Online
Support in Telegram
Service works 24/7



Administrator turned off mobile version of the website

If you an administrator, turn on mobile version in the control panel

COINDROP LEGAL CENTER

Privacy Policy

The procedure for processing, storing, protecting, and transferring COINDROP users personal data when using the website, creating orders, contacting support, and passing AML / KYC / SoF checks.

Only necessary dataThe Service processes data needed for orders, security, communication with the user, AML / KYC / SoF, and resolution of disputed situations.
Access is restrictedReview materials, receipts, correspondence, and payment details are used only by authorized persons and contractors to the necessary extent.
User rights are preservedThe User may request information about processing, as well as correction, blocking, or deletion of data if there are no legal grounds for storage.
1

General Provisions

1.1. This Privacy Policy and Personal Data Processing Policy defines the procedure for processing, storing, using, transferring, and protecting the personal data of users of the coindrop.trade website.

1.2. "COINDROP", "Service", "Operator", or "We" means the online service coindrop.trade and the person administering the operation of the Service, determining the purposes, scope, and methods of personal data processing. Contact for personal data matters: support@coindrop.trade.

1.3. "User", "Customer", or "You" means an individual using the website, creating an Order, contacting Support, passing a review, or otherwise interacting with the Service.

1.4. This Policy applies together with the Rules and Terms of Exchange Operations, the AML / KYC / SoF Policy, the terms of a specific Order, and other documents published on the website.

1.5. Use of the website, creation of an Order, ticking a separate consent checkbox, sending a request to Support, submitting documents, or otherwise providing data means that the User has read this Policy and agrees to the processing of data within the limits necessary for the purposes specified in it.

1.6. The Service is intended for adult Users. If the Service becomes aware that data has been provided by a minor without legal grounds, processing may be restricted, and the Order may be cancelled or suspended until the circumstances are clarified.

2

Terms and Principles

2.1. Personal data means any information relating to a directly or indirectly identified or identifiable individual.

2.2. Personal data processing means any action or set of actions performed with personal data, including collection, recording, systematization, accumulation, storage, clarification, extraction, use, transfer, provision, access, depersonalization, blocking, deletion, and destruction.

2.3. The Operator processes data on a lawful and fair basis, only for predetermined purposes, in a scope corresponding to such purposes, and does not store data longer than necessary for the purposes of processing, execution of the Order, security, disputes, legal requirements, and protection of the rights of the parties.

2.4. The Service does not sell Users personal data, does not provide paid access to the User database, and does not disclose data to an unlimited circle of persons, except where the User independently publishes information on third-party platforms or where disclosure is required by law.

2.5. The User is responsible for the accuracy of the data provided and for having a legal basis to transfer third-party data to the Service if such data is specified by the User in an Order, receipt, statement, correspondence, or other material.

3

Data Categories

3.1. Contact data: email, Telegram profile, or other contact details that the User provides when creating an Order, contacting Support, or otherwise interacting with the Service.

3.2. Order data: Order number, exchange direction, amounts, rate, fee, status, date and time of actions, selected payment method, payment details, digital currency addresses, network, memo / tag, TxID, receipts, payment confirmations, screenshots, statements, payment comments, and other information relating to the operation.

3.3. Communication data: correspondence with Support, requests, claims, responses, records of actions in the personal account, dispute materials, and information provided in a disputed situation, AML-Hold, refund, or payment check.

3.4. Technical data: IP address, user-agent, information about the browser, device, operating system, language, approximate region by IP, cookie files, session ID, date and time of visit, referral source, interface events, errors, security logs, and anti-fraud metrics.

3.5. AML / KYC / SoF data: documents and information confirming identity, ownership of payment details, source of funds, economic purpose of the operation, ownership of a wallet, account, card, bank account, or digital currency address, as well as the results of internal and external checks.

3.6. The Service does not request passwords, seed phrases, private keys, one-time codes, CVV, full bank card number, device access, or other data that allows disposal of the User funds. If the User accidentally provides such information, the Service may delete, hide, or not use it.

3.7. The Service does not seek to receive special categories of personal data, including information about health, political views, religious beliefs, intimate life, or biometric templates. If such information is accidentally contained in the materials provided, it is not used for other purposes and may be deleted or hidden if this does not interfere with the review of the operation and protection of the rights of the parties.

4

Purposes of Processing

4.1. Creation, processing, execution, restoration, cancellation, recalculation, and support of Orders.

4.2. Communication with the User, sending operational notifications, clarification of payment details, payment confirmation, receipt confirmation, and processing of requests, claims, reviews, and disputed situations.

4.3. AML / KYC / SoF control, checking transactions, addresses, payment details, source of funds, ownership of payment instruments, and preventing fraud, sanctions evasion, use of third-party payment details, forged documents, disputed payments, and other abuses.

4.4. Ensuring the security of the website, personal account, payment processes, communications, internal infrastructure, anti-fraud control, incident investigation, and protection of Users.

4.5. Compliance with legal requirements, requests from competent authorities, courts, banks, payment systems, monitoring platforms, partners, and other persons where there is a legal basis or a need to protect the rights of the Service and Users.

