SpreadLabs
Features Exchanges Pricing Docs
Telegram community Open dashboard
Legal

Privacy Policy

Version 1.0 Effective 27 August 2026

1. About this policy

This policy explains what personal data SpreadLabs collects, why we collect it, how long we keep it, who we share it with, and what rights you have over it.

It applies to spreadlabs.io, its subdomains, our alert bot on Telegram, and any related service we operate (together, the "Service"). It applies whether or not you hold an account.

It does not apply to the cryptocurrency exchanges whose public market data we display, to Telegram itself, to our payment provider, or to any other third party you deal with directly. Those organisations handle your data under their own policies.

This policy is written to the standard of the EU General Data Protection Regulation (GDPR), which we apply to all users regardless of where they are located. Where Ukrainian law imposes additional or different requirements, those are noted in clause 15.

Terms defined in our Terms of Use have the same meaning here.


2. What we collect

2.1 Data you give us

Account data. When you register: email address, password (stored only as a cryptographic hash — we never see or store your actual password), display name, and timezone.

Alert configuration. The conditions, thresholds, tokens, venues and pairs you set alerts on.

Saved configuration. Watchlists, saved filters, custom widgets and dashboard layouts.

Telegram identifier. If you connect the Alert Bot, we store your Telegram user ID. This is the only way to deliver notifications to you on Telegram. We do not store your Telegram username, phone number, profile photo or contacts.

Correspondence. Anything you write to us by email, including the content of support requests.

2.2 Data we generate about your account

Subscription data. Your plan level, Subscription Period start and end dates, and renewal status.

Payment records. For each payment: the NOWPayments invoice identifier, the amount, the asset, the fiat reference exchange rate applied at invoice generation, and the payment timestamp.

We do not store wallet addresses, private keys, or any payment credentials. Those are held by NOWPayments, not by us. See clause 2.4.

Consent records. When you accept our Terms of Use at registration, we record the date and time, your IP address, the versions of the Terms of Use and this Privacy Policy that you accepted, and the exact wording you were shown. We are legally required to be able to evidence this.

Referral records. If you participate in the referral programme, we record which account referred which, and the Referral Credit granted. Where you arrive through a referral link, the referral code is read from the link at the moment you register and stored against your account. We do not track you across visits for this purpose — see clause 5.3.

2.3 Data collected automatically

Server logs. Our servers record: IP address, timestamp, requested URL, HTTP status code, user-agent string, and referring page.

Usage and click-through data. We record which pages, tokens, pairs and venues you view and interact with, and the sequence in which you do so.

Network and security data. Cloudflare sits in front of our infrastructure and independently logs request metadata, including IP addresses, for security, filtering and abuse prevention.

2.4 Data we deliberately do not collect

We want to be explicit about this, because it is unusual for a platform in this sector:

  • No exchange API keys. We never ask for them and you must never send them to us.
  • No private keys, seed phrases or wallet credentials.
  • No wallet addresses. Payment is handled entirely by NOWPayments.
  • No payment card or bank details. We do not accept fiat payment.
  • No identity documents. We do not perform KYC.
  • No special category data — nothing about health, ethnicity, politics, religion, biometrics or sexual orientation.
  • No data from our Telegram community groups. Those are informal and outside the Service. We do not extract, store or profile member data from them.

3. Why we use your data, and our legal basis

Under GDPR every use of personal data needs a lawful basis. Ours are set out below.

