1STOPCRYPTO PRIVACY POLICY
Version 1.0
Effective Date: July 5, 2026
Last Updated: July 5, 2026
INTRODUCTION
Welcome to 1StopCrypto.
At 1StopCrypto ("1StopCrypto," "Company," "we," "our," or "us"), we recognize that privacy is fundamental to maintaining the trust of our users.
This Privacy Policy explains how we collect, use, disclose, store, protect, and otherwise process information relating to individuals who access or use the 1StopCrypto website, applications, APIs, browser extensions, software, wallet connection interfaces, and related services (collectively, the "Platform").
This Privacy Policy forms part of our Terms of Service.
By using the Platform, you acknowledge that you have read and understood this Privacy Policy.
If you do not agree with this Privacy Policy, you should discontinue use of the Platform.
IMPORTANT NOTICE REGARDING NON-CUSTODIAL SERVICES
One of the most important characteristics of 1StopCrypto is that it operates exclusively as a non-custodial software platform.
Accordingly:
We do not collect or store:
- your wallet Private Keys;
- your wallet Recovery Phrase;
- your seed phrase;
- your wallet password;
- your cryptographic signing credentials.
We cannot:
- recover lost wallets;
- reset blockchain passwords;
- restore lost Recovery Phrases;
- recover Private Keys;
- access your Digital Assets;
- reverse blockchain transactions.
Your wallet remains under your exclusive control at all times.
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal information collected through:
- the 1StopCrypto website;
- mobile applications;
- browser extensions;
- wallet connection interfaces;
- APIs;
- customer support;
- email communications;
- marketing communications;
- surveys;
- beta programs;
- social media interactions;
- events;
- future Platform services.
This Privacy Policy does not apply to information collected directly by independent third-party providers.
Those providers maintain their own privacy policies governing their collection and processing of personal information.
Examples include:
- Buy Crypto providers;
- KYC providers;
- payment processors;
- decentralized wallet providers;
- blockchain analytics providers;
- identity verification providers.
2. INFORMATION WE COLLECT
Depending upon how you interact with the Platform, we may collect several categories of information.
A. Information You Provide Directly
You may voluntarily provide information including:
- name;
- email address;
- username;
- company name;
- customer support inquiries;
- survey responses;
- marketing preferences;
- bug reports;
- feature requests;
- feedback;
- communications with our support team.
You are not required to provide personal information simply to browse publicly available portions of the Platform.
B. Wallet Information
When you voluntarily connect a cryptocurrency wallet, we may collect:
- public wallet address;
- blockchain network;
- wallet type;
- wallet connection method;
- wallet session identifiers;
- supported token balances visible through public blockchain data;
- public transaction history accessible from blockchain networks.
Public wallet addresses are generally considered pseudonymous rather than anonymous.
Blockchain activity associated with public addresses may become attributable to an individual when combined with additional information.
C. Blockchain Information
Because blockchain networks are public ledgers, we may process publicly available blockchain information including:
- wallet balances;
- token holdings;
- NFT ownership;
- publicly visible transaction history;
- transaction hashes;
- timestamps;
- block numbers;
- gas fees;
- blockchain network identifiers;
- smart contract interactions.
This information is generally obtained from public blockchain networks.
We do not make blockchain data private.
We cannot modify blockchain records.
D. Technical Information
We automatically collect certain technical information necessary for operating and securing the Platform.
Such information may include:
- IP address;
- browser type;
- browser version;
- operating system;
- device type;
- language preferences;
- screen resolution;
- referring websites;
- pages visited;
- clickstream information;
- session duration;
- timestamps;
- crash reports;
- error logs;
- diagnostic information.
E. Usage Information
We may collect information describing how the Platform is used.
Examples include:
- features accessed;
- buttons clicked;
- pages viewed;
- navigation paths;
- session duration;
- API usage;
- search activity;
- wallet connection frequency;
- swap requests initiated;
- Buy Crypto requests initiated;
- feature adoption.
Usage information assists us in improving the Platform.
F. Cookies and Similar Technologies
We use cookies and similar technologies to:
- remember user preferences;
- authenticate sessions;
- improve security;
- understand Platform performance;
- analyze website traffic;
- improve user experience.
Additional information regarding cookies appears in our Cookie Policy.
G. Communications
When Users communicate with us, we may collect:
- email content;
- support tickets;
- attachments;
- correspondence;
- chat transcripts;
- customer satisfaction surveys;
- communication preferences.
Communications may be retained for quality assurance, training, security, legal compliance, and dispute resolution.
3. INFORMATION WE DO NOT COLLECT
Unlike custodial cryptocurrency exchanges, 1StopCrypto intentionally does not collect certain highly sensitive wallet credentials.
Specifically, we do not knowingly collect:
- Private Keys;
- Recovery Phrases;
- seed phrases;
- wallet passwords;
- hardware wallet PIN codes;
- hardware wallet backup phrases.
We strongly recommend that Users never transmit such information to anyone claiming to represent 1StopCrypto.
Our personnel will never request this information.
