Legal
Privacy & cookie policy
This policy explains what personal data CryptoMarketView (“CMV”, “we”, “us”) collects when you use our website and mobile apps, how we use it, and what choices you have. Last updated: 31 August 2026.
Overview
CMV is a crypto charting and watchlist service. We collect the minimum data needed to run your account, sync your watchlists, and deliver live market data. We do not sell your personal data, and we do not use advertising or third-party analytics trackers on the website.
You can use many chart and watchlist features without creating an account. When you do sign in, we store account details on our servers and cache preferences in your browser or device so the app feels fast and familiar.
Who we are
The data controller for CMV is CryptoMarketView, operating at cryptomarketview.space. For privacy questions or to exercise your rights, contact us at privacy@cryptomarketview.space.
Data we collect
Account and profile data
When you create an account or sign in, we may collect:
- Email address and display name when you register with email and password.
- Password — stored only as a one-way hash; we never store your password in plain text.
- Sign-in method metadata — for example whether you use email, passkey, TOTP two-factor authentication, or a social provider (Google, Microsoft, or Apple).
- Passkey credentials — public key material, credential identifiers, and related WebAuthn metadata needed to verify your passkey.
- TOTP secret — if you enable an authenticator app for two-factor authentication.
- External login identifiers — a provider-specific subject ID and the name and email returned by that provider when you use social sign-in.
Watchlists and saved content
If you are signed in, watchlist names, sort order, and the trading pairs you add (for example binance:BTCUSDT) are stored on our servers and synced across your devices. Chart layout APIs exist on our backend, but chart indicators, drawings, and viewport preferences are currently stored locally in your browser or device until full layout sync is enabled in the clients.
Browser and device storage
We use localStorage on the web (and equivalent on-device storage in our mobile apps) to remember your session, theme, watchlist cache, and chart preferences. See the Cookies & storage section for a full list.
Market data usage
Live prices, candles, and instrument metadata come from public exchange feeds. Requesting market data does not require an account. Our market-data gateway may assign an anonymous session identifier for WebSocket connections; it is not linked to your CMV account.
Technical and security data
- IP address — used for rate limiting, abuse prevention, and protecting sign-in endpoints. IP-based counters are held in Redis with short TTLs.
- Server and application logs — request metadata, errors, and operational telemetry (via OpenTelemetry) to keep the service reliable. These logs are not used for advertising or behavioural profiling.
- Hosting logs — our website host (Vercel) and cloud provider (Microsoft Azure) generate standard access and infrastructure logs.
Data we do not collect
- We do not run Google Analytics, Meta Pixel, or similar advertising trackers.
- We do not collect payment card or banking details — CMV is free to use.
- We do not read your private exchange accounts or wallet balances; we only display public market data.
How we use your data
We use personal data to:
- Create and authenticate your account.
- Send transactional emails such as address verification (via Resend).
- Sync watchlists and related account settings across devices.
- Remember your theme and chart preferences on your device.
- Protect the service against abuse, credential stuffing, and fraud.
- Operate, debug, and improve reliability of our APIs and infrastructure.
- Comply with legal obligations and respond to lawful requests.
We do not use your data for targeted advertising or sale to data brokers.
Legal bases (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on:
- Contract — processing needed to provide the account, watchlist sync, and security features you sign up for.
- Legitimate interests — keeping the service secure, preventing abuse, and maintaining operational logs, balanced against your rights.
- Consent — where required for non-essential browser storage in your region, and when you choose optional sign-in providers that load their own scripts.
- Legal obligation — where we must retain or disclose information under applicable law.
How long we keep data
- Account data — kept while your account is active and for a reasonable period afterward to handle disputes, security investigations, and legal requirements.
- Email verification tokens — stored as hashes until used or expired.
- Rate-limit and abuse counters — short-lived entries in Redis, typically minutes to hours.
- Server logs — retained according to our cloud logging configuration, generally rolling off after a limited period unless needed for an incident.
- Local browser storage — remains on your device until you clear it or uninstall the app.
Security
Passwords are hashed with industry-standard algorithms. API access uses HTTPS and short-lived JWT access tokens. Passkeys and TOTP provide additional account protection. We apply rate limiting and lockouts on authentication endpoints. No method of transmission or storage is completely secure; please use a strong, unique password and enable two-factor authentication where available.
International transfers
CMV uses cloud providers that may process data in the European Union, the United States, and other countries where they maintain facilities. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms for transfers outside your country.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate account information (display name and email in account settings).
- Delete your account and associated data.
- Restrict or object to certain processing.
- Export your data in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise these rights, email privacy@cryptomarketview.space. We may need to verify your identity before responding.
Children
CMV is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this policy when our practices or legal requirements change. We will post the revised version on this page and update the “Last updated” date. For material changes affecting how we use personal data, we may provide additional notice in the product or by email.
Contact
Questions about this policy or your personal data: privacy@cryptomarketview.space
Product help (not data-protection requests): see our Help centre.
Investment disclaimer
CMV displays live market prices and charting tools for information only. Nothing on this service constitutes investment, financial, legal, or tax advice, or a recommendation to buy or sell any asset.