Privacy Policy
1. About this policy
This policy explains what personal data SpreadLabs collects, why we collect it, how long we keep it, who we share it with, and what rights you have over it.
It applies to spreadlabs.io, its subdomains, our alert bot on Telegram, and any related service we operate (together, the "Service"). It applies whether or not you hold an account.
It does not apply to the cryptocurrency exchanges whose public market data we display, to Telegram itself, to our payment provider, or to any other third party you deal with directly. Those organisations handle your data under their own policies.
This policy is written to the standard of the EU General Data Protection Regulation (GDPR), which we apply to all users regardless of where they are located. Where Ukrainian law imposes additional or different requirements, those are noted in clause 15.
Terms defined in our Terms of Use have the same meaning here.
2. What we collect
2.1 Data you give us
Account data. When you register: email address, password (stored only as a cryptographic hash — we never see or store your actual password), display name, and timezone.
Alert configuration. The conditions, thresholds, tokens, venues and pairs you set alerts on.
Saved configuration. Watchlists, saved filters, custom widgets and dashboard layouts.
Telegram identifier. If you connect the Alert Bot, we store your Telegram user ID. This is the only way to deliver notifications to you on Telegram. We do not store your Telegram username, phone number, profile photo or contacts.
Correspondence. Anything you write to us by email, including the content of support requests.
2.2 Data we generate about your account
Subscription data. Your plan level, Subscription Period start and end dates, and renewal status.
Payment records. For each payment: the NOWPayments invoice identifier, the amount, the asset, the fiat reference exchange rate applied at invoice generation, and the payment timestamp.
We do not store wallet addresses, private keys, or any payment credentials. Those are held by NOWPayments, not by us. See clause 2.4.
Consent records. When you accept our Terms of Use at registration, we record the date and time, your IP address, the versions of the Terms of Use and this Privacy Policy that you accepted, and the exact wording you were shown. We are legally required to be able to evidence this.
Referral records. If you participate in the referral programme, we record which account referred which, and the Referral Credit granted. Where you arrive through a referral link, the referral code is read from the link at the moment you register and stored against your account. We do not track you across visits for this purpose — see clause 5.3.
2.3 Data collected automatically
Server logs. Our servers record: IP address, timestamp, requested URL, HTTP status code, user-agent string, and referring page.
Usage and click-through data. We record which pages, tokens, pairs and venues you view and interact with, and the sequence in which you do so.
Network and security data. Cloudflare sits in front of our infrastructure and independently logs request metadata, including IP addresses, for security, filtering and abuse prevention.
2.4 Data we deliberately do not collect
We want to be explicit about this, because it is unusual for a platform in this sector:
- No exchange API keys. We never ask for them and you must never send them to us.
- No private keys, seed phrases or wallet credentials.
- No wallet addresses. Payment is handled entirely by NOWPayments.
- No payment card or bank details. We do not accept fiat payment.
- No identity documents. We do not perform KYC.
- No special category data — nothing about health, ethnicity, politics, religion, biometrics or sexual orientation.
- No data from our Telegram community groups. Those are informal and outside the Service. We do not extract, store or profile member data from them.
3. Why we use your data, and our legal basis
Under GDPR every use of personal data needs a lawful basis. Ours are set out below.
