Legal

Privacy Policy

Last updated: 6/20/2026

1. Who we are

CryptoTaxCompanion (the "Service") is operated by Kabelo Simis Nchee ("we", "us"), who acts as the data controller for personal data processed in connection with the Service. You can contact us at privacy@cryptotaxcompanion.com.

2. Data we collect

  • Account data — email, password (hashed), display name.
  • Tax & transaction data — CSVs you upload, wallet addresses, exchange identifiers, transaction details, computed tax lots and gains.
  • Support communications — messages you send us.
  • Usage telemetry — pages visited, feature usage, error logs, device identifiers, IP address.
  • Cookies — essential cookies for authentication and security.

Payment information (card details, billing address, tax ID) is collected by our payment provider Paddle, not by us.

3. Why we use it (purposes & legal bases)

  • Provide the Service (account, importing, AI categorization, tax reports) — performance of contract.
  • Security & fraud prevention — legitimate interests.
  • Customer support — performance of contract / legitimate interests.
  • Product improvement (aggregate, non-identifying analytics) — legitimate interests.
  • Legal & regulatory compliance — legal obligation.
  • Marketing emails (where applicable) — consent, which you can withdraw at any time.

4. Who we share data with

  • Sub-processors — hosting, database, AI inference, email, analytics, error monitoring providers.
  • Paddle.com Market Limited — Merchant of Record handling payments, subscription billing, tax compliance and invoicing.
  • Professional advisers — legal, accounting, where required.
  • Authorities — where required by law or to protect rights.

We do not sell your personal data.

5. Read-only access

When you connect exchanges or wallets, we only request read-only credentials. We never have the ability to move or trade your assets.

6. International transfers

Your data may be processed in countries outside your own. Where this involves transfers from the EEA/UK to a third country, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

7. Retention

We retain account and transaction data while your subscription is active and for a reasonable period after cancellation to meet legal, accounting and audit obligations. After that, we delete or anonymise the data. You can request earlier deletion at any time.

8. Your rights

Subject to applicable law (including GDPR / UK GDPR / CCPA), you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent. EEA/UK users may also lodge a complaint with their national supervisory authority. We will respond to verified requests within one month.

9. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, audit logging, and provider-managed key storage.

10. Cookies

We use essential cookies (authentication, security) and may use limited analytics cookies. You can manage cookies through your browser settings.

11. Changes

We will notify you of material changes by email or in-app notice. The "Last updated" date at the top of this page indicates the current version.

12. Contact

Email privacy@cryptotaxcompanion.com for any privacy-related question.