XExchange Privacy Policy
Effective date: September 23, 2026
This Privacy Policy describes the categories of information XExchange may process when a user visits xexchange.io, creates a crypto-to-crypto exchange order, contacts support or makes a privacy request.
XExchange is designed around a transaction-based service model rather than a persistent trading account. That reduces some account-level data requirements, but it does not mean that no information is processed or that blockchain activity becomes private.
Information Associated with an Exchange Order
To create, process and support an exchange, XExchange may process transaction-related information such as:
- order ID;
- selected source and destination assets;
- selected source and destination networks;
- amount entered for the order;
- deposit and destination wallet addresses;
- blockchain transaction hashes;
- order status and timestamps;
- quote or route information associated with the order;
- additional destination fields such as a tag or memo when the route requires them.
This information is used to execute the transaction, track its status, investigate errors and provide support.
Blockchain Data
Wallet addresses and transaction hashes can be public information when they are recorded on a transparent blockchain.
XExchange may use blockchain data to:
- detect deposits;
- monitor confirmation status;
- verify transaction details;
- identify a payout transaction;
- investigate a support request;
- apply security or compliance controls.
XExchange cannot remove transaction records that a public blockchain stores by design.
For a general explanation, see Crypto Privacy and Blockchain Transactions.
Support and Communication Data
When a user contacts XExchange, the service may process the information included in the message.
This can include:
- email address;
- order ID;
- transaction hash;
- description of the issue;
- screenshots or technical details voluntarily supplied by the user;
- correspondence required to resolve the request.
Users should not send seed phrases, private keys, wallet passwords or authentication codes. These are not required for legitimate XExchange support.
Technical and Security Data
XExchange may process limited technical information needed to operate, secure and troubleshoot the service.
Depending on the implementation, this can include:
- IP address;
- request timestamps;
- browser or device information;
- security and anti-abuse logs;
- error and performance logs;
- session or request identifiers.
The site should collect only technical data that has an operational, security or abuse-prevention purpose.
Cookies and Similar Technologies
XExchange may use strictly necessary cookies or similar storage when required for site or session functionality.
Analytics, advertising or other optional tracking should only be used if it is actually implemented and disclosed through the appropriate site controls.
This policy does not claim that optional analytics or advertising cookies are in use when they have not been implemented.
Why XExchange Processes Information
Information may be processed for purposes such as:
- creating and executing exchange orders;
- showing order status;
- detecting source transactions and confirmations;
- sending the payout to the destination selected by the user;
- providing transaction support;
- preventing fraud, abuse or technical attacks;
- applying risk-based transaction review when required;
- maintaining service reliability and troubleshooting errors;
- responding to privacy, compliance or security requests.
XExchange should not collect information simply because it might be useful later without a defined service purpose.
Service Provider Categories
XExchange may rely on service-provider categories needed to operate the website and exchange process, such as:
- hosting and infrastructure providers;
- network or blockchain infrastructure;
- transaction-processing or liquidity infrastructure;
- email or support infrastructure;
- security and anti-abuse services.
This policy does not name a specific vendor unless that relationship has been confirmed and is relevant to the final implementation.
Retention
XExchange retains information only for as long as reasonably necessary for the purpose for which it was processed, including transaction execution, support, security, fraud prevention, compliance review and operational recordkeeping.
The service does not publish an exact universal retention period because different categories of information can have different operational requirements.
Data that is stored on a public blockchain is outside the normal deletion model of a website database and may remain publicly available according to that blockchain’s design.
Security Handling
XExchange should limit access to operational data to the systems and people that require it for the relevant service function.
Security practices should focus on:
- minimizing unnecessary sensitive data;
- protecting support and operational access;
- using transaction identifiers rather than wallet secrets;
- monitoring abuse and suspicious activity;
- avoiding collection of seed phrases or private keys.
No website can promise that every technical or security risk is impossible.
Privacy Requests
Privacy questions or requests can be sent to [email protected].
If the request concerns a specific exchange order, include the order ID or relevant transaction hash so the service can identify the correct record without requesting wallet secrets.
A response may require enough information to verify that the request relates to the relevant service interaction.
Compliance Data
Some transaction information may also be processed for risk-based AML or security review when required.
The XExchange AML Policy describes the transaction-review model. Information collected for compliance review should remain limited to what is necessary for that review and the related service obligations.
Public Blockchain Visibility
A privacy-focused exchange cannot make every source or payout transaction invisible.
When a route uses a transparent blockchain, addresses, transaction hashes, amounts, timestamps and transaction history may be publicly inspectable.
The absence of a persistent XExchange account does not remove the underlying blockchain record.
Contact
Privacy requests: [email protected]
General support: [email protected]
Security reports: [email protected]
See XExchange Contacts for guidance on what information to include.
FAQ
Does XExchange create a permanent trading account for every user?
The standard service model is transaction-based and does not require a persistent trading account.
What order information can XExchange process?
Order IDs, selected assets and networks, amounts, wallet addresses, transaction hashes, status information and other data needed to execute or support the transaction can be processed.
Are wallet addresses and transaction hashes personal data?
They can be public blockchain identifiers and may also become associated with a person through other information. XExchange therefore treats them as transaction data that should not be exposed unnecessarily.
Does XExchange use cookies?
Strictly necessary storage may be used where required by site functionality. Optional analytics or advertising cookies should only be used if actually implemented and disclosed.
How long is information kept?
Information is retained only as long as reasonably necessary for its service, support, security, compliance or operational purpose. XExchange does not state one invented universal retention period.
Can XExchange delete blockchain transactions?
No. Confirmed transactions stored by a public blockchain are governed by that network and cannot be removed from the ledger by XExchange.
How can I make a privacy request?
Email [email protected] with enough information to identify the relevant service interaction. Never send a seed phrase or private key.