Skip to main content

ZIPMEX PRIVACY POLICY

Last Updated: 02.04.2026
Supplement E to the ZIPMEX Terms of Service
THIS PRIVACY POLICY DESCRIBES HOW THE ZIPMEX INTERFACE COLLECTS, USES, STORES, SHARES, AND PROTECTS INFORMATION IN CONNECTION WITH YOUR USE OF THE INTERFACE LOCATED AT https://trade.zipmex.com. BY ACCESSING OR USING THE INTERFACE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.
INTRODUCTION
1.1 Who We Are
This Privacy Policy is issued by the contributors and maintainers of the ZIPMEX interface ("Operator," "we," "us," or "our"). We act as the data controller with respect to the personal data we process through the Interface. For data protection inquiries, contact us at: [email protected]
1.2 Scope
This Privacy Policy applies to all personal data collected through or in connection with the Interface. It does not apply to:
(a) data collected by third-party Protocols, wallet providers, blockchain networks, or other services you interact with through the Interface — these are governed by their own privacy policies;
(b) data publicly recorded on blockchain networks, which is outside our control (see Section 7); or
(c) data collected by other websites or services linked from the Interface.
1.3 Applicable Law
We process personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and other applicable privacy laws in jurisdictions where Users access the Interface.---

DATA WE COLLECT
2.1 Data You Provide
We collect the following data when you voluntarily provide it:
(a) Wallet address — your public blockchain wallet address, collected when you connect your wallet to the Interface;
(b) Self-certification data — representations you make when accepting Terms of Service, including confirmation of age, jurisdiction, and eligibility;
(c) Communications — any information you provide when contacting us via email or other channels;
(d) Access restriction requests — if you request to be blocked from certain services or features of the Interface.
2.2 Data Collected Automatically
When you access or use the Interface, we may automatically collect:
(a) IP address — used for geolocation, compliance with geographic restrictions, and security purposes. We may truncate or anonymize IP addresses after initial processing;
(b) Device and browser information — device type, operating system, browser type and version, screen resolution, and language preferences;
(c) Usage data — pages visited, features accessed, actions taken (e.g., swap initiated, position opened), timestamps, referring URLs, and session duration;
(d) Performance data — page load times, errors, and technical diagnostics.
2.3 Data from Third Parties
We may receive data from the following third-party sources:
(a) Blockchain analytics providers — wallet risk scores, sanctions screening results, and transaction pattern analysis used for compliance purposes;
(b) Geolocation services — IP-based geographic location data used to enforce geographic restrictions;
(c) VPN and proxy detection services — data indicating whether a connection originates from a VPN, proxy, Tor node, or datacenter IP; and
(d) Publicly available blockchain data — transaction history, wallet balances, and smart contract interactions recorded on public blockchain networks.
2.4 Data We Do NOT Collect
We do not collect:
(a) your name, physical address, phone number, or government-issued identification;
(b) your email address (unless you voluntarily contact us);
(c) your private keys, seed phrases, or wallet passwords;
(d) your bank account or credit card information; or
(e) biometric data.

HOW WE USE YOUR DATA
3.1 Purposes and Legal Bases
We process personal data for the following purposes:
Purpose Data Used Legal Basis (GDPR)
Providing the Interface Wallet address, usage data Performance of contract (Art. 6(1)(b))
Geographic restriction enforcement IP address, geolocation Legitimate interest (Art. 6(1)(f))
Sanctions and compliance screening Wallet address, blockchain analytics Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f))
VPN and circumvention detection IP address, connection metadata Legitimate interest (Art. 6(1)(f))
Security and fraud prevention IP address, device info, usage patterns Legitimate interest (Art. 6(1)(f))
Interface improvement and analytics Anonymized usage data, performance data Legitimate interest (Art. 6(1)(f))
Responding to inquiries Communications data Legitimate interest (Art. 6(1)(f)) or consent (Art. 6(1)(a))
Legal compliance All data as required Legal obligation (Art. 6(1)(c))
Access restriction enforcement Wallet address, request data Legitimate interest (Art. 6(1)(f))
3.2 Legitimate Interest Assessment
Where we rely on legitimate interest as a legal basis, we have conducted a balancing assessment and determined that our legitimate interests (compliance with sanctions laws, prevention of unauthorized access, security of the Interface, and improvement of services) are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 8).

