Privacy Policy

Effective date: August 11, 2026

1. Who we are

Coinomatic (“we”) provides rule-based crypto-to-fiat automation that runs against your own exchange account. Contact: info@coinomatic.io.

2. Data we collect today

  • Cookie preference — your consent choice is stored in your browser (localStorage), not on our servers.

The marketing site does not run analytics or advertising trackers. If analytics are introduced, they will load only after consent and this policy will be updated first.

3. Data the product processes

  • Account data — your account identifier, email address, and registration and authentication records.
  • Workspace and automation data — workspace settings, exchange connection details, and the automation rules and limits you configure.
  • Activity data — execution logs, transaction history, notifications, and export requests used to operate the service and show your account history.
  • Exchange credentials — the API credentials you submit to connect your exchange account. Credentials are protected by encryption at rest and access controls. After submission, plaintext credentials are not returned to the browser or written to logs, metrics, executions, transactions, or exports.
  • Billing data — plan, subscription, customer, and payment-status records. Stripe processes payment-card and payment-method details; Coinomatic does not store full card details.
  • Support data — messages you send to support and the sanitized account context used to answer them.

4. Sharing and processors

We disclose data only as needed to operate Coinomatic, follow your instructions, protect the service, or comply with law. Our service providers are Vercel for marketing-site hosting; Amazon Web Services for authentication, application hosting, storage, platform logging, and transactional email; Stripe for checkout, subscriptions, and payments; and OpenRouter for hosted AI-assisted support conversations. Support context is sanitized before it is sent to the hosted support provider, and exchange credentials are excluded. When an automation runs, Coinomatic sends the requested API operation to the exchange you connected.

We do not sell personal data or share it for cross-context behavioral advertising.

5. Retention and deletion

In production, operational records, execution history, and transaction data are retained for up to 90 days. Generated export artifacts are available for up to seven days. Platform logs are retained for up to 14 days. Exchange credentials are retained until you disconnect the exchange or delete your account. Account and subscription records are retained while needed to provide the service and for legitimate security, fraud-prevention, billing, dispute, and legal-record purposes.

To request account or personal-data deletion, email info@coinomatic.io. We may verify your identity before acting on a request. Deletion may not immediately remove data from backup systems, and we may retain limited records where required by law or needed to establish or defend legal claims.

6. Your rights

California residents may have rights under the CCPA, as amended by the CPRA, to know and access the personal information we collect, request deletion, request correction of inaccurate information, and receive equal service and pricing without discrimination for exercising those rights. Coinomatic does not sell personal information or share it for cross-context behavioral advertising.

Submit a request to info@coinomatic.io. Describe the request and the email address associated with your account. We will verify and respond to requests as required by applicable law.