CryptoEscrowDesk
How It Works Fees FAQ Guides Log In Start an Escrow
Home › Privacy Policy

Privacy Policy

Our binding data protection commitment: privacy-by-design architecture, zero third-party trackers, cryptographic pseudonymization, and full GDPR & CCPA compliance.

Version 3.2 Effective: September 2026 GDPR (EU/UK) & CCPA / CPRA Aligned Zero Advertising Trackers
Terms of Service Privacy Policy AML & Compliance Policy

Our Privacy-First Architectural Pledge

We do not use third-party analytics trackers (such as Google Analytics or Meta Pixel), we do not set advertising cookies, and we never sell, rent, or monetize your personal data. Application security logs utilize one-way salted cryptographic hashes for IP addresses rather than storing raw client IPs.

Table of Contents
  1. 1. Data Controller & Scope
  2. 2. Privacy by Design Principles
  3. 3. Categories of Data We Collect
  4. 4. Legal Bases for Processing
  5. 5. Purposes of Data Processing
  6. 6. Cookies & Tracking Policy
  7. 7. Data Sharing & Third Parties
  8. 8. Cross-Border Data Transfers
  9. 9. Cryptographic & System Security
  10. 10. Data Retention Schedule
  11. 11. Your Legal Privacy Rights
  12. 12. California Privacy Rights (CCPA)
  13. 13. Children’s Privacy Policy
  14. 14. Policy Updates & DPO Contact

1. Data Controller & Scope

This Privacy Policy applies to all personal data collected, processed, and maintained by CryptoEscrow Desk LLC (trading as CryptoEscrowDesk, “the Platform”, “we”, “us”, or “our”) in connection with your access to our website, application interfaces, customer support channels, and digital asset escrow services.

For the purposes of the General Data Protection Regulation (EU GDPR / UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable international data privacy legislation, CryptoEscrow Desk LLC operates as the primary Data Controller (Registered Office: 300 Delaware Avenue, Suite 210, Wilmington, DE 19801, USA). If you have any questions regarding how your data is processed, or wish to exercise your statutory rights, please contact our Data Protection Officer at info@cryptoescrowdesk.com.

↑ Back to top

2. Privacy by Design & Architectural Principles

We built our platform around the fundamental principle that sensitive financial escrow operations must prioritize user confidentiality, data minimization, and technical defenses:

  • Data Minimization: We strictly collect only the minimum personal information required to execute escrow agreements, verify on-chain deposits, resolve disputes, and satisfy anti-money laundering (AML) and counter-terrorist financing (CFT) statutory obligations.
  • IP Pseudonymization: To protect against brute-force attacks and rate-limit abuse, our application computes a salted cryptographic HMAC hash (HMAC-SHA256) of your IP address combined with an application secret. We do not store raw, unhashed IP addresses in our application activity records.
  • Password Security: Passwords are never stored in plaintext. They are hashed using modern, compute-intensive cryptographic hashing algorithms (e.g. Argon2id / bcrypt) with unique per-user salts.
  • Append-Only Security Logs: Sensitive administrative actions and double-entry ledger state transitions are logged with immutable IDs and timestamped deltas, deliberately excluding PII payloads.
↑ Back to top

3. Categories of Personal Data We Collect

We collect and process personal data across distinct operational categories:

A. Information You Provide Directly

  • Account Registration Details: Your email address, chosen public display name, and securely hashed authentication credentials.
  • Transaction Specifications: Transaction titles, deal terms, contract descriptions, agreed milestone conditions, and target counterparty email addresses.
  • Transaction Communications: Messages, files, access credentials, license keys, and delivery receipts exchanged within the encrypted per-transaction discussion thread.
  • Support Communications: Inquiries, dispute evidence, and correspondence submitted to our customer support or compliance desks.

B. Blockchain & Public Ledger Data

  • Cryptocurrency Wallet Addresses: Assigned dedicated deposit addresses, buyer refund wallet addresses, and seller payout destination addresses (e.g. Bitcoin, Ethereum, Tron).
  • On-Chain Transaction Identifiers: Blockchain transaction hashes (TxIDs), block numbers, gas fees, and transfer timestamps.

Public Blockchain Notice

Please note that public decentralized blockchains (such as Bitcoin, Ethereum, and Tron) are publicly readable, distributed ledgers. Cryptocurrency transactions broadcast to these networks become permanently recorded and visible to the global public by design.

C. Technical & Operational Security Data

  • Security Hashes: Salted HMAC hashes of client IP addresses for login throttling and audit purposes.
  • Session Identifiers: Secure, HTTP-only session cookies required to maintain authenticated state during your active session.
  • Audit Trail Records: Timestamped records of transaction state transitions (e.g., funding verified, delivery marked, payout broadcast).

