TL;DR. This is a marketing site with a testnet demonstration. We use one essential cookie to remember that you've acknowledged the cookie banner. We do not use any third-party analytics, advertising trackers, or session-recording tools. We collect the bare minimum — server logs, anything you send us, and demo input — and you can email us to delete it.
Who is the controller
The data controller is Steven, sole trader, operating from England, United Kingdom. There is no legal entity behind the operator; this is a one-person business. If you later license and launch a stack of your own, you are the controller for your users' data — not us.
What we collect
We collect different categories depending on how you use the site:
Public website (this site)
- Server access logs: IP address (truncated to /24 within 24h), user-agent string, requested URL, response code, timestamp.
- The cookie-banner acknowledgement (see Cookies below).
Testnet demonstration
- Any value you type into the demo (for example a sample wallet address or worker name) is processed only to run the demonstration. It concerns a test network with no monetary value.
- If the demo signs you in, a session cookie and any optional 2FA setting you enable (TOTP secret or WebAuthn credential metadata, encrypted at rest).
When you contact us
- Your email address and whatever you put in your message, so we can reply and discuss an engagement.
Why we collect it
- Operate the website and demonstration (lawful basis: legitimate interests — running the service you connected to).
- Respond to enquiries and scope software engagements (lawful basis: legitimate interests / steps towards a contract).
- Detect abuse (DDoS, spam, account take-over attempts) — legitimate interests.
Cookies
We use one cookie:
-
gcc_cookies_accepted— valueessential, 365-day expiry, set on first visit when you dismiss the cookie banner. No tracking, no third-party content, no marketing.
If the demonstration signs you in, you additionally receive an HTTP-only session cookie scoped to that demo, valid for 30 days on a sliding window. It is not shared with any third party and is never read by JavaScript.
Who we share with
We do not sell your data. We share it only with:
- Our hosting provider, which stores the server logs on disk.
- Law enforcement or a regulator, if compelled by a valid UK court order or production notice.
Retention
- Server access logs: 30 days, then deleted.
- Demonstration data and any demo sign-in: kept only while needed to run the demo, and reset when the testnet is reset.
- Enquiry emails: kept while we are in contact and for a reasonable period afterwards, then deleted.
Your rights
Under UK GDPR you have the right to:
- Access the data we hold about you.
- Correct anything that's wrong.
- Have it deleted (subject to any legal retention requirements).
- Restrict or object to processing.
- Receive a copy in a portable format.
- Complain to the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these, email steven@getcrypto.co.in. We aim to respond within 30 days as required by the Regulation. There is no charge.
Security
Our infrastructure runs hardened, fail2ban-monitored, key-only-SSH servers behind a UFW firewall. All traffic is served over TLS. Any data at rest is encrypted using a master key held only on the operator's machine. We collect as little as possible in the first place.
No system is ever fully secure. If we are compromised in a way that affects your data, we will notify you and the ICO within 72 hours as required.
Contact
Privacy questions: steven@getcrypto.co.in. Postal address available on request.