What we use Why Legal basis
Email, password hash, display name, timezone To create and operate your account, authenticate you, and contact you about the Service Contract — Art. 6(1)(b)
Subscription and payment records To give you the access you paid for, process renewals, and handle refunds Contract — Art. 6(1)(b)
Payment records To meet accounting and tax obligations Legal obligation — Art. 6(1)(c)
Consent records (timestamp, IP, version, wording) To evidence that you accepted our Terms, as consumer law requires us to be able to do, and to defend any dispute about it Legal obligation — Art. 6(1)(c); Legal claims — Art. 9(2)(f), Art. 17(3)(e)
Alert configuration and Telegram ID To deliver the alerts you asked for Contract — Art. 6(1)(b)
Saved configuration To store your watchlists, filters and layouts between sessions Contract — Art. 6(1)(b)
Referral records To operate the referral programme and detect abuse of it Contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) for abuse detection
Server logs To keep the Service running, diagnose faults, and investigate incidents Legitimate interests — Art. 6(1)(f)
Cloudflare security logs To protect against attack, abuse and unauthorised access Legitimate interests — Art. 6(1)(f)
Usage and click-through data To understand how the Service is used and improve it Legitimate interests — Art. 6(1)(f)
Correspondence To answer you Contract or Legitimate interests — Art. 6(1)(b) or (f)

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and concluded it is not — the processing is limited to what operating and securing the Service requires. You can object to any of it at any time under clause 10.

We do not sell your personal data. We do not share it for advertising. We do not run advertising on the Service.


4. Marketing

We do not send marketing email.

Every email we send is transactional — it exists because you did something or because we owe you a notice:

  • account verification and password reset
  • payment confirmation and invoice
  • renewal reminder, one day before your Subscription Period ends
  • notice of material changes to our Terms of Use
  • responses to your support requests
  • security or service notices

You cannot unsubscribe from these while you hold an account, because they are how we meet obligations we have to you. If you no longer want them, close your account.

If we ever introduce marketing email, it will be opt-in, and consent will be requested separately.


5. Cookies and similar technologies

We do not display a cookie banner, because we do not set any cookie that requires one.

5.1 What we use

Strictly necessary cookies only. These are needed to deliver a service you have asked for, and under the ePrivacy Directive they do not require consent:

Purpose What it does
Authentication Keeps you logged in between page loads
Security Cloudflare's protection against bots and automated abuse
Preferences you set Remembers interface choices such as timezone or layout

5.2 What we do not use

  • No advertising cookies
  • No tracking or attribution cookies
  • No third-party analytics — no Google Analytics, no Plausible, no PostHog, no equivalent
  • No social media pixels or embedded trackers
  • No cross-site or cross-device tracking
  • No localStorage or similar device storage for tracking purposes

5.3 Referrals do not use cookies

If you arrive through a referral link, the referral code travels in the link itself. It is read when you register and recorded against your account at that point. Nothing is stored on your device, and you are not tracked between visits.

The practical consequence is that a referral is attributed only if you register during the same visit. If you follow a referral link, leave, and come back later through a different route, the referral will not be attributed.

5.4 Analytics without cookies

Our usage analysis (clause 2.3) is carried out from our own server-side logs. It does not use cookies, browser fingerprinting, or any device storage.

5.5 Controlling cookies

You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from logging in.


6. Who we share your data with

We share personal data only with the service providers listed below, only to the extent each needs it, and only under contracts that require them to protect it. We do not sell data, and we do not share it with advertisers, data brokers or analytics companies.

Provider Role What it handles Location
Hetzner Online GmbH Application hosting and database All account, subscription, configuration and log data Germany
The Constant Company (Vultr) Application hosting Account and log data Germany
Hetzner Online GmbH Backup storage Encrypted backups of account, subscription, configuration and log data, held on separate infrastructure from the primary systems, retained on a rolling 7-day cycle Germany
The Constant Company (Vultr) Exchange data collection No personal data — outbound collection of public market data only Japan
Cloudflare, Inc. DNS, security, WAF, email routing Request metadata including IP addresses; inbound email in transit Global edge network
Resend Transactional email delivery Email address and message content EU (eu-west)
Google (Google Workspace) Our own email mailboxes Content of correspondence you send us EU and US
NOWPayments Payment processing Payment data you provide to them directly See their policy
Telegram Alert delivery Your Telegram user ID and alert message content See their policy

We may also disclose data where we are legally required to — for example in response to a binding order from a court or competent authority — or where necessary to establish, exercise or defend legal claims.

If our business is sold or merged, data may transfer to the acquirer, who would remain bound by this policy or a materially equivalent one. We would notify you before that happened.

