Privacy Policy
Your privacy is important to us. This policy explains how BitLoot collects, uses, protects, and shares your personal information when you use our platform.
1. Introduction
BitLoot ("we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cryptocurrency-powered digital marketplace platform (the "Platform").
By accessing or using BitLoot, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Platform.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide when using our Platform:
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | Email address, password (hashed) | Account creation, authentication, order management |
| Transaction Data | Purchase history, order details, cryptocurrency wallet addresses | Order processing, payment verification, delivery |
| Communication Data | Support inquiries, chat messages, feedback | Customer support, service improvement |
| User Content | Reviews, ratings, comments | Community features, product feedback |
2.2 Information Collected Automatically
When you access our Platform, we automatically collect certain information:
| Data Type | Examples | Purpose |
|---|---|---|
| Device Information | Browser type, operating system, device type | Platform optimization, security |
| IP Address | IP address, approximate location | Fraud prevention, security, compliance |
| Session Data | Login sessions, device fingerprint | Security, session management |
2.3 Information We Do NOT Collect
- Full cryptocurrency wallet private keys
- Government-issued ID numbers (unless required by law)
- Biometric data
- Information from minors under 18
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Essential Services
- Processing and fulfilling your orders
- Verifying cryptocurrency payments
- Delivering digital products and keys securely
- Managing your account and preferences
- Sending order confirmations and delivery notifications
3.2 Security & Fraud Prevention
- Detecting and preventing fraudulent transactions
- Protecting against unauthorized access
- Monitoring for security threats
- Enforcing our Terms of Service
3.3 Communication
- Responding to your support requests
- Sending important service updates
- Providing promotional content (with your consent)
- Notifying you of changes to our policies
3.4 Improvement & Analytics
- Analyzing usage patterns to improve our Platform
- Developing new features and services
- Conducting research and analytics
- Personalizing your experience
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
Contract Performance
Processing necessary to fulfill our contract with you (e.g., processing orders, delivering products, managing your account).
Legitimate Interests
Processing for our legitimate business interests (e.g., fraud prevention, security, analytics) where those interests don't override your rights.
Consent
Where you've given explicit consent (e.g., marketing communications, newsletter subscriptions).
Legal Compliance
Processing required to comply with legal obligations (e.g., tax records, responding to legal requests).
5. Information Sharing
5.1 Service Providers
We work with trusted third-party service providers to operate our platform. These providers only receive the minimum data necessary to perform their specific functions:
| Service Category | Purpose | Data Shared |
|---|---|---|
| Payment Processing | Cryptocurrency payment verification | Order amount, payment status |
| Email Delivery | Transactional communications | Email address, order info |
| Cloud Infrastructure | Secure data storage & delivery | Encrypted data only |
5.2 We Do NOT Sell Your Data
5.3 Legal Disclosures
We may disclose your information if required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from public authorities
- Protect our rights, privacy, safety, or property
- Investigate potential violations of our Terms of Service
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. When you delete your account, your personal data is permanently removed after a 30-day grace period to allow for account recovery if the deletion was accidental.
7. Data Security
We implement comprehensive security measures to protect your personal information:
AES-256-GCM encryption for sensitive data at rest; TLS 1.3 for data in transit.
Role-based access control; minimal privilege principle for staff access.
Secure cloud infrastructure with DDoS protection, WAF, and regular security audits.
OTP-based email verification; secure password hashing with bcrypt.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data (with certain exceptions for legal compliance).
Right to Data Portability
Receive your data in a structured, commonly used format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent
Withdraw consent at any time for consent-based processing.
To exercise any of these rights, please contact us at privacy@bitloot.com. We will respond within 30 days.
10. Third-Party Services
To operate our Platform effectively, we work with trusted third-party service providers in the following categories:
Payment Processing
We use secure cryptocurrency payment processors to handle transactions. These providers may collect payment-related data (wallet addresses, transaction amounts) in accordance with their own privacy policies.
Infrastructure & Security
We use industry-leading cloud infrastructure and security services to protect our platform and your data. These services may process technical data (IP addresses, request headers) for security and performance purposes.
Email Communications
We use secure email delivery services to send transactional emails (order confirmations, key delivery, account notifications). These services process email addresses and message content to deliver communications.
11. International Data Transfers
BitLoot operates globally, and your data may be processed in countries other than your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by relevant authorities
- Data processing agreements with all service providers
- Encryption of data in transit and at rest
- Compliance with applicable data protection laws
12. Children's Privacy
BitLoot is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@bitloot.com, and we will promptly delete such information.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy with a new "Last Updated" date
- Sending email notification to registered users (for significant changes)
- Displaying a prominent notice on the Platform
We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after changes constitutes acceptance of the updated policy.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters, please indicate this in your subject line.
Your Privacy Matters
At BitLoot, we believe in transparency and respect for your personal data. We're committed to protecting your privacy while providing the best possible digital marketplace experience. If you have any concerns, don't hesitate to reach out.