1. Overview
CoinSir (hereinafter "the Company") values the privacy of its users and complies with the Korean Personal Information Protection Act (PIPA), the Act on Promotion of Information and Communications Network Utilization and Information Protection, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA). This policy explains the categories of personal data we collect, purposes of processing, retention periods, third-party disclosures, and user rights.
2. Personal Data Collected
We collect the following personal data to provide our services:
Required
- Email address
- Password (stored encrypted)
- Service usage records and subscription information
Optional
- Google OAuth2 authentication data (for social login)
- Creem payment transaction information (for paid services)
- Telegram user ID (for Telegram alerts)
- Device push token (FCM registration token) — when receiving mobile app push alerts
Automatically Collected
- IP address, browser type, access timestamps
- Service usage logs (page visits, alert history)
- Information collected via cookies and similar technologies (see Section 7)
3. Purpose of Collection and Use
- Account registration, authentication, and management
- Delivering cryptocurrency price fluctuation alerts
- Subscription management, payment processing, and refunds
- Customer support and dispute resolution
- Service improvement, analytics, and new feature development
- Fraud prevention and security maintenance
- Legal compliance (tax, accounting, law enforcement cooperation)
4. Data Retention and Destruction
Personal data is destroyed without delay once the purpose of collection is fulfilled. However, the following data may be retained as required by law:
- Records of contracts or subscription withdrawal: 5 years (E-Commerce Act)
- Records of payment and supply of goods: 5 years (E-Commerce Act)
- Records of consumer complaints or dispute resolution: 3 years (E-Commerce Act)
- Login records: 3 months (Protection of Communications Secrets Act)
- Upon account deletion: destroyed immediately after legally required retention periods expire
5. Data Processing Delegation
We delegate data processing to the following service providers:
- Creem (Creem Inc.) — Payment processing
- Google LLC — OAuth authentication, cloud infrastructure (Google Cloud Platform)
- Delegated processors handle personal data only within the scope of their delegated purpose, and we fulfill our duty of management and supervision.
6. Disclosure to Third Parties
We do not disclose personal data to third parties as a matter of principle. Exceptions are limited to:
- When the user has given prior consent
- When required by law enforcement or investigative authorities under applicable law
- When minimum necessary information must be provided to payment processors
7. Use of Cookies
We use cookies for the following purposes:
- Session management and login state persistence (JWT tokens)
- CSRF protection security cookies
- Google OAuth2 authentication cookies
- User preference settings (e.g., language selection)
8. Cross-Border Transfers
Your personal data may be transferred internationally for service operations:
- Google Cloud Platform (US/Global) — Cloud infrastructure
- Creem (US) — Payment processing
9. Your Rights
You (or your legal representative) may exercise the following rights at any time:
- Access, correction, or deletion of personal data
- Suspension (restriction) of data processing
- Account deletion and withdrawal of consent
- Data portability (request transfer to another service)
Additional Rights for EU/EEA Residents (GDPR)
- Right to restriction of processing
- Right to object to processing
- Right to refuse automated decision-making
- Right to lodge a complaint with a supervisory authority
Additional Rights for California Residents (CCPA/CPRA)
- Right to know the categories and purposes of collected data
- Right to request deletion of personal information
- Right to opt out of data sales/sharing (we do not sell personal data)
- Right to non-discrimination for exercising your rights
10. Security Measures
We implement the following measures to protect your personal data:
- Encrypted password storage (bcrypt hashing)
- Data transmission encryption via HTTPS/TLS
- Access control management and minimization
- Regular security vulnerability assessments
- Access log monitoring and management
11. Data Protection Officer
For inquiries, complaints, or to exercise your rights regarding data processing, please contact:
- Email: hello@coinsir.net
- Response time: Within 10 business days
12. Remedies for Rights Infringement
If you need assistance regarding a personal data breach, you may contact the following organizations (Korea):
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
- Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- Supreme Prosecutors' Office Cyber Investigation Division (spo.go.kr / 1301)
- National Police Agency Cyber Bureau (police.go.kr / 182)
13. Policy Changes
This policy is effective from March 20, 2026. If changes are made due to amendments in laws, policies, or security technologies, we will announce them through the service at least 7 days prior to the effective date.