Privacy Policy
1. Information we collect
Depending on how you use IBIT, we may collect:
- Account data: name, email address, password (stored as a secure hash), optional phone number, referral/sponsor codes, and account identifiers (e.g. IBIT user ID).
- Verification data: email one-time codes and phone/SMS one-time codes used to verify your account. Phone verification may be processed via Firebase Authentication / Google infrastructure.
- Wallet & transaction data: deposit/withdrawal requests, wallet addresses you provide, package selections, balances, and related ledger history needed to operate the platform.
- Security & device data: login timestamps, IP address, approximate location derived from IP, browser/device type, and anti-abuse signals (including reCAPTCHA / app verification tokens where required).
- Support communications: messages you send to support, including attachments you choose to provide.
- Usage data: pages/features you use inside the app, crash/diagnostic logs, and basic analytics events.
2. How we use information
- Create and secure your account, and verify email/phone ownership.
- Provide trading, bot, deposit, withdrawal, referral, salary, and reward features.
- Prevent fraud, abuse, unauthorized access, and spam (including rate limits and security checks).
- Send transactional notices (verification codes, security alerts, deposit/withdrawal updates).
- Respond to support requests and enforce our Terms of Service.
- Meet legal, tax, accounting, and regulatory obligations where applicable.
- Improve reliability, performance, and user experience of the service.
We do not sell your personal information.
3. Legal bases (where applicable)
Where required by law (for example GDPR-style regimes), we process data based on: performance of a contract (providing the service), legitimate interests (security, fraud prevention, service improvement), consent (where we ask for it), and legal obligations.
4. How we share information
We may share personal information with:
- Service providers / processors that help us run the platform, such as hosting providers, email delivery, SMS / phone authentication providers (including Google Firebase / Google Cloud for phone OTP and related verification), analytics, and security tooling.
- Blockchain networks when you initiate on-chain deposits or withdrawals (wallet addresses and transaction hashes become public on the relevant chain).
- Professional advisers (legal, accounting) under confidentiality obligations when needed.
- Authorities when required by law, court order, or to protect rights, safety, and the integrity of the platform.
Phone numbers submitted for SMS verification are used only to send verification codes and secure your account, and are processed according to this Policy and the processor’s terms.
5. Google / Firebase services
If you use phone/SMS verification, Google Firebase Authentication (and related Google APIs) may process your phone number and verification metadata on our behalf to deliver OTP codes and prevent abuse. Google’s use of information is also described in the Google Privacy Policy and applicable Firebase / Google API terms.
We configure these services for account security. We do not use phone verification data for unrelated advertising.
6. International transfers
Our servers, processors, and subprocessors may be located in countries other than yours. Where required, we use appropriate safeguards for cross-border transfers.
7. Data retention
- Account and transaction records are kept while your account is active and for a period afterward as needed for security, disputes, audits, and legal retention.
- OTP codes and short-lived verification tokens are retained only for the verification window (or until used/expired).
- Support tickets may be retained as needed to resolve issues and improve service quality.
8. Security
We use industry-standard measures such as encrypted transport (HTTPS), hashed passwords, access controls, and monitoring. No method of transmission or storage is 100% secure; please use a strong unique password and protect your devices.
9. Your rights and choices
Subject to applicable law, you may request access, correction, deletion, or export of certain personal data, or object to / restrict certain processing. You may also:
- Update profile details in the app where available.
- Request account closure / data deletion by contacting support (some records may be retained where legally required).
- Opt out of non-essential marketing messages if we send them (transactional/security messages will still be sent).
10. Children
IBIT is not directed to children under 18 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will take appropriate steps.
11. Cookies and similar technologies
We use essential cookies/local storage for login sessions and preferences, and may use limited analytics or security cookies. You can control cookies through your browser settings; disabling essential storage may break login or core features.
12. Third-party links
Our site may link to third-party sites (for example social channels). Their privacy practices are their own; review their policies before providing information.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes may also be notified in-app or by email where appropriate. Continued use of the service after an update means you acknowledge the revised Policy.
14. Contact
For privacy questions or requests:
- Email: support@ibitglobal.exchange
- Website: https://ibitglobal.exchange/
Related: Terms of Service