| What we use | Why | Legal basis |
|---|---|---|
| Email, password hash, display name, timezone | To create and operate your account, authenticate you, and contact you about the Service | Contract — Art. 6(1)(b) |
| Subscription and payment records | To give you the access you paid for, process renewals, and handle refunds | Contract — Art. 6(1)(b) |
| Payment records | To meet accounting and tax obligations | Legal obligation — Art. 6(1)(c) |
| Consent records (timestamp, IP, version, wording) | To evidence that you accepted our Terms, as consumer law requires us to be able to do, and to defend any dispute about it | Legal obligation — Art. 6(1)(c); Legal claims — Art. 9(2)(f), Art. 17(3)(e) |
| Alert configuration and Telegram ID | To deliver the alerts you asked for | Contract — Art. 6(1)(b) |
| Saved configuration | To store your watchlists, filters and layouts between sessions | Contract — Art. 6(1)(b) |
| Referral records | To operate the referral programme and detect abuse of it | Contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) for abuse detection |
| Server logs | To keep the Service running, diagnose faults, and investigate incidents | Legitimate interests — Art. 6(1)(f) |
| Cloudflare security logs | To protect against attack, abuse and unauthorised access | Legitimate interests — Art. 6(1)(f) |
| Usage and click-through data | To understand how the Service is used and improve it | Legitimate interests — Art. 6(1)(f) |
| Correspondence | To answer you | Contract or Legitimate interests — Art. 6(1)(b) or (f) |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and concluded it is not — the processing is limited to what operating and securing the Service requires. You can object to any of it at any time under clause 10.
We do not sell your personal data. We do not share it for advertising. We do not run advertising on the Service.
4. Marketing
We do not send marketing email.
Every email we send is transactional — it exists because you did something or because we owe you a notice:
- account verification and password reset
- payment confirmation and invoice
- renewal reminder, one day before your Subscription Period ends
- notice of material changes to our Terms of Use
- responses to your support requests
- security or service notices
You cannot unsubscribe from these while you hold an account, because they are how we meet obligations we have to you. If you no longer want them, close your account.
If we ever introduce marketing email, it will be opt-in, and consent will be requested separately.
5. Cookies and similar technologies
We do not display a cookie banner, because we do not set any cookie that requires one.
5.1 What we use
Strictly necessary cookies only. These are needed to deliver a service you have asked for, and under the ePrivacy Directive they do not require consent:
| Purpose | What it does |
|---|---|
| Authentication | Keeps you logged in between page loads |
| Security | Cloudflare's protection against bots and automated abuse |
| Preferences you set | Remembers interface choices such as timezone or layout |
5.2 What we do not use
- No advertising cookies
- No tracking or attribution cookies
- No third-party analytics — no Google Analytics, no Plausible, no PostHog, no equivalent
- No social media pixels or embedded trackers
- No cross-site or cross-device tracking
- No localStorage or similar device storage for tracking purposes
5.3 Referrals do not use cookies
If you arrive through a referral link, the referral code travels in the link itself. It is read when you register and recorded against your account at that point. Nothing is stored on your device, and you are not tracked between visits.
The practical consequence is that a referral is attributed only if you register during the same visit. If you follow a referral link, leave, and come back later through a different route, the referral will not be attributed.
5.4 Analytics without cookies
Our usage analysis (clause 2.3) is carried out from our own server-side logs. It does not use cookies, browser fingerprinting, or any device storage.
5.5 Controlling cookies
You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from logging in.
6. Who we share your data with
We share personal data only with the service providers listed below, only to the extent each needs it, and only under contracts that require them to protect it. We do not sell data, and we do not share it with advertisers, data brokers or analytics companies.
| Provider | Role | What it handles | Location |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting and database | All account, subscription, configuration and log data | Germany |
| The Constant Company (Vultr) | Application hosting | Account and log data | Germany |
| Hetzner Online GmbH | Backup storage | Encrypted backups of account, subscription, configuration and log data, held on separate infrastructure from the primary systems, retained on a rolling 7-day cycle | Germany |
| The Constant Company (Vultr) | Exchange data collection | No personal data — outbound collection of public market data only | Japan |
| Cloudflare, Inc. | DNS, security, WAF, email routing | Request metadata including IP addresses; inbound email in transit | Global edge network |
| Resend | Transactional email delivery | Email address and message content | EU (eu-west) |
| Google (Google Workspace) | Our own email mailboxes | Content of correspondence you send us | EU and US |
| NOWPayments | Payment processing | Payment data you provide to them directly | See their policy |
| Telegram | Alert delivery | Your Telegram user ID and alert message content | See their policy |
We may also disclose data where we are legally required to — for example in response to a binding order from a court or competent authority — or where necessary to establish, exercise or defend legal claims.
