1. Overview

This Privacy Policy explains how Vertisan Vortex ("we", "us", "our") collects, uses, shares, and protects personal information when you use our P2P exchange, mobile/desktop site, and related services (collectively, the "Services"). By using the Services, you agree to this Policy.

We design our Services for anti-fraud, AML/KYC compliance, and secure P2P settlement. Some processing is required by law (e.g., identity verification, record keeping).

2. Information we collect

We collect the following categories of information:

2.1 Account & profile

  • Name, username, email, password, language.

  • Contact details you provide (optional fields like phone or address if enabled).

  • Firebase/FCM push notification tokens (saved when you opt in to notifications).

2.2 Identity (KYC/AML) — where enabled/required

  • Government ID images/data, selfies/biometrics (liveness), date of birth, nationality, sanction/pep screening results, and verification status.

2.3 Financial & trade

  • Internal wallet balances and movements (deposits, payouts, charges/fees).

  • Trades, advertisements, payment windows/methods used, dispute records and decisions.

  • On‑chain metadata where relevant (addresses, tx hashes) and risk signals from anti‑fraud/on‑chain analytics providers.

2.4 Usage & device

  • IP address, device/browser info, timestamps (security logs), session activity (e.g., login, password change), pages visited.

  • reCAPTCHA diagnostics to prevent abuse (see §10).

2.5 Communications

  • Support tickets, contact‑us forms, chat messages in trades, email delivery status, and your notification preferences.

We may collect information from third parties (e.g., KYC vendors, sanctions lists, fraud‑prevention providers) to comply with laws and protect the platform.

3. Why we process your information (purposes & legal bases)

We process your information for:

  • Providing the Services (create account, list/accept trades, manage wallets).
    Legal bases: contract performance; legitimate interests.

  • Identity verification & AML/CTF compliance (where required by law).
    Legal bases: legal obligation; substantial public interest (EU/UK); legitimate interests.

  • Fraud prevention & platform security, dispute handling, rate‑limiting and abuse prevention.
    Legal bases: legitimate interests; legal obligation.

  • Payments and settlements, including fees/charges and receipts.
    Legal bases: contract performance; legitimate interests.

  • Communications (transactional emails, trade/chat alerts, push notifications).
    Legal bases: contract performance; consent (for optional marketing/push).

  • Analytics & service improvement (aggregated usage, bug fixing).
    Legal bases: legitimate interests; consent where required.

  • Legal claims and compliance (record keeping, tax, responding to lawful requests).
    Legal bases: legal obligation; legitimate interests.

Where we rely on consent, you may withdraw it at any time (this does not affect prior lawful processing).

4. Cookies and similar technologies

We use essential cookies for login sessions and security. With your consent, we may use optional cookies for analytics. You can control cookies from your browser settings or our preferences banner (if enabled). See our Cookie Notice for details.

5. How we share information

We do not sell your personal information. We share it with:

  • Service providers acting on our instructions: cloud hosting, email/SMS delivery, push notifications (e.g., Firebase), analytics, security/fraud prevention (e.g., reCAPTCHA), identity verification/KYC, payment and payout processors, and on‑chain analytics.

  • Other users to complete a P2P trade (limited details shown in the trade chat and order).

  • Law enforcement/regulators where required by applicable law or to protect rights, safety, or the integrity of our Services.

  • Corporate transactions (merger, acquisition) subject to appropriate safeguards.

Service providers are bound by confidentiality and process data only on our documented instructions.

6. International data transfers

We may process and store data in countries other than yours. Where required (e.g., EU/UK), we use lawful transfer mechanisms such as Standard Contractual Clauses and implement appropriate safeguards. You may request a copy of the relevant safeguards.

7. Data retention

We keep personal information only as long as necessary for the purposes above and to comply with laws. Typical periods:

  • Account data: for the life of the account; on closure we retain minimal records for 0 months for support and audit.

  • KYC/AML & trade records: retained for 5–10 years after account closure or as required by AML/financial laws in your jurisdiction.

  • Logs & security data: typically 12–24 months, unless needed for an investigation.

  • Marketing preferences: until you opt out or delete your account.

Actual retention may vary by jurisdiction and legal requirements.

8. Security

We implement technical and organizational measures designed to protect your data, including TLS encryption in transit, access controls, audit logging, and secure development practices. No system is 100% secure; you are responsible for maintaining strong, unique passwords and enabling 2‑factor authentication where available.

9. Third‑party services

9.1 Google reCAPTCHA

We use reCAPTCHA to protect forms against abuse. reCAPTCHA collects hardware and software information (e.g., device, app, and activity data) and sends it to Google for analysis. Use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.

9.2 Firebase Cloud Messaging (push)

If you enable push notifications, we store your device/token to deliver notifications. You can revoke permission in your browser or OS settings.

9.3 Payment/KYC/Fraud vendors

Where necessary we share data with payment, KYC/identity and fraud‑prevention/on‑chain analytics providers to verify your identity, prevent fraud, and comply with AML/CTF rules.

10. Children’s privacy

Our Services are not directed to children under the age of 18, and we do not knowingly collect data from them. If you believe a child has provided personal information, contact us to delete it.

11. Automated decisions & profiling

We may use automated systems to detect fraud, assess risks, and enforce platform rules (e.g., blocking suspicious trades, limiting features). You may request human review of certain decisions where required by law.

12. Links to other sites

Our Services may contain links to third‑party websites. We are not responsible for their privacy practices. Review those policies separately.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date. Material changes will be highlighted or notified to you where required.

14. Contact us

If you have questions or requests about this Policy or your personal information, contact:
Email: privacy@vertisanvortex.com


PWA

vertisanvortex.com

Install Progressive Web Application

This site has app functionality. Install it on your device for extensive experience and easy access.