Privacy Policy
Last updated: [2025-10-22]
1) What We Collect
Account and contact: email, password hash, 2FA status, settings.
Usage and device: IP address, browser and device information, timestamps, logs, pages, app events.
Transaction data: deposit and withdrawal addresses, amounts, transaction IDs, order history.
Support: messages, tickets, attachments, phone information if you contact us by phone.
Optional verification if requested: government ID, selfie, proof of address, sanctions or PEP screening results.
Cookies and local storage for login sessions, preferences, analytics, and abuse prevention.
We do not collect or store your private keys.
2) How We Use Data
Create and secure your account including two-factor authentication, fraud, and abuse prevention.
Provide trading, wallet, and support services.
Comply with legal obligations such as AML, CTF, sanctions, tax, or court orders.
Communicate about service changes, security updates, or marketing. You may opt out of marketing messages.
Analyze and improve performance, user experience, and reliability.
3) Legal Bases
Contract performance for providing our services.
Legitimate interests for security, anti-fraud, and service improvement.
Consent for marketing cookies or certain communications.
Legal obligations for AML, CTF, and sanctions checks.
4) Sharing
We may share data with the following parties:
• Service providers for cloud hosting, analytics, email, customer support, security or anti-fraud, blockchain analytics, and optional KYC verification.
• Affiliates under common control following this Policy.
• Authorities where legally required.
• In case of business transfers such as a merger or acquisition.
We do not sell personal data.
5) International Transfers
If data is transferred internationally, we apply appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
6) Retention
We retain data as necessary to provide services and meet legal obligations such as AML retention periods, then delete or anonymize it.
7) Security
We use administrative, technical, and organizational measures including encryption in transit, least-privilege access, logging, and two-factor authentication support.
No system is completely secure. Keep your account credentials and 2FA information safe.
8) Your Rights
Depending on your region, you may have rights to access, correct, delete, restrict, or object to processing, request data portability, and withdraw consent.
Contact support@cosmonaut.exchange for any request. We may need to verify your identity and certain legal exceptions may apply.
9) Children
Cosmonaut is not intended for minors under 18. We do not knowingly collect data from children.
10) Third-Party Links
Links to third parties such as other exchanges for off-ramp are outside our control. Review their policies before using those services.
11) Changes
We will post updates here with a new effective date. Material changes may also be notified by email or in-app.