CoinVast logoCoinVast
Legal

Privacy policy

Last updated

Most privacy policies are long because the company collects a lot. This one is long because we wanted to show our work. The complete list of what we hold fits in the card below, six lines, and the rest of the page exists so you can check that those six lines are true.

Some orientation before the detail. CoinVast is an instant crypto exchange with no accounts. You never tell us your name, your email, or what your face looks like. So this page is mostly about the data a swap creates on its own, the boring server plumbing around it, and the short list of situations where anyone else could see any of it. Read it next to the terms and the trust page and the three documents agree. They were written by the same people in the same week, which helps.

The honest note before the policy

CoinVast launched in 2026 and the operating company behind it is being formed right now. A privacy lawyer has not yet gone through this page line by line. Everything below describes how the service actually works today, written by the people who built it, but until counsel signs off you should read it as a working draft. When the entity is registered we will name it here, confirm which privacy laws formally apply (GDPR and its cousins) and what your rights requests look like under them, and mark every change at the top of this page. Opening a privacy policy with a confession felt like the right tone to set.

The short version

Six lines. If you quote one thing from this page, quote this box. Everything after it is the proof.

  • 1. No accounts exist here, so we never collect your name, email, phone number, ID, or photo.
  • 2. We keep what a swap itself creates: pair, amounts, rate, addresses, transaction hashes, timestamps.
  • 3. Standard nginx server logs with IP addresses exist for about 7 days, then rotate away.
  • 4. Visitors get zero cookies. The only cookie on the whole domain is the login session for our own staff.
  • 5. Your My swaps list lives in your browser’s localStorage and never leaves your device.
  • 6. We sell nothing to anyone, and a legal demand can only get the little that is on this list.

What we collect

Everything in this section exists because a swap cannot run without it. Nobody sat in a meeting inventing extra fields to ask you for. The order record is the product, so here is the product, piece by piece, with the reason each piece has to exist.

The pair and amounts. What you are sending, what you want back, and how much. Without this there is no swap to run, just a website looking at you expectantly.

The rate and the spread. The exact rate you accepted, our flat 2% spread locked at the moment you created the swap. We keep it so the quote you agreed to is the quote we honor, and so a dispute six months later is a lookup instead of an argument about memory.

The deposit address. We generate it, we watch it, and when your payment lands there we credit your order. It is ours, not yours, and it exists for exactly one order.

Your payout address. The address your new coins go to. This is the least optional field in the history of forms.

Your refund address. Optional, but we nag about it, because it is the guaranteed way back if screening fails or something on our side breaks. A refund with nowhere to go is a much worse afternoon for everyone.

Transaction hashes. The receipts. They are already public on their blockchains; we pin them to your order page so you can verify every leg of the swap on any block explorer you like.

A timestamped status timeline. When the order was created, when the deposit appeared, when it confirmed, when the payout went out. It powers the order page and it is where support finds answers when you email us.

The screening result. Each deposit is risk-screened before the exchange runs, and the result is stored with the order. The screening section below covers what that involves and who sees what.

Support email. If you write to [email protected], we keep the thread so we can answer and follow up. This is the one door through which a name or an email address can enter our systems, and you are the one who decides to open it.

Notice what is missing from that list. Not one field describes you, the human. Addresses and hashes describe coins. That is the whole design.

What we deliberately do not collect

This is the section we are proudest of, and it is mostly a list of empty space. No name. No email address. No phone number, so no SMS codes at 2 a.m. No date of birth, no home address, no passport, no driver’s license, no selfie, no selfie-holding-passport, no video call where a stranger asks you to turn your head slowly to the left. No password either, because there is no account for one to protect.

And no surveillance dressed up as product analytics. No Google Analytics. No Meta pixel, no TikTok pixel, no ad SDKs. No session-replay script recording your cursor as it hovers over the Monero option. No fingerprinting library guessing who you are from your fonts and your screen size. The pages you load come from us and talk to us, and you can confirm that in your browser’s network tab in about a minute.

