Privacy Policy – CoinXpe
Privacy Policy - CoinXpe
CoinXpe (“Company”, “we”, “our”, or “us”) is operated by SUPERMINT INFOTECH PRIVATE LIMITED, a company incorporated under the Companies Act, 2013, having its registered office at PLOT NO 6, KHASRA NO 407 MISHRPUR Guramba Lucknow Uttar Pradesh India 226026.
This Privacy Policy explains how we collect, use, store, share, and protect personal data of users (“User”, “you”, or “your”) who access or use the CoinXpe website, mobile applications, APIs, or related services (collectively, the “Platform”).
This Policy is aligned with:
- Information Technology Act, 2000
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Prevention of Money Laundering Act, 2002 (PMLA)
- FIU-IND AML/CFT Guidelines for Virtual Digital Asset Service Providers
- Applicable banking and regulatory requirements in India
1. Personal Data We Collect
To comply with legal, regulatory, and banking obligations, we collect the following categories of data:
1.1 Identity & KYC Information
Collected for onboarding, verification, and AML compliance:
- Full name
- Date of birth
- Gender (where applicable)
- PAN
- Aadhaar (masked / offline verification only, where applicable)
- Photograph (selfie / live capture)
1.2 Bank & Financial Information
Required for INR on-ramp and off-ramp services:
- Bank account number
- IFSC code
- Account holder name
- UPI ID
- Bank Statement (In case of Suspicious transaction found)
1.3 Transaction & Wallet Data
- Deposit and withdrawal history
- Buy & Sell History
- Order history
- Fiat and crypto balances
- TDS records (as applicable)
- All the required information related to any transaction activity
1.4 Communication Records
- Customer support interactions
- Email, chat, and ticket history
2. Purpose of Data Collection
We collect and process personal data for the following purposes:
- User onboarding and identity verification
- Compliance with AML, CFT, and KYC obligations
- Transaction processing (INR and crypto)
- Fraud detection, prevention, and investigation
- Risk assessment and transaction monitoring
- Compliance reporting to FIU-IND and other authorities
- Responding to legal requests and law enforcement orders
- Customer support and grievance handling
- Platform security, audit, and internal controls
- Statutory record keeping
3. Data Storage & Retention
3.1 Data Storage
- All personal data is stored on secure servers located in India or in jurisdictions permitted under Indian law.
- We use industry-standard encryption, access control, and monitoring mechanisms.
- Access to sensitive data is restricted to authorized personnel only on a need-to-know basis.
3.2 Data Retention Period
In accordance with PMLA and FIU-IND guidelines:
- KYC and transaction data is retained for a minimum of 5 to 10 years after the end of the business relationship or completion of the transaction, whichever is later.
- Logs, audit trails, and compliance records may be retained longer if required by law, investigation, or court order.
- Data required for ongoing disputes, investigations, or regulatory proceedings will not be deleted until resolution.
4. Sharing & Disclosure of Information
We may share user data strictly on a need-based and lawful basis with the following entities:
4.1 Banks & Payment Partners
- Partner banks
- Nodal / escrow account providers
- Payment gateways
- UPI and banking intermediaries
This sharing is required for:
- Processing INR transactions
- Reconciliation
- Fraud prevention
- Regulatory compliance
4.2 FIU-IND & Government Authorities
We are legally obligated to share information with:
- Financial Intelligence Unit – India (FIU-IND)
- Enforcement Directorate (ED)
- Income Tax Department
- Law enforcement agencies
- Courts or tribunals
This includes:
- Suspicious Transaction Reports (STRs)
- Large transaction reports
- User KYC and transaction records
All such partners are contractually bound by confidentiality and data protection obligations.
5. User Rights
Subject to applicable laws and regulatory obligations, users have the following rights:
5.1 Access & Correction
- Request access to personal data held by CoinXpe
- Request correction of inaccurate or outdated information
5.2 Data Deletion (Limited)
Users may request deletion of personal data only if:
- There is no ongoing legal, regulatory, or compliance requirement
- The business relationship has ended
- Retention is not mandated under PMLA or other laws
CoinXpe reserves the right to deny deletion requests where data retention is legally required.
5.3 Withdrawal of Consent
Where processing is based on consent, users may withdraw consent; however, this may result in:
- Suspension or termination of services
- Account restrictions
6. Account Suspension & Freezing
CoinXpe may restrict, suspend, or freeze user accounts and associated funds without prior notice if required due to:
- Suspicious or fraudulent activity
- AML / CFT concerns
- Law enforcement or regulatory instructions
- Court orders
7. Data Security Measures
CoinXpe implements reasonable security practices including:
- Encryption at rest and in transit
- Role-based access control
- Multi-factor authentication
- Continuous monitoring and logging
- Periodic internal and external audits
Despite best efforts, no system is completely secure. Users acknowledge and accept inherent risks associated with digital platforms.
8. Children’s Privacy
CoinXpe services are not intended for individuals below 18 years of age. We do not knowingly collect data from minors.
9. Changes to This Policy
CoinXpe reserves the right to update this Privacy Policy at any time to reflect:
- Legal or regulatory changes
- Operational updates
- Business requirements
Revised policies will be published on the website and become effective immediately.
10. Contact Information
For privacy-related queries, please contact: