Scope of this be1crypto.com privacy policy
This policy takes effect on September 1, 2026 and applies to everything you do with be1crypto.com: the website, the mobile apps, the trading terminal, the Earn program, and every support conversation in between. It covers personal data about account holders, applicants whose verification was declined, and visitors who never open an account at all.
It does not cover what happens on a public blockchain. Once a withdrawal is broadcast, it is recorded on a ledger nobody controls, including us: we cannot edit, hide or delete an on-chain record, and anyone can inspect it. Nor does it cover third-party sites we link to, wallets you connect from, or the account terms themselves, which sit in our terms and conditions and risk disclaimer.
Who controls your data
be1crypto.com is the data controller for everything described here, at 24 Exchange Plaza, Suite 1900, New York, NY 10005. Controller means we decide what is collected and why, and carry the legal responsibility for those decisions. Our vendors are processors: they act on written instructions and cannot repurpose your data.
Our Data Protection Officer reports independently of the commercial side of the business, reviews every new data flow before it ships, signs off on retention schedules, and can veto a feature. Contact details are in section 13.
What personal data we collect
Data reaches us four ways: you give it to us, the platform records it as you trade, our security systems generate it, and regulated partners return it after a check. The table maps every category to why we hold it, the lawful basis, and when it is deleted or aggregated.
| Category | What it includes | Why we hold it | Lawful basis | Retention |
|---|---|---|---|---|
| Identity and KYC | Legal name, date of birth, nationality, government ID image, liveness selfie, proof of address | Confirm you are a real, eligible person before an account can fund or trade | Legal obligation (AML and sanctions rules); performance of our contract with you | 5 years after account closure |
| Financial and transaction | Bank or card details, deposits, withdrawals, order history, fiat balances, tax residency | Settle payments, produce statements, detect fraud, meet reporting duties | Performance of contract; legal obligation | 7 years from the transaction date |
| Blockchain addresses | Deposit and withdrawal addresses used with us, transaction hashes, chain-analytics risk scores | Route funds correctly and screen counterparties against illicit-finance lists | Performance of contract; legal obligation | 5 years after the address is last used |
| Device and technical | IP address, browser and OS version, device fingerprint, time zone, login timestamps | Secure sessions, flag unfamiliar logins, block credential stuffing, debug faults | Legitimate interests (account security) | 18 months |
| Usage and analytics | Pages viewed, features opened, referring page, events tied to a rotating analytics ID | Find where the product confuses people, and measure whether a fix helped | Consent, given through the cookie banner | 14 months, then aggregated |
| Communications | Support tickets, chat transcripts, recorded calls, email correspondence | Answer your question and keep a record of what we told you | Performance of contract; legitimate interests | 3 years after the ticket closes |
| Marketing preferences | Subscription status, opt-in and opt-out timestamps, campaign engagement | Send only what you asked for, and prove that you asked for it | Consent | Until you opt out, plus 3 years of evidence |
What we deliberately do not collect
We never ask for your seed phrase, private keys or recovery words, and no employee will ever request them. We do not buy data from brokers to enrich your profile. We do not use biometric templates for advertising: the liveness check is compared once against your ID photo, then the template is discarded. Why these checks exist is covered in this overview of know-your-customer obligations, and our how it works guide shows where verification sits in signup.
How we use your data
Every use falls into one of six buckets, and we do not quietly add a seventh:
- Running your account. Executing orders, settling deposits and withdrawals, issuing statements and tax summaries.
- Verification and compliance. Sanctions screening, transaction monitoring, suspicious-activity reporting, legally required record-keeping.
- Security. Detecting account takeover, rate-limiting abuse, investigating fraud, confirming a withdrawal really came from you.
- Support. Answering your ticket with the context needed to answer it properly.
- Product improvement. Consented analytics showing which screens people abandon, aggregated wherever that still answers the question.
- Communication. Service notices you cannot opt out of, such as a security alert, and marketing email you can opt out of in one click.
Apart from automated fraud and sanctions screening, we do not use your trading activity to make automated decisions with legal or similarly significant effects. Those screens can pause a withdrawal or restrict an account. When that happens a human compliance analyst reviews the case, and you can contest the outcome through our support team.
When we share data, and what we never sell
Your data is shared on a need-to-know basis with a short list of categories, each under a written data processing agreement that limits what the recipient may do with it:
- Identity and AML vendors
- Your ID document, selfie and address proof are checked by specialist verification and sanctions-screening providers under written processing agreements.
- Payment processors and banks
- Card networks, acquiring banks and our custodial banking partners receive only what is needed to move a specific deposit or withdrawal.
- Cloud hosting and infrastructure
- Encrypted data sits with enterprise cloud providers in the US and the EU. They host it; they are contractually barred from using it.
- Analytics and email tooling
- Only where you consented, and only with pseudonymous identifiers rather than your KYC record.
- Professional advisers and auditors
- External counsel, accountants and our SOC 2 auditor, bound by professional confidentiality.
- Law enforcement and regulators
- Only on valid legal process: a subpoena, court order or properly issued regulatory demand. We review each request, refuse overbroad ones, and tell you unless a gag order forbids it.
We do not sell your personal data. We do not share it for cross-context behavioral advertising, take no payment for handing customer lists to anyone, and do not trade data with other exchanges. Those terms carry precise legal meanings in California, and our answer under each is no. If be1crypto.com is ever acquired, data may transfer with the business, and we will tell you in advance so you can close your account first.
