CRISP is designed to operate on a non-custodial basis. We do not collect or store your private keys or seed phrases, and we do not custody your digital assets.
1. Who We Are
The controller or business responsible for your personal data is: CRISP Email: privacy@crisp.bot Support: support@crisp.bot2. Personal Data We Collect
The personal data we collect depends on how you use the Services. We may collect the following categories of personal data:
We do not intentionally collect sensitive personal data such as government identifiers, health information, biometric identifiers, precise geolocation, religious beliefs, or similar sensitive categories unless you voluntarily provide it to us or it is necessary for a specific support, security, legal, or compliance purpose and permitted by applicable law.
3. How We Collect Personal Data
We collect personal data in the following ways:- Directly from you, such as when you create or connect an account, interact with the Telegram bot, contact support, configure alerts, use execution-support features, or subscribe to paid Services.
- Automatically through the Services, such as through logs, cookies, local storage, analytics tools, security tools, and product telemetry.
- From public sources, such as public blockchain networks, public smart contracts, public market venues, public wallet activity, and publicly available market or trader information.
- From third parties, such as wallet infrastructure providers, authentication providers, hosting providers, analytics providers, payment processors, communication tools, compliance tools, RPC providers, and market infrastructure partners.
4. How We Use Personal Data
We may use personal data for the following purposes:
We may also use aggregated, de-identified, or anonymized data for business, analytics, research, product development, security, and reporting purposes. We do not attempt to re-identify data that we have de-identified unless permitted by law and necessary to test or maintain our de-identification processes.
5. Legal Bases for Processing
Where applicable law requires a legal basis for processing, such as in the European Economic Area, the United Kingdom, or similar jurisdictions, we rely on one or more of the following legal bases:
You may withdraw consent where processing is based on consent. Withdrawal does not affect processing that occurred before withdrawal.
6. Blockchain Transparency and Public Data
Blockchain networks, prediction-market venues, and certain decentralized protocols are public or semi-public by design. This means wallet addresses, transaction hashes, smart-contract interactions, market positions, order activity, and other on-chain or market-related records may be visible to anyone and may remain accessible indefinitely. CRISP may process public blockchain and public market data to provide analytics, trader profiles, wallet tracking, rankings, alerts, market insights, execution-support tools, and other product features. Public blockchain records are generally not controlled by CRISP and may not be capable of being deleted, modified, or fully dissociated from a wallet address once published.CRISP does not custody your assets and does not control third-party wallets, blockchains, smart contracts, protocols, or prediction-market venues. Your use of any third-party wallet, venue, protocol, or blockchain is subject to its own terms, privacy policy, risks, and technical rules.
7. Trader Profiles, Wallet Labels, Signals, and Automated Analysis
The Services may generate or display analytics derived from public blockchain data, public market data, user activity, and third-party data. This may include trader profiles, wallet labels, rankings, alerts, opportunity signals, risk indicators, behavioral summaries, performance metrics, and similar analytics. These analytics are intended to provide product functionality and informational insights. They should not be treated as financial, legal, tax, investment, or professional advice. Unless we clearly state otherwise, CRISP does not use automated analysis to make legally binding decisions about you or decisions that produce similarly significant legal effects. If applicable law gives you rights relating to automated decision-making or profiling, you may contact us using the details in this Privacy Policy.8. How We Share Personal Data
We may disclose personal data to the following categories of recipients:- Service providers and processors, such as hosting providers, cloud infrastructure providers, database providers, analytics providers, wallet or authentication infrastructure providers, support tools, payment processors, communications providers, security vendors, compliance vendors, and professional service providers.
- Wallet, blockchain, market, and execution infrastructure providers, where sharing is necessary to provide, route, support, or troubleshoot user-requested actions or product features.
- Payment and subscription providers, where needed to process subscriptions, payments, billing, invoicing, refunds, fraud checks, and related records.
- Professional advisers, such as lawyers, auditors, accountants, insurers, consultants, and compliance advisers.
- Authorities, regulators, law enforcement, courts, or counterparties, where required by law, legal process, sanctions obligations, court order, regulatory request, or where necessary to protect rights, safety, property, users, CRISP, or system integrity.
- Corporate transaction parties, such as counterparties and advisers involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar transaction, subject to appropriate safeguards where required.
- Other users or the public, where information is part of public product features, public wallet analytics, trader profiles, leaderboards, or public blockchain and market data.
- Other parties with your direction or consent.
9. Cookies, Local Storage, and Similar Technologies
If you use a CRISP website or web application, we may use cookies, local storage, pixels, SDKs, tags, and similar technologies for the following purposes:- Strictly necessary technologies, such as authentication, session management, security, load balancing, fraud prevention, and core product functionality.
- Preferences, such as remembering your settings, display preferences, or user choices.
- Performance and analytics, such as understanding usage, improving reliability, identifying errors, and measuring product performance.
- Marketing or communications, where enabled and permitted by law, such as measuring campaign performance or sending relevant product updates.
10. International Data Transfers
We may process and store personal data in countries other than the country where you live, including countries that may have data protection laws different from those in your jurisdiction. Where required by applicable law, we use appropriate safeguards for international transfers, such as standard contractual clauses, data processing agreements, equivalent contractual protections, adequacy decisions, or other lawful transfer mechanisms recognized by applicable law.11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Our retention periods depend on the type of data, the purpose of processing, the nature of the Services, legal requirements, security needs, and whether retention is necessary to resolve disputes or enforce agreements.
When we no longer need personal data, we will delete it, anonymize it, aggregate it, or de-link it where feasible. Public blockchain records and data controlled by third-party services may not be capable of being deleted by CRISP.
12. Security
We use administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, loss, misuse, alteration, or destruction. These measures may include access controls, encryption in transit, environment separation, logging and monitoring, vendor due diligence, least-privilege access, incident response processes, and internal security controls.13. Your Rights and Choices
Depending on your location and applicable law, you may have the right to:- Access or obtain a copy of personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Request deletion of personal data we control.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Request portability of certain personal data.
- Opt out of marketing communications.
- Opt out of certain sales, sharing, targeted advertising, or profiling where applicable.
- Lodge a complaint with a data protection authority, regulator, or privacy authority where applicable.