Information We Collect
We collect limited data necessary to provide and improve our services.
- Account Information: When you create an account, we collect your email address and password (securely hashed).
- Portfolio Data: We store the asset and transaction data you input to help you manage your portfolio. This data is private and accessible only by you.
- Device & Log Information: We may collect technical information (e.g., browser type, IP address, timestamps) to ensure platform stability and security.
- Preferences: We store non-identifiable settings (e.g., layout or theme) locally in your browser.
How We Use Your Information
We only use your information to operate, secure, and improve our service.
- To operate and improve the CryptoStash platform
- To provide personalized portfolio management tools
- To respond to your support inquiries or feedback
- To secure our platform against unauthorized use
- To send occasional service-related updates or notifications
Authentication and Security
We use modern, secure technologies to protect your data and identity.
- CryptoStash uses JWT (JSON Web Tokens) for authentication. This method allows us to validate your session securely without using cookies or storing sensitive session data in your browser.
- All passwords are securely hashed, and data transmission is encrypted using HTTPS.
- We follow modern security practices to protect your data against loss, misuse, or unauthorized access.
Cookies and Tracking
We don’t use cookies. Your session is handled securely through token-based authentication.
- CryptoStash does not use cookies for authentication or tracking.
- We may use browser-based local storage for non-sensitive settings such as theme preferences or UI configurations.
- We do not use third-party ad trackers or invasive analytics.
Third-Party Services
We use a few external services to fetch some data, like asset prices. These services never collect any of your personal or portfolio data.
- Some third-party APIs may be used to provide market data such as prices, tickers, or coin metadata.
- These services are only used for data retrieval and have no access to your account or stored information.
- We ensure that all integrations respect your privacy and do not share your data externally.
Your Rights and Choices
You have full control over your data at any time.
- You may view, update, or delete your account at any time.
- You may request a full deletion of your data by contacting us.
- You can export your portfolio data via the app using CSV.
Data Retention
We store your data only as long as needed for your account to function.
- We retain your information only as long as your account remains active.
- If you delete your account, your portfolio data will be permanently removed from our systems within a reasonable timeframe.
Changes to This Policy
We’ll notify you if we make any meaningful updates to this Privacy Policy.
- We may update this Privacy Policy to reflect changes in features, services, or legal requirements.
- We will notify users of significant changes and update the effective date accordingly.
Contact Us
Have questions? Reach out to our team directly.
- For any questions, concerns, or requests related to your privacy, please contact us.
Effective Date: 2025-01-01
Last Updated: 2025-01-01