Privacy Policy

How EBCMX collects, uses and protects your personal data — including what we deliberately do not do: no analytics, no ad tech, no automated decisions.

September 7, 2026

1.Who we are

EBCMX is a spot cryptocurrency exchange, available at https://ebcmx.com and operated by ECA, Corp. In this notice, "EBCMX", "we", "us" and "our" mean that company.

We decide what personal data is collected through EBCMX and why. Where another company handles personal data on our behalf — hosting our database, storing verification documents, sending our email — it acts on our instructions, and the categories of company that do so are set out under "Who we share it with". Those categories are exhaustive: a company outside them receives no personal data from us — the only other outside code involved anywhere is the licensed charting library that draws the market chart, which we serve from our own domain.

If you want to reach a person about anything in this notice, write to support@ebcmx.com. A human reads that inbox.

2.What this notice covers

This notice applies to the EBCMX website, the account dashboard, the trading terminal, the deposit and withdrawal flows, the identity-verification flow, and the transactional email we send you. It applies whether you hold an account or are only browsing the public pages.

It does not cover websites we link to. Once you leave ebcmx.com, the operator of that site decides what happens to your data.

It is also worth saying what EBCMX is not, because it determines what we never collect. EBCMX offers spot trading only. There is no margin trading and there are no futures or derivatives of any kind. There are no staking, lending, borrowing, yield, earn or interest products. There is no user-facing trading API and no API keys. EBCMX operates no payment rail: no card processing and no direct bank integration. There is no social login or OAuth sign-in. Nowhere in the product do we produce investment, tax or legal advice, recommendations, ratings, portfolio suggestions or forecasts. Because those products do not exist, entire categories of personal data that such products would require are never collected.

3.The personal data we process

Holding an account on a spot exchange means we hold personal data about you: what you give us when you open and verify the account, what your use of the exchange generates, and the standard request data that every web server and network sees. This notice does not itemise those fields. If you want to know exactly what we hold about you, ask us — the access right set out below entitles you to a copy, and we will give you one.

The signup email-domain check — including on abandoned signups

This one is easy to miss, so we are stating it plainly. Every time someone attempts to create an account, the domain part of the email address entered — the part after the @, never the local part before it — is looked up against public DNS to check whether that domain can actually receive mail. This happens on the attempt itself, which means it also happens on signups that are abandoned and never completed. The lookup is a standard public DNS query; the public DNS resolvers that answer it see the domain being queried and nothing else about you. We do this to stop accounts being created against addresses that can never receive a confirmation or a security notice.

4.How we use it

We use personal data to run the exchange and for nothing else. Specifically:

  • To create, secure and operate your account, including sign-in, two-factor authentication, passkeys and the Global Settings Lock.
  • To accept, match and settle your orders, and to charge the correct maker or taker fee for your 30-day volume tier.
  • To credit deposits once they reach our confirmation threshold, to hold deposits below the minimum floor rather than crediting them, and to process withdrawals to addresses you have confirmed.
  • To verify your identity, by human review, and to keep the record of that review.
  • To protect the exchange and its users from fraud, unauthorised access and abuse.
  • To keep the financial and anti-money-laundering records we are required to keep.
  • To send you transactional email — confirmations, security notices, verification outcomes and funding notifications. We do not run a marketing email programme.
  • To answer you when you contact support.
  • To show the site in your language and theme.

We do not use your personal data to advertise to you, to score you, to rank you, or to sell you anything.

5.We load no analytics, advertising, session-replay or telemetry SDK of any kind

None. This is not a hedge or a statement of intent — it is a fact about the code we ship, verified by enumerating every production dependency EBCMX runs on, not one of which is an analytics, advertising, session-replay or telemetry package.

There is no analytics product on this site. There is no advertising pixel, tag manager, conversion tracker, retargeting script or cross-site identifier. There is no session-replay tool recording your mouse, your keystrokes or your screen. There is no product-telemetry or heatmap SDK. We load nothing whose purpose is to measure, record or report how you use the site; the only third-party code running on our pages at all is the licensed charting library that draws the market chart on the trading terminal.