4.6. Maintaining internal records, service quality analytics, technical support, error control, interface improvement, and website stability.

4.7. Sending advertising or informational messages only with the User consent or another legal basis. Operational notifications related to an Order are not advertising.

5

Legal Grounds and Consents

5.1. Personal data is processed on the basis of the User consent, performance of the user agreement and the terms of the Order, legitimate interests of the Service and third parties, the need to prevent fraud, ensure security, consider claims, and comply with legal requirements.

5.2. The User consent must be specific, subject-defined, informed, conscious, and unambiguous. The Service may record consent by a separate checkbox, technical log, document version record, date, time, IP address, email, Order number, and other acceptance parameters.

5.3. If separate consent is required for a specific type of data or action, the Service requests it separately or offers an alternative method of interaction if such method is technically and legally possible.

5.4. The User may withdraw consent by contacting Support. After consent is withdrawn, the Service stops processing data unless there are other legal grounds for continuing processing, including execution of the Order, security, AML / KYC / SoF, a dispute, refund, legal requirements, or protection of the rights of the parties.

5.5. Withdrawal of consent or a request to delete data does not mean automatic deletion of information required for an open Order, review, refund, AML-Hold, accounting, legal, or dispute records, and does not release the User from the obligation to provide accurate data if the operation cannot be lawfully and safely completed without it.

5.6. If the User transfers third-party data to the Service, the User confirms that the necessary consents have been obtained or that another legal basis exists for such transfer. The Service may request confirmation of the lawfulness of such data transfer or refuse to use third-party payment details.

6

KYC / SoF, Documents, and Images

6.1. When reviewing an Order, payment details, payment, digital currency address, or source of funds, the Service may request documents, selfies, video confirmation, proof of ownership of a card, bank account, wallet, account, TxID, receipt, PDF payment receipt, statement, transaction certificate, explanation of the origin of funds, and other materials necessary to assess the risk.

6.2. KYC / SoF documents and materials are used only for checking the operation, ownership of payment details, security, AML / KYC / SoF, dispute resolution, refunds, and interaction with partners, monitoring platforms, banks, payment systems, and competent authorities to the necessary extent.

6.3. The User should hide unnecessary information that is not related to the review, provided this does not make the document unsuitable for analysis. The Service does not require showing CVV, one-time codes, passwords, seed phrases, private keys, or full access to a banking app.

6.4. Photos, selfies, and videos may contain an image of the face and may be used to verify the fact of the request, ownership of the document, payment details, or account by the User. The Service does not create a public image database, does not make images publicly available, and does not use them for marketing.

6.5. If, in a specific case, a face image or other material is used in a manner that qualifies as biometric personal data under applicable law, it is processed only with separate consent, written consent or an equivalent form of consent, or another legal basis. The Service does not use the Unified Biometric System and does not create a biometric template of the User unless otherwise expressly stated separately.

6.6. Refusal to provide documents or confirmations may lead to suspension of the Order, inability to execute it, refusal of service, refund after verification of payment details, or another lawful method of resolving the situation if without such materials it is impossible to confirm the security of the operation and ownership of funds or payment details.

7

Cookies and Technical Data

7.1. The website may use cookies, local storage, session ID, technical logs, anti-fraud metrics, and similar technologies for website operation, session storage, fraud protection, error analysis, interface improvement, and confirmation of User actions.

7.2. Technical data may include IP address, user-agent, device type, browser, operating system, language, approximate region by IP, visit time, referral source, clicks, form actions, errors, Order statuses, and other events necessary for security and operation of the service.

7.3. The User may restrict cookies in browser settings, but in this case some website, personal account, Order creation, fraud protection, or status display functions may work incorrectly.

7.4. The Service may use depersonalized or aggregated analytics if such information does not allow identification of a specific User without the use of additional information.

8

Transfer to Third Parties

8.1. The Service may transfer personal data to third parties only to the extent necessary for the purposes of this Policy, execution of the Order, security, AML / KYC / SoF, refund, dispute resolution, compliance with law, or protection of the rights of the parties.

8.2. Data may be transferred to hosting providers, data centers, email, chat, notification, CRM, anti-fraud tool, AML analyzer, blockchain analytics providers, legal consultants, auditors, partners, monitoring platforms, banks, payment systems, exchanges, wallet providers, and other persons involved in the review, execution, or settlement of the operation.

8.3. AML analyzers and blockchain analytics tools usually receive digital currency addresses, TxID, network, amount, risk labels, and technical review parameters. Identity documents and KYC / SoF materials are transferred to such persons only when necessary and where there is a legal basis.

8.4. Upon a request from a monitoring platform, bank, payment system, partner, or competent authority, the Service may provide information necessary to review a specific situation in a scope that does not disclose unnecessary personal data of other Users and does not create an unjustified risk to infrastructure security.

8.5. When transferring data to processors acting on instruction, the Service takes reasonable measures to ensure that such persons process data only for its intended purpose, maintain confidentiality, and apply necessary protection measures.

8.6. The Service does not disclose personal data of another User, partner, recipient, sender, or employee without a legal basis, request from a competent authority, court act, monitoring platform rules, or the need to protect the rights of the parties within applicable law.