Why so absolute about it? Because data we never collect is data that cannot leak. It cannot sit in a breach dump. It cannot be subpoenaed, because it does not exist. It cannot be sold by a rogue employee, or by a future owner with worse values than ours. Every privacy promise that depends on willpower can be broken under pressure. A promise enforced by architecture cannot, and not collecting is the strongest architecture there is. It is also, conveniently, the cheapest.

The honest limit: none of this makes you invisible. Blockchains are public, your wallet has a history, and we keep the order records described above. We never claim otherwise, and the anonymity question gets a straight answer in the FAQ below. What this section means is narrower and still rare: on our side, there is no you in the data. There are only coins, moving.

Server logs, honestly

Nearly every web server on earth keeps access logs, and ours are no exception. Our nginx servers record the standard line: an IP address, the URL requested, a timestamp, and a user agent string. The hosting layers we run on keep their own short-lived equivalents. Market prices are fetched server-side from public market data, so those requests carry nothing about you at all.

What the logs are for: rate limiting, blocking scrapers and attack traffic, and figuring out why a page returned an error at 3 a.m. What they are not for: profiles. They are not joined to orders, they are not mined for patterns about you, and nobody here reads them recreationally. They rotate out after about 7 days, which is our policy default, and after that they are gone.

Now the part most privacy services skip. We will not tell you “we never see your IP,” because for a website that statement is almost never true, and we would rather be accurate than soothing. The cautionary tale here is eXch: a service that marketed itself as no-logs until German authorities seized it in April 2025 and recovered 8 terabytes of data. Eight terabytes is a lot of no logs. Our answer is not to pretend logs do not exist. It is to keep them brief, boring, and disconnected from anything that could become a profile.

Cookies, the real list

A decade of consent banners has trained everyone to expect a drawer full of toggles labeled things like “legitimate interest.” Here is our complete cookie inventory instead. For visitors: none. Zero cookies. Not a session cookie, not a preference cookie, not an “essential” cookie that is somehow also essential to an ad network. You can browse every page, get quotes, and run a full swap without a single cookie being set in your browser. This is also why there is no cookie banner on the site. There is nothing to consent to.

One cookie exists on the domain, and we will tell you exactly what it is. When one of our own staff logs in to the admin panel to operate the service, their browser gets a signed session cookie so they do not have to re-enter credentials on every click. It lasts at most 7 days and it is never set for visitors. That is the entire cookie story. If you ever find a cookie from us as a regular visitor, something is wrong and we want to hear about it.

Then there is My swaps, the list of recent orders the site can show you. That list is stored in your browser’s localStorage, on your machine, written and read only by your browser. It is never transmitted to us, and we could not look at it if we wanted to. Two consequences follow. The good one: your swap history is yours alone. The sharp edge: if you clear your browser data, the list is gone and we cannot restore it, because we never had it. So bookmark your order links. Each link is the receipt for its swap, and it works from any browser.

Screening, what a provider sees

Every swap is screened before it starts. That ordering is the core of how CoinVast works, and it has a privacy side worth spelling out: what does the screening actually look at, and what does the risk-data provider on the other end get to see?

What gets checked: the addresses on your order and the deposit transaction, against blockchain risk data and sanctions lists. So the provider sees addresses, transaction hashes, and amounts. Every one of those is already public on the blockchain. The screening adds context to public data; it does not receive private data, because the swap never generates any.

What the provider never sees: your identity, because we do not have one to share. Not your IP address, not your browser details, not your support emails. We screen coins, not people. There is no dossier moment where a swap gets attached to a human, because no human is recorded anywhere in the flow.

And the outcomes, since they are part of the privacy story too. Pass: the swap runs, and a completed swap is final. Fail: your deposit is automatically returned to your refund address, minus the network fee, and nobody emails you demanding a passport to “release” anything, because nothing is held. The one exception is a sanctions-listed address, which is rejected outright; in those cases the law can also restrict whether the funds may be returned at all. It is the single exception, and we print it everywhere rather than hope you never hit it.

