Your privacy is important to us. This policy explains how Exbit collects, uses, stores, and protects your personal data.
When you create an account, verify your identity, or use our services, we collect information that you voluntarily provide, including:
When you access or use the Platform, we automatically collect certain information, including:
We may receive information about you from third-party sources, including identity verification providers (such as Jumio and Onfido), blockchain analytics firms (such as Chainalysis), credit bureaus, sanctions screening services, and social media platforms when you choose to link your account or sign in via a third-party service.
We use the information we collect for the following purposes:
Exbit uses cookies and similar tracking technologies to enhance your experience on the Platform. The types of cookies we use include:
You can manage your cookie preferences through your browser settings or through our cookie consent banner. Disabling certain cookies may affect the functionality of the Platform.
We do not sell your personal data. We may share your information with the following categories of third parties:
All third-party service providers are contractually obligated to protect your data and to use it only for the purposes specified by Exbit.
We retain your personal data for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Specific retention periods include:
When personal data is no longer required, it is securely deleted or anonymized so that it can no longer be associated with you.
Exbit implements industry-leading technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact our Data Protection Officer at [email protected]. We will respond within 30 days (or the timeframe required by applicable law). We may require identity verification before processing your request.
For California residents (CCPA/CPRA): You have the right to know what personal information is collected, to request deletion, to opt out of the sale of personal information, and to not be discriminated against for exercising your rights. Exbit does not sell personal information as defined by the CCPA.
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
For EEA users, our EU representative is Exbit Europe GmbH, Friedrichstrasse 68, 10117 Berlin, Germany.
Eight categories of personal data power the Exbit platform. Each card explains why we collect it and how long we keep it.
Legal name, date of birth, nationality, government ID number.
Why: KYC, AML and sanctions screening.
Retention: 5 years after closure.
Email, phone number and residential address.
Why: Account notices, 2FA, security alerts.
Retention: Active account + 3 years.
Tokenised bank and card references, crypto deposit/withdrawal addresses.
Why: Settle fiat and crypto transfers.
Retention: 7 years (tax records).
IP address, user-agent, device fingerprint, geolocation.
Why: Fraud detection and session integrity.
Retention: 24 months.
Trades, logins, pages viewed, API calls, feature interactions.
Why: Product analytics and audit trails.
Retention: 24 months (raw), 5 years (aggregated).
Support tickets, live-chat transcripts, inbound emails and call notes.
Why: Case handling and quality assurance.
Retention: 3 years after closure.
Scans of passport/ID, selfie, proof-of-address, liveness video frames.
Why: Identity verification under FATF rules.
Retention: 5 years after closure.
Consent records, newsletter topics, campaign-response signals.
Why: Honor opt-ins and opt-outs precisely.
Retention: Consent lifetime + 3 years.
Exercise any of these rights by emailing our Data Protection Officer. We respond within 30 days.
Correct anything inaccurate or incomplete on your profile or in our records.
How: [email protected]
Ask us to delete your data, subject to mandatory AML retention periods.
How: [email protected]
Receive your data in a structured, machine-readable format (JSON/CSV).
How: [email protected]
Pause our processing of your data while a complaint or correction is resolved.
How: [email protected]
Object to processing based on legitimate interest, including direct marketing.
How: [email protected]
Revoke any consent you previously gave, effective from the date of withdrawal.
How: [email protected]
File a complaint with your national data-protection authority (CNIL, ICO, BfDI, etc.).
How: [email protected]
These vendors process data on our behalf under strict GDPR-compliant contracts.