If any person requests your Recovery Phrase while claiming to represent 1StopCrypto, you should treat that communication as fraudulent unless independently verified through official Company channels.
4. HOW WE COLLECT INFORMATION
We collect information through several methods.
Directly from Users
Examples include:
- account registration;
- newsletter subscriptions;
- support requests;
- surveys;
- contact forms;
- bug reports;
- beta program participation.
Automatically
Information may be collected automatically through:
- browser technologies;
- cookies;
- analytics software;
- server logs;
- security monitoring;
- fraud prevention systems;
- application telemetry.
From Blockchain Networks
Public blockchain information is collected through:
- blockchain nodes;
- blockchain indexing providers;
- blockchain APIs;
- publicly available distributed ledgers.
From Third-Party Providers
We may receive information from independent providers including:
- payment providers;
- analytics providers;
- cloud infrastructure providers;
- fraud prevention providers;
- KYC providers;
- customer support platforms.
Each third-party provider remains responsible for its own privacy practices.
5. PURPOSES FOR WHICH WE USE INFORMATION
We use collected information only for legitimate business and legal purposes.
Examples include:
Providing Platform Services
Including:
- enabling wallet connections;
- displaying blockchain information;
- facilitating integrations with third-party providers;
- maintaining user preferences.
Operating the Platform
Including:
- hosting;
- maintenance;
- software updates;
- bug fixes;
- troubleshooting;
- customer support.
Security
Including:
- detecting fraud;
- preventing abuse;
- identifying suspicious activity;
- protecting Company infrastructure;
- investigating security incidents;
- preventing unauthorized access.
Compliance
Including compliance with:
- applicable law;
- court orders;
- subpoenas;
- regulatory requests;
- sanctions laws;
- anti-money laundering requirements where applicable.
Improving the Platform
Including:
- feature development;
- performance optimization;
- user experience improvements;
- analytics;
- quality assurance;
- beta testing.
Communications
Including:
- responding to inquiries;
- customer support;
- service announcements;
- policy updates;
- legal notices;
- security notifications.
Marketing
Where permitted by law and consistent with user preferences, we may use contact information to send:
- newsletters;
- feature announcements;
- educational materials;
- promotional communications;
- product updates.
Users may opt out of marketing communications at any time using the unsubscribe mechanism contained within such communications or by contacting us directly.
6. LEGAL BASES FOR PROCESSING PERSONAL INFORMATION
Where applicable law requires a legal basis for processing personal information, including under the General Data Protection Regulation ("GDPR"), the Company relies on one or more of the following legal bases.
Performance of a Contract
We process personal information where necessary to:
- provide the Platform;
- authenticate users;
- respond to customer support requests;
- maintain user accounts;
- provide requested services;
- communicate regarding Platform operations.
Compliance with Legal Obligations
We process information where necessary to comply with applicable legal obligations, including:
- court orders;
- subpoenas;
- governmental requests;
- sanctions compliance;
- fraud prevention;
- cybersecurity obligations;
- regulatory reporting obligations where applicable.
Legitimate Interests
We may process personal information where necessary for our legitimate business interests, provided such interests are not overridden by applicable privacy rights.
Examples include:
- improving Platform functionality;
- maintaining Platform security;
- fraud detection;
- preventing abuse;
- diagnosing technical issues;
- product development;
- customer support;
- analytics;
- business planning;
- legal risk management.
Consent
Where required by applicable law, we process personal information based upon your consent.
Examples include:
- marketing communications;
- optional cookies;
- participation in certain research activities;
- future optional Platform features.
Where processing relies upon consent, you may withdraw consent at any time, although such withdrawal will not affect processing conducted prior to withdrawal.
7. HOW WE SHARE INFORMATION
The Company does not sell Users' personal information in exchange for monetary compensation.
We share personal information only where reasonably necessary to operate the Platform, comply with applicable law, protect legitimate interests, or with User authorization.
Information may be shared with the following categories of recipients.
A. Service Providers
We engage trusted service providers to assist in operating the Platform.
Examples include providers of:
- cloud hosting;
- content delivery;
- cybersecurity;
- customer support;
- analytics;
- infrastructure monitoring;
- email delivery;
- software development;
- data storage;
- backup services;
- fraud prevention;
- payment infrastructure for Company operations.
Service providers are contractually required to process information only as instructed by the Company and to implement reasonable security measures.
B. Buy Crypto Providers
When Users elect to purchase cryptocurrency through integrated providers, information necessary to complete the requested transaction may be shared with the selected provider.
Depending upon the provider and applicable law, this information may include:
- IP address;
- device information;
- wallet address;
- transaction details;
- contact information;
- information voluntarily submitted during the purchase process.
The Company does not control the independent provider's privacy practices.
Users should review the provider's privacy policy before completing any transaction.
C. Identity Verification Providers
Certain integrated services require independent identity verification.
Where applicable, Users may be redirected to an independent provider to complete Know Your Customer ("KYC") verification.
Information submitted during KYC verification is generally collected directly by the independent provider.