When we would disclose

Start with what never happens. We do not sell data. We do not rent it, trade it, or “share it with select partners to improve your experience.” There are no advertisers and no data brokers in this story, partly on principle and partly because a pile of addresses and hashes would make a terrible ad product anyway.

Two kinds of disclosure do exist, and here they are plainly. First, service providers: the hosting our site runs on, the database that stores order records, and the risk-data provider described in the screening section all process data on our behalf, each receiving only what its job requires, under its own security terms. That is how websites work, and pretending otherwise would be silly.

Second, legal process. If we receive a valid court order, warrant, or equivalent legal demand, properly issued and properly served, we comply. We are an exchange, not a resistance movement, and we will not pretend to be one. But here is the sentence that matters: we can only hand over what we have. The complete inventory is the order records the demand can identify (pair, amounts, rate, deposit, payout and refund addresses, transaction hashes, timestamps, status history), the screening result stored with each order, whatever nginx logs still exist inside the roughly 7-day window, and any support emails you chose to send us. That is the entire warehouse. There is no name on the shelf unless you typed one into an email.

This is what minimal collection buys in practice. The strongest disclosure policy is not a brave promise to fight every order. It is having almost nothing to disclose when one arrives.

How long we keep things

Retention windows are choices, so we are printing ours as a table instead of hiding behind “as long as necessary,” the phrase that has never once told a reader anything. These are our current policy defaults. Counsel may adjust some of them when the operating entity is formalized, and if that happens the change lands on this page with the date at the top refreshed.

WhatHow longWhy
Order records: pair, amounts, rate, addresses, transaction hashes, status timeline5 years from completionThey are the receipt. Disputes, refunds, and the record-keeping rules that apply to services like ours.
Screening resultsSame 5 years, stored with the orderProof of why a swap ran, was refunded, or was rejected.
Server access logs: IP, URL, timestamp, user agentAbout 7 days, automatic rotationRate limiting, abuse blocking, and debugging. Nothing else.
Support email threads2 years after the last message, sooner on requestSo a follow-up six months later still makes sense to whoever answers it.
Staff admin session cookie7 days maximum, then re-loginLets our own staff stay signed in to operate the service. Never set for visitors.
My swaps list (localStorage)Until you clear your browser dataLives on your device. We cannot read it, keep it, or delete it.

The 5-year window for order records follows common record-keeping rules for exchange-like services. We would love to keep less, and if counsel tells us we can, we will.

Your choices

Privacy here is mostly something you do, not something you ask us for, because there is no account to configure. All of the following is general, lawful hygiene. None of it is advice to evade any law, and your taxes do not disappear because nobody asked your name.

Use a fresh address per swap. Address reuse is the loudest signal on a public blockchain. Most wallets generate new addresses for free, in one tap. This is the highest-value habit on the list and it costs nothing.

Receive into a wallet you control. Your own wallet, ideally talking to your own node if you run one. Sending a payout into an exchange’s shared deposit address ties the swap to an account somewhere else, which quietly undoes the point.

Consider privacy coins for the parts that matter. Most chains are transparent by design. Monero is private at the protocol level, and we support native XMR in both directions, not a wrapped stand-in. Different tools, different jobs.

Fill in the refund address. Ten seconds of pasting guarantees that a failed screening or a hiccup on our side ends with coins back in an address you control, automatically.

Keep support emails lean. An order ID and a description of the problem is everything we need. The less you put in an email, the less exists anywhere. We are likely the only support team that asks you to share less.

And if a week of IP-in-a-log bothers you, ordinary network privacy tools like a reputable VPN are lawful, widely used, and none of our business. The site does not care how you arrive.

Children

The service is for adults, 18 and over, as the terms require. It is not directed at children and we do not knowingly collect anything from them, which is easier than usual to keep, since we knowingly collect almost nothing from anyone. The flip side of having no identity data is that we cannot tell ages. If you believe a minor has used the service, email [email protected] with the order ID and we will deal with it.