If our business is sold or merged, data may transfer to the acquirer, who would remain bound by this policy or a materially equivalent one. We would notify you before that happened.
6.1 A note on NOWPayments and Telegram
NOWPayments processes your payment as an independent controller, not as our processor. When you pay, you interact with them directly. The wallet address you pay from, the blockchain transaction, and any data they collect are governed by their privacy policy, not ours. We receive only the invoice-level records listed at clause 2.2.
Telegram is a third-party messaging platform. To use our Alert Bot you must have a Telegram account, which is a relationship between you and Telegram. We send messages to your Telegram user ID; Telegram controls delivery and stores the message history under its own policy. Our Alert Bot is ours; Telegram is not.
7. Where your data is held
Your account data, configurations, subscription records and logs are stored on servers in the European Union — in Germany, with Hetzner and Vultr. Transactional email is delivered through Resend's EU region.
Three qualifications, stated plainly:
(a) Cloudflare operates a global network. Requests to spreadlabs.io are handled by whichever Cloudflare edge location is nearest to you, which may be outside the EEA. Cloudflare processes this metadata under the European Commission's Standard Contractual Clauses.
(b) Google is a US company. Our own mailboxes are on Google Workspace. Correspondence you send us may be processed in the United States. Google is certified under the EU–US Data Privacy Framework.
(c) We operate from Ukraine. MERCURY SOLUTIONS LLC is a Ukrainian company, and authorised personnel access systems from Ukraine. Ukraine is not the subject of an EU adequacy decision.
Our Tokyo server collects public market data from exchanges. It holds no personal data and no user traffic is routed to it.
8. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is open |
| Alert and saved configuration | While your account is open |
| Telegram user ID | Until you disconnect the Alert Bot, or your account is deleted |
| Server logs | 30 days, then automatically deleted |
| Cloudflare security logs | Per Cloudflare's own retention |
| Usage and click-through data | While your account is open |
| Payment and invoice records | As required by Ukrainian accounting and tax law, which may exceed the life of your account |
| Consent records | For the duration of your account, and 3 years after it closes |
| Correspondence | While needed to handle your query and a reasonable period afterwards |
| Backups | 7 days, on a rolling cycle, after which each backup is overwritten or deleted |
8.1 Deleting your account
You can delete your account at any time from your settings, or by emailing [email protected].
When you do:
(a) access ends immediately;
(b) your data enters a 30-day grace period, during which you can contact us to restore the account;
(c) after 30 days, your account data, configurations, Telegram identifier and usage records are permanently deleted from our live systems;
(d) your data may persist in encrypted backups for up to 7 days after that point, and is fully erased no later than 37 days after you request deletion. Backups are isolated, are not used for any operational purpose, and are never restored to recover an individual account. Your data is erased from them as each backup reaches the end of its cycle and is overwritten or deleted;
(e) payment and invoice records are retained where accounting law requires. Consent records — the date, time, IP address and wording of your acceptance of our Terms — are retained for 3 years after your account closes, and then permanently deleted. This period reflects the general limitation period for bringing a legal claim, after which the records serve no further purpose. Both sets of records are kept in isolation, are not used for any other purpose, and are not linked back to any active profile;
(f) deleting your account does not entitle you to a refund. See clause 8 of the Terms of Use.
9. Who is responsible for your data
The controller of your personal data is:
| Company | MERCURY SOLUTIONS LLC |
| Registration code (EDRPOU) | 46156831 |
| Address | 7/9 Yaroslavskyi Lane, Podilskyi District, Kyiv 04071, Ukraine |
| Privacy contact | [email protected] |
"Controller" means we decide what data is collected and why.
We have not appointed a Data Protection Officer. We are not a public authority, our core activity is not large-scale monitoring of individuals, and we do not process special category data, so the conditions in Art. 37 GDPR do not apply. Direct all privacy questions to [email protected].
10. Your rights
Under GDPR you have the following rights. All are free to exercise, and you exercise them by emailing [email protected].
Access — a copy of the personal data we hold about you, and an explanation of how we use it.