The Company may receive limited status information such as:
- verification completed;
- verification pending;
- verification unsuccessful;
- eligibility determination.
The Company generally does not receive copies of identity documents unless specifically disclosed.
D. Blockchain Networks
Users should understand that blockchain technology is inherently public.
When Users authorize blockchain transactions:
- wallet addresses;
- transaction amounts;
- timestamps;
- transaction hashes;
- smart contract interactions;
- token transfers;
- may become permanently visible on public blockchain networks.
The Company cannot alter, delete, or conceal blockchain records.
Public blockchain information may remain publicly accessible indefinitely.
E. Legal Requirements
The Company may disclose information where reasonably necessary to:
- comply with applicable law;
- respond to valid legal process;
- protect Company rights;
- investigate suspected fraud;
- enforce contractual rights;
- protect Users;
- protect public safety;
- respond to regulatory inquiries;
- satisfy sanctions obligations.
Nothing in this Privacy Policy obligates the Company to notify Users where notice is prohibited by law.
F. Corporate Transactions
If the Company participates in:
- a merger;
- acquisition;
- financing;
- restructuring;
- bankruptcy;
- sale of assets;
- change of control;
personal information may be transferred as part of that transaction, subject to applicable law.
Any successor organization will remain subject to obligations substantially consistent with this Privacy Policy unless Users are otherwise notified.
8. THIRD-PARTY WEBSITES AND SERVICES
The Platform may contain links to independent third-party websites, applications, protocols, or services.
Examples include:
- cryptocurrency wallet providers;
- decentralized exchanges;
- blockchain explorers;
- blockchain protocols;
- payment providers;
- educational resources;
- documentation websites;
- social media platforms.
The Company does not control these third-party services.
Their privacy practices are governed by their own policies.
Users are encouraged to review the privacy policy of every third-party service they access.
The Company is not responsible for the privacy, security, content, or practices of third-party websites.
9. INTERNATIONAL DATA TRANSFERS
The Company may process personal information using infrastructure located in multiple jurisdictions.
Accordingly, personal information may be transferred to, processed in, or accessed from jurisdictions other than the User's country of residence.
Where required by applicable law, the Company will implement appropriate safeguards designed to protect transferred information.
Such safeguards may include:
- contractual protections;
- organizational safeguards;
- technical safeguards;
- security controls;
- other lawful transfer mechanisms recognized by applicable law.
Users acknowledge that privacy protections may differ among jurisdictions.
10. DATA RETENTION
The Company retains personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy unless a longer retention period is required or permitted by law.
Retention periods depend upon factors including:
- legal obligations;
- regulatory requirements;
- dispute resolution;
- fraud prevention;
- enforcement of agreements;
- cybersecurity investigations;
- legitimate business needs.
Examples include:
Customer Support Records
May be retained for a reasonable period to:
- improve customer service;
- resolve disputes;
- investigate abuse;
- comply with legal obligations.
Security Logs
May be retained to:
- investigate cybersecurity incidents;
- detect fraud;
- improve Platform security;
- comply with legal obligations.
Analytics Data
May be retained in aggregated or de-identified form for product improvement and business analysis.
Blockchain Information
The Company cannot delete information permanently recorded on public blockchain networks.
Users acknowledge that blockchain records may remain publicly available indefinitely regardless of any request submitted to the Company.
11. INFORMATION SECURITY
The Company maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction.
Examples of safeguards may include:
- encryption in transit;
- encryption at rest where appropriate;
- access controls;
- authentication systems;
- security monitoring;
- vulnerability management;
- incident response procedures;
- network segmentation;
- least-privilege access controls;
- secure software development practices;
- logging and auditing;
- employee security training.
Despite these measures, no method of electronic transmission or storage can be guaranteed to be completely secure.
Accordingly, the Company cannot guarantee absolute security.
Users share responsibility for protecting their own information by:
- maintaining secure devices;
- using strong passwords;
- enabling multi-factor authentication where available;
- safeguarding wallet credentials;
- protecting Recovery Phrases;
- maintaining updated software;
- avoiding phishing attempts;
- verifying website authenticity before connecting wallets.
Users should immediately report suspected security incidents affecting their interaction with the Platform.
12. CHILDREN'S PRIVACY
The Platform is intended for use only by individuals who are at least eighteen (18) years of age or the age of legal majority in their jurisdiction, whichever is greater.
The Company does not knowingly collect personal information from children.
If the Company becomes aware that it has inadvertently collected personal information from a child in violation of applicable law, the Company will take reasonable steps to delete such information as soon as practicable, unless retention is required by law.
If you believe that a child has provided personal information to the Company, please contact us using the contact information provided at the end of this Privacy Policy.
13. YOUR PRIVACY RIGHTS
Depending upon your jurisdiction, you may have certain rights regarding your personal information.
Subject to applicable law, these rights may include:
- the right to know what personal information we collect;
- the right to access personal information;
- the right to request correction of inaccurate information;
- the right to request deletion of certain personal information;
- the right to obtain a copy of certain personal information;
- the right to object to certain processing activities;
- the right to restrict certain processing;
- the right to withdraw consent where processing is based upon consent;
the right to lodge a complaint with an appropriate supervisory authority where applicable.