Changes to this policy

This policy will change, because the service will grow and because counsel, when they arrive, will have opinions. The same two commitments we make in the terms apply here. Every change lands on this page with the date at the top refreshed, and material changes get called out plainly rather than slipped in between commas. And the direction of travel is a promise of its own: the list of what we collect should only ever get shorter or stay the same. If it ever had to grow, that would be the headline of the update, not a footnote.

Contact

Questions, corrections, or rights requests: [email protected]. A human reads that inbox, the same humans who wrote this page.

On rights requests, here is what they look like in practice, given how little we hold. Access: tell us an order ID and we will tell you exactly what we have for it, which is the order record and its screening result; if you have emailed us before, we can include that thread. Deletion: support threads can be deleted on request, while order records sit under the 5-year record-keeping window described above, so we usually cannot delete those early, and we will say so directly instead of going quiet. Depending on where you live, you may have formal rights with formal names. The notice at the top explains where the formalities stand; the inbox works either way.

Privacy questions, answered straight

Do you log IP addresses?

Yes, briefly, and we would rather say so than perform innocence. Our servers keep standard nginx access logs, which include IP addresses, for about 7 days before they rotate out. They exist for rate limiting, abuse blocking and debugging, and they are not joined to orders or used to build profiles. Any website that tells you it never sees your IP is describing its marketing, not its server. When eXch was seized in April 2025, authorities recovered 8 terabytes of data from a service that called itself no-logs. Our approach is smaller promises that are actually true.

Can you delete my data?

Some of it, and we will be straight about which part. The My swaps list is in your own browser, so you can delete it yourself in two clicks. Support emails are deleted on request, and at the latest two years after the thread goes quiet, unless a legal duty says otherwise. Order records are the hard part: under our current policy they are kept for 5 years because they are the receipt for a financial transaction, the thing that lets us resolve disputes and meet record-keeping rules. Write to [email protected] with an order ID and we will tell you exactly what we hold for it.

Do you use Google Analytics or any tracking scripts?

No. No Google Analytics, no Meta pixel, no ad SDKs, no session replay, no fingerprinting scripts. You can verify this yourself in about a minute: open your browser's developer tools, watch the network tab, and load any page on this site. The requests you see go to us. The honest cost of this choice is that we know very little about our own traffic, and we have decided we can live with that.

What exactly would law enforcement get with a valid warrant?

The complete inventory: the order records they can identify (pair, amounts, rate, addresses, transaction hashes, timestamps and status history), the screening result attached to each order, whatever server logs still exist inside the roughly 7-day window, and any emails you chose to send us. That is the whole list. There is no name, photo or document on it, because we never collected one. We comply with valid legal process, and we can only hand over what exists.

Is swapping on CoinVast anonymous?

No identity is attached to your swap on our side, because we never ask for one. But anonymous is a bigger word than that. Most blockchains are public, your wallet has a history anyone can read, and we keep order records as described on this page. If you want privacy at the protocol level, that is Monero's job, and we support native XMR in both directions. No-KYC means we do not know who you are. It does not make the blockchain forget what it saw.

Do you sell or share data with advertisers?

No. We have no advertisers, no data partners, and honestly nothing they would want. Our entire dataset is addresses, amounts and transaction hashes, most of which are already public on a blockchain. Our revenue is the spread, a flat 2% printed on every quote. When a service is free and asks who you are, you are the product. We charge openly and never ask, which keeps the relationship simple.

Why is there no cookie banner?

Because there are no cookies to consent to. Visitors to this site receive zero cookies, so a banner would be asking permission for something we do not do. The one cookie on the domain is the session cookie our own staff use to log in to the admin panel, and it is never set in a visitor's browser. If you ever do see a cookie from us as a regular visitor, that is a bug. Tell us and we will fix it.

This policy, the terms and the trust page describe one service and agree with each other. If you ever spot a contradiction, tell us at [email protected] and we will fix the documents rather than deny the contradiction.

Keep reading

Related pages

The best data protection is data we never had.

Start a swap

No account · no cookies for visitors · spread printed on every quote

Privacy Policy: What We Keep, What We Never Collect — CoinVast