletion, and to limit use of sensitive personal information (we do not use sensitive data to infer characteristics).
  • You will not be discriminated against for exercising your rights.

If you believe your rights have been infringed, you may lodge a complaint with your local supervisory authority (e.g., your EEA Data Protection Authority or the UK ICO).

14) Children’s Privacy

The Services are not directed to children under 16 (or the age defined by your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can delete it.

16) Changes to This Policy

We may update this Policy from time to time. The “Last updated” date above shows the latest revision. Material changes will be notified via the Site or email (if you have an account). Continued use after an update constitutes acceptance.

17) Contact Us

Questions or requests regarding privacy can be sent to:

Annex: Categories of Processors/Sub-Processors (Illustrative)

Replace with your actual vendors and links to their data processing addenda where applicable.

  • Cloud hosting & databases (e.g., AWS/GCP/Azure)
  • Error monitoring & logging (e.g., Sentry/CloudWatch)
  • Analytics/metrics (privacy-focused analytics or GA4 with IP anonymization)
  • Email delivery (e.g., Postmark/SendGrid)
  • Payment processing (e.g., Stripe/Paddle)
  • Customer support/CRM (e.g., Help Scout/Intercom)
  • Security/CDN (e.g., Cloudflare)