The availability of these rights depends upon applicable law and the nature of the information requested.
Certain information may be exempt from deletion or modification where retention is required by law or necessary to establish, exercise, or defend legal claims.
The Company may request reasonable information necessary to verify the identity of the individual submitting a privacy request before fulfilling such request.
Verification procedures are intended to protect Users against unauthorized disclosure of personal information.
Limitations Relating to Blockchain Data
Because the Platform interacts with public blockchain networks, certain information cannot be modified or deleted by the Company.
Examples include:
- public wallet addresses;
- blockchain transaction hashes;
- publicly recorded token transfers;
- smart contract interactions;
- publicly available blockchain metadata.
Such information is permanently recorded on decentralized blockchain networks and generally cannot be altered, deleted, or removed by the Company.
Accordingly, requests relating to blockchain records may be technically impossible to fulfill.
14. CALIFORNIA PRIVACY RIGHTS
If you are a California resident, you may have additional privacy rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), subject to applicable exemptions.
Subject to applicable law, California residents may have the right to:
- know the categories of personal information collected;
- know the categories of sources from which personal information is collected;
- know the business purposes for collecting personal information;
- know the categories of third parties with whom information is shared;
- request access to certain personal information;
- request deletion of certain personal information;
- request correction of inaccurate personal information;
- request information regarding certain disclosures;
- limit certain uses of sensitive personal information where applicable.
The Company will not discriminate against Users for exercising applicable privacy rights.
Sale or Sharing of Personal Information
As of the Effective Date of this Privacy Policy, the Company does not sell Users' personal information for monetary consideration.
The Company also does not knowingly sell or share personal information for cross-context behavioral advertising as those terms are defined under applicable California law.
If our practices materially change in the future, this Privacy Policy will be updated accordingly.
15. GDPR AND OTHER INTERNATIONAL PRIVACY RIGHTS
Where applicable, individuals located in jurisdictions recognizing privacy rights similar to those provided under the General Data Protection Regulation ("GDPR") may have additional rights.
Subject to applicable law, these rights may include:
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing;
- the right to withdraw consent;
- the right to lodge a complaint with a supervisory authority.
These rights are not absolute.
The Company may decline requests where permitted by applicable law, including where processing is necessary:
- to comply with legal obligations;
- to establish, exercise, or defend legal claims;
- to protect the rights of others;
- for fraud prevention;
- for cybersecurity purposes;
- for other lawful business purposes.
16. MARKETING COMMUNICATIONS
Where permitted by applicable law, the Company may send Users communications regarding:
- Platform updates;
- newly available features;
- educational materials;
- newsletters;
- promotional campaigns;
- product announcements;
- Company events.
Users may opt out of marketing communications at any time by:
- using the unsubscribe mechanism included within marketing emails;
- updating communication preferences, where available;
- contacting the Company directly.
Opting out of marketing communications does not affect transactional or operational communications, including:
- security alerts;
- policy updates;
- customer support responses;
- legal notices;
- service announcements;
- account-related notifications.
17. DO NOT TRACK SIGNALS
Some web browsers transmit "Do Not Track" ("DNT") signals.
Because there is currently no universally accepted standard governing the interpretation of DNT signals, the Platform does not currently respond differently to such signals.
If industry standards or applicable legal requirements regarding DNT signals materially change, the Company may revise its practices and update this Privacy Policy accordingly.
18. CHANGES TO THIS PRIVACY POLICY
The Company may update this Privacy Policy periodically to reflect:
- changes in applicable law;
- changes in regulatory guidance;
- changes in Platform functionality;
- improvements in security practices;
- changes to third-party service providers;
- changes in business operations;
- other operational or legal developments.
When material changes are made, the Company will update the "Last Updated" date appearing at the beginning of this Privacy Policy and may provide additional notice where required by applicable law.
Continued use of the Platform after the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Privacy Policy.
If you do not agree with a revised Privacy Policy, you should discontinue use of the Platform.
19. CONTACTING US
Questions, requests, or concerns regarding this Privacy Policy or the Company's privacy practices may be directed to:
1StopCrypto
Legal Entity: BLUE SOFT LLC
Business Address: 10200 S Roberts Rd Unit #4235 Palos Hills, IL 60465
Privacy Email: [email protected]
Legal Email: [email protected]
Support Email: [email protected]
Website: https://1stopcrypto.com
If you submit a privacy request, please provide sufficient information to allow the Company to verify your identity and understand the nature of your request.
The Company will respond within the timeframes required by applicable law.
20. PRIVACY PRINCIPLES
As a non-custodial cryptocurrency platform, the Company's privacy philosophy is guided by the following principles:
We collect only the information reasonably necessary to operate and improve the Platform.
We do not take custody of users' Digital Assets.
We do not store users' Private Keys or Recovery Phrases.
