CMVCRYPTO MARKET VIEW
Sign in

Legal

Privacy & cookie policy

This policy explains what personal data CryptoMarketView (“CMV”, “we”, “us”) collects when you use our website and mobile apps, how we use it, and what choices you have. Last updated: 31 August 2026.

Overview

CMV is a crypto charting and watchlist service. We collect the minimum data needed to run your account, sync your watchlists, and deliver live market data. We do not sell your personal data, and we do not use advertising or third-party analytics trackers on the website.

You can use many chart and watchlist features without creating an account. When you do sign in, we store account details on our servers and cache preferences in your browser or device so the app feels fast and familiar.

Who we are

The data controller for CMV is CryptoMarketView, operating at cryptomarketview.space. For privacy questions or to exercise your rights, contact us at privacy@cryptomarketview.space.

Data we collect

Account and profile data

When you create an account or sign in, we may collect:

  • Email address and display name when you register with email and password.
  • Password — stored only as a one-way hash; we never store your password in plain text.
  • Sign-in method metadata — for example whether you use email, passkey, TOTP two-factor authentication, or a social provider (Google, Microsoft, or Apple).
  • Passkey credentials — public key material, credential identifiers, and related WebAuthn metadata needed to verify your passkey.
  • TOTP secret — if you enable an authenticator app for two-factor authentication.
  • External login identifiers — a provider-specific subject ID and the name and email returned by that provider when you use social sign-in.

Watchlists and saved content

If you are signed in, watchlist names, sort order, and the trading pairs you add (for example binance:BTCUSDT) are stored on our servers and synced across your devices. Chart layout APIs exist on our backend, but chart indicators, drawings, and viewport preferences are currently stored locally in your browser or device until full layout sync is enabled in the clients.

Browser and device storage

We use localStorage on the web (and equivalent on-device storage in our mobile apps) to remember your session, theme, watchlist cache, and chart preferences. See the Cookies & storage section for a full list.

Market data usage

Live prices, candles, and instrument metadata come from public exchange feeds. Requesting market data does not require an account. Our market-data gateway may assign an anonymous session identifier for WebSocket connections; it is not linked to your CMV account.

Technical and security data

  • IP address — used for rate limiting, abuse prevention, and protecting sign-in endpoints. IP-based counters are held in Redis with short TTLs.
  • Server and application logs — request metadata, errors, and operational telemetry (via OpenTelemetry) to keep the service reliable. These logs are not used for advertising or behavioural profiling.
  • Hosting logs — our website host (Vercel) and cloud provider (Microsoft Azure) generate standard access and infrastructure logs.

Data we do not collect

  • We do not run Google Analytics, Meta Pixel, or similar advertising trackers.
  • We do not collect payment card or banking details — CMV is free to use.
  • We do not read your private exchange accounts or wallet balances; we only display public market data.

How we use your data

We use personal data to:

  • Create and authenticate your account.
  • Send transactional emails such as address verification (via Resend).
  • Sync watchlists and related account settings across devices.
  • Remember your theme and chart preferences on your device.
  • Protect the service against abuse, credential stuffing, and fraud.
  • Operate, debug, and improve reliability of our APIs and infrastructure.
  • Comply with legal obligations and respond to lawful requests.

We do not use your data for targeted advertising or sale to data brokers.

Cookies & browser storage

CMV does not set first-party HTTP cookies for authentication or tracking. Your signed-in session is stored in browser localStorage and sent to our API as a Bearer token. We do set one small cookie, cmv-consent-required, to remember whether your region requires a consent notice (set by our edge middleware from your country code).

Local storage on the website

  • cmv.auth.session — access token, user ID, display name, email, and expiry (signed-in users only).
  • cmv.watchlists.v3.<userId> — cached watchlist snapshot for faster load and offline resilience.
  • cmv.theme — light or dark theme preference.
  • cmv.chartTimeframe.v1, cmv.chartIndicators.v1, cmv.chartViewport.v1, cmv.chartLineDrawings.v2, cmv.chartPriceLines.v1, cmv.chartPriceScaleMode.v1, cmv.drawingStyle.v1 — chart UI state on your device.
  • cmv.privacy.consent — records that you accepted this notice (where shown).

Third-party cookies and scripts

If you choose Sign in with Google or Microsoft, those providers may load their own scripts and set cookies on their domains to complete authentication. We receive only the identity information contained in the token they return to us. Apple Sign In follows the same pattern when enabled.

Our website requests asset logos and market-cap metadata from CoinGecko using only public asset symbols (for example BTC, ETH) — not your account details.

Managing storage

You can clear site data in your browser settings, which signs you out and resets local preferences. To remove server-side account data, contact us or delete your account when that option is available in account settings.

Third-party service providers

We share data only with processors that help us run CMV:

  • Microsoft Azure — hosts our user API, SQL database, market-data gateway, Redis, and related infrastructure in the cloud.
  • Vercel — hosts the public website and edge middleware.
  • Resend — delivers verification and other transactional email to your address.
  • Google, Microsoft, Apple — when you use their sign-in buttons; each provider's privacy policy applies to their processing.
  • CoinGecko — receives asset symbol queries for icons and market-cap labels shown in the UI.
  • Crypto exchanges (Binance, Kraken, Coinbase, Bybit, KuCoin, Bitstamp, and related public data sources) — provide anonymous market data only; no user account data is sent to them.

We do not authorise these providers to use your personal data for their own marketing.

How long we keep data

  • Account data — kept while your account is active and for a reasonable period afterward to handle disputes, security investigations, and legal requirements.
  • Email verification tokens — stored as hashes until used or expired.
  • Rate-limit and abuse counters — short-lived entries in Redis, typically minutes to hours.
  • Server logs — retained according to our cloud logging configuration, generally rolling off after a limited period unless needed for an incident.
  • Local browser storage — remains on your device until you clear it or uninstall the app.

Security

Passwords are hashed with industry-standard algorithms. API access uses HTTPS and short-lived JWT access tokens. Passkeys and TOTP provide additional account protection. We apply rate limiting and lockouts on authentication endpoints. No method of transmission or storage is completely secure; please use a strong, unique password and enable two-factor authentication where available.

International transfers

CMV uses cloud providers that may process data in the European Union, the United States, and other countries where they maintain facilities. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms for transfers outside your country.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate account information (display name and email in account settings).
  • Delete your account and associated data.
  • Restrict or object to certain processing.
  • Export your data in a portable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise these rights, email privacy@cryptomarketview.space. We may need to verify your identity before responding.

Children

CMV is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this policy when our practices or legal requirements change. We will post the revised version on this page and update the “Last updated” date. For material changes affecting how we use personal data, we may provide additional notice in the product or by email.

Contact

Questions about this policy or your personal data: privacy@cryptomarketview.space

Product help (not data-protection requests): see our Help centre.

Investment disclaimer

CMV displays live market prices and charting tools for information only. Nothing on this service constitutes investment, financial, legal, or tax advice, or a recommendation to buy or sell any asset.