Legal

Privacy Policy

Last updated: 16 August 2026
Plain summary. We keep as little as possible: your email address, the assets you track and your alert settings. We never see your card details, we do not sell your data, and you can have your account deleted at any time.

1. Who is responsible for your data

CryptoAlertly, is the controller of the personal data described here.

2. What we collect

  • Your email address, given when you create an account. It is your login and where alerts are sent.
  • Your password, stored only as a secure one-way hash. We cannot read it, and neither can anyone who obtained a copy of our database.
  • Your watchlist and alert settings: which assets you follow and the price levels you chose.
  • Notifications we generated for you, kept for 30 days.
  • Community content you choose to post. Questions and answers are public, shown next to a display name derived from your email address.
  • Basic technical data such as your IP address, used to rate-limit sign-ups and logins so the service is not abused.

We do not collect your name, address, phone number, wallet addresses, exchange keys or any financial account information.

3. What we never see

Card and payment details are never sent to us. Payments are handled by Paddle.com, our Merchant of Record, on their own systems. We receive only a confirmation that a subscription started, changed or ended, plus the reference identifiers needed to link it to your account.

4. Why we use it

  • To run your account and deliver the alerts you asked for (performance of our contract with you).
  • To take payment and manage subscriptions (contract).
  • To keep the service secure and prevent abuse (legitimate interest).
  • To answer your support messages (legitimate interest).

We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.

5. Who else processes data

We rely on a small number of providers, only for the purposes above:

  • Paddle — payments, invoicing and tax, as Merchant of Record.
  • Our email provider — delivering alert and password-reset emails.
  • Our hosting provider — running the server that stores the database.
  • CoinGecko and Finnhub — market prices. These receive the asset symbols being checked, never your personal data.

6. Cookies

We use one essential cookie: the session cookie that keeps you logged in, and which also remembers your language choice. It is not used for tracking or advertising, and there are no third-party advertising or analytics cookies on this site. Because it is strictly necessary to provide a service you asked for, no consent banner is required.

7. How long we keep things

  • Account data: while your account exists.
  • Price history and notifications: about 30 days, then deleted automatically.
  • Password-reset links: they expire within hours and work only once.
  • Payment records: kept by Paddle for the period their own tax obligations require.

8. Your rights

You can ask us to:

  • give you a copy of the data we hold about you;
  • correct anything inaccurate;
  • delete your account and its data;
  • stop sending alert emails, which you can also do yourself with the switch in your Account settings.

Email us and we will act on your request without undue delay, and within one month. If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.

Deleting your account removes your email address, watchlist, alerts and notifications. Community posts you made may remain visible with the display name removed, so that discussions others took part in stay readable.

9. Security

Passwords are hashed, the site is served over HTTPS, session cookies are restricted so scripts cannot read them, and sign-in attempts are rate limited. No system is perfectly secure, but we keep the amount of data we hold deliberately small so there is little to lose.

10. International transfers

Our providers may process data outside your country. Where that happens we rely on the safeguards those providers have in place, such as standard contractual clauses.

11. Children

The service is not intended for anyone under 18, and we do not knowingly collect data from children.

12. Changes

If we change this policy we will update the date at the top of this page, and tell registered users by email when the change is significant.

How to contact us

Email: support@cryptoalertly.com

CryptoAlertly