We strive to implement commercially reasonable administrative, technical, and organizational safeguards to protect the information we process.
We work with reputable third-party service providers and require appropriate contractual protections where applicable.
We seek to provide transparent information about our data processing practices.
We respect users' privacy rights as required by applicable law.
We continuously review and improve our privacy and security practices as our Platform evolves.
APPENDIX A
CALIFORNIA PRIVACY NOTICE
This California Privacy Notice supplements the 1StopCrypto Privacy Policy and applies only to individuals who are residents of the State of California.
This notice is intended to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and related regulations.
For purposes of this Appendix A, the terms "personal information," "sensitive personal information," "consumer," "business purpose," "commercial purpose," "sale," "share," and "service provider" have the meanings given to them under applicable California privacy law.
If there is a conflict between this Appendix A and another section of the Privacy Policy, this Appendix A controls solely with respect to California residents and solely to the extent required by California law.
A.1 Categories of Personal Information We Collect
Depending on how you interact with the Platform, we may collect the following categories of personal information.
Identifiers
Examples include:
- name;
- email address;
- username;
- IP address;
- device identifiers;
- online identifiers;
- wallet public addresses;
- account identifiers.
We collect identifiers to operate the Platform, communicate with users, provide customer support, maintain security, detect fraud, and comply with legal obligations.
Internet or Other Electronic Network Activity Information
Examples include:
- browser type;
- operating system;
- device type;
- pages viewed;
- features used;
- referring URLs;
- session duration;
- clickstream activity;
- diagnostic logs;
- error logs;
- security logs;
- wallet connection events.
We collect this information to operate, maintain, secure, troubleshoot, and improve the Platform.
Commercial Information
Examples may include:
- records of products or services considered;
- Buy Crypto transactions initiated through third-party providers;
- swap requests initiated through the Platform;
- subscription or account history, if applicable;
- customer support history.
For clarity, 1StopCrypto does not take custody of Digital Assets and does not itself process cryptocurrency purchase transactions unless expressly disclosed.
Financial Information
Where applicable, limited financial-related information may be processed in connection with third-party services.
Examples may include:
- payment transaction status received from a third-party provider;
- purchase eligibility status;
- transaction amount;
- wallet address used for settlement;
- blockchain transaction identifiers.
Payment card numbers, bank account details, and identity verification documents are generally collected directly by independent third-party providers rather than by 1StopCrypto.
Geolocation Information
We may collect approximate location information derived from IP address.
We do not intentionally collect precise GPS-level location information unless expressly disclosed and consented to where required by law.
Approximate location may be used for:
- fraud prevention;
- security;
- regional compliance;
- restricted jurisdiction screening;
- localization;
- analytics.
Professional or Employment-Related Information
We may collect professional or employment-related information if you voluntarily provide it, such as when contacting us regarding business partnerships, employment opportunities, vendor relationships, or enterprise services.
Inferences
We may derive limited inferences from usage information to understand:
- product preferences;
- feature usage;
- support needs;
- security risk indicators;
- likely interest in certain Platform features.
We do not use such inferences to make legally significant decisions about consumers unless expressly disclosed.
A.2 Sensitive Personal Information
Under California law, certain information may be considered sensitive personal information.
Depending on how you use the Platform and third-party services, sensitive personal information may include:
- government identification information submitted to independent KYC providers;
- precise geolocation, if ever collected with consent;
- account login credentials;
- wallet authentication-related metadata;
- information revealing financial activity;
- information required for fraud prevention or compliance.
As a non-custodial platform, 1StopCrypto does not collect or store your Private Keys, Recovery Phrases, or seed phrases.
We do not use sensitive personal information for purposes requiring a right to limit under California law unless we provide the required notice and opportunity to exercise that right.
A.3 Sources of Personal Information
We collect personal information from the following categories of sources:
- directly from you;
- automatically from your device or browser;
- from your use of the Platform;
- from public blockchain networks;
- from wallet connection interfaces;
- from third-party service providers;
- from fraud prevention and security providers;
- from customer support communications;
- from public sources where permitted by law.
A.4 Purposes for Collection, Use, and Disclosure
We collect, use, and disclose personal information for the following business and commercial purposes:
- providing the Platform;
- enabling wallet connections;
- displaying blockchain information;
- facilitating third-party provider integrations;
- providing customer support;
- maintaining account functionality;
- securing the Platform;
- detecting fraud;
- preventing misuse;
- complying with legal obligations;
- responding to legal process;
- enforcing our Terms;
- improving Platform performance;
- debugging;
- analytics;
- internal reporting;
- product development;
- communicating with users;
- sending marketing communications where permitted by law;
- maintaining records;
- protecting the rights, property, and safety of users, the Company, and others.
A.5 Categories of Third Parties to Whom We Disclose Personal Information
We may disclose personal information to the following categories of third parties:
- cloud hosting providers;
- analytics providers;
- customer support providers;
- cybersecurity providers;
- fraud prevention providers;
- blockchain infrastructure providers;
- wallet connection providers;
- Buy Crypto providers;
- identity verification providers;
- payment providers;
- legal and professional advisers;
- regulators and governmental authorities where required;
- successor entities in corporate transactions.