6.1 A note on NOWPayments and Telegram

NOWPayments processes your payment as an independent controller, not as our processor. When you pay, you interact with them directly. The wallet address you pay from, the blockchain transaction, and any data they collect are governed by their privacy policy, not ours. We receive only the invoice-level records listed at clause 2.2.

Telegram is a third-party messaging platform. To use our Alert Bot you must have a Telegram account, which is a relationship between you and Telegram. We send messages to your Telegram user ID; Telegram controls delivery and stores the message history under its own policy. Our Alert Bot is ours; Telegram is not.


7. Where your data is held

Your account data, configurations, subscription records and logs are stored on servers in the European Union — in Germany, with Hetzner and Vultr. Transactional email is delivered through Resend's EU region.

Three qualifications, stated plainly:

(a) Cloudflare operates a global network. Requests to spreadlabs.io are handled by whichever Cloudflare edge location is nearest to you, which may be outside the EEA. Cloudflare processes this metadata under the European Commission's Standard Contractual Clauses.

(b) Google is a US company. Our own mailboxes are on Google Workspace. Correspondence you send us may be processed in the United States. Google is certified under the EU–US Data Privacy Framework.

(c) We operate from Ukraine. MERCURY SOLUTIONS LLC is a Ukrainian company, and authorised personnel access systems from Ukraine. Ukraine is not the subject of an EU adequacy decision.

Our Tokyo server collects public market data from exchanges. It holds no personal data and no user traffic is routed to it.


8. How long we keep it

Data Retention
Account data While your account is open
Alert and saved configuration While your account is open
Telegram user ID Until you disconnect the Alert Bot, or your account is deleted
Server logs 30 days, then automatically deleted
Cloudflare security logs Per Cloudflare's own retention
Usage and click-through data While your account is open
Payment and invoice records As required by Ukrainian accounting and tax law, which may exceed the life of your account
Consent records For the duration of your account, and 3 years after it closes
Correspondence While needed to handle your query and a reasonable period afterwards
Backups 7 days, on a rolling cycle, after which each backup is overwritten or deleted

8.1 Deleting your account

You can delete your account at any time from your settings, or by emailing [email protected].

When you do:

(a) access ends immediately;

(b) your data enters a 30-day grace period, during which you can contact us to restore the account;

(c) after 30 days, your account data, configurations, Telegram identifier and usage records are permanently deleted from our live systems;

(d) your data may persist in encrypted backups for up to 7 days after that point, and is fully erased no later than 37 days after you request deletion. Backups are isolated, are not used for any operational purpose, and are never restored to recover an individual account. Your data is erased from them as each backup reaches the end of its cycle and is overwritten or deleted;

(e) payment and invoice records are retained where accounting law requires. Consent records — the date, time, IP address and wording of your acceptance of our Terms — are retained for 3 years after your account closes, and then permanently deleted. This period reflects the general limitation period for bringing a legal claim, after which the records serve no further purpose. Both sets of records are kept in isolation, are not used for any other purpose, and are not linked back to any active profile;

(f) deleting your account does not entitle you to a refund. See clause 8 of the Terms of Use.


9. Who is responsible for your data

The controller of your personal data is:

Company MERCURY SOLUTIONS LLC
Registration code (EDRPOU) 46156831
Address 7/9 Yaroslavskyi Lane, Podilskyi District, Kyiv 04071, Ukraine
Privacy contact [email protected]

"Controller" means we decide what data is collected and why.

We have not appointed a Data Protection Officer. We are not a public authority, our core activity is not large-scale monitoring of individuals, and we do not process special category data, so the conditions in Art. 37 GDPR do not apply. Direct all privacy questions to [email protected].


10. Your rights

Under GDPR you have the following rights. All are free to exercise, and you exercise them by emailing [email protected].

Access — a copy of the personal data we hold about you, and an explanation of how we use it.

Rectification — correction of anything inaccurate or incomplete. You can change most account data yourself in settings.

