Privacy Policy
A short, plain description of what ReChange collects, why, and how long we keep it.
1. Who we are
[ReChange Labs OU], registered in [jurisdiction] under number [registration number], is the controller of the personal data described here. Contact us at [privacy@rechange.pro].
This policy covers the ReChange website, dashboard and API. It does not cover the websites of merchants who use ReChange, or public blockchains.
2. What we collect
Only what the product actually needs:
3. What we don't collect
- No advertising or analytics trackers, and no tracking pixels.
- No card numbers or bank details — we never touch fiat rails.
- No phone number.
- No profile picture. Google offers us one during sign-in; we discard it.
- We do not sell personal data, and we do not share it for advertising.
4. Cookies and local storage
We set two cookies, both strictly necessary, so no consent banner is required:
rechange_session
Keeps you logged in. HttpOnly, SameSite=Lax. 30 days or until you log out
rechange_oauth
One-time anti-forgery value protecting Google sign-in. 10 minutes
Your browser also stores rechange-theme and rechange-lang in local storage to remember your preferences. These never leave your device.
Our pages load fonts from Google Fonts, which means Google receives your IP address when a page loads.
5. Why we use it
We do not send marketing email unless you ask for it, and you can stop it at any time.
6. Who we share with
Some providers are outside your country. Where personal data leaves the EEA or the UK, we rely on adequacy decisions or standard contractual clauses.
7. Blockchain data is public
8. How long we keep it
9. Security
- Passwords are hashed with bcrypt. We cannot read them.
- Session tokens and API keys are stored only as hashes.
- Session cookies are HttpOnly, SameSite=Lax, and Secure over HTTPS.
- Google sign-in is protected by a one-time anti-forgery value.
- Access to production data is limited to staff who need it.
No system is perfectly secure. Report anything you find to [security@rechange.pro].
10. Your rights
Depending on where you live, you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere. Write to [privacy@rechange.pro] and we will respond within 30 days.
AML law requires us to keep transaction and verification records for 5 years, so a deletion request will not clear those.
11. Changes and contact
We will update the version and date at the top of this page when it changes.
Related: Terms of Service · AML & KYC Policy