Staking plans How it works FAQ Get the app About us Sign in Create account
Legal

Privacy policy

We collect the minimum data needed to run your account safely, we never sell it, and you can ask for a copy or deletion at any time. This policy explains exactly what is stored, why, for how long and who can access it.

Last updated September 5, 2026 Version 2.0 About 9 minutes to read [email protected]

1. Who is responsible

TWS Wallet, operator of twswallet.com, is the controller of the personal data described here. Questions and requests can be sent to [email protected]; write "Privacy" in the subject line so the request is routed to the right person.

2. Data we collect

CategoryExamplesSource
Account dataE-mail address, username, full name, hashed password, referral code, date of registrationYou, at registration and in Settings
Financial ledgerDeposits, stakes, rewards, withdrawals, balance history, withdrawal addresses, payment references and transaction hashesGenerated by your use of the Platform
Security dataIP address, country (from our CDN), browser and device type, time of each sign-in, password changes, security alertsCollected automatically
Usage dataPages viewed, time of visit, referring site, session length, anonymous visitor identifierCollected automatically (see section 4)
CommunicationsMessages you send through the contact form or by e-mail, support notes about your accountYou
Verification dataWhere we need to verify identity or source of funds: identity document details, proof of address, proof of wallet ownershipYou, on request

We do not collect seed phrases, private keys, exchange passwords or card details. We never ask for them.

3. Why we use it and legal basis

  • To provide the service (contract): create and run your account, credit deposits, run stakes, pay rewards and withdrawals, show your history.
  • To keep accounts secure (legitimate interest and legal obligation): detect sign-ins from new locations, block fraud and account takeover, review withdrawals, keep an audit trail of administrative actions.
  • To meet legal duties (legal obligation): anti-money-laundering and sanctions checks, responding to lawful requests, tax and accounting record-keeping.
  • To improve the Platform (legitimate interest): understand which pages are used, on which devices, and where performance is slow.
  • To communicate with you (contract and legitimate interest): in-app notifications and e-mails about deposits, rewards, withdrawals, security and changes to terms.

Where we rely on legitimate interest we have balanced it against your rights; you can object as described in section 10.

4. Cookies and analytics

We use only first-party cookies that are needed for the Platform to work or to measure its use. No advertising or cross-site tracking cookies are set.

CookiePurposeLifetime
sessionKeeps you signed in and protects forms against cross-site request forgerySession, or 30 days with "keep me signed in"
remember_tokenRestores your session when you chose "keep me signed in"30 days
ts_vidRandom visitor identifier used for aggregate visit statistics (unique visitors, new vs returning)12 months
ts_sidRandom session identifier used to count sessions and pages per session30 minutes of inactivity
tw-themeRemembers light or dark theme (stored in your browser, not sent to us)Until cleared

Our visit statistics are generated on our own server; no third-party analytics service receives your data. The statistics record the page path, time, referring site, country, browser and device type, the visitor identifier and, for signed-in members, the account. They are kept for 90 days and are visible only to our support team.

5. Blockchain data

Deposits and withdrawals are transactions on public blockchains. The addresses, amounts and transaction hashes involved are permanently and publicly visible on those networks and cannot be deleted by us or anyone else. We store the transaction hash and address in your ledger so you can verify each payment. Our system reads public blockchain explorers to detect incoming payments; it does not send your personal data to them beyond the address being checked.

6. Who we share data with

  • Infrastructure providers: our hosting provider and content-delivery network (Cloudflare), which process traffic to deliver the site and protect it from attacks.
  • E-mail delivery: the mail service that sends account and security e-mails.
  • Price and blockchain data providers: public APIs used to price deposits and to detect payments; they receive the address or asset being looked up, not your identity.
  • Authorities and advisers: where required by law, to protect our rights or to prevent fraud.

We do not sell personal data and we do not share it with advertisers or data brokers.

7. International transfers

Our servers and providers may be located in countries other than yours. Where data leaves the region in which it was collected, we rely on the provider's contractual safeguards (such as standard contractual clauses) and on technical measures like encryption in transit and at rest.

8. How long we keep data

DataRetention
Account profileWhile the account is open. On closure the profile is anonymised (e-mail and username replaced) within 30 days.
Financial ledgerKept for the period required by accounting and anti-money-laundering rules, typically 5 to 7 years after the last transaction, then deleted.
Security log (sign-ins, alerts)12 months.
Visit statistics90 days, then deleted automatically.
Support messages24 months after the conversation is closed.
Verification documentsDeleted once verification is complete, unless law requires retention.

9. How we protect data

  • All connections use HTTPS; the site is served through a CDN with DDoS protection.
  • Passwords are stored as salted hashes and are never visible to staff.
  • Administrative access is limited to named staff, every administrative action is written to an audit log, and withdrawals require a manual review.
  • You are alerted in-app when your account is accessed from a new IP address or your password changes.
  • Receiving addresses are derived from public keys only; no private keys are kept on the web server.
  • Backups are encrypted and access-controlled.

10. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and to lodge a complaint with your data-protection authority. You can exercise most of these yourself:

  • Access and portability: your dashboard shows every transaction; the Wallet page offers a CSV export of your full ledger.
  • Correction: update your name and password in Settings; contact us to change the e-mail address.
  • Deletion: close your account in Settings (once no stakes are active and the balance is withdrawn). Ledger data that we must keep by law is retained in anonymised form.
  • Objection: to object to visit statistics, block or delete the ts_vid and ts_sid cookies in your browser.

For anything else, e-mail [email protected]. We answer within 30 days and may ask you to confirm your identity first.

11. Notifications and e-mail

Service messages (deposit confirmed, withdrawal paid, security alerts, changes to terms) are part of running your account and cannot be switched off while the account is open. We do not send marketing e-mail unless you opt in, and every such e-mail contains an unsubscribe link.

12. Children

The Platform is not intended for anyone under 18. We do not knowingly collect data from minors; if you believe a minor has opened an account, contact us and we will close it and delete the data.

13. Changes to this policy

We will post any changes on this page and update the date above. If a change materially affects how we use your data, we will also notify you in-app before it takes effect.

14. Contact

TWS Wallet · twswallet.com · [email protected] (subject "Privacy") · or use the contact form.