Privacy Policy

Last updated: September 18, 2026

This policy describes what CryptoMint stores, why, and what you can ask us to do about it. It describes the service as it is actually built — not a generic template.

1. What we store

There is no sign-up form, so we hold less than you might expect. Specifically:

  • ●Your wallet address, which is your account identifier.
  • ●The orders and bids you place: the address you bought, the amount, the currency, the network, the transaction hash you paid with, and timestamps.
  • ●In-app notifications we send you about your orders and auctions.
  • ●For addresses you generated yourself and chose to list for sale: the private key, encrypted (see section 3). We cannot read it without the encryption key, and the encryption key is held separately from the database.
  • ●For free claims: on-chain activity is checked so that free claims can be rate-limited.
  • ●Operational records of administrative actions, so that delivery re-issues and other privileged operations can be audited.

2. What we do not store

  • ●No passwords — there are none. Logging in is a wallet signature.
  • ●No email address, unless you choose to give us one when contacting support.
  • ●No payment card details. We never receive them; payment happens on-chain.
  • ●No plaintext private key for addresses you generated in your browser and did not list for sale. Those keys never leave your device.
  • ●No third-party analytics, advertising, or behavioural tracking scripts. There is no Google Analytics, no ad pixel, and no session recording on this site.

3. How private keys are protected

Where a private key has to be held so that a purchased address can be delivered, it is encrypted with AES-256-GCM under a per-key data key, and that data key is itself encrypted under a master key kept outside the database.

Delivery happens through a single-use link. After the key has been shown to you, the link cannot be claimed again.

4. Data stored in your browser

We use your browser's local storage for two things, and nothing else:

  • ●"token" — your session, so you do not have to sign a message on every page.
  • ●"cryptomint.locale" — your language preference, so we do not reset it on every visit.
  • ●We do not set third-party cookies and we do not track you across other sites. Clearing your browser storage signs you out and resets the language to your browser default.

5. Blockchains are public

Payments and address balances live on public blockchains. Transaction hashes, sender and recipient addresses, and amounts are visible to anyone, permanently, and we cannot remove or alter them. That is a property of the networks, not something we control.

6. Why we are allowed to process this

We process the data above to perform the contract you enter into when you place an order or bid, and for our legitimate interest in keeping the service working and free of abuse. Where we rely on your consent — such as your language preference — you can withdraw it at any time by clearing that setting.

7. How long we keep it

Orders, bids, and the audit trail are kept while your account exists and afterwards as long as needed for accounting, dispute resolution, and legal obligations. Encrypted private keys are retained after delivery so that a delivery link can be re-issued if you lose yours; they remain encrypted throughout.

8. Your choices

  • ●You can ask us what we hold about your wallet address, and ask us to correct or delete it.
  • ●Deletion removes the account record, orders, and bids. It cannot remove anything already written to a public blockchain — nobody can.
  • ●Deleting your account may make it impossible to re-issue a delivery link for a key you have lost.
  • ●To make any of these requests, write to dcsoceo@gmail.com from a channel where you can also prove control of the wallet address in question.

9. Sharing

We do not sell personal data and we do not share it for advertising. We use infrastructure providers — a hosting and edge-computing provider, and public blockchain nodes — which necessarily process requests on our behalf. We disclose data where the law requires it.

10. Contact

Privacy questions and data requests: dcsoceo@gmail.com.