Legal
Privacy Policy
What we collect, why we collect it, and the control you have over your data.
Effective date: 4 July 2026
This Privacy Policy describes how CoinBeacon handles your personal data when you use our website and application. By using CoinBeacon, you agree to the practices described here.
1. Who we are
CoinBeacon (“CoinBeacon”, “we”, “us”) is a market-monitoring and alerting service for cryptocurrency markets. We are not an exchange, broker, custodian, or financial adviser. This policy explains what personal data we process when you use our website and application, and the choices you have.
If you have any questions about this policy or your data, contact us at support@coinbeacon.io.
2. Information we collect
Account data: the email address and password you use to register. Passwords are never stored in plain text — they are hashed with bcrypt.
Alert and configuration data: the alerts, watchlists, and notification settings you create, including any delivery-channel details you provide (for example a Discord webhook URL).
Usage and analytics data: actions you take in the product (such as creating an alert or verifying your email) so we can understand feature usage and improve the service.
Technical data: IP address, browser/user-agent, and server logs generated when you interact with our API. We use these for security, abuse prevention, and rate limiting.
3. How we use your information
To provide the service: authenticate you, run your alerts, and deliver notifications through the channels you choose.
To communicate with you: send transactional emails such as email verification, password resets, and the alerts you have configured.
To keep the service secure: detect and prevent abuse, enforce rate limits, and protect accounts (for example, temporary lockout after repeated failed logins).
To improve the product: analyse aggregate, de-identified usage trends.
4. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the service you sign up for), our legitimate interests (to secure and improve the service), and your consent where required (for example, optional communications). You may withdraw consent at any time.
5. Cookies and analytics
Essential storage: the application stores your session token in your browser (session storage) to keep you signed in, and sets a lightweight cookie to reflect your signed-in state across our website and app. These are required for the service to work.
Analytics: we use Google Analytics 4, provided by Google, to understand how visitors use our website and app — for example which pages are viewed and key actions such as creating an alert — so we can improve the product. Google processes this data as our service provider. We do not send Google your email address or other information that directly identifies you.
Session recording and heatmaps: if you accept analytics, we also use Microsoft Clarity, provided by Microsoft, which records how pages are used — mouse movement, clicks, scrolling, and the pages you move between — and aggregates this into heatmaps, so we can find layout and usability problems. Clarity masks the contents of input fields and dropdowns before anything leaves your browser, and by default also masks email addresses and numbers; we additionally mark the signed-in account area of the app so that it is never captured. Clarity sets its own cookies: “_clsk”, which links the pages of one visit into a single recording, and “_clck”, which stores an identifier so Clarity can recognise a returning visitor to our site. Microsoft may also set cookies of its own when the script loads.
Unlike Google Analytics, Clarity is not loaded at all until you accept: if you decline, or have not yet chosen, no Clarity script runs, no recording takes place, and no Clarity cookies are set. Where you visit our app directly without ever seeing the consent banner, Clarity does not run.
Your choice (consent): analytics cookies and session recording are off by default. The first time you visit we ask for your consent with a banner, and we only set analytics cookies or record a session if you choose “Accept”. If you “Decline”, no analytics cookies are stored and no session recording takes place. You can change your decision at any time from Settings → Privacy inside the app, where a single switch turns analytics and session recording on or off; turning it off takes effect immediately and clears the cookies involved. You can also clear the “cb_consent” cookie (or all cookies) in your browser, which brings the banner back, or install Google’s Analytics opt-out browser add-on.
Product analytics (first-party): separately from Google Analytics, we record events about how the product itself is used — pages viewed and actions such as creating an alert, running a scan, or changing a setting — together with the time, the page, and, where you are signed in, your account. This data is stored in our own database and is not shared with advertisers or sold. We use it to see which features are used and where people get stuck.
This does not use cookies. When you are signed in, events are recorded against your account. When you are signed out, we generate a random identifier held only in your browser's session storage, which is erased when you close the tab — it is not a cookie, not a persistent device identifier, and cannot be used to recognise you on another site or on a later visit. If you then create an account in the same session, the actions you took immediately beforehand are linked to your new account so we can understand how people get started.
How long we keep it: individual event records are deleted after 90 days. We keep aggregated daily counts (totals per day, with no free-text detail) for up to two years so we can see long-term trends.
We do not use analytics data to serve ads, and we do not sell it or use it to build advertising profiles. Google Analytics runs with advertising features off, and we configure Microsoft Clarity with advertising storage denied, so it does not share data with Microsoft Advertising. Declining analytics prevents any of these cookies being set at all.
6. How we share information
We do not sell your personal data. We share data only with service providers that help us operate — such as our email delivery provider, our hosting infrastructure, and, where you have accepted analytics, Google (Google Analytics) and Microsoft (Clarity) — and only as needed to run the service.
If you configure a third-party delivery channel (for example Discord), the alert content you choose to send is delivered to that third party and is then subject to their terms and privacy practices.
We may disclose information where required by law or to protect our rights, users, or the security of the service.
7. Data retention
We keep account and alert data for as long as your account is active. If you delete your account or ask us to delete your data, we remove or anonymise it within a reasonable period, except where we must retain certain records to comply with legal obligations or resolve disputes.
8. Security
We use industry-standard measures including encryption in transit (HTTPS), hashed passwords, scoped access controls, and rate limiting. No method of transmission or storage is completely secure, but we work to protect your information and respond promptly to issues.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email support@coinbeacon.io and we will respond in line with applicable law.
10. Market data
Prices, funding rates, and other market data shown in the product are sourced from public exchange feeds and provided for informational purposes only. They are not investment advice and may be delayed or inaccurate.
11. Children
CoinBeacon is not intended for anyone under 18, and we do not knowingly collect data from children.
12. International transfers
We may process and store data in countries other than your own. Where we transfer personal data internationally, we take steps to ensure it remains protected in accordance with applicable law.
13. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you.
14. Contact
Questions about your privacy? Email us at support@coinbeacon.io.