Each disclosure is made for a business purpose, legal purpose, or with user direction.
A.6 Sale or Sharing of Personal Information
As of the Effective Date, 1StopCrypto does not sell personal information for monetary consideration.
As of the Effective Date, 1StopCrypto does not knowingly share personal information for cross-context behavioral advertising as those terms are defined under California privacy law.
If our practices change, we will update this Privacy Policy and provide any required opt-out mechanism.
A.7 Retention of Personal Information
We retain personal information only for as long as reasonably necessary for the purposes described in the Privacy Policy, including:
- providing the Platform;
- maintaining security;
- preventing fraud;
- complying with legal obligations;
- resolving disputes;
- enforcing agreements;
- maintaining business records.
Retention periods vary based on the nature of the information and the purpose for which it is processed.
Blockchain records are not controlled by 1StopCrypto and may remain publicly available indefinitely.
A.8 California Consumer Rights
Subject to applicable law and verification requirements, California residents may have the following rights.
Right to Know
You may request that we disclose:
- the categories of personal information we collected about you;
- the categories of sources from which personal information was collected;
- the business or commercial purposes for collecting, selling, or sharing personal information;
- the categories of third parties to whom personal information was disclosed;
- the specific pieces of personal information collected about you.
Right to Delete
You may request deletion of personal information we collected from you, subject to legal exceptions.
We may deny deletion requests where retention is necessary to:
- complete a transaction requested by you;
- provide services requested by you;
- detect security incidents;
- prevent fraud;
- debug errors;
- exercise free speech;
- comply with legal obligations;
- maintain internal uses reasonably aligned with consumer expectations;
- establish, exercise, or defend legal claims.
We cannot delete information permanently recorded on public blockchain networks.
Right to Correct
You may request correction of inaccurate personal information maintained by us.
We may request documentation reasonably necessary to evaluate the correction request.
Right to Opt Out of Sale or Sharing
Because we do not currently sell or share personal information as defined by California law, we do not currently provide a sale/share opt-out link.
If our practices change, we will provide required notices and opt-out mechanisms.
Right to Limit Use of Sensitive Personal Information
We do not use sensitive personal information for purposes requiring a right to limit under California law unless we provide the required notice and mechanism.
Right to Non-Discrimination
We will not discriminate against you for exercising your California privacy rights.
This means we will not, solely because you exercised your privacy rights:
- deny goods or services;
- charge different prices;
- provide a different level or quality of service;
- suggest that you may receive different treatment.
A.9 How to Submit a California Privacy Request
California residents may submit privacy requests by contacting:
Privacy Email: [email protected]
Legal Email: [email protected]
Mailing Address: 10200 S Roberts Rd Unit #4235 Palos Hills, IL 60465
Your request should include sufficient information to allow us to verify your identity and understand the request.
We may ask for additional information where necessary to verify the request.
A.10 Authorized Agents
California residents may designate an authorized agent to submit requests on their behalf.
We may require:
- written authorization signed by the consumer;
- verification of the consumer's identity;
- verification of the agent's authority;
proof that the agent is registered with the California Secretary of State where required by law.
We may deny requests from agents who cannot provide sufficient authorization.
A.11 Response Timing
We will respond to verified California privacy requests within the time required by applicable law.
If additional time is needed, we may extend the response period where permitted by law and provide notice explaining the extension.
A.12 Blockchain Limitations
California privacy rights may be limited where personal information exists on public blockchain networks.
Because public blockchains are decentralized systems not controlled by 1StopCrypto, we cannot:
- delete blockchain transactions;
- modify wallet transaction histories;
- remove public wallet addresses from blockchain ledgers;
- reverse blockchain confirmations;
- erase smart contract events;
- alter transaction hashes.
Users should consider the public and permanent nature of blockchain transactions before using the Platform.
APPENDIX B
U.S. STATE PRIVACY RIGHTS ADDENDUM
This U.S. State Privacy Rights Addendum supplements the 1StopCrypto Privacy Policy and applies to residents of U.S. states that have enacted comprehensive consumer privacy laws applicable to the Company.
This Appendix is intended to provide additional disclosures and rights information for residents of states including, where applicable:
- Virginia;
- Colorado;
- Connecticut;
- Utah;
- Texas;
- Oregon;
- Montana;
- Delaware;
- Iowa;
- Indiana;
- Tennessee;
- New Jersey;
- New Hampshire;
- Nebraska;
- Kentucky;
- Minnesota;
- Maryland;
- Rhode Island;
- and other U.S. states that enact similar comprehensive privacy laws.
Because state privacy laws continue to evolve, this Appendix will be interpreted to provide rights required by applicable state law only to residents entitled to those rights.
If a specific state privacy law does not apply to the Company or to a particular individual, nothing in this Appendix creates rights beyond those required by applicable law.
