Cruxlee

Privacy Policy

Last updated: October 2, 2026

This Privacy Policy explains how Cruxlee ("we", "us", "our") collects, uses, and protects your personal data when you use cruxlee.com (the "Service"), in accordance with the EU/UK General Data Protection Regulation (GDPR).

Cruxlee is operated as an individual/sole-trader project under the brand name "Cruxlee." For any privacy inquiry, including exercising your rights under GDPR, contact: bobanavramovik@gmail.com

1. What Data We Collect

DataWhy we collect itWhere it's stored
Email addressAccount identification, sign-in (“magic link”), purchase confirmation, supportFirebase (Google Cloud)
Payment/active status (paid or not)To grant or restrict access to the ServiceFirebase
Telegram chat ID (if you choose to link Telegram)To send you trading signal alertsFirebase
Watchlist (coins you track)To personalize charts and alertsFirebase
Hashed IP address (one-way, non-reversible)Anti-abuse rate limiting on login/checkout attemptsFirebase
Temporary checkout record (email + payment status)To process your one-time paymentFirebase

We do not collect or store:

  • Your cryptocurrency wallet address (handled entirely by our payment processor, NOWPayments — we never see or store it)
  • Your Telegram username (only an internal chat ID, which cannot be used to look you up on Telegram by anyone browsing)
  • Your IP address in reversible/plain form (only a one-way cryptographic hash is kept, which cannot be converted back into your actual IP address)
  • Passwords (we use passwordless email sign-in)

2. Legal Basis for Processing (GDPR)

We process your data under the following legal bases:

  • Contract — to provide the Service you purchased (account access, signal delivery, dashboard functionality)
  • Legitimate interest — to prevent fraud and abuse (e.g., the hashed IP rate-limiting)
  • Consent — where you voluntarily choose to link your Telegram account

3. How We Use Your Data

  • To authenticate you and grant/restrict access based on payment status
  • To deliver trading signal alerts via Telegram, if you've linked your account
  • To send transactional emails (e.g., sign-in links, purchase confirmation) via our email provider, Resend
  • To prevent abuse of login or checkout flows via hashed-IP rate limiting

We do not use your data for advertising, and we do not sell your data to third parties.

4. Third Parties Who Process Data On Our Behalf

ServicePurposeData involved
Firebase (Google)Authentication & databaseEmail, Telegram chat ID, watchlist, hashed IP
NOWPaymentsPayment processingPayment/checkout data (wallet address never touches our systems)
ResendTransactional email deliveryEmail address
Telegram Bot APIAlert deliveryTelegram chat ID
VercelWebsite hostingStandard web request logs
Binance, CoinGecko, alternative.meMarket data (not user data)No personal data shared

Each of these providers processes data under their own privacy policies and may be located outside your country; where this involves a transfer outside the EU/UK, these providers generally rely on their own GDPR-compliant safeguards (e.g., Standard Contractual Clauses).

5. Data Retention

We retain your account data for as long as your account exists. Temporary checkout records and Telegram verification codes are short-lived and automatically expire (verification codes within 10 minutes). If you request account deletion, we will delete your personal data within a reasonable timeframe, except where retention is required by law (e.g., payment records for tax purposes).

6. Your Rights Under GDPR

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten"), subject to legal retention requirements
  • Restrict or object to certain processing
  • Data portability (receive your data in a portable format)
  • Withdraw consent at any time where processing is based on consent (e.g., unlinking Telegram)
  • Lodge a complaint with your national data protection authority (in the UK, the ICO; in an EU country, your national Data Protection Authority)

To exercise any of these rights, contact bobanavramovik@gmail.com. We will respond within the timeframe required by GDPR (generally one month).

7. Security

We rely on Firebase's and our other providers' built-in security infrastructure. IP addresses are stored only as irreversible hashes specifically to minimize the personal data we hold. Wallet addresses never enter our systems at all. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.

8. Children's Privacy

The Service is not directed at and should not be used by anyone under 18. We do not knowingly collect data from minors.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

10. Contact

For any question about this Privacy Policy or your data: bobanavramovik@gmail.com