BitQaan Legal

Privacy Notice

Privacy Notice for BitQaan's customer account, wallet, portfolio, project application, security, and support flows.

Document version
V1.0
Effective date
1 August 2026
Last updated
1 August 2026

1. Who We Are

This Privacy Notice explains how BitQaan uses personal information in connection with app.bitqaan.com and related customer services.

In this notice, BitQaan, we, us, and our mean the operator of the BitQaan customer platform. You can contact BitQaan about privacy matters through the official support or contact channels made available in the app or on official BitQaan websites.

2. Information We Collect

Account data may include email address, account identifiers, account status, verification status, profile display name or avatar where provided, and account timestamps.

Wallet data may include public blockchain addresses, chain IDs, connected-wallet status, wallet verification messages, hashed nonces, signatures submitted to establish wallet control, and blockchain transaction references. The current customer application does not collect or store private keys or wallet recovery phrases.

Project application data may include company name, contact name, contact email, project name, token name, token symbol, initial supply, decimals, optional chain ID, application notes, submission status, and timestamps.

Technical and communication data may include IP address, user agent, session/security data, logs, timestamps, email verification and password reset events, support requests, administrative messages, and service notifications.

3. How We Use Information

BitQaan uses information to provide accounts, authenticate users, secure the platform, verify connected wallets, display portfolio and wallet activity, process token project applications, detect fraud or abuse, communicate service information, meet legal obligations, and improve reliability.

BitQaan does not use the current customer application to collect private keys or wallet recovery phrases.

4. Lawful Bases

Where UK data-protection law applies, BitQaan may rely on contract for account access and requested services; legitimate interests for security, abuse prevention, service reliability, and customer support; legal obligation where laws require record keeping, fraud prevention, sanctions, tax, or regulatory compliance; and consent where optional processing legally requires it.

The lawful basis may vary by purpose, service, and user location.

5. Blockchain Data

Public blockchain data may be publicly visible and may be difficult or impossible to alter or erase at blockchain level.

BitQaan database records, such as wallet-link records in the customer app, are separate from public blockchain records. Rights requests may be handled differently for BitQaan-held records and public blockchain data.

6. Wallet Secrets

BitQaan's current customer application does not collect or store your private keys or wallet recovery phrase.

Never send recovery phrases, private keys, raw signing secrets, or wallet seed words to BitQaan support. BitQaan support should not ask for them.

7. Sharing

Recipient categories may include infrastructure/cloud providers, database/hosting providers, email providers, security providers, professional advisers, payment or blockchain providers where applicable, and legal or regulatory authorities where required.

BitQaan shares information only where needed to provide, secure, operate, support, or comply with obligations connected to the platform.

8. International Transfers

Personal information may be processed outside your country depending on hosting, email, security, support, infrastructure, and service-provider arrangements.

Where legally required, BitQaan uses appropriate safeguards for international transfers.

9. Retention

BitQaan keeps personal information only for as long as reasonably necessary for the purpose collected, including legal, security, dispute, audit, and operational needs.

Retention periods may differ for account records, session/security logs, wallet-link records, project applications, support communications, purchase/payment records, and legal/compliance records.

10. Security

The current app uses password hashing, HTTP-only secure session cookies, email verification and password reset tokens stored as hashes, access controls on protected routes, audit logs, rate limits, Nginx security headers, and non-root app execution.

No online service can be guaranteed absolutely secure. Users must also protect their account credentials and wallet devices.

11. Cookies and Local Storage

The current app uses an essential `bitqaan_session` cookie for authenticated sessions and Google OAuth state cookies for Google sign-in flow integrity. Native BTQ send result data may be kept in browser sessionStorage when the disabled send feature is enabled in a controlled context.

See the Cookie Notice for more detail.

12. Your Rights

Depending on circumstances and lawful basis, data-protection rights may include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent.

Some rights may be limited where retention is required for legal, security, fraud-prevention, blockchain, or dispute reasons.

13. Automated Decision-Making

BitQaan may use account status, security, risk, and fraud-prevention checks to protect users and the platform.

Where legally required, BitQaan will provide information about decisions that have legal or similarly significant effects and are made solely by automated means.

14. Children

BitQaan is not intended for children. Do not use the platform if you do not have legal capacity to agree to the Terms or if applicable law prohibits your use.

15. Privacy Complaints

For privacy questions or requests, contact BitQaan through the official support or contact channels made available in the app or on official BitQaan websites.

Where applicable, you may also have the right to complain to a data-protection authority.

16. Updates

This notice may be updated when the data processing inventory, processors, cookies, customer markets, products, or legal requirements change.

Material changes should be notified where appropriate, with clear effective and last-updated dates.

Change History

V1.0 effective from 1 August 2026. Future policy versions must be retained instead of silently overwritten.