D. Compliance & Identity Verification Data (When Triggered)

Where required under statutory AML/CFT regulations, our AML & Compliance Policy, or high-value risk thresholds, we may collect:

  • Government-issued photo identification (Passport, National ID card, Driver’s License);
  • Biometric facial liveness verification;
  • Proof of residential address (utility bill or bank statement within 90 days);
  • For corporate accounts: Certificate of Incorporation, Memorandum of Association, and Ultimate Beneficial Owner (UBO) registers (>25% control).
↑ Back to top

4. Legal Bases for Data Processing (GDPR Article 6)

Under the European Union and United Kingdom General Data Protection Regulation, we process your personal data exclusively under the following recognized legal bases:

  • Performance of a Contract (Art. 6(1)(b) GDPR): Processing necessary to create your account, hold digital assets in escrow, match deposits, enforce the agreed Escrow Instructions, adjudicate disputes, and disburse payouts.
  • Compliance with Legal & Regulatory Obligations (Art. 6(1)(c) GDPR): Processing required to comply with binding statutory mandates, including anti-money laundering (AML), counter-terrorist financing (CFT), financial sanctions screening, tax reporting, accounting record retention, and lawful judicial subpoenas.
  • Legitimate Interests (Art. 6(1)(f) GDPR): Processing necessary to maintain system security, detect and prevent fraud, mitigate denial-of-service (DDoS) and brute-force attacks, protect honest buyers and sellers, and ensure platform operational integrity.
  • Consent (Art. 6(1)(a) GDPR): Where you have granted explicit consent for specific optional features or non-transactional communications (which you may withdraw at any time).
↑ Back to top

5. Purposes of Data Processing

We process your personal information strictly for legitimate commercial and operational purposes:

  • Facilitating, administering, and settling cryptocurrency escrow transactions;
  • Matching incoming blockchain deposits to specific transaction references on our double-entry ledger;
  • Delivering essential transactional status notifications (e.g. deposit received, milestone delivered, dispute opened, funds released);
  • Investigating, mediating, and arbitrating disputes between transacting counterparties;
  • Preventing, detecting, and mitigating cyberattacks, credential stuffing, phishing, and multi-accounting fraud;
  • Screening transactions against global sanctions databases and high-risk on-chain wallet clusters;
  • Responding to customer support tickets and compliance inquiries.
↑ Back to top

6. Cookies & Tracking Technologies Policy

Our cookie policy is simple and privacy-centric:

Cookie Name Type Purpose Duration
Secure Session ID Strictly Necessary (1st Party) Maintains authenticated user session; flagged HttpOnly, Secure, SameSite=Lax. Session / 2 Hours Inactivity
CSRF Token Strictly Necessary (1st Party) Prevents Cross-Site Request Forgery attacks on state-changing forms. Session

Zero Third-Party Trackers: We do not load Google Analytics, Meta / Facebook Pixel, Twitter/X trackers, advertising beacons, or third-party fingerprinting scripts. Your browsing activity on CryptoEscrowDesk is never shared with advertising networks or data brokers.

↑ Back to top

7. Data Sharing, Disclosures & Third Parties

We do not sell, rent, trade, or commercialize your personal information. Disclosures are strictly limited to the following operational scenarios:

  • Transaction Counterparties: When participating in an escrow deal, your counterparty sees only your public display name and messages sent within the transaction thread. Your email address, password hash, and underlying banking/KYC documents are never exposed to counterparties.
  • Infrastructure Sub-Processors: We engage trusted hosting, server, and transactional email infrastructure providers operating under strict Data Processing Agreements (DPAs) with mandatory confidentiality and encryption standards.
  • Legal & Law Enforcement Authorities: We disclose personal data only when legally compelled by a valid subpoena, court order, search warrant, or binding statutory AML/CFT reporting mandate from competent regulatory bodies.
  • Corporate Restructuring: In the event of a merger, acquisition, reorganization, or sale of assets, user records may be transferred subject to equivalent confidentiality and data protection safeguards.
↑ Back to top

8. Cross-Border International Data Transfers

As a global digital asset platform, your information may be processed and stored on secure servers located in multiple jurisdictions. When transferring personal data outside the European Economic Area (EEA) or United Kingdom (UK), we ensure adequate levels of data protection by implementing:

  • European Commission Standard Contractual Clauses (SCCs);
  • UK International Data Transfer Addendum (IDTA);
  • End-to-end cryptographic encryption in transit (TLS 1.3) and robust encryption at rest (AES-256).
↑ Back to top

9. Cryptographic & System Security Controls

We implement state-of-the-art administrative, technical, and physical security measures to safeguard personal data and escrow assets:

  • Immutable Double-Entry Ledger: All financial entries are append-only. Database triggers prevent any updating or deletion of posted ledger entries.
  • Role-Based Access Control (RBAC): Access to user data and administrative tools is strictly restricted on a least-privilege basis. High-value releases require dual administrative sign-off.
  • Fail-Closed Security Architecture: Rate limiting, CSRF verification, and login authentication enforce fail-closed security logic.
  • Cold Storage for Digital Assets: Escrow deposits above active operational floats are secured in institutional-grade multi-signature cold storage vaults.
↑ Back to top

10. Data Retention & Disposal Schedule

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, resolve disputes, and satisfy statutory financial and compliance regulations:

Data Category Retention Period Legal & Operational Rationale
Active Account Profile Duration of active account lifecycle Facilitates ongoing escrow access; deleted upon verified closure request.
Transaction & Ledger Records 5 to 7 Years post-completion Mandatory statutory retention under AML/CFT and financial accounting laws.
Identity Verification (KYC) Records 5 Years post-account closure Statutory compliance with anti-money laundering regulations.
Security & Rate-Limiting Logs Rolling 15 to 30 Days Brute-force defense and automated abuse mitigation; purged cyclically.
↑ Back to top

11. Your Legal Privacy Rights (GDPR & Global Standards)

Depending on your jurisdiction of residence, you enjoy comprehensive legal rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): You have the right to request a complete copy of the personal data we hold about you.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate or incomplete personal information.
  • Right to Erasure (“Right to be Forgotten”, Art. 17 GDPR): You may request the deletion of your account and personal data, subject to mandatory statutory retention exemptions for completed financial and ledger records.
  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to restrict the processing of your data under specific contested circumstances.
  • Right to Data Portability (Art. 20 GDPR): You may request an export of your personal data and transaction history in a structured, commonly used, machine-readable format (JSON/CSV).
  • Right to Object (Art. 21 GDPR): You may object at any time to processing based on our legitimate interests.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your competent national Data Protection Supervisory Authority (such as the ICO in the UK, CNIL in France, or BfDI in Germany).

To exercise any of these rights, please email our Data Protection team at info@cryptoescrowdesk.com. We respond to all verified requests within thirty (30) calendar days.

↑ Back to top

12. California Consumer Privacy Rights (CCPA / CPRA)

Under the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA), California residents are entitled to specific statutory disclosures:

  • Categories of Personal Information Collected: Identifiers (email, username, hashed IP), commercial information (transaction records), and internet activity (session logs).
  • No Sale or Sharing: CryptoEscrowDesk has not sold or shared any personal information of consumers to third parties for cross-context behavioral advertising in the preceding twelve (12) months.
  • Right to Know & Delete: California consumers may submit verifiable requests to know what personal information we collect and request deletion.
  • Right to Non-Discrimination: We will never discriminate against you, deny services, charge different prices, or provide a different quality of service for exercising your CCPA privacy rights.
↑ Back to top

13. Children’s Privacy Policy

Our platform and escrow services are strictly restricted to individuals who are at least eighteen (18) years of age. We do not knowingly solicit, collect, or process personal data from children or individuals under the age of majority. If we become aware that personal data of a minor has been inadvertently collected, we will immediately take steps to permanently delete such information from our systems.

↑ Back to top

14. Policy Updates & DPO Contact

We may periodically update this Privacy Policy to reflect changes in our operational architecture, technological capabilities, or evolving legal frameworks. When updates occur, we will revise the “Effective” date at the top of this document. Continued use of the platform following notification constitutes acknowledgment of the revised terms.

For any privacy-related questions, data access requests, or regulatory inquiries, please contact our Data Protection Officer:

  • Data Controller: CryptoEscrow Desk LLC
  • Data Protection Officer: Sarah Jenkins, Data Protection Officer
  • Registered Address: 300 Delaware Avenue, Suite 210, Wilmington, DE 19801, USA
  • Email: info@cryptoescrowdesk.com
  • Telephone: +1 (813) 586-4511
  • Subject Line: DATA PRIVACY INQUIRY / DPO ESCALATION
↑ Back to top

CryptoEscrowDesk

A human-verified crypto escrow service. Funds are held by a neutral third party and released only when the buyer confirms delivery.

Escrow Services

Bitcoin Escrow USDT Escrow Ethereum Escrow USDC Escrow Litecoin Escrow P2P & OTC Escrow Crypto Middleman Service

Use Cases

Domain Names Freelance Work Marketplace Purchases Social Media Accounts Telegram Deals Avoiding Crypto Scams

Company

What Is Crypto Escrow? How It Works Fees Guides About Us Contact FAQ

Legal

Terms of Service Privacy Policy AML Policy

© 2026 CryptoEscrow Desk LLC (trading as CryptoEscrowDesk). Registered in Delaware, United States, File No. DE-7394812. Registered Office: 300 Delaware Avenue, Suite 210, Wilmington, DE 19801, USA. FinCEN Registered MSB (Registration #3100024891024). Cryptocurrency transactions are irreversible; always verify escrow addresses before transferring funds.