COOKIES AND TRACKING TECHNOLOGIES
4.1 Cookies
The Interface may use strictly necessary cookies to maintain session state and enforce security measures. We do not use advertising cookies, tracking cookies, or third-party marketing cookies.
4.2 Analytics
We may use privacy-focused analytics services to collect anonymized or aggregated usage data for the purpose of improving the Interface. Where analytics tools are used, they process only anonymized or aggregated data that does not identify individual users and do not set tracking cookies. We do not use Google Analytics or other analytics services that create detailed user profiles or require cookie consent under applicable law.
4.3 Local Storage
The Interface may use browser local storage to save your preferences (e.g., display settings, slippage tolerance, accepted terms version). This data is stored locally on your device and is not transmitted to the Operator.---

DATA SHARING AND DISCLOSURE
5.1 Third-Party Service Providers
We may share personal data with the following categories of third-party service providers who process data on our behalf:
(a) Blockchain analytics providers — for wallet sanctions screening and compliance (e.g., services that screen wallet addresses against OFAC SDN lists and other sanctions databases);
(b) Geolocation and VPN detection providers — for enforcement of geographic restrictions;
(c) Infrastructure providers — hosting, CDN, and security services (e.g., Cloudflare); and
(d) Communication providers — if you contact us via email or other channels.
All third-party service providers are contractually obligated to process personal data only on our instructions and in accordance with applicable data protection laws.
5.2 Legal and Regulatory Disclosure
We may disclose personal data if required by law, regulation, legal process, or governmental request, including:
(a) response to valid subpoenas, court orders, or legal proceedings;
(b) compliance with regulatory requests from financial regulators, law enforcement agencies, or sanctions authorities;
(c) protection of the rights, property, or safety of the Operator, Users, or third parties; and
(d) enforcement of these Terms.
5.3 No Sale of Personal Data
We do not sell, rent, lease, or trade your personal data to third parties for monetary or other valuable consideration.
5.4 Blockchain Disclosure
When you initiate a transaction through the Interface, your wallet address and transaction details are permanently and publicly recorded on the applicable blockchain network. This data is not shared by us — it is inherent to the operation of public blockchain technology. See Section 7 for more information.---

DATA RETENTION
6.1 Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Data Category Retention Period
Wallet addresses (for sanctions screening) Duration of use + 5 years
IP addresses (raw) 90 days, then anonymized
Usage and analytics data (anonymized) 2 years
Communications data 2 years from last interaction
Access restriction records Indefinite (to enforce restrictions)
Legal compliance records As required by applicable law
6.2 Anonymization
Where possible, we anonymize or pseudonymize personal data after the applicable retention period expires. Anonymized data that can no longer be linked to an identifiable individual is not subject to this Privacy Policy.
BLOCKCHAIN DATA
7.1 Public Nature of Blockchain
You acknowledge that blockchain networks (including Solana, Ethereum, and other networks accessible through the Interface) are public, transparent, and immutable. When you execute a transaction through the Interface, the following data is permanently and publicly recorded on the blockchain:
(a) your wallet address;
(b) the transaction details (amounts, token addresses, smart contract interactions);
(c) the timestamp of the transaction; and
(d) any data embedded in the transaction payload.
7.2 Immutability
Blockchain data cannot be modified, deleted, or erased after it has been confirmed on the network. This is a fundamental property of blockchain technology and is not within the control of the Operator or any other party.
7.3 Pseudonymous Nature
Wallet addresses are pseudonymous identifiers. While a wallet address does not directly reveal your identity, it may be linked to your identity through blockchain analytics, exchange KYC records, social media disclosures, or other means. We strongly recommend that you understand the privacy implications of using public blockchain networks before using the Interface.
7.4 GDPR Right to Erasure and Blockchain
Under GDPR Article 17, data subjects have the right to request erasure of personal data ("right to be forgotten"). However, we cannot erase data that has been recorded on public blockchain networks because:
(a) we do not control the blockchain infrastructure;
(b) blockchain data is immutable by design; and
(c) erasure of on-chain data is technically impossible.
We can erase personal data that we hold in our own systems (e.g., IP addresses, usage logs, communications). If you exercise your right to erasure, we will delete all personal data within our control, but we cannot delete data recorded on the blockchain. We will inform you of this limitation when processing your request.---

