Privacy Policy
1. Scope
This Policy covers the IXOR website, Telegram bot, payment monitoring, referral program, and support.
IXOR acts as controller where it determines the purposes and means of processing. Telegram, exchanges, blockchain networks, hosting providers, and other vendors process data under their own terms.
2. Data we process
Telegram profile data: numeric identifier, username, name, Telegram Web App authentication data, and identifiers needed to link the website and bot.
Product settings: selected exchanges, filters, minimum ROI, signal types, language, dashboard preferences, subscription status, and expiry.
Payment data: invoice ID, plan, asset, network, expected and received amount, deposit address, transaction hash, block, confirmations, status, and gateway response. We do not request seed phrases or private keys.
Referral data: code or slug, attribution, participant relationships, confirmed purchases, rewards, conversions to subscription days, payout requests, BNB Smart Chain USDT payout address, payout transaction hash, and admin audit trail.
Technical data: IP address, user agent, session cookie, request time, errors, security events, performance data, and diagnostics. We do not request users’ exchange API keys or trading-account contents.
Product analytics: pseudonymous funnel events such as login, trial, filter setup, first delivered signal, graph view, invoice creation, confirmed payment, and renewal. Events are linked with an HMAC pseudonym instead of a Telegram ID; username, IP, wallet address, transaction hash, and message text are not stored in this analytics dataset.
Support data: messages and evidence you voluntarily provide.
3. Sources
We obtain data from you, Telegram authentication, public blockchains and RPC services, CryptoGateway, and automatically from website sessions.
Exchange market data generally relates to markets rather than an identified user.
4. Purposes and legal bases
Contract performance: create an account, save settings, provide trial and subscription access, issue an invoice, confirm payment, deliver signals, and process referral rewards.
Legitimate interests: secure accounts and infrastructure, prevent abuse and duplicate trials, diagnose failures, measure quality, maintain an auditable payment record, and improve the interface.
Legal obligations: keep required financial and technical records, respond to lawful requests, and protect legal rights. Where consent is the basis, it may be withdrawn prospectively.
5. Cookies and local storage
We use necessary cookies for signed or encrypted sessions, CSRF protection, language, and secure login. Pending referral attribution may be stored until registration. Theme and interface preferences may be stored locally in the browser.
Authentication and protected features cannot operate without essential cookies. IXOR currently does not use third-party advertising cookies or sell data for targeting.
6. Sharing
Data may be shared with Telegram for login and messaging; infrastructure providers for hosting, databases, monitoring, backups, and security; and CryptoGateway, RPC providers, and blockchains for issuing and verifying payments.
Blockchain addresses and transactions are public by design. We may disclose data in response to a valid legal demand, to advisers protecting rights, or to a successor in a business reorganization subject to applicable safeguards.
Providers receive only data needed for their function and process it under their terms and applicable law.
7. International processing
Telegram, blockchain nodes, cloud infrastructure, and other providers may operate in multiple countries. Data may therefore be processed outside your country. We apply reasonable contractual and technical safeguards where required.
8. Retention
Account and settings data is retained while the account is used and for a reasonable period afterward for recovery, security, and disputes.
Payment ledger, confirmations, referral accruals, conversions, and payouts are retained as needed for financial integrity, prevention of double use, law, and legal claims. Account deletion must not enable a second trial or reuse of a spent reward.
Short-term logs are rotated under operational policy; incident records may be retained longer. Data no longer needed is deleted, anonymized, or isolated in backups until scheduled rotation.
Product analytics events are retained in the operational database for no more than 400 days and are then automatically deleted.
9. Security
We use secure cookies, CSRF protection, rate limits, access control, admin audit logs, transport encryption, backups, and component separation.
No system is absolutely secure. Protect your Telegram account, device, and wallets, and never send passwords, seed phrases, or private keys.
10. Your rights
Depending on applicable law, you may request access, correction, a copy, restriction, objection, portability, or deletion, withdraw consent, and complain to a supervisory authority.
We may verify identity through the linked Telegram account. Some records cannot be immediately deleted when needed for ledger integrity, fraud prevention, legal obligations, or disputes.
11. Children
The Service is not intended for anyone below the age of independent consent and contracting under applicable law. Contact support if you believe a child supplied data without a lawful basis.
12. Changes and contact
We publish revisions here with a new date and provide an available notice for material changes where required by law.
For privacy requests, use the support form linked from the official @ixor_arbitrage channel. Only authorized administrators can see the request. Never send private keys, seed phrases, or passwords.