ShapeShift Privacy Policy

ShapeShift Exchange UK Limited

Online Privacy Notice

Data protection and security are important to ShapeShift Exchange UK Limited and its subsidiaries (“ShapeShift”; “we”), as is your trust in our company and services. ShapeShift is committed to processing your personal data responsibly and in compliance with legal requirements.

This Online Privacy Notice describes how we collect and process your personal data when you use our website www.shapeshift.io (including any sub-sites thereof; “the website”).

Personal data we collect and process in order to make the website available

You can visit the website and obtain information about our services without telling us who you are. As with any connection with a webserver, however, the server on which we host the website automatically logs and temporarily stores certain technical data.

Technical data that is stored includes the IP address and operating system of your device, the data and time of access, or the type of browser you use to access the website. This is required for technical reasons to make the website available to you. To the extent we, thereby, process personal data, we do so based on our legitimate interest to bring you the best possible user experience and to safeguard the security and stability of our systems.

Our website uses fonts by Google LLC (“Google”) (“Google Fonts”). To integrate Google Fonts into the website, your browser establishes a connection to the Google server. In doing so, the IP address of your device is transmitted to Google. Google logs records of font queries and protects this data from unauthorized access. Google analyzes aggregated data to optimize Google Fonts and identify which websites use Google Fonts. Further information on Google Fonts can be found here: https://fonts.google.com. Further information on how Google handles personal data can be found here: https://policies.google.com/privacy?hl=en.

Personal data we collect and process to provide services to you and to respond to your inquiries

If you interact with registration, application, order or inquiry forms on the website (e.g. signing up for an account, namely in order to use our financial services; application for becoming an affiliate of ShapeShift or requesting support regarding a transaction), we will collect the information that you provide to us. We collect and process this personal data for the purpose of providing services and information about our services to you.

This will regularly include your public wallet addresses (destination and refund wallet address), your full name, your residence address, your date of birth, your phone number, your social security number or other tax identification number, details about your government issued identification such as identification number and expiration date, and your e-mail address.

Where such processing of your personal data is not strictly necessary to perform our contractual obligations to you or to comply with legal requirements (such as in connection with providing financial services to you), we will use this personal data based on our legitimate interest to verify your identity, to respond to your inquiry, to contact you if we have any questions about your inquiry, to follow up on your inquiry, to process your registrations, applications or orders, to develop, enhance and improve our products and services, to bring you the best possible experience or to safeguard the security and stability of our services. Further, based on our legitimate interest to inform our customers and partners about new developments, products, services or offers, we will send you certain commercial information (e.g. our newsletter or blog posts). However, you may at any time opt-out of receiving such information.

We store all of the personal data you provide to us in an encrypted fashion.

We use services of SendGrid to send transactional emails, including account creation emails, password resets, purchase receipts, and account notifications. Further information on data protection and your options in connection with the services of SendGrid can be found here: https://sendgrid.com/policies/privacy/.

We use the services of Net-Results, an email automation platform, to better reach ShapeShift product subscribers who have opted in to receive such communications. Emails are sent out to convey information such as monthly updates, asset additions, product news, partnerships, event announcements, and survey requests.

Net-Results and its service providers automatically collects certain information using tracking technologies like cookies, web beacons and similar technologies, and through web forms. Customer Data is never sold, and is not shared with third parties for those third parties’ own business interests. Records containing customer data may, from time to time, be used in debugging or troubleshooting or in connection with investigations of platform performance issues or security incidents, as well as for the purposes of detecting and preventing spam or fraudulent activity, and detecting and preventing system exploits and abuse.

Further information on data protection and your options in connection with the services of Net-Results can be found here: https://www.net-results.com/privacy-policy/.

We use services of Zendesk, Inc. (“Zendesk”) to answer live queries on the website, in which we have a legitimate interest. Zendesk uses cookies in order to provide these services. Further information on data protection and your options in connection with the services of Zendesk can be found here: https://www.zendesk.com/company/customers-partners/privacy-policy/ (Zendesk Privacy Policy) and https://www.zendesk.com/company/customers-partners/cookie-policy/ (Zendesk Cookie Policy).

We also use services of IDology Inc. to verify the personal data you provide to us. Further information on data protection and your options in connection with the services of IDology can be found here: https://www.idology.com/privacy-policy.

Data we collect and process to analyze and improve the use of the website; use of cookies

In addition, based on our legitimate interest to bring you the best possible user experience, we analyze the use of the website to gain insight on how we may improve our services. The website uses cookies (text files that are downloaded to your computer or mobile device when you visit a website) to support this analysis.

The data we collect may include information on the type of web browser or device you use to access the website, the geographical region where you access the website, the date and time of your access, and the parts of the website you access.

We also use cookies to analyze the use of the website, to optimize our services and to enable the use of marketing tools. Further information on web analysis and our marketing activities can be found below.

We use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies to collect the information that is required to evaluate your use of the website in order to create reports on the use of the website and to provide other services that support our analysis and improvement of the use of the website, in which we have a legitimate interest.

We use Google Analytics only with IP anonymization enabled. This means that your IP address will be shortened beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Accordingly, Google only stores the information collected via cookies in anonymous form and processes it in aggregated form. You can prevent Google Analytics from using your data by downloading and installing a browser add-on to disable Google Analytics (https://tools.google.com/dlpage/gaoptout?hl=en). Further information on data protection and your options in connection with Google Analytics can be found here: https://support.google.com/analytics/answer/6004245?hl=en.

