1. Who is responsible
TWS Wallet, operator of twswallet.com, is the controller of the personal data described here. Questions and requests can be sent to [email protected]; write "Privacy" in the subject line so the request is routed to the right person.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | E-mail address, username, full name, hashed password, referral code, date of registration | You, at registration and in Settings |
| Financial ledger | Deposits, stakes, rewards, withdrawals, balance history, withdrawal addresses, payment references and transaction hashes | Generated by your use of the Platform |
| Security data | IP address, country (from our CDN), browser and device type, time of each sign-in, password changes, security alerts | Collected automatically |
| Usage data | Pages viewed, time of visit, referring site, session length, anonymous visitor identifier | Collected automatically (see section 4) |
| Communications | Messages you send through the contact form or by e-mail, support notes about your account | You |
| Verification data | Where we need to verify identity or source of funds: identity document details, proof of address, proof of wallet ownership | You, on request |
We do not collect seed phrases, private keys, exchange passwords or card details. We never ask for them.
3. Why we use it and legal basis
- To provide the service (contract): create and run your account, credit deposits, run stakes, pay rewards and withdrawals, show your history.
- To keep accounts secure (legitimate interest and legal obligation): detect sign-ins from new locations, block fraud and account takeover, review withdrawals, keep an audit trail of administrative actions.
- To meet legal duties (legal obligation): anti-money-laundering and sanctions checks, responding to lawful requests, tax and accounting record-keeping.
- To improve the Platform (legitimate interest): understand which pages are used, on which devices, and where performance is slow.
- To communicate with you (contract and legitimate interest): in-app notifications and e-mails about deposits, rewards, withdrawals, security and changes to terms.
Where we rely on legitimate interest we have balanced it against your rights; you can object as described in section 10.
4. Cookies and analytics
We use only first-party cookies that are needed for the Platform to work or to measure its use. No advertising or cross-site tracking cookies are set.
| Cookie | Purpose | Lifetime |
|---|---|---|
| session | Keeps you signed in and protects forms against cross-site request forgery | Session, or 30 days with "keep me signed in" |
| remember_token | Restores your session when you chose "keep me signed in" | 30 days |
| ts_vid | Random visitor identifier used for aggregate visit statistics (unique visitors, new vs returning) | 12 months |
| ts_sid | Random session identifier used to count sessions and pages per session | 30 minutes of inactivity |
| tw-theme | Remembers light or dark theme (stored in your browser, not sent to us) | Until cleared |
Our visit statistics are generated on our own server; no third-party analytics service receives your data. The statistics record the page path, time, referring site, country, browser and device type, the visitor identifier and, for signed-in members, the account. They are kept for 90 days and are visible only to our support team.
5. Blockchain data
Deposits and withdrawals are transactions on public blockchains. The addresses, amounts and transaction hashes involved are permanently and publicly visible on those networks and cannot be deleted by us or anyone else. We store the transaction hash and address in your ledger so you can verify each payment. Our system reads public blockchain explorers to detect incoming payments; it does not send your personal data to them beyond the address being checked.
6. Who we share data with
- Infrastructure providers: our hosting provider and content-delivery network (Cloudflare), which process traffic to deliver the site and protect it from attacks.
- E-mail delivery: the mail service that sends account and security e-mails.
- Price and blockchain data providers: public APIs used to price deposits and to detect payments; they receive the address or asset being looked up, not your identity.
- Authorities and advisers: where required by law, to protect our rights or to prevent fraud.
We do not sell personal data and we do not share it with advertisers or data brokers.
7. International transfers
Our servers and providers may be located in countries other than yours. Where data leaves the region in which it was collected, we rely on the provider's contractual safeguards (such as standard contractual clauses) and on technical measures like encryption in transit and at rest.
8. How long we keep data
| Data | Retention |
|---|---|
| Account profile | While the account is open. On closure the profile is anonymised (e-mail and username replaced) within 30 days. |
| Financial ledger | Kept for the period required by accounting and anti-money-laundering rules, typically 5 to 7 years after the last transaction, then deleted. |
| Security log (sign-ins, alerts) | 12 months. |
| Visit statistics | 90 days, then deleted automatically. |
| Support messages | 24 months after the conversation is closed. |
| Verification documents | Deleted once verification is complete, unless law requires retention. |
9. How we protect data
- All connections use HTTPS; the site is served through a CDN with DDoS protection.
- Passwords are stored as salted hashes and are never visible to staff.
- Administrative access is limited to named staff, every administrative action is written to an audit log, and withdrawals require a manual review.
- You are alerted in-app when your account is accessed from a new IP address or your password changes.
- Receiving addresses are derived from public keys only; no private keys are kept on the web server.
- Backups are encrypted and access-controlled.
10. Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and to lodge a complaint with your data-protection authority. You can exercise most of these yourself:
- Access and portability: your dashboard shows every transaction; the Wallet page offers a CSV export of your full ledger.
- Correction: update your name and password in Settings; contact us to change the e-mail address.
- Deletion: close your account in Settings (once no stakes are active and the balance is withdrawn). Ledger data that we must keep by law is retained in anonymised form.
- Objection: to object to visit statistics, block or delete the
ts_vidandts_sidcookies in your browser.
For anything else, e-mail [email protected]. We answer within 30 days and may ask you to confirm your identity first.
11. Notifications and e-mail
Service messages (deposit confirmed, withdrawal paid, security alerts, changes to terms) are part of running your account and cannot be switched off while the account is open. We do not send marketing e-mail unless you opt in, and every such e-mail contains an unsubscribe link.
12. Children
The Platform is not intended for anyone under 18. We do not knowingly collect data from minors; if you believe a minor has opened an account, contact us and we will close it and delete the data.
13. Changes to this policy
We will post any changes on this page and update the date above. If a change materially affects how we use your data, we will also notify you in-app before it takes effect.
14. Contact
TWS Wallet · twswallet.com · [email protected] (subject "Privacy") · or use the contact form.