Privacy Policy
Last updated: April 2026
1. Introduction
AccrueLabs ("we", "our", or "us") is committed to protecting your personal data in accordance with applicable data-protection legislation, including the EU General Data Protection Regulation (GDPR) and equivalent national regimes. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have.
2. Data We Collect
We collect the following categories of personal data:
- Account data: email address, hashed password, 2FA secret and enrolment status, Telegram chat ID if linked.
- Transaction data: deposits, withdrawals, pool participation, share balance, realised and unrealised PnL, on-chain transaction hashes and destination addresses.
- KYC data (where required): full name, date of birth, residential address, government-issued identity document, proof of address, source-of-funds information.
- Technical data: IP address, user-agent, access and error timestamps, session identifiers, basic usage analytics.
- Communication data: messages and attachments you send us via email, in-platform contact forms, or support channels.
3. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)) — operating your account, processing deposits and withdrawals, providing the market-making service.
- Compliance with legal obligations (Art. 6(1)(c)) — AML/KYC record-keeping, sanctions screening, tax reporting, responding to lawful authority requests.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, platform security, service improvement, defending legal claims.
- Consent (Art. 6(1)(a)) — where we ask for explicit opt-in (for example, optional Telegram notifications).
4. How We Use Your Data
We use your personal data to:
- create and operate your account, including authentication and 2FA;
- process deposits and withdrawals, track performance, and calculate fees;
- send service notifications, security alerts, and — if you opt in — performance updates;
- comply with anti-money-laundering (AML), know-your-customer (KYC) and sanctions obligations;
- monitor and improve the platform, including investigating bugs and abuse;
- respond to support requests and, where applicable, legal claims.
5. Data Retention
We retain personal data for as long as your account is active plus an additional period required by law. Account and transaction records relating to financial activity are typically retained for five to ten (5–10) years after account closure, in line with AML and tax record-keeping obligations in the relevant jurisdictions. Technical logs and analytics are retained for a shorter period (typically up to twelve (12) months) unless needed for a specific security or legal purpose.
6. Your Rights
Under the GDPR (and equivalent regimes) you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion ("right to be forgotten"), subject to our overriding legal retention obligations.
- Right to restriction — ask us to limit how we process your data in certain circumstances.
- Right to portability — receive your data in a structured, commonly used and machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent — where processing relies on your consent, you may withdraw it at any time, without affecting the lawfulness of prior processing.
- Right to lodge a complaint — with the supervisory authority in your country of residence.
To exercise any of these rights, contact us at [email protected]. We will respond within one (1) month, as required by the GDPR.
7. Cookies & Similar Technologies
We use strictly necessary cookies and local-storage items to keep you signed in, preserve your UI preferences, and protect the platform against abuse. We do not use third-party advertising cookies, cross-site trackers, or behavioural ad targeting. A short summary of active storage keys is available on request.
8. Third-Party Processors
To operate the Service we share limited personal data with carefully selected third parties acting as processors on our behalf. Current key processors include:
- MEXC Global — order execution and custody of pool assets under the Operator's sub-accounts.
- Cloud infrastructure provider — hosting of backend services and databases (within the EU where possible).
- Resend — transactional email delivery (account, security and service emails).
- Cloudflare — DNS, CDN and DDoS protection.
- Google (Authenticator / OAuth) — if you choose to enable 2FA or sign in with Google.
- Telegram — if you choose to link your account for notifications.
Where a transfer takes place outside the EEA, we rely on the European Commission's standard contractual clauses or an adequacy decision.
9. Data Security
We apply industry-standard technical and organisational measures to protect your data, including TLS encryption in transit, bcrypt password hashing, TOTP-based two-factor authentication, encrypted at-rest database backups, restricted-access sub-account architecture, origin IP lockdown, and audit logging. While no system is perfectly secure, we aim to detect and mitigate incidents promptly and will notify affected users without undue delay where required by law.
10. Contact
For any privacy-related inquiries, contact our Data Protection contact at [email protected].