Rectification — correction of anything inaccurate or incomplete. You can change most account data yourself in settings.
Erasure — deletion of your data, subject to records we are legally required to keep. In practice this means payment and invoice records, and the consent record evidencing your acceptance of our Terms, which we keep for 3 years after your account closes (clause 8.1(e)). Erasing that record would remove the only proof that you agreed to the Terms under which you used the Service, so Art. 17(3)(b) and (e) permit us to retain it.
Restriction — a pause on our use of your data while a dispute about it is resolved.
Portability — your data in a structured, machine-readable format, or transmitted to another provider where technically feasible.
Objection — you may object at any time to processing based on legitimate interests. This includes our collection of usage and click-through data. If you object, we will stop unless we can demonstrate compelling grounds that override your interests.
Withdrawal of consent — where we rely on consent, you may withdraw it at any time. This does not affect processing already carried out.
10.1 How we handle requests
We respond within one month of receiving your request. If a request is complex we may extend this by up to two further months, and we will tell you within the first month if that happens.
We may ask you to verify your identity before acting, to prevent someone else obtaining your data.
10.2 Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects. The Service displays market data and calculated metrics; it does not make decisions about you.
10.3 Complaints
If you think we have handled your data improperly, please contact us first — we would rather resolve it directly.
You also have the right to complain to a supervisory authority. If you are in the EU or UK, you may complain to the authority in your country of residence, place of work, or where the issue occurred. If you are in Ukraine, the competent authority is the Ukrainian Parliament Commissioner for Human Rights.
11. Security
We protect your data with measures appropriate to the risk, including:
- encryption in transit (TLS) for all connections
- passwords stored only as cryptographic hashes, never in readable form
- infrastructure protected by Cloudflare's firewall and abuse filtering
- access to production systems restricted to authorised personnel
- encrypted backups held on infrastructure separate from our primary systems, so that data can be restored following a failure
- no storage of the highest-risk data at all — no exchange API keys, no wallet credentials, no payment details, no identity documents (clause 2.4)
No system is perfectly secure. You are responsible for keeping your password confidential and for activity under your account. Use a strong, unique password, and tell us immediately at [email protected] if you think your account has been accessed without your permission.
12. If there is a data breach
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as Art. 33 GDPR requires.
If the breach is likely to result in a high risk to you, we will notify you directly and without undue delay, and tell you what happened, what data was involved, what we are doing about it, and what you should do.
13. Children
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.
14. Anonymous visitors
You can browse the public areas of the Platform without an account.
If you do, we still record server logs and Cloudflare security data as described at clause 2.3, including your IP address, because that is how the Service is delivered and protected. We do not link that data to any identity, and it is deleted on the 30-day cycle at clause 8.
15. Ukrainian law
We are established in Ukraine, and in addition to GDPR we are subject to the Law of Ukraine "On Personal Data Protection" (No. 2297-VI).
Where the two regimes differ, we apply whichever gives you stronger protection. In practice this means we apply GDPR standards to all users, including those in Ukraine.
Users in Ukraine have rights under that law which broadly correspond to those in clause 10, including the right to know what data is held, to access it, to have it corrected or deleted, and to complain to the Ukrainian Parliament Commissioner for Human Rights. Exercise them the same way — email [email protected].
16. Changes to this policy
We may update this policy. The current version is always at spreadlabs.io/privacy with a version number and date at the top.
Where a change materially affects how we handle your data — a new purpose, a new category of data, a new recipient, or a longer retention period — we will notify you by email to your account address before it takes effect.
For minor changes such as clarifications, corrections or formatting, we will update the page and the version number without individual notice.
If you do not accept a change, you may delete your account under clause 8.1.
17. Contact
For anything relating to your personal data — questions, requests, complaints, or exercising any right in clause 10:
Or by post:
MERCURY SOLUTIONS LLC
7/9 Yaroslavskyi Lane, Podilskyi District
Kyiv 04071, Ukraine
Email is faster, and is our preferred channel.