Coinbest Privacy Policy

Version 0.3 · Prepared 2026-08-27

1. Scope

This Privacy Policy explains how Coinbest handles information when you visit coinbest.io, request a quote, create an exchange, track an exchange, or contact support.

Coinbest's current exchange flow does not require a user account, username, password, profile, or account-based exchange history.

2. Information Coinbest may process

2.1 Exchange and transaction data

Depending on the exchange, this may include:

  • selected crypto assets and networks;
  • send and receive amounts;
  • provider quote data;
  • destination wallet address and memo/tag when supplied;
  • refund wallet address and memo/tag when supplied;
  • server-side provider order identifiers;
  • Coinbest local exchange reference;
  • normalized exchange status;
  • blockchain transaction identifiers when supplied by the provider;
  • timestamps and technical records needed to operate or troubleshoot the exchange.

Wallet addresses and blockchain transaction identifiers may be public on the relevant blockchain.

2.2 Account-free access and security data

Coinbest uses an opaque Exchange Status access token so an exchange can be tracked without an account.

The server stores the access token in hashed form in accordance with the Coinbest security architecture.

Coinbest may also process technical or security metadata such as IP address, request timestamps, browser or user-agent information, rate-limit information, error events, and similar infrastructure logs where generated by the service.

2.3 Support communications

If you contact support, Coinbest may receive:

  • your email address or Telegram username;
  • the information contained in your message;
  • a safe exchange reference;
  • public blockchain information you choose to provide for troubleshooting.

Do not send seed phrases, private keys, wallet passwords, recovery phrases, or other wallet-control secrets.

2.4 AML/KYC information

The integrated exchange provider may require identity or source-of-funds verification for a particular exchange.

Provider-required verification may take place through a backend-approved provider flow.

Coinbest does not claim that it routinely collects or stores identity documents itself.

If Coinbest later introduces direct identity-document collection, this Privacy Policy and the product controls must be updated before that processing is introduced.

3. Why information is processed

Coinbest may process information to:

  • provide catalog, quote, validation, exchange creation, and status functionality;
  • preserve account-free exchange continuity;
  • prevent duplicate Create operations;
  • secure and troubleshoot the service;
  • operate abuse-prevention and rate-limit controls;
  • provide customer support;
  • comply with applicable legal or compliance obligations;
  • establish, exercise, or defend legal claims.

4. Third parties and service providers

Coinbest may share or transmit information only as reasonably necessary with:

  • the integrated exchange provider;
  • blockchain networks through normal transaction activity;
  • hosting, infrastructure, database, security, monitoring, and communications providers;
  • professional advisers where reasonably necessary;
  • competent authorities where disclosure is legally required.

Third parties may process information under their own policies and responsibilities.

Coinbest does not sell personal data to advertisers.

5. Provider data

The integrated exchange provider controls significant parts of exchange execution, including provider quote data, deposit instructions, execution, status, and provider-required verification.

Information needed to perform an exchange may therefore be processed by the provider under its own privacy and compliance obligations.

Coinbest does not control every downstream use made by an independent provider.

6. Public blockchain data

Public blockchain transactions can be permanently visible to anyone.

Wallet addresses, transaction hashes, amounts, smart-contract interactions, and related blockchain information may be observable independently of Coinbest.

Coinbest cannot erase or alter information already recorded on a public blockchain.

7. Cookies, local storage, and analytics

Coinbest may use strictly necessary browser storage or cookies when required for security, usability, or technical operation.

The current product does not require an account cookie.

Coinbest does not treat this section as blanket authorization for non-essential analytics, advertising, or marketing tracking. If those technologies are later introduced, the product and this Policy must be updated and consent controls added where required.

8. Retention

Coinbest retains information only for as long as reasonably necessary for exchange operation, support, security, dispute handling, compliance, and legal obligations.

Operational exchange records may include data needed to preserve quote/Create integrity, idempotency, provider linkage, status, and security evidence.

Coinbest may delete or anonymize information when it is no longer reasonably required and no legal or operational reason requires continued retention.

9. Security

Coinbest uses safeguards appropriate to the current architecture, including:

  • server-side provider credentials;
  • hashed Exchange Status access tokens;
  • normalized provider errors;
  • restrictions on browser authority over provider and commercial fields.

No online service or blockchain interaction can be guaranteed completely secure.

You are responsible for protecting your device, wallet, and private Exchange Status link.

10. International processing

Coinbest's exchange provider and infrastructure providers may operate in countries different from your own.

Information may therefore be processed outside the country from which you access Coinbest.

11. Your choices and rights

Depending on applicable law, you may have rights relating to access, correction, deletion, restriction, objection, portability, or information about processing.

Some requests may be limited where information must be retained for legal, security, AML/KYC, dispute, or transaction-integrity reasons.

Because Coinbest is account-free, Coinbest may need enough information to verify that a requester is entitled to information associated with an exchange.

Coinbest will never ask for a seed phrase or private key as proof.

Privacy requests: Support@coinbest.io

12. Children

Coinbest is not intended for persons who are under 18 or below the applicable legal age required to enter into a binding agreement.

13. Third-party links

Coinbest may link to provider, verification, blockchain explorer, or other third-party services.

Their privacy practices are governed by their own policies.

14. Changes to this Policy

Coinbest may update this Policy when the service, data practices, providers, or applicable requirements change.

The current version and effective date will be published on coinbest.io.

15. Contact

For privacy requests, email is the preferred channel.

Never send seed phrases, private keys, wallet passwords, or recovery phrases.

See also the Terms of Use and AML / KYC Policy.