B.1 Personal Data Covered by This Addendum
For purposes of this Appendix, "personal data" or "personal information" generally means information linked or reasonably linkable to an identified or identifiable individual, subject to exclusions under applicable state law.
Personal data may include:
- identifiers;
- contact information;
- device information;
- online identifiers;
- IP address;
- wallet public address;
- approximate location;
- internet or electronic network activity;
- customer support communications;
- transaction-related metadata;
- usage analytics;
- preferences;
- other information described in the Privacy Policy.
Personal data generally does not include information that is:
- publicly available;
- de-identified;
- aggregated;
- subject to certain federal privacy laws;
- excluded by applicable state privacy law.
Public blockchain data may be publicly available and may also be permanently recorded on blockchain networks.
B.2 Categories of Personal Data We Process
Depending on your interaction with the Platform, we may process the following categories of personal data:
- identifiers;
- contact information;
- account information;
- public wallet addresses;
- blockchain transaction metadata;
- internet or electronic network activity;
- device and browser information;
- approximate geolocation;
- customer support communications;
- fraud prevention signals;
- security logs;
- analytics data;
- marketing preferences.
We do not collect or store Private Keys, Recovery Phrases, or seed phrases.
B.3 Purposes of Processing
We process personal data for purposes including:
- providing the Platform;
- enabling wallet connections;
- displaying blockchain balances and transaction information;
- facilitating integrations with third-party providers;
- providing customer support;
- maintaining security;
- detecting fraud;
- preventing unlawful activity;
- complying with legal obligations;
- enforcing our Terms;
- improving products and services;
- analytics;
- debugging;
- communications;
- marketing where permitted;
- business operations;
- corporate transactions.
B.4 Sensitive Data
Some state privacy laws provide special rights regarding sensitive data.
Sensitive data may include:
- government identification information;
- precise geolocation;
- financial account information;
- biometric data;
- racial or ethnic origin;
- religious beliefs;
- health information;
- sexual orientation;
- citizenship or immigration status;
- information from a known child.
1StopCrypto does not seek to collect sensitive data unless necessary for a disclosed purpose or where collected by an independent provider.
Where sensitive data is collected by a Buy Crypto provider, KYC provider, payment provider, or identity verification provider, such collection is governed primarily by that provider's privacy policy.
Where applicable law requires consent to process sensitive data, we will obtain consent or rely on another legally permitted basis before processing such data.
B.5 Sale of Personal Data
1StopCrypto does not currently sell personal data as that term is defined under applicable comprehensive state privacy laws.
If our practices change, we will update this Privacy Policy and provide any required opt-out mechanism.
B.6 Targeted Advertising
1StopCrypto does not currently use personal data for targeted advertising as defined under applicable comprehensive state privacy laws.
If our practices change, we will provide any required disclosures and opt-out mechanisms.
B.7 Profiling
1StopCrypto does not currently engage in profiling in furtherance of decisions that produce legal or similarly significant effects concerning consumers.
We may use automated tools for:
- fraud prevention;
- cybersecurity;
- abuse detection;
- compliance screening;
- operational analytics.
These activities are intended to protect the Platform and Users and are not designed to make legally significant consumer decisions unless expressly disclosed.
B.8 Consumer Privacy Rights
Subject to applicable state law and verification of your identity, residents of covered U.S. states may have one or more of the following rights regarding their personal data.
The availability of these rights depends upon the law applicable to your state of residence.
Right to Access
You may request confirmation regarding whether we process your personal data.
Where required by law, you may also request access to the personal data we maintain about you.
Subject to applicable law, access requests may include:
- categories of personal data processed;
- purposes of processing;
- categories of third parties receiving personal data;
- specific pieces of personal data maintained by the Company.
Right to Correction
You may request correction of inaccurate personal data maintained by the Company.
We may request reasonable documentation necessary to verify the requested correction.
The Company may decline correction requests where:
- the requested information is accurate;
- the request cannot reasonably be verified;
- correction is prohibited by applicable law;
- the information exists solely on public blockchain networks beyond the Company's control.
Right to Deletion
Subject to applicable law, you may request deletion of personal data maintained by the Company.
Deletion requests remain subject to numerous statutory exceptions, including where retention is reasonably necessary to:
- complete requested transactions;
- detect or prevent fraud;
- investigate security incidents;
- comply with legal obligations;
- exercise legal claims;
- establish or defend legal rights;
- maintain internal records;
- preserve Platform security;
- comply with financial recordkeeping obligations.
The Company cannot delete information permanently recorded on decentralized blockchain networks.
Right to Data Portability
Where required by applicable law, you may request a copy of certain personal data in a portable and, where technically feasible, readily usable format.
The Company may decline portability requests where:
- technically infeasible;
- prohibited by law;
- the information requested is publicly available blockchain information;
- disclosure would adversely affect the rights of another person.
Right to Opt Out
Where applicable law provides such rights, you may request to opt out of:
- targeted advertising;
- sale of personal data;
- profiling in furtherance of decisions producing legal or similarly significant effects.