9

Cross-Border Transfer and Storage

9.1. Due to the use of infrastructure, communication, analytics, email, anti-fraud, AML, chat services, or other contractors, certain data may be transferred or become accessible outside the Russian Federation if this is necessary for the operation of the Service, review of the operation, communication with the User, or protection of the rights of the parties.

9.2. Cross-border transfer of personal data is carried out only in compliance with applicable law, including assessment of the admissibility of transfer, notification of the authorized body where required, and application of reasonable protection measures.

9.3. With respect to the personal data of citizens of the Russian Federation, the Service complies with database localization requirements in the cases and within the limits provided by the laws of the Russian Federation.

9.4. If the use of a specific foreign service, payment infrastructure, AML tool, monitoring platform, or communication channel is impossible without transferring certain data outside the Russian Federation, the User understands that refusal of such transfer may limit the ability to create, execute, review, or settle an Order.

10

Retention Periods and Deletion

10.1. Data related to Orders, payments, payment details, technical logs, correspondence, and requests is stored for the period necessary to execute the Order, make a refund, resolve disputes, protect against fraud, and interact with monitoring platforms, banks, payment systems, partners, and competent authorities, but usually not less than 36 months from the date of completion of the Order.

10.2. KYC / SoF materials, identity checks, ownership of payment details, source of funds, AML-Hold, disputed operations, and claims may be stored for up to 5 years, unless a longer period is required by law, dispute, request from a competent authority, partner rules, or the need to protect the rights of the parties.

10.3. If there remains a risk of proceedings related to an Order, payment, refund, payment reversal, AML-Hold, complaint, claim, monitoring platform request, or court dispute, the retention period may be extended until final resolution of the situation and expiration of a reasonable period for protecting the rights of the parties.

10.4. Upon achievement of the processing purposes or loss of the need for storage, data is deleted, destroyed, or depersonalized unless otherwise required by law, contract, dispute, security, or protection of the rights of the Service and Users.

10.5. Backups and technical archives may retain data for a technologically necessary period until scheduled updating or deletion of such copies, provided that access is restricted and protection measures are applied.

11

Data Security

11.1. The Service applies legal, organizational, and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution, and other unlawful actions.

11.2. Data transmission on the website is carried out using secure connections if this is supported by the User and website infrastructure. Access to review materials and disputed operation materials is restricted to authorized persons on a need-to-access basis.

11.3. The Service may apply access rights separation, action logging, session control, backups, internal data processing rules, antivirus and network protection, encryption, or other measures corresponding to the nature and risk of processing.

11.4. Employees, representatives, and contractors who receive access to personal data must use it only for work purposes and maintain confidentiality.

11.5. The User must independently ensure the security of their device, email, Telegram, personal account, banking apps, wallets, passwords, and other access tools. The Service is not responsible for the consequences of the User transferring data to fraudsters, fake accounts, or third parties outside the official channels of the Service.

11.6. If a security incident is identified, the Service takes reasonable measures to localize it, eliminate consequences, restore data, and notify persons or authorities in cases where such notification is required by law.

12

User Rights

12.1. The User has the right to request information about the processing of personal data, purposes, legal grounds, processing methods, data composition, storage periods, persons to whom data may be disclosed, and other information provided by applicable law.

12.2. The User has the right to request correction, blocking, or destruction of personal data if it is incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated processing purpose.

12.3. The User request must allow reliable identification of the applicant and the connection of the request with a specific Order, account, email, payment details, or other data. The Service may request additional confirmations if without them there is a risk of disclosing data to a third party.

12.4. A response to the request is sent within the timeframes provided by applicable law. If the request requires additional verification, the Service may extend the response period with a reasoned notice where this is permitted by law.

12.5. The Service may refuse deletion, blocking, or disclosure of data in whole or in part if this violates the rights of other persons, operation security, AML / KYC / SoF, confidentiality of the review, legal requirements, a court act, a request from a competent authority, or the need to protect the rights of the Service and Users.

12.6. Personal data requests should be sent to support@coindrop.trade or through the online chat on the website.

13

Final Provisions

13.1. The Service may change this Policy due to changes in legislation, operating model, infrastructure, partners, payment methods, AML / KYC / SoF procedures, security requirements, or user documents.

13.2. The new version of the Policy takes effect from the moment it is published on the website unless another effective date is specified in the new version. Orders created after publication of the new version are governed by the new version of the Policy.

13.3. The fact of acceptance of the Policy, document version, date and time of acceptance, IP address, email, Order number, Order parameters, checkbox mark, and technical actions of the User may be recorded in the Service logs and used to confirm the terms that were in effect at the moment of creation or processing of the Order.

13.4. If any provision of the Policy is found invalid or unenforceable, this does not affect the validity of the remaining provisions.

13.5. Current legal information is available on the page https://coindrop.trade/legal-information. The Rules and Terms of Exchange Operations are available on the page https://coindrop.trade/siterules. The AML / KYC / SoF Policy is available on the page https://coindrop.trade/kycaml-policy.

13.6. For questions related to personal data processing, the User may contact Support at support@coindrop.trade or through the online chat on the website.