crypt.pe — Privacy Policy
Effective Date: 30 May 2026 Last Updated: 12 September 2026 Operator: 3-102-969985 S.R.L. (Sociedad de Responsabilidad Limitada), registered with the National Registry (Registro Nacional) of Costa Rica. Domicile: Escazú, San José, Costa Rica.
This Privacy Policy explains what personal data crypt.pe ("we", "us", "our") collects, how we use it, and the rights you have over it. It is drafted to comply with Costa Rica's Law No. 8968 (Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales) and its regulations (Executive Decree No. 37554-JP, as amended), and it also applies to all users of the Service worldwide, including users in the European Economic Area (EEA), the United Kingdom, and other jurisdictions that grant similar rights.
In short: we collect the minimum data needed to make crypt.pe work, we never sell it, and we never share it with advertisers.
1. Who we are
The data controller (responsable de la base de datos under Law No. 8968) for the Service is 3-102-969985 S.R.L., domiciled in Escazú, San José, Costa Rica. You can reach us at legal@crypt.pe.
The supervisory authority for data protection in Costa Rica is PRODHAB (Agencia de Protección de Datos de los Habitantes, prodhab.go.cr).
2. What we collect
We collect only the following categories of personal data:
We do not collect: legal name, date of birth, government ID, phone number, residential address, financial-institution data, or any other "know-your-customer" identifier. The Service is non-custodial and does not require these fields.
3. How visitor analytics work — privacy by design
When a person visits a public profile or invoice page, we record a single anonymous view event so the page owner can see traffic.
That event is keyed by a SHA-256 hash of (visitor IP + user-agent + UTC day + server-side random salt). We never store the raw IP or user-agent for this counter. The hash rotates at UTC midnight, so we cannot link visitors across days through it, and a creator viewing their own page while logged in is excluded from the count entirely.
Separately from this per-page counter, the website runs the product-analytics tools described in Section 5a (Google Analytics and PostHog), which use their own cookies and identifiers as disclosed in the Cookie Policy.
4. Payment data
For each on-chain transfer to one of your displayed wallet addresses, we record: the sender address, recipient address, transaction hash, asset, amount, the USD value at the time, and the timestamp. This is the same data that exists publicly on the blockchain — we surface it back to you in your dashboard.
If you use crypt.pe as a payment gateway and pass merchant metadata (for example, customer email or your own order ID) when creating an order, we store it against that order so we can include it in receipts and outbound webhooks. We do not use it for any other purpose.
5. Sub-processors
We share strictly necessary data with the following service providers:
- Alchemy — blockchain indexing and address-activity webhooks. Receives your public wallet addresses (already public on-chain).
- Resend — transactional email delivery. Receives the recipient email and the email body for receipts and gateway notifications.
- Coinbase public price feed — receives no user data; used only for our USD pricing cache.
- Cloudflare — DNS and DDoS protection. Sees request metadata (IP, headers) at the edge.
- Google LLC (Google Analytics 4) — website traffic analytics. Receives pseudonymous analytics identifiers, page-view events, referrer, approximate location derived from IP, and device/browser metadata.
- PostHog, Inc. — product analytics. Receives pseudonymous identifiers, page-view and interaction events (autocapture), web-vitals performance data, optional survey responses, and session recordings used to diagnose usability problems.
5a. Website analytics (Google Analytics and PostHog)
We use Google Analytics 4 (measurement ID G-6N69X4XTWM) and PostHog to understand how the website is used and to improve it. These tools load only after you accept the on-site cookie consent control; if you reject or make no choice, they are not loaded. They process the data listed above under each provider's terms. Purposes: traffic measurement, product improvement and usability diagnostics. Lawful basis (EEA/UK): your consent, which you may withdraw at any time via "cookie settings" in the site footer, browser controls, content blockers, the Google Analytics opt-out add-on, or by emailing legal@crypt.pe. Retention follows each provider's configured limits; you may request access to or deletion of analytics data linked to you via legal@crypt.pe. Cookie and storage details are in the Cookie Policy.
We do not use Facebook Pixel, Hotjar, Mixpanel, Segment, or advertising/retargeting trackers, and we do not sell personal data.
6. Cookies
We use a first-party cookie, cryptpe_theme, to remember your light/dark theme preference, and our analytics providers (Google Analytics, PostHog) set their own cookies and browser-storage entries as described in Section 5a. We do not use cookies for advertising. The dashboard uses an in-browser JWT stored in localStorage instead of a session cookie. Full details, including a complete cookie and storage table and opt-out options, are in our Cookie Policy.
7. Legal bases for processing
Costa Rica (Law No. 8968). We process personal data on the basis of your informed consent, granted when you sign up and accept this Privacy Policy, and — for security and fraud-prevention data — on the basis of the lawful operation of the Service. You may withdraw your consent at any time (Section 8). We do not sell, distribute, or commercialize personal data; our databases are used exclusively for internal operation of the Service, which places them within the internal-use exemption from PRODHAB database registration under Law No. 8968 and its regulations.
EU/UK GDPR. If you are in the EEA or UK, we process your personal data under one or more of the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, prevent fraud, and improve product quality.
- Consent — for any optional feature you separately opt in to (none today).
- Legal obligation — to comply with applicable law, including responding to lawful requests from authorities.
8. Your rights
Under Costa Rica's Law No. 8968 you hold the so-called ARCO rights — Access, Rectification, Cancellation (erasure), and Opposition — over your personal data. Subject to the laws of your jurisdiction, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase (cancel) your account and associated personal data;
- Restrict or object (oppose) to certain processing;
- Port your data to another service;
- Withdraw consent at any time (where consent is the legal basis); and
- Lodge a complaint — with PRODHAB if you are in Costa Rica, or with your local data-protection authority elsewhere.
To exercise any of these rights, email us at legal@crypt.pe with the subject "data request". We will respond within five (5) business days, the response window established by Law No. 8968 for ARCO requests (and in any event no later than the 30 days permitted in other jurisdictions).
9. Data retention
- Account data — kept while your account is active. You can delete it at any time; we purge within 30 days of a verified request.
- Payment records — kept while your account is active. Blockchain records are in any case permanent and outside our control.
- Visitor hashes — rotated at UTC midnight; "yesterday's visitor" is unrecoverable.
- Anonymised aggregates — may be kept after account closure for product-statistics and accounting purposes.
10. International transfers
The Service is operated from San José, Republic of Costa Rica, and our sub-processors operate globally. Where personal data is transferred outside your jurisdiction, we rely on appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) to protect it, and we ensure any recipient offers a level of protection consistent with Law No. 8968.
11. Children
The Service is not directed at children. You must be at least 18 years old to use the Service (consistent with our Terms of Service). We do not knowingly collect personal data from minors. If you believe we have, please contact us and we will delete it.
12. Security
We use industry-standard safeguards including TLS encryption in transit, bcrypt password hashing, separate webhook signing secrets, and strict access controls on our infrastructure, consistent with the technical and organizational security measures required by Law No. 8968 and its regulations. No system is perfectly secure. If a personal-data breach occurs, we will notify PRODHAB and affected users within five (5) business days of becoming aware of it, as required by Costa Rican law, and without undue delay in all other jurisdictions.
13. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be flagged on the Service with at least 14 days' notice. The latest version is always available at https://crypt.pe/privacy.
14. Contact
Privacy questions, data requests, or complaints: legal@crypt.pe.
© 2026 3-102-969985 S.R.L. · Escazú, San José, Costa Rica.