We use services of Cloudflare, Inc. (“Cloudflare”) in order to identify trusted web traffic (i.e. to identify individual clients behind a shared IP address and apply security settings on a per-client basis), in which we have a legitimate interest. Cloudflare uses cookies in order to provide these services. The cookies do not correspond to any user ID in your web application, and do not store any personal data. Further information on data protection and your options in connection with the services of Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/(Cloudflare Privacy Policy) and https://www.cloudflare.com/cookie-policy/ (Cloudflare Cookie Policy).

We use online interactive services of ShareThis, Inc (“ShareThis”). The services of ShareThis allows users to share information on the website more easily via social networks, in which we have a legitimate interest. If you visit the website containing the social plugin of ShareThis (“ShareThis Plugin”), your browser establishes a connection to the ShareThis server and loads the ShareThis Plugin and its content on your browser in order to be integrated into the website you visit. The ShareThis Plugin uses cookies and informs ShareThis that you visited the website. Further data may be collected if you interact with the ShareThis Plugin (e.g. by clicking on the dedicated icon or by sharing information via the ShareThis Plugin). The information collected by ShareThis may include user data (including IP address) and the geographical region as well as technical data. Your browser may also establish a connection to the servers of the social networks implemented in the ShareThis Plugin. These social networks may use cookies for their own purposes. Further information on data protection and your options in connection with these social networks can be found in the privacy policies of these social networks. Further information on data protection and your options in connection with the services of Cloudflare can be found here: https://www.sharethis.com/privacy/.

By adjusting your web-browser’s settings accordingly, you can prevent the storage of cookies on your device and the collection of data. Note, however, that some functions of the website may be limited or unavailable if you disable the storing of cookies.

Data that we collect and process to target potential customers

We use Google Tag Manager to generate tags for the website and applications. These tags enable us to tailor marketing measures for our services to potential customers (re-targeting).

We use advertising technologies by Google (AdWords). Google sets conversion cookies in accordance with our settings in Google Tag Manager. This is necessary for checking the effectiveness of the respective advertising campaigns. We have a legitimate interest in this. We also use Google Tag Manager to set re-targeting tags. These tags enable us to target users with information about our services when they visit different websites. For information regarding your choices in relation to usage-based online advertising, see: http://www.youronlinechoices.com. For information about your options in connection with cookies, see above “Data we collect and process to analyze and improve the use of the website; use of cookies”.

How we process and protect your personal data; how long we store it

We collect, process and protect your personal data responsibly and in accordance with applicable laws. We process it only for the purposes for which you provide the personal data to us or as set forth in this Online Privacy Notice. We store your personal data only for as long as this is necessary.

We collect and process your personal data only for the purposes for which you provide us with these data, as set forth in this Online Privacy Notice or in accordance with applicable laws.

We apply adequate technical and organizational security measures, commensurate with the level of known risk, in order to protect the confidentiality and integrity of the personal data we collect on the website.

We store your personal data only for as long as this is necessary for us to fulfil the purposes for which the data was collected, as set forth in this Online Privacy Notice, or, when applicable, as long as we are legally required to retain the personal data.

With whom we share your personal data

In connection with the offers and services provided on the website, to protect our legitimate interests or to fulfil legal requirements, it may be necessary to share your personal data with subsidiaries (currently KeepKey, LLC), with business partners of ShapeShift as well as with applicable public authorities and law enforcement.

Specifically, such sharing of data may be necessary to manage your registration (such as to verify your identity), to respond to your inquiry, to execute the transaction, to provide access to additional information, or to follow up on your inquiry and inform you on new services or offers.

Further, to the extent we are requested by public authorities or courts and legally required to do so, we will share your personal data with them or other third parties.

The data sharing may include transfers to companies or organizations in countries without an adequate standard of data protection. In these cases, we transfer personal data in accordance with applicable provisions on the international transfer of personal data, such as, where applicable, the respective provisions of the EU General Data Protection Regulation (GDPR).

The rights you have regarding your personal data

You have certain individual rights regarding the personal data that we collect and process about you through the website.

You have the right to access or receive certain information about the personal data we process about you. You also have a right to have your personal data rectified, to object to the processing of your personal data, or to ask us to restrict processing or delete your personal data. If the GDPR applies and we process your personal data to perform a contract with you or based on your consent, you also have the right to receive a copy of your personal data for the purpose of transferring such data to a third party.

Please note, however, that your rights are subject to exceptions or derogations. Specifically, we may need to further process and retain your personal data to perform a contract with you or your company or organization, to protect our legitimate interests (such as the establishment, exercise or defense of legal claims) or to comply with legal requirements. To the extent permitted by law, namely to protect the rights and freedoms of others or to protect our own legitimate interests, we may therefore refuse to satisfy your request or we may satisfy your request only restrictedly.

Lastly, you have a right to lodge a complaint with a competent supervisory authority.

Who we are and how to contact us

ShapeShift is the controller in relation to the collection and processing of personal data through the website. ShapeShift Exchange UK Limited is a corporation formed under the laws of the United Kingdom.

If you have any questions or concerns, you may contact us by writing to ShapeShift as set forth below.

To inquire about the collection or processing of your personal data in connection with the website, or if you have any questions or concerns about this Online Privacy Notice, you may contact us through the ShapeShift Help Center, located here: https://shapeshift.zendesk.com/hc/en-us.

For all correspondence, please include any necessary identifying information such as your name, return e-mail or physical address, and any transaction IDs relevant to your request. Failure to do so may prevent us from providing a response.

How we can change this Online Privacy Notice

We reserve the right to change this Online Privacy Notice at any time. The version published on the website is the applicable version.

December 2018