This policy explains what personal data CoinsFlow collects when you use the website, the dashboard, the Payments API, hosted payment pages and the Litecoin explorer, why we collect it, and what you can ask us to do with it.
What we collect
- Account data: your email address and a one-way hash of your password (we never store the password itself). If you turn on two-factor authentication, its secret is stored encrypted.
- Security records: for every sign-in attempt we keep the time, the IP address, the browser's user-agent and whether it succeeded. We keep the same for your active sessions so you can see and sign them out.
- Business data: your merchants, invoices, the order ids, descriptions and metadata you attach to them, withdrawals and their destination addresses, webhook endpoints, and the emails we send you.
- Blockchain data: transactions to and from addresses we issue. This data is public on the blockchain by nature.
- Support chat: the messages you send us.
We use one cookie, which keeps you signed in. We do not use advertising or tracking cookies, and we do not sell personal data.
When your customer pays an invoice we see what the blockchain shows: the paying address, the amount and the transaction. We do not collect your customers' names or emails unless you put them in an invoice's fields; please do not.
Why
- To provide the Service: create invoices, detect payments, credit and pay out your balance.
- To keep accounts safe: detect password guessing, show you where you are signed in, and investigate misuse.
- To meet legal obligations, such as record keeping and responding to lawful requests.
- To tell you about your account: payment and withdrawal notices, password resets, and service changes.
Who we share it with
Only with the providers that run the Service for us (hosting, our content delivery network and our email provider), under agreements that let them use it only for that, and with authorities when the law requires it. Blockchain transactions are public by design.
How long we keep it
- Account and business records: while your account is open, and afterwards for as long as the law requires us to keep financial records.
- Sign-in records: up to 180 days. Expired sessions are deleted automatically.
- Unsent emails: up to 7 days.
Your rights
You can ask for a copy of your personal data, ask us to correct it, or ask us to delete it where we are not required to keep it. Contact us through the support chat; we answer within 30 days. You may also complain to your data protection authority.
Security
Passwords and API keys are stored only as hashes. Two-factor secrets are encrypted. The keys that control funds are held by a separate, isolated service and never touch the website or the API. All traffic is encrypted in transit.
Changes
We will post any update here and, for significant changes, tell you in the dashboard. The identity of the data controller and a postal address will be added here once our legal review is complete.