Erasure — deletion of your data, subject to records we are legally required to keep. In practice this means payment and invoice records, and the consent record evidencing your acceptance of our Terms, which we keep for 3 years after your account closes (clause 8.1(e)). Erasing that record would remove the only proof that you agreed to the Terms under which you used the Service, so Art. 17(3)(b) and (e) permit us to retain it.

Restriction — a pause on our use of your data while a dispute about it is resolved.

Portability — your data in a structured, machine-readable format, or transmitted to another provider where technically feasible.

Objection — you may object at any time to processing based on legitimate interests. This includes our collection of usage and click-through data. If you object, we will stop unless we can demonstrate compelling grounds that override your interests.

Withdrawal of consent — where we rely on consent, you may withdraw it at any time. This does not affect processing already carried out.

10.1 How we handle requests

We respond within one month of receiving your request. If a request is complex we may extend this by up to two further months, and we will tell you within the first month if that happens.

We may ask you to verify your identity before acting, to prevent someone else obtaining your data.

10.2 Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects. The Service displays market data and calculated metrics; it does not make decisions about you.

10.3 Complaints

If you think we have handled your data improperly, please contact us first — we would rather resolve it directly.

You also have the right to complain to a supervisory authority. If you are in the EU or UK, you may complain to the authority in your country of residence, place of work, or where the issue occurred. If you are in Ukraine, the competent authority is the Ukrainian Parliament Commissioner for Human Rights.


11. Security

We protect your data with measures appropriate to the risk, including:

  • encryption in transit (TLS) for all connections
  • passwords stored only as cryptographic hashes, never in readable form
  • infrastructure protected by Cloudflare's firewall and abuse filtering
  • access to production systems restricted to authorised personnel
  • encrypted backups held on infrastructure separate from our primary systems, so that data can be restored following a failure
  • no storage of the highest-risk data at all — no exchange API keys, no wallet credentials, no payment details, no identity documents (clause 2.4)

No system is perfectly secure. You are responsible for keeping your password confidential and for activity under your account. Use a strong, unique password, and tell us immediately at [email protected] if you think your account has been accessed without your permission.


12. If there is a data breach

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as Art. 33 GDPR requires.

If the breach is likely to result in a high risk to you, we will notify you directly and without undue delay, and tell you what happened, what data was involved, what we are doing about it, and what you should do.


13. Children

The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.


14. Anonymous visitors

You can browse the public areas of the Platform without an account.

If you do, we still record server logs and Cloudflare security data as described at clause 2.3, including your IP address, because that is how the Service is delivered and protected. We do not link that data to any identity, and it is deleted on the 30-day cycle at clause 8.


15. Ukrainian law

We are established in Ukraine, and in addition to GDPR we are subject to the Law of Ukraine "On Personal Data Protection" (No. 2297-VI).

Where the two regimes differ, we apply whichever gives you stronger protection. In practice this means we apply GDPR standards to all users, including those in Ukraine.

Users in Ukraine have rights under that law which broadly correspond to those in clause 10, including the right to know what data is held, to access it, to have it corrected or deleted, and to complain to the Ukrainian Parliament Commissioner for Human Rights. Exercise them the same way — email [email protected].


16. Changes to this policy

We may update this policy. The current version is always at spreadlabs.io/privacy with a version number and date at the top.

Where a change materially affects how we handle your data — a new purpose, a new category of data, a new recipient, or a longer retention period — we will notify you by email to your account address before it takes effect.

For minor changes such as clarifications, corrections or formatting, we will update the page and the version number without individual notice.

If you do not accept a change, you may delete your account under clause 8.1.


17. Contact

For anything relating to your personal data — questions, requests, complaints, or exercising any right in clause 10:

[email protected]

Or by post:

MERCURY SOLUTIONS LLC
7/9 Yaroslavskyi Lane, Podilskyi District
Kyiv 04071, Ukraine

Email is faster, and is our preferred channel.

SpreadLabs Privacy Policy · v1.0 · effective 27 August 2026 Terms of Use →
SpreadLabs © 2026
Pricing Docs Telegram Privacy Terms