Consequently: we do not sell personal data, we do not share it for advertising or for anyone else's marketing, and no third-party cookie is set by EBCMX's own code. The one qualification is the content-delivery and security layer that sits in front of the site, which sets its own operational cookies; that is described under "Cookies and local storage".

6.Human review, and no automated decision-making

Identity verification at EBCMX is done by people. You upload your documents through the dashboard, and a trained reviewer on our team looks at them and sets your account's verification status. That is the whole mechanism.

There is no automated face-match, no liveness detection, no OCR extraction of your documents, and no automated sanctions screening. No algorithm approves or rejects you.

There is also no automated enforcement of any kind anywhere in the product: no auto-ban, no auto-freeze, no auto-reject, no geofencing, and no automated refusal of a signup. Every adverse action against an account is a decision taken by a person, recorded in the audit log against that person.

We perform no profiling. We do not build behavioural, risk or creditworthiness profiles, and no decision affecting you is produced solely by automated processing. If a decision has gone against you and you want to understand it, write to support@ebcmx.com — there is a human on the other end of that decision who took it.

7.Who we share it with

Running an exchange means some specialist companies handle data on our behalf. We describe them by category rather than by name. The categories below are exhaustive: a company outside them handles no personal data for us.

  • Infrastructure providers — the compute, hosting and deployment services the EBCMX application runs on, together with the network layer that sits in front of the site, protects it from attack and delivers it quickly. Every request you make necessarily passes through them.
  • A managed database provider — hosts the primary database, which is the exchange's system of record.
  • A document-storage provider — holds the identity documents you upload for verification and for account recovery, under a compliance-mode retention lock (see "How long we keep it").
  • A third-party institutional custody provider — holds custody of the assets and executes on-chain movements; it receives the transaction data needed to do that.
  • A transactional email provider — receives what it needs in order to deliver the notices we send you.
  • Public DNS infrastructure — answers the signup deliverability check described above. It receives nothing else about you.
  • Public market-data services — supply the reference prices behind the index price and the market data on the site. No personal data is sent to them; they are listed for completeness because they are outside services the product depends on.

No data broker, ad network, analytics vendor or affiliate receives personal data from EBCMX, because none is wired into the product at all.

Separately from those processors, we may disclose personal data where we are legally obliged to, or where it is necessary to establish, exercise or defend legal claims. Such disclosures are not routine and are never automated: each one is reviewed by a person and recorded.

8.How long we keep it, and what deletion actually does

We want to be direct about this, because "delete my account" does not mean on an exchange what it means on a social network.

Your account record carries a deletion lifecycle: the moment you request deletion, the moment your record becomes eligible to be purged, and the moment it was purged. Requesting deletion starts a retention clock — it is not an instant erase. Records needed for financial and anti-money-laundering recordkeeping are retained for the required period first, and are then purged. We are not stating a specific number of years here; that figure belongs in a legal characterisation this notice does not attempt.

Identity documents are stored under a compliance-mode retention lock. That is a storage guarantee that works in one direction: for the duration of the retention period, the object cannot be deleted or altered by anyone — not by you, not by our support team, not by our engineers, not by an attacker who obtained our credentials. The same property that makes your documents tamper-proof means we genuinely cannot delete them early. When the retention period expires, they can be removed.

The ledger and the staff audit log are append-only by design. Entries in them are corrected by writing a compensating entry, never by editing or erasing history. This is what makes the exchange's books auditable, and it is also a limit on what erasure can mean for transaction records.

9.How we protect it

Some of the protection is organisational, but most of it is structural — built so that a mistake or a compromise has a smaller blast radius.