Where your data lives and how it crosses borders
Primary storage is in the United States, with an encrypted replica in the European Union. Support is delivered from teams in North America and Europe, so personal data belonging to EU and UK residents can be processed outside the region where it was collected.
For those transfers we rely on the European Commission's Standard Contractual Clauses, plus the UK International Data Transfer Addendum where the UK regime applies. Before a transfer begins we run a transfer impact assessment covering the destination country's surveillance laws and the remedies actually available to you, then add strong encryption and strict key separation so data in transit is unreadable to an intermediary. The text of the EU regime is published at gdpr.eu.
How we protect your data
Privacy without security is a promise with nothing behind it. These are the controls that matter most for a platform holding both identity documents and money; our security page goes further.
- Encryption in transit and at rest. TLS 1.3 for every connection, AES-256 for stored data, separate keys per data class so one compromised key does not open everything.
- HSM key custody. Withdrawal signing keys live in FIPS 140-2 Level 3 hardware security modules, generated inside the module, never exportable in plaintext, with multiple approvals on large withdrawals.
- Least-privilege access. Nobody holds standing access to production KYC documents. Access is role-based, requested per case, time-boxed, logged and reviewed quarterly.
- Independent assurance. An annual SOC 2 Type II report covering security, availability and confidentiality, plus third-party penetration tests against web, API and mobile.
- Framework alignment. Controls are mapped to the NIST Cybersecurity Framework, so gaps are tracked against a published standard rather than an internal opinion.
Honest limitation: no control set removes risk entirely. Phishing that captures your own credentials, malware on your device, or a SIM-swap against your phone number defeats controls that sit on our side of the line. Use an authenticator app rather than SMS codes, set a withdrawal address allowlist, and treat any message asking for a code as hostile.
Cookies and similar technologies
Strictly necessary cookies keep you signed in, remember your language and protect forms against cross-site request forgery; they run without consent because the service does not work without them. Analytics and preference cookies run only after you accept them in the banner, and you can change that choice any time from the cookie settings link in the footer. The full inventory, listing each cookie with its provider, lifetime and purpose, is on our cookie policy page.
Your rights under GDPR and CCPA
Which rights apply depends on where you live, but we extend the substance of both frameworks to every customer. Maintaining two standards of respect is not worth the engineering.
Rights under the GDPR
- Access a copy of the personal data we hold about you
- Correct anything inaccurate or incomplete
- Erase data we no longer have a legal reason to keep
- Restrict processing while a dispute is being resolved
- Receive your data in a portable, machine-readable file
- Object to processing based on our legitimate interests
- Withdraw consent at any time, without affecting past lawful use
- Complain to your national supervisory authority
Rights under the CCPA and CPRA
- Know the categories of personal information collected and the purposes
- Know the categories of third parties that received it
- Request a copy of the specific pieces collected about you
- Delete personal information, subject to legal retention duties
- Correct inaccurate personal information
- Limit the use of sensitive personal information
- Opt out of sale or sharing (we do neither, so there is nothing to opt out of)
- Receive equal service and pricing after exercising any right
How to exercise a right
- Email dpo@be1cryptos.com from the address on your account, or open a ticket through the contact page, and say which right you are using.
- We verify it is really you, re-checking identity against your existing verification record. Handing an account history to an impostor would be the larger privacy failure.
- We acknowledge within 5 business days and respond substantively within 30 days for GDPR requests and 45 days for CCPA requests. Complex cases may extend once, and we say why before the clock runs out.
- There is no charge. An authorized agent may act for you with written permission.
Some limits we will state openly: we cannot delete AML records inside their statutory retention window, and we cannot erase a blockchain transaction. If you disagree with our handling, EU and UK residents may complain to their supervisory authority, and California residents can review the Attorney General's guidance on CCPA rights and enforcement. Requests that touch suspicious-activity reports are the one area where we cannot confirm or deny what exists, because the law that requires those filings also forbids disclosing them.
Children's data
be1crypto.com is for adults. You must be at least 18 to open an account, and age is checked during identity verification rather than by a self-declared checkbox. We do not knowingly collect personal data from anyone under 18. If we learn a minor has created an account, we freeze it, return any remaining balance to the source of funds where lawful, and delete the associated data except what compliance rules force us to keep. A parent or guardian who believes a minor has registered should write to the DPO immediately.
If there is a data breach
We keep an incident response plan with named owners and a fixed escalation path. If a breach is likely to risk your rights, we notify the relevant supervisory authority within 72 hours of becoming aware, as EU law requires, and notify affected customers without undue delay where the risk is high. US state breach laws set their own deadlines; we follow the strictest that applies. The notice will say what happened, which data was involved, what we have already done, and what you should do, such as rotating a password or revoking API keys.
Changes to this policy
We review this policy annually and whenever a new data flow, vendor or legal requirement changes the picture; the effective date above always reflects the current version. For material changes, meaning a new purpose, a new category of recipient or a longer retention period, we email account holders at least 14 days ahead and, where consent is the basis, ask again rather than assume.
Contact our Data Protection Officer
Privacy questions, rights requests and complaints all go to one place, and a person reads them.
- Email: dpo@be1cryptos.com
- General support: support@be1cryptos.com
- Phone: +1 (888) 555-0142
- Post: Data Protection Officer, be1crypto.com, 24 Exchange Plaza, Suite 1900, New York, NY 10005, United States
If you are deciding whether to trust us with money as well as data, read this alongside our security controls, the account terms, and the practical walkthrough on buying crypto. A policy is only as good as the operations behind it, and we would rather you check.