Legal

Privacy Policy

Last updated:

Your privacy matters to us. This Privacy Policy explains how Coinvest IQ collects, uses, and safeguards your personal information. We never sell your data to third parties.

1 Who We Are

("the Company", "we", "us", "our") operates the investment platform accessible at this website. We act as data controller for personal information collected through the platform.

For any privacy-related inquiries, contact our Data Protection Officer at:

2 Information We Collect

We collect the following categories of personal data:

Account Information: Full name, username, email address, and a bcrypt-hashed password when you register an account.

Financial Information: Transaction records including deposit amounts, payment proof uploads, wallet addresses for withdrawals, and investment plan activity. We do not store full credit card numbers or private cryptographic keys.

Identity & Verification Data: Where required by regulatory obligations, we may request government-issued identity documents.

Technical Data: IP address, device type, browser user agent, login timestamps, and session data collected automatically when you access the platform.

Communications: Messages sent to our support team, notification preferences, and any content you submit through platform forms.

3 How We Use Your Information

We use your personal data for the following purposes:

  • Account management: To create, maintain, and secure your investment account.
  • Transaction processing: To process deposits, credit investment returns, and authorise withdrawals.
  • Security monitoring: To detect, investigate, and prevent fraud, unauthorised access, and abuse.
  • Legal compliance: To comply with anti-money laundering (AML), know-your-customer (KYC), and other applicable legal requirements.
  • Communications: To send transactional emails (sign-in alerts, deposit confirmations, withdrawal updates) and platform notifications.
  • Service improvement: To analyse usage patterns and improve platform features (using anonymised, aggregated data only).

We do not use your personal data for unsolicited marketing without your explicit consent.

4 Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract performance: Processing necessary to fulfil the services you have requested (account management, transaction processing, investment plans).
  • Legal obligation: Compliance with applicable AML, KYC, and financial regulatory requirements.
  • Legitimate interests: Fraud prevention, platform security, and service quality improvement, where these do not override your privacy rights.
  • Consent: For optional communications such as marketing updates, where you have provided explicit opt-in consent.

5 Data Sharing & Third Parties

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

We may share your data with:

  • Payment processors and blockchain networks: To validate and process cryptocurrency transactions. Note that blockchain transactions are inherently public.
  • Email service providers: Our transactional email system (configured via Hostinger SMTP) to deliver account notifications.
  • Law enforcement: When required by valid legal process, court order, or regulatory authority.
  • Service infrastructure: Hosting providers (Hostinger) operating under data processing agreements that protect your information.

Any third parties we engage are required to handle your data in accordance with applicable privacy laws and our contractual data protection requirements.

6 Data Retention

We retain your personal data for as long as your account remains active and for a period thereafter as required by law or legitimate business purposes:

  • Account data: Retained for the duration of your account plus 7 years post-closure for legal and audit purposes.
  • Transaction records: Retained for a minimum of 5 years in compliance with financial record-keeping regulations.
  • Technical logs: Typically purged after 90 days unless required for active security investigations.
  • Support communications: Retained for 2 years from the date of last contact.

7 Cookies & Tracking

The platform uses strictly necessary session cookies to maintain your authenticated session. These cookies are:

  • Set as HttpOnly and SameSite=Strict to prevent cross-site request forgery.
  • Transmitted only over HTTPS connections.
  • Automatically expired on session close or after the configured session lifetime.

We do not use third-party tracking cookies, advertising networks, or cross-site analytics tools. TradingView widgets on the homepage may load cookies from TradingView.com subject to their own privacy policy.

8 Your Data Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete personal information via your profile settings or by contacting support.
  • Erasure: Request deletion of your data where no legal retention obligation applies.
  • Restriction: Request that we limit processing of your data in certain circumstances.
  • Portability: Receive your data in a structured, machine-readable format where technically feasible.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw any previously given consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at . We will respond within 30 days.

9 Security Measures

We implement robust technical and organisational security measures to protect your personal data:

  • All passwords are hashed using bcrypt (cost factor 12) — we never store plaintext passwords.
  • Security PINs for sensitive operations are independently hashed and never stored in plain form.
  • All data transmitted between your browser and our servers is encrypted via TLS (HTTPS).
  • Session tokens are regenerated on login and expire automatically.
  • Failed login attempts trigger automatic brute-force lockout protection.
  • All administrative actions are logged in an immutable audit trail.
  • Server-side error logs containing diagnostic information are stored in access-restricted files, never exposed to browser output.

10 Children's Privacy

The platform is strictly for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we discover that an account has been created by a minor, it will be immediately suspended and associated data deleted. If you believe a child has registered on our platform, please contact us immediately.

11 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. We will notify registered users of material changes at least 14 days in advance via email. The date at the top of this page reflects when the policy was last updated.

Continued use of the Service after changes take effect constitutes your acceptance of the revised Privacy Policy.

12 Contact & Complaints

For any privacy-related questions, requests, or complaints, please contact us:

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 Coinvest IQ. All rights reserved.