Skip to main content

1. About this policy

This Privacy Policy explains how BITRACE LIMITED and/or its affiliates (collectively, “Bitrace,” “we,” or “us”) collect, use, disclose, and protect personal data in connection with our website, documentation, products, APIs, investigation workbench, and related services (collectively, the “Services”). Personal data means information that identifies, or can reasonably be linked to, an individual under applicable law. This policy applies to visitors, customers, authorized users, and people who contact us. Customers may also submit data about other people through the Services. Where a customer determines why and how that data is used, the customer is responsible for providing any required notices and establishing a lawful basis for its submission and use. Bitrace and its customers may have separate responsibilities under applicable privacy laws, as described in the User Agreement. If a separate agreement governs particular processing, that agreement also applies. Public blockchain information, such as addresses and transaction hashes, may be linked to an individual when combined with other information. We treat it as personal data where applicable law requires.

2. Information we collect

Depending on how you interact with us, we may collect:
  • Account and business contact details: name, organization, job title, email address, account identifiers, login credentials, and preferences provided during registration or account management.
  • Customer-submitted information: blockchain addresses, transaction hashes, case details, reports, and other information submitted through the APIs, workbench, or support channels. This may include information about a customer’s clients, counterparties, or other individuals.
  • Service and device information: IP address, browser and device details, log-in and activity logs, API requests, usage statistics, and security or diagnostic records generated when you access the Services.
  • Communications and commercial information: support requests, feedback, correspondence, subscription details, and billing or payment-related records relevant to our relationship with you.
  • Public and third-party information: publicly available blockchain records and information received from service providers or other sources used to provide risk analysis and related services, subject to applicable law.
You should avoid submitting personal data that is not needed for your use of the Services.

3. How we use information

We use personal data as appropriate to:
  • provide, operate, maintain, and support the Services, including account access, API responses, blockchain analysis, risk assessment, and investigations;
  • manage customer relationships, respond to inquiries, and administer subscriptions and billing;
  • monitor performance, troubleshoot issues, secure accounts and systems, and prevent fraud or misuse;
  • improve and develop our products, analytics, and risk models, where permitted by law and applicable agreements;
  • comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims; and
  • send service-related notices and, where permitted, information about our offerings. You can ask us to stop sending optional marketing messages.
Where required by applicable law, we rely on an appropriate legal basis, such as performance of a contract, compliance with a legal obligation, our legitimate interests where not overridden by your rights, or your consent. The applicable basis depends on the data and the purpose of processing.

4. Cookies and analytics

Our website and documentation may use cookies or similar technologies to make pages work, remember preferences, understand usage, and improve performance. The documentation site is configured to use Google Analytics 4, which may collect information about visits and interactions. You can manage cookies through your browser settings and, where available, any consent controls presented on the site. Disabling cookies may affect some features. Where consent is required, we will seek it before using non-essential technologies.

5. When we share information

We may share personal data, as needed and subject to appropriate safeguards, with:
  • affiliates and personnel involved in operating and supporting the Services;
  • hosting, infrastructure, analytics, payment, and other service providers acting on our behalf;
  • a reseller or a third-party product provider where your arrangement or choice requires access, as described in the User Agreement;
  • professional advisers, regulators, law enforcement, or other parties when required by law or reasonably necessary to protect rights and security; and
  • parties to a proposed or completed business transaction, subject to applicable confidentiality and legal requirements.
Customer-submitted information may also be used to generate results for the customer in accordance with the applicable agreement. We do not treat information as anonymous merely because it contains a blockchain address rather than a name.

6. International transfers, security, and retention

Our Services may involve processing by Bitrace, its affiliates, or service providers in different jurisdictions. Where personal data is transferred across borders, we take steps required by applicable law to protect it. We use appropriate administrative, technical, and physical measures to protect personal data against unauthorized access, loss, misuse, or disclosure. As noted in the User Agreement, safeguards for customer-submitted data include encryption in transit. No method of transmission or storage is completely secure. We keep personal data only for as long as reasonably needed for the purposes described in this policy, including providing the Services, meeting contractual and legal obligations, resolving disputes, and maintaining security records. Retention depends on the type of data, applicable agreements, and legal requirements. We then delete or de-identify it where appropriate, subject to permitted backups and legal holds. Public blockchain records may remain available on networks outside our control even after we delete our own copies.

7. Your choices and rights

Depending on your location and applicable law, you may have the right to request access to, correction or deletion of, or a copy of your personal data; object to or restrict certain processing; or withdraw consent where processing is based on consent. Withdrawal does not affect processing already carried out lawfully. You may also have the right to complain to a relevant data protection authority. To make a request, email support@bitrace.io. We may need to verify your identity before responding. If your information was submitted by a customer, we may direct your request to that customer or coordinate with them, as appropriate. Rights are subject to exceptions and limits under applicable law.

8. Changes and contact

We may update this policy as our practices or legal requirements change. We will post the revised version on this page and provide additional notice where required by law. Please review this page periodically. For questions about this policy or Bitrace’s handling of personal data, contact support@bitrace.io.