Privacy Policy
Last updated: September 29, 2026
This Privacy Policy explains what personal data Garantex.app (“we”, “us”) collects when you use our website and exchange service (the “Service”), why we collect it, how long we keep it, who we share it with and what rights you have. Our guiding principle is data minimisation: we collect only what is needed to complete your exchange, keep it secure and meet our legal obligations. We do not require an account, and we never sell personal data.
1. Summary
- No registration: every exchange is identified only by an Exchange ID, a PIN and a private link.
- Standard mode: we store exchange details plus your IP address and browser details, and your e-mail if you give it.
- Anonymous mode: we store exchange details only – no IP address, browser details or e-mail with the exchange.
- No advertising, analytics or tracking cookies.
- Verification documents are requested only when an exchange is flagged, and handled under strict access controls.
2. Who is responsible
The operator of Garantex.app is the controller of the personal data described in this policy. You can reach us through a support ticket or at [email protected].
3. Data we collect
3.1 Exchange details (both modes)
To perform an exchange we must record: the assets, networks and amounts; the rate and fees; the recipient address and Memo/Tag; the refund address if you give one; the deposit and payout transaction hashes; the status history; the Exchange ID and a one-way encrypted (hashed) version of your PIN; and the date and time of each step. We cannot read your PIN.
3.2 Standard mode
In addition to 3.1, we store the IP address and browser user-agent from which the exchange was created, and the e-mail address you choose to provide for status notifications.
3.3 Anonymous mode
We store only the data in 3.1. We do not store your IP address, browser user-agent or e-mail address with the exchange. The home page feed of recent exchanges shows anonymous exchanges with more strongly rounded amounts and a less precise time.
3.4 Support tickets
The subject and messages you send and our replies, linked to the exchange they concern. Please do not include unnecessary personal data in tickets.
3.5 Verification
Only if an exchange is flagged under our AML/KYC Policy: identity documents, a selfie or liveness check, proof of address, source-of-funds information and any other documents you submit, together with the result of the review.
3.6 Card purchases
Card payments are processed by an independent payment partner, which collects your card and billing details directly and acts as a separate controller under its own privacy notice. We receive only the payment result and a reference. We never see or store your full card number.
3.7 Security data
To protect exchanges against PIN guessing, we temporarily record the IP address of failed PIN attempts and block it after repeated failures. These records are removed when the lock period ends. They are not linked to any exchange.
3.8 Technical delivery
Like every website, our servers and our content delivery / security network (such as Cloudflare) necessarily process your IP address to deliver pages and protect the Service against attacks. Web fonts are loaded from Google Fonts, which receives your IP address when your browser requests them. Technical server logs are kept to a minimum, restricted to administrators and rotated regularly.
4. Public blockchain data
Blockchains are public. Your deposit and payout transactions, including addresses and amounts, are permanently visible to anyone and cannot be deleted by us or anyone else. Anonymous mode limits what we store; it does not change what is public on-chain. Using a fresh receiving address improves your on-chain privacy.
5. Why we use data and on what basis
- To perform your exchange (quote, deposit matching, payout, refunds, status pages and notifications) – necessary to perform our contract with you.
- To provide support – necessary to perform our contract and our legitimate interest in resolving issues.
- To prevent fraud and protect the Service (rate limiting, abuse detection, security logs) – our legitimate interest in keeping the Service safe.
- To comply with the law (transaction screening, verification, record keeping, responding to authorities) – legal obligation.
- To improve the Service using aggregated, non-personal statistics – our legitimate interest.
We do not use your data for marketing, and we do not build profiles for advertising.
6. Automated screening
Exchanges and addresses are automatically screened for links to illicit activity or sanctions. A match may put an exchange on hold. No final decision to refuse an exchange or retain funds is made without human review, and you can contact support to explain your situation.
7. Who we share data with
- Liquidity providers and exchange partners – the exchange details needed to complete the conversion.
- Payment partners – for card purchases, the order details needed to process the payment.
- Blockchain analytics providers – deposit and payout addresses and transaction hashes for screening.
- Verification providers – if verification is required, the documents you submit, to check their authenticity.
- Hosting, security and infrastructure providers – who process data on our behalf and under our instructions.
- Authorities – law enforcement, regulators or courts, where we are legally required to or to protect our rights.
- A successor – if our business is sold or reorganised, subject to this policy.
Price data is fetched from public market data sources; no personal data is sent to them. We never sell or rent personal data.
8. International transfers
Our providers may process data in other countries. Where data is transferred to a country without an equivalent level of protection, we rely on appropriate safeguards such as standard contractual clauses.
9. How long we keep data
- Exchange records – for as long as anti-money-laundering and accounting laws require, typically five years after the exchange, then deleted or anonymised.
- IP address and browser details (Standard mode) – kept with the exchange record for the same period, as they form part of the transaction record.
- E-mail address (Standard mode) – kept with the exchange record and used only for notifications about that exchange.
- Support tickets – for the same period as the related exchange.
- Verification documents – for the period required by anti-money-laundering law, typically five years after the verification or the last related exchange.
- Failed PIN attempt records – until the lock period ends (minutes).
- Server logs – short-term, rotated regularly.
10. Security
We use encrypted connections (HTTPS), hashed PINs, private unguessable exchange links, rate limiting, restricted and logged administrative access, and the principle of least privilege. Verification documents are accessible only to authorised compliance staff. No system is completely secure; if a breach affecting your data occurs, we will act and notify as required by law.
11. Cookies and local storage
We use a single strictly necessary session cookie. It keeps you signed in to an exchange you opened with its PIN or link, protects forms against cross-site request forgery and is deleted when you close your browser, or after at most 12 hours. We also store three small preferences in your browser's local storage: your light/dark theme choice, whether you have already seen the Anonymous mode introduction, and that you have accepted our cookie notice. This data never leaves your device. We use no advertising, analytics or third-party tracking cookies. On your first visit a short notice informs you about these cookies; you can delete them at any time in your browser settings, but the Service may then not work correctly.
12. Your rights
Depending on the law that applies to you, you may have the right to access your data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. You may also complain to your local data protection authority.
To exercise your rights, open a support ticket with your Exchange ID and PIN, or write to [email protected]. Because we do not have accounts – and in Anonymous mode store no contact data – we can only identify data relating to you through the Exchange ID and PIN. We may be unable to delete data that we are legally required to keep, but we will restrict its use to that purpose.
13. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has used the Service, please contact us.
14. Changes to this policy
We may update this policy from time to time. The current version is always published on this page with its “Last updated” date. If we make significant changes, we will highlight them on the website.
15. Contact
For privacy questions or requests, open a support ticket or e-mail [email protected].