Privacy Policy
Last updated: October 2, 2026
This Privacy Policy explains how Cruxlee ("we", "us", "our") collects, uses, and protects your personal data when you use cruxlee.com (the "Service"), in accordance with the EU/UK General Data Protection Regulation (GDPR).
Cruxlee is operated as an individual/sole-trader project under the brand name "Cruxlee." For any privacy inquiry, including exercising your rights under GDPR, contact: bobanavramovik@gmail.com
1. What Data We Collect
| Data | Why we collect it | Where it's stored |
|---|---|---|
| Email address | Account identification, sign-in (“magic link”), purchase confirmation, support | Firebase (Google Cloud) |
| Payment/active status (paid or not) | To grant or restrict access to the Service | Firebase |
| Telegram chat ID (if you choose to link Telegram) | To send you trading signal alerts | Firebase |
| Watchlist (coins you track) | To personalize charts and alerts | Firebase |
| Hashed IP address (one-way, non-reversible) | Anti-abuse rate limiting on login/checkout attempts | Firebase |
| Temporary checkout record (email + payment status) | To process your one-time payment | Firebase |
We do not collect or store:
- Your cryptocurrency wallet address (handled entirely by our payment processor, NOWPayments — we never see or store it)
- Your Telegram username (only an internal chat ID, which cannot be used to look you up on Telegram by anyone browsing)
- Your IP address in reversible/plain form (only a one-way cryptographic hash is kept, which cannot be converted back into your actual IP address)
- Passwords (we use passwordless email sign-in)
2. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract — to provide the Service you purchased (account access, signal delivery, dashboard functionality)
- Legitimate interest — to prevent fraud and abuse (e.g., the hashed IP rate-limiting)
- Consent — where you voluntarily choose to link your Telegram account
3. How We Use Your Data
- To authenticate you and grant/restrict access based on payment status
- To deliver trading signal alerts via Telegram, if you've linked your account
- To send transactional emails (e.g., sign-in links, purchase confirmation) via our email provider, Resend
- To prevent abuse of login or checkout flows via hashed-IP rate limiting
We do not use your data for advertising, and we do not sell your data to third parties.
4. Third Parties Who Process Data On Our Behalf
| Service | Purpose | Data involved |
|---|---|---|
| Firebase (Google) | Authentication & database | Email, Telegram chat ID, watchlist, hashed IP |
| NOWPayments | Payment processing | Payment/checkout data (wallet address never touches our systems) |
| Resend | Transactional email delivery | Email address |
| Telegram Bot API | Alert delivery | Telegram chat ID |
| Vercel | Website hosting | Standard web request logs |
| Binance, CoinGecko, alternative.me | Market data (not user data) | No personal data shared |
Each of these providers processes data under their own privacy policies and may be located outside your country; where this involves a transfer outside the EU/UK, these providers generally rely on their own GDPR-compliant safeguards (e.g., Standard Contractual Clauses).
5. Data Retention
We retain your account data for as long as your account exists. Temporary checkout records and Telegram verification codes are short-lived and automatically expire (verification codes within 10 minutes). If you request account deletion, we will delete your personal data within a reasonable timeframe, except where retention is required by law (e.g., payment records for tax purposes).
6. Your Rights Under GDPR
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten"), subject to legal retention requirements
- Restrict or object to certain processing
- Data portability (receive your data in a portable format)
- Withdraw consent at any time where processing is based on consent (e.g., unlinking Telegram)
- Lodge a complaint with your national data protection authority (in the UK, the ICO; in an EU country, your national Data Protection Authority)
To exercise any of these rights, contact bobanavramovik@gmail.com. We will respond within the timeframe required by GDPR (generally one month).
7. Security
We rely on Firebase's and our other providers' built-in security infrastructure. IP addresses are stored only as irreversible hashes specifically to minimize the personal data we hold. Wallet addresses never enter our systems at all. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
8. Children's Privacy
The Service is not directed at and should not be used by anyone under 18. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
10. Contact
For any question about this Privacy Policy or your data: bobanavramovik@gmail.com