Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how FraudCoins.com (“we”, “us”) handles information when you visit the website. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and applicable Lithuanian law.
1. Data controller
The data controller is the operator of FraudCoins.com. For any privacy matter — including access, correction, or deletion requests — contact privacy@fraudcoins.com.
2. What data we collect
Most of the Website is static. Depending on how you use it, we may process:
- Local storage on your device — your theme preference and cookie-consent choice, plus (once you sign in) a session token and your public username. This stays in your browser.
- Account data (optional) — if you create an account to post comments or keep a watchlist, we store your username and, depending on the method: your email address and a bcrypt-hashed password; or a Google account identifier; or your public wallet address. We never store passwords in plain text or receive your wallet private keys.
- Comments & watchlist — the comments you post (shown publicly with your username) and the coins you choose to watch, including whether you opted into email alerts.
- Security / rate-limiting — we briefly record IP addresses for actions such as sign-in, registration and the token checker to prevent abuse.
- Server log data — our hosting provider may record standard technical information (IP address, browser type, pages requested) to operate and secure the service.
- Contact data — if you email us, we process what you send in order to reply.
You can delete your account and all associated data at any time from your account page. We do not knowingly collect special categories of personal data.
3. Third-party services
Market data and coin images are loaded from CoinGecko. When your browser requests this data, your IP address is necessarily visible to that provider, subject to its own privacy policy. Coin images may be served from CoinGecko-controlled domains.
If you open the donation dialog, a QR image of the selected receiving address is generated via api.qrserver.com; this requires sending the public wallet address to that service.
If you sign in, additional processors are involved: Google (for Google sign-in — your Google ID token is sent to Google for verification) and Moralis (for MetaMask wallet sign-in and the token checker — your wallet address and signed message, or a contract address you enter, are sent to Moralis). Both are based in the United States. Your account data is stored in our database hosting.
3a. Advertising (Google AdSense)
We may display advertising supplied by Google AdSense. Google and its partners use cookies and similar technologies to serve ads based on your prior visits to this and other websites, and to measure ad performance. Google may use a unique identifier and process your IP address for this purpose.
You can learn how Google uses information from sites that use its services at policies.google.com/technologies/partner-sites, and opt out of personalised advertising at google.com/settings/ads or aboutads.info. For users in the EEA/UK, a Google-certified consent message is shown before personalised ads are served.
3b. Email alerts
If you add a coin to your watchlist with an email-registered account, we may email you when that coin is newly flagged. Every alert email includes an unsubscribe option, and you can turn alerts off by unwatching the coin or deleting your account.
4. Legal bases for processing (GDPR Art. 6)
- Legitimate interests — operating, securing (including rate-limiting) and improving the Website.
- Consent — for non-essential cookies/storage (advertising, the scan ping) and for email alerts you opt into.
- Performance of a service — providing your account, comments and watchlist at your request.
- Pre-contract — responding to your enquiries.
5. Cookies & local storage
We use only essential browser storage. See our Cookie Policy for details and how to manage it.
6. Data retention
Account data (username, email/credentials, comments, watchlist) is kept until you delete your account, after which it is removed from our database. Security/rate-limit IP records are short-lived and purged automatically. We keep contact correspondence only as long as needed to handle your request. Server logs are retained per our hosting provider’s standard periods. Device storage persists until you clear it.
7. Your rights
Under the GDPR you have the right to:
- access, rectify, or erase your personal data;
- restrict or object to processing;
- data portability;
- withdraw consent at any time;
- lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) or your local supervisory authority.
You can delete your account and all associated data yourself from your account page, and delete individual comments inline. To exercise any other right, email privacy@fraudcoins.com.
8. International transfers
Some providers process data outside the European Economic Area — notably Google and Moralis (United States), and CoinGecko. Where this occurs, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework.
9. Children
The Website and accounts are not directed at children under 16. By creating an account you confirm you are at least 16. If you believe a child has provided us data, contact privacy@fraudcoins.com and we will delete it.
10. Changes
We may update this Policy. The “last updated” date above reflects the latest version.