ReChange
Exchange Privacy Policy FAQ Contacts
Sign in Get started
ReChange
Exchange Privacy Policy FAQ Contacts
Dark mode
Sign in Register

Privacy Policy

A short, plain description of what ReChange collects, why, and how long we keep it.

Version 1.0 Effective 31 August 2026

1. Who we are

[ReChange Labs OU], registered in [jurisdiction] under number [registration number], is the controller of the personal data described here. Contact us at [privacy@rechange.pro].

This policy covers the ReChange website, dashboard and API. It does not cover the websites of merchants who use ReChange, or public blockchains.

2. What we collect

Only what the product actually needs:

Email address, display name You, at registration — or from Google if you use Google sign-in
Password Stored only as a bcrypt hash. We cannot recover it
Google account identifier Google, if you sign in with Google
Session records Stored only as a hash. Generated when you log in
API keys Stored as a hash plus a short visible prefix. Generated when you create a key
Invoice records Amount, asset, network, deposit address, status, timestamps — created as you use the Service
Payout wallet Address and network, provided by you when you connect a wallet
Verification documents Where AML rules require them — see the AML Policy

3. What we don't collect

  • No advertising or analytics trackers, and no tracking pixels.
  • No card numbers or bank details — we never touch fiat rails.
  • No phone number.
  • No profile picture. Google offers us one during sign-in; we discard it.
  • We do not sell personal data, and we do not share it for advertising.

4. Cookies and local storage

We set two cookies, both strictly necessary, so no consent banner is required:

rechange_session Keeps you logged in. HttpOnly, SameSite=Lax. 30 days or until you log out
rechange_oauth One-time anti-forgery value protecting Google sign-in. 10 minutes

Your browser also stores rechange-theme and rechange-lang in local storage to remember your preferences. These never leave your device.

Our pages load fonts from Google Fonts, which means Google receives your IP address when a page loads.

5. Why we use it

Running your account, processing payments Performance of our contract
AML, fraud prevention, record keeping Legal obligation
Security, abuse prevention, debugging Legitimate interest
Service notices and support Contract and legitimate interest

We do not send marketing email unless you ask for it, and you can stop it at any time.

6. Who we share with

Google (if you use Google sign-in) Identifier, email, verified status and name
Hosting and infrastructure Whatever is technically necessary, under contract
Verification and analytics providers Where AML rules require checks
Regulators and law enforcement What the law compels us to disclose
A buyer or successor If the business is sold or reorganised

Some providers are outside your country. Where personal data leaves the EEA or the UK, we rely on adequacy decisions or standard contractual clauses.

7. Blockchain data is public

We cannot delete anything from a blockchain. Addresses and transactions are written to a public ledger that we do not control. Deleting your ReChange account does not remove them.

8. How long we keep it

Sessions Up to 30 days, or until you log out
Account data While your account is open
Transaction and verification records 5 years after the relationship ends (AML law)
API keys Until you revoke them

9. Security

  • Passwords are hashed with bcrypt. We cannot read them.
  • Session tokens and API keys are stored only as hashes.
  • Session cookies are HttpOnly, SameSite=Lax, and Secure over HTTPS.
  • Google sign-in is protected by a one-time anti-forgery value.
  • Access to production data is limited to staff who need it.

No system is perfectly secure. Report anything you find to [security@rechange.pro].

10. Your rights

Depending on where you live, you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere. Write to [privacy@rechange.pro] and we will respond within 30 days.

AML law requires us to keep transaction and verification records for 5 years, so a deletion request will not clear those.

11. Changes and contact

We will update the version and date at the top of this page when it changes.

Privacy and data rights [privacy@rechange.pro]
Security reports [security@rechange.pro]
Everything else [legal@rechange.pro]

Related: Terms of Service · AML & KYC Policy

ReChange

Instant crypto exchange. Swap between USDT, BTC, ETH, and TRX with real-time rates and low fees.

Exchange

Swap Rates Fees Limits

Company

About Careers

Legal

Terms Privacy AML policy
© 2026 ReChange Labs. All rights reserved. All systems operational