As of the Effective Date of this Privacy Policy:
- 1StopCrypto does not sell personal data as defined by applicable state privacy laws;
- 1StopCrypto does not knowingly engage in targeted advertising as defined by such laws;
- 1StopCrypto does not use profiling to make legally significant decisions concerning consumers.
Should these practices materially change, this Privacy Policy will be updated and required opt-out mechanisms will be provided.
Right to Withdraw Consent
Where processing is based upon consent, and where applicable law grants such a right, you may withdraw consent at any time.
Withdrawal of consent shall not affect processing lawfully conducted prior to withdrawal.
Certain Platform functionality may become unavailable if consent is withdrawn.
B.9 Exercising Your Rights
Privacy requests may be submitted using the contact information provided in this Privacy Policy.
Requests should include sufficient information to allow us to:
- identify the requesting individual;
- verify identity;
- understand the scope of the request;
- respond appropriately.
The Company may request additional information where reasonably necessary to verify identity.
We will use verification information solely for purposes of processing the request.
B.10 Appeals Process
Certain state privacy laws provide consumers the right to appeal a denial of a privacy request.
Where applicable law provides such rights, consumers whose requests have been denied may submit an appeal by contacting:
Privacy Email: [email protected]
Appeals should include:
- the original request;
- the Company's response, if available;
an explanation of why the consumer believes the request should have been granted.
The Company will review appeals in accordance with applicable law.
Where required by applicable law, we will provide information regarding additional rights to contact the appropriate state regulatory authority if an appeal is denied.
B.11 Authorized Agents
Where permitted by applicable law, consumers may authorize another person to submit requests on their behalf.
The Company may require reasonable evidence of authority, including:
- signed written authorization;
- power of attorney;
- identity verification;
- other documentation reasonably necessary to prevent fraud.
The Company reserves the right to deny requests submitted by individuals who cannot demonstrate sufficient authority to act on behalf of the consumer.
B.12 Verification Procedures
To protect Users against unauthorized disclosure of personal information, the Company employs reasonable verification procedures before responding to privacy requests.
Verification procedures may include:
- confirming email ownership;
- confirming wallet ownership where appropriate;
- verifying previously supplied account information;
- requesting additional identifying information;
- confirming support history;
- confirming recent Platform interactions.
The Company will request only the information reasonably necessary to verify identity.
Failure to complete verification may prevent the Company from fulfilling a request.
B.13 Public Blockchain Information
Because 1StopCrypto is a non-custodial cryptocurrency platform, certain information exists independently of the Company.
Information permanently recorded on decentralized blockchain networks may include:
- wallet addresses;
- transaction hashes;
- token transfers;
- smart contract interactions;
- block numbers;
- timestamps;
- publicly visible token balances.
The Company cannot:
- delete blockchain records;
- modify blockchain history;
- erase smart contract events;
- remove wallet addresses from public blockchains;
- alter validator records.
Accordingly, certain privacy rights may be technically impossible to fulfill with respect to public blockchain information.
B.14 Future Changes to State Privacy Laws
State privacy laws continue to evolve rapidly.
The Company reserves the right to update this Appendix to:
- reflect newly enacted privacy legislation;
- comply with amended statutes;
- incorporate new regulatory guidance;
- expand consumer rights;
- modify operational practices.
Material updates will be reflected by updating the "Last Updated" date appearing at the beginning of the Privacy Policy.
APPENDIX C
EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND PRIVACY ADDENDUM
This Appendix applies only to individuals located in:
- the European Economic Area ("EEA");
- the United Kingdom ("UK");
Switzerland,
to the extent applicable privacy laws govern the Company's processing of their personal data.
Nothing in this Appendix expands the territorial scope of applicable privacy laws beyond that required by law.
C.1 Representative
Where required by applicable law, the Company will designate an EEA or UK representative and publish the representative's contact information.
Until such appointment becomes legally required, privacy requests should be directed to the Company using the contact information provided in this Privacy Policy.
C.2 International Transfers
Personal data may be transferred outside the EEA, UK, or Switzerland.
Where required, the Company will implement appropriate safeguards, which may include:
- Standard Contractual Clauses approved by the European Commission;
- the UK International Data Transfer Addendum;
- other lawful transfer mechanisms recognized under applicable law.
C.3 Additional GDPR Rights
Subject to applicable law, individuals may have the right to:
- object to processing based upon legitimate interests;
- request restriction of processing;
- request portability of certain personal data;
- withdraw consent;
- lodge complaints with an applicable supervisory authority.
The exercise of these rights remains subject to statutory limitations.
C.4 Automated Decision-Making
The Company does not currently use automated decision-making or profiling that produces legal or similarly significant effects concerning individuals.
Security-related fraud detection, abuse prevention, and cybersecurity monitoring do not constitute automated decision-making for these purposes unless otherwise required by applicable law.
C.5 Supervisory Authorities
Individuals located within the EEA, UK, or Switzerland may have the right to submit complaints to their local data protection authority if they believe the Company's processing of personal data violates applicable privacy law.
The Company encourages individuals to contact us first so we may attempt to resolve concerns promptly.