YOUR RIGHTS
8.1 Rights Under GDPR and UK GDPR
If you are located in the European Economic Area ("EEA"), European Union ("EU"), or the United Kingdom ("UK"), you have the following rights under applicable data protection law:
(a) Right of access (Art. 15) — you have the right to request confirmation of whether we process your personal data and to obtain a copy of such data;
(b) Right to rectification (Art. 16) — you have the right to request correction of inaccurate personal data;
(c) Right to erasure (Art. 17) — you have the right to request deletion of your personal data, subject to the blockchain limitations described in Section 7.4;
(d) Right to restriction (Art. 18) — you have the right to request restriction of processing in certain circumstances;
(e) Right to data portability (Art. 20) — you have the right to receive your personal data in a structured, commonly used, machine-readable format;
(f) Right to object (Art. 21) — you have the right to object to processing based on legitimate interest, including for direct marketing purposes;
(g) Right to withdraw consent (Art. 7) — where processing is based on consent, you have the right to withdraw consent at any time; and
(h) Right to lodge a complaint — you have the right to lodge a complaint with a supervisory authority in your country of residence.
8.2 How to Exercise Your Rights
To exercise any of the above rights, contact us at: [email protected]
We will respond to your request within thirty (30) days. We may request additional information to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.
8.3 Rights Under Other Jurisdictions
If you are located in a jurisdiction with data protection laws that provide additional rights (e.g., California Consumer Privacy Act, Brazil LGPD, Switzerland FADP), you may exercise equivalent rights by contacting us at the address above.

INTERNATIONAL DATA TRANSFERS
9.1 Transfer Mechanisms
Your personal data may be transferred to and processed in countries outside your country of residence, including countries that may not provide an equivalent level of data protection. Where we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, including:
(a) transfers to countries recognized by the European Commission as providing adequate data protection;
(b) Standard Contractual Clauses approved by the European Commission; or
(c) other lawful transfer mechanisms under applicable data protection law.
9.2 Blockchain Transfers
Transaction data recorded on public blockchains is accessible globally and is not subject to traditional data transfer restrictions. By using the Interface and executing blockchain transactions, you acknowledge that your transaction data will be publicly available worldwide.

DATA SECURITY
10.1 Security Measures
We implement reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:
(a) encryption of data in transit (TLS/SSL);
(b) access controls limiting personnel access to personal data on a need-to-know basis;
(c) regular review of data processing practices; and
(d) use of security-focused infrastructure providers.
10.2 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, the Operator will notify the relevant supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, the Operator will also notify affected data subjects without undue delay, in accordance with GDPR Article 34, unless one of the exceptions in Article 34(3) applies.
10.3 No Guarantee
Despite our efforts, no method of electronic transmission or storage is 100% secure. We cannot guarantee the absolute security of your personal data. You acknowledge that the transmission of information over the internet is inherently insecure and that we cannot guarantee the security of data transmitted to or from the Interface.

CHILDREN
The Interface is not directed at, and we do not knowingly collect personal data from, individuals under the age of eighteen (18). If you are under eighteen (18) years of age, do not access or use the Interface. If we become aware that we have collected personal data from an individual under eighteen (18), we will take steps to delete such data promptly.

CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date at the top of this Policy and may provide additional notice through the Interface. Your continued use of the Interface after any modification constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.

DATA PROTECTION OFFICER
Given the nature and scale of our data processing activities, we have not appointed a formal Data Protection Officer ("DPO"). For all data protection inquiries, requests, or complaints, please contact:
Email: [email protected]
We will respond to all inquiries within thirty (30) days.

EU REPRESENTATIVE
If the Operator is not established in the EU but processes personal data of individuals in the EU, GDPR Article 27 may require the appointment of an EU representative. If this requirement applies, the Operator will designate an EU representative and update this Privacy Policy with their contact details. Until such designation, data protection inquiries from EU residents may be directed to: [email protected]

CONTACT
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact:
Email: [email protected]

© 2026 ZIPMEX. All rights reserved. This Privacy Policy is part of the ZIPMEX Terms of Service.