Legal

Privacy Policy

What we collect, why, who we share it with, and how to get it deleted.

Last updated

1. Who we are

BTCFi.ai is a non-custodial Ordinals NFT marketplace aggregator operated by Octus GmbH, Grabenstrasse 15A, 6340 Baar, Canton of Zug, Switzerland (CHE-454.761.214) — part of the Uniside group. Full company details are in our imprint. Octus GmbH is the data controller for the personal data described below. For privacy questions or to exercise your rights, write to privacy@btcfi.ai.

2. What we collect

We collect the minimum needed to operate the service.

DataWhyRetention
Your Bitcoin address, when you connect a walletTo display the inscriptions you own and your watchlistWhile you use the service, then 30 days
A one-way hash of your IP address — never the raw IPRate limiting and abuse detection90 days
User-Agent stringBrowser compatibility checks30 days
Page views, viewport size, web vitalsProduct analytics and performance monitoring90 days, aggregated thereafter
Watchlist and cart contentsSo they persist across reloads and devicesUntil you remove them; carts clear after 24h

What we never collect: private keys, seed phrases, or mnemonics — ever. Nor email addresses, real names, phone numbers, KYC documents, or persistent advertising identifiers. There is no signup and no account.

3. Why we may process it

PurposeLawful basis (GDPR Art. 6)
Operating the marketplacePerformance of contract — Art. 6(1)(b)
Rate limiting and abuse preventionLegitimate interest — Art. 6(1)(f)
Service-quality analyticsLegitimate interest — Art. 6(1)(f)
Complying with lawLegal obligation — Art. 6(1)(c)

4. Who we share it with

Only the processors below, only for the stated purpose. We do not sell, lease, or trade your data, share it with advertising networks, or use it to train AI models.

ProcessorPurposeRegion
Vercel Inc.Frontend hostingUS, with EU edge
Railway Corp.Backend, database, and cache hostingUS (US East)
Cloudflare Inc.Authoritative DNS and email routingGlobal
Marketplace partnersPublic listing and sales data for the venues we aggregate. Ordinals Wallet is the only venue enabled today; the live set is reported by /health/adapters.Various

During Phase 1 browsing we query those marketplaces for public listing data only — we do not send them your wallet address. When you follow a link to complete a purchase, you are interacting with that marketplace directly, under its own privacy policy.

5. International transfers

Where we transfer data outside Switzerland or the EEA — for example to the US-based hosts above — we rely on Swiss adequacy via the Swiss–US Data Privacy Framework, GDPR adequacy via the EU–US Data Privacy Framework, and EU Standard Contractual Clauses as an additional safeguard. You may request a copy of the clauses at privacy@btcfi.ai.

6. Your rights

Under the FADP and GDPR you may:

  • Access the personal data we hold about you
  • Have inaccurate data corrected
  • Have your data erased
  • Restrict or object to processing based on legitimate interest
  • Receive your data in a machine-readable format
  • Lodge a complaint with a supervisory authority — the FDPIC in Switzerland, or your local DPA in the EU

To exercise any of these, email privacy@btcfi.ai. We respond within 30 days. For anything stored in your browser — watchlist, cart, recently viewed — you can erase it yourself at any time by clearing this site’s data.

7. Cookies and local storage

We use no advertising cookies and no third-party analytics. Everything below is first-party and functional.

KeyPurposeLifetime
btcfi:walletRemembers your connected walletUntil you disconnect
btcfi:cartPersists your cart24 hours
btcfi:themeRemembers your display preferenceUntil cleared
Service Worker cacheOffline-first asset caching7 days

8. Security

  • TLS in transit for every connection between your browser and the service
  • Database and cache traffic runs on the hosting provider’s private network, not the public internet
  • Wallet keys are never transmitted to or stored by us
  • Managed, encrypted database backups
  • Production access restricted to authorised personnel with SSO and 2FA, and logged

To report a vulnerability, email security@btcfi.ai. We welcome coordinated disclosure and will not pursue good-faith research.

9. How long we keep it

  • Hashed IP addresses — 90 days
  • Wallet-keyed data — while you actively use the service, then 30 days
  • Audit logs — 24 months

After the retention period we delete or anonymise the data.

10. Children

The service is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a minor has provided us data, contact privacy@btcfi.ai and we will delete it.

11. Automated decision-making

We do not make automated decisions with legal or similarly significant effects about you. The routing engine picks the best available price algorithmically, but that is a service-quality function, not a decision about you.

12. Changes to this policy

We will announce material changes on the site, and the “Last updated” date above always reflects the latest revision.

13. Contact

TopicAddress
Privacy questions and data requestsprivacy@btcfi.ai
Security disclosuressecurity@btcfi.ai
Generalhello@btcfi.ai
Swiss supervisory authorityFDPIC

See also our Terms of Service.

BTCFi.aiunknown
——