Last updated: 29 August 2026 · Effective date: 29 August 2026
This Policy explains what personal data Bitegit collects when you use our website and mobile
application (the “Platform”), why we collect it, who we share it with, and the choices you
have. It should be read together with the User Agreement.
Bitegit (“Bitegit”, “we”, “us”) is the controller of the personal data described here.
For privacy questions, or to exercise your rights, contact
privacy@bitegit.com.
2. What data we collect
2.1 Data you give us
Account data: email address, a password (stored only as a salted hash — we never store your
password in readable form), and an optional referral code.
Identity-verification (KYC) data: where you complete verification — your legal name, date of
birth, nationality/country, residential or contact address, government-issued identity document
images, and a facial photograph/selfie used for a liveness and match check.
Payment-method data for P2P: the payment-method details you choose to save for peer-to-peer
trades (for example a UPI ID, bank account name and number, or wallet handle).
Transaction instructions: deposit/withdrawal addresses and networks, conversion and trade
amounts, internal-transfer recipients, and any note you add.
Communications: messages you send in P2P order chat, support tickets and their attachments,
dispute evidence, and any correspondence with us.
Security settings: whether two-factor authentication is enabled (we store the 2FA secret in
encrypted form), your anti-phishing code, and your withdrawal-address whitelist.
2.2 Data we collect automatically
Device & connection data: IP address, approximate location derived from IP, device and
browser type, operating system, and app version.
Usage & security logs: log-in times and outcomes, new-device/new-IP events, actions you
take on the Platform, wallet and ledger entries, and audit records of security-relevant events.
These are kept for fraud prevention, security, and legal compliance.
Local storage: a session token and small preferences stored on your device so you stay
signed in and the app remembers your settings.
2.3 Data from third parties
Verification results and risk signals from our identity-verification and anti-fraud providers.
Market and price data from third-party exchanges and data providers (this does not identify you).
3. Why we use it & our legal bases
Purpose
Legal basis (where applicable)
Create and operate your account; execute the transactions you request
Performance of our contract with you
Identity verification, sanctions screening, anti-money-laundering and fraud prevention
Legal obligation; legitimate interests
Securing accounts and the Platform (2FA, login alerts, audit logs)
Legitimate interests; legal obligation
Providing customer support and resolving disputes
Performance of contract; legitimate interests
Sending service and security notifications by email
Performance of contract; legitimate interests
Complying with lawful requests from authorities and enforcing our terms
Legal obligation; legitimate interests
We do not sell your personal data, and we do not use it for third-party advertising.
4. Who we share it with
Service providers who process data on our instructions, including: our cloud database and
application hosting providers; our email delivery provider (for OTP and notification emails);
and our identity-verification / anti-fraud providers.
Other users, to the limited extent necessary for a transaction — for example, in a P2P order
your counterparty sees your Platform username, your chat messages, and the payment-method
details you choose to share for that trade.
Authorities and regulators where we are legally required to disclose data, or where necessary
to investigate fraud or protect the rights, property, or safety of Bitegit or others.
Acquirers in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Where data is stored & international transfers
Your data is stored on managed cloud infrastructure (database and application hosting) that may be
located outside your country of residence. Where data is transferred internationally, we rely on
appropriate safeguards such as standard contractual clauses or an adequacy decision, where required
by law.
6. How long we keep it
Account and transaction records, KYC data, and security/audit logs: kept for the life of your
account and then for the period required by applicable anti-money-laundering and record-keeping
law (commonly five to seven years) after account closure.
P2P chat and support messages: kept while needed to operate the service and resolve
disputes, then deleted or anonymised on a rolling basis.
Marketing preferences: kept until you change them.
7. How we protect it
Passwords are stored only as salted hashes; they are never stored or logged in readable form.
KYC document images and two-factor secrets are encrypted at rest using authenticated encryption
(AES-256-GCM).
Data in transit is protected with TLS.
Access to production data is limited to staff who need it, and security-relevant actions are
logged.
We offer account-level protections you control: two-factor authentication, an anti-phishing
code, new-device login alerts, and a withdrawal-address whitelist. We strongly recommend
enabling them.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have the right to: access the personal data we hold about you;
correct inaccurate data; request deletion; restrict or object to certain processing; receive a
portable copy of data you gave us; and withdraw consent where we rely on it. You may also complain to
your local data-protection authority.
Some data cannot be deleted while your account is open or while we are legally required to keep it
(for example KYC and transaction records). To make a request, contact
privacy@bitegit.com. We may need to verify your identity first.
9. Cookies & local storage
On the website we use strictly necessary cookies to keep you signed in and to protect against
fraud. The mobile app uses on-device storage for your session token and preferences. We do not use
advertising or cross-site tracking cookies.
10. Children
The Services are not directed to anyone under 18, and we do not knowingly collect data from
children. If you believe a child has given us data, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. If a change is material we will notify you through the
Platform or by email before it takes effect. The “last updated” date at the top shows the current
version.