  • Authentication is handled by an established, self-hosted authentication system pinned to an exact version. We do not implement our own password hashing, session tokens or multi-factor logic.
  • Two-factor authentication and passkeys are available, as is a Global Settings Lock that you can apply to your account's security settings.
  • Session checks run inside each page and layout that needs them, rather than at a single middleware chokepoint that a crafted request could route around.
  • Custody sits with a third-party institutional custody provider. EBCMX writes no wallet, key-management or custody code of its own, and no private key or seed phrase exists anywhere in our codebase.
  • Withdrawals require the destination address to be confirmed before funds can be sent to it, and move through a two-stage suspense model rather than a single irreversible step.
  • Deposits credit only after EBCMX's own per-asset, per-network confirmation threshold is met — deliberately independent of what the custody vendor reports.
  • The ledger is enforced by the database itself: a per-asset zero-sum constraint means an unbalanced transaction physically cannot commit. Trade settlement happens inside the same database transaction as the match, so a settlement failure rolls the entire match back rather than leaving books that disagree.
  • The running application holds only the database privileges it needs. Fee rates, for example, are configuration the runtime can read but has no ability to change.
  • Identity documents are stored under a compliance-mode retention lock, which makes them tamper-proof for their retention period.
  • Staff actions against an account are written to an append-only audit log attributing each action to the person who took it.

No system is perfect, and we do not claim any certification, audit or insurance here. What we claim is what the code does.

10.Your choices and requests

You can ask us to do the following, and we will act on it:

  • Access — ask what personal data we hold about you and get a copy of it.
  • Correction — ask us to correct data that is wrong. Some verification fields can only be changed by resubmitting documents, because their whole purpose is to be evidenced.
  • Deletion — ask us to delete your account. This starts the retention clock described above rather than erasing everything at once, and we will tell you plainly what will be retained and why.
  • Objection or restriction — ask us to stop or limit a specific use of your data. We will tell you honestly if a use is one we cannot stop while your account remains open.
  • Preferences — change your notification settings, language and theme yourself at any time from your account.
  • Complaint — tell us if you think we have handled your data badly. A person will look at it.

Make any of these requests from the email address on your account, to support@ebcmx.com. We may need to confirm it is really you before we act, particularly for access and deletion requests — for a financial account, verifying the requester is part of protecting you.

You will never be charged for making a request, and making one will not degrade your access to the exchange.

11.Cookies and local storage

EBCMX uses cookies and browser storage for one purpose: to make the site work. This notice does not count them, because a number written here stops being true the day one is added or removed. The current inventory — every cookie and every stored item, what it is for and how long it lasts — is our Cookie Policy, published at ebcmx.com/cookies.

By category, what is stored on your device is:

  • Signing you in — the session cookie an account depends on, and the short-lived cookie that carries you through a second-factor or device check while you are signing in.
  • Remembering a choice you made — the language you picked, the light or dark interface, the markets you starred, how you arranged the trading screen, how many rows a table shows, and whether you asked for your balances to be hidden on screen.
  • Recognising the browser you signed in from — described in its own paragraph below, because it is the one item here that is about you rather than about the page.
  • Recovering from a failed page load — a short-lived note that lets the page reload itself once, and only once, when part of the site fails to download.

The device record, plainly. When you sign in successfully we set a long-lived cookie — about a year — carrying a random identifier for that browser, and we record that browser against your account together with details of the browser itself and of the connection it was seen on. That record is what lets you list the devices that have reached your account and remove one, and it is why signing in again from a browser you have used before does not look new to us. It carries no name, no email address and nothing you typed.

No third-party cookie is set by EBCMX's own code. There is no analytics cookie, no advertising cookie and no cross-site identifier, because there is no analytics or advertising code on the site at all.

We show no cookie banner and ask for no cookie consent, because there is nothing here to consent to. Everything we set is either required for the site to work or a preference you chose yourself; none of it measures you, profiles you or follows you to another site. You can clear all of it from your browser at any time, and the Cookie Policy explains what happens when you do.

One honest qualification: a content-delivery and security layer sits in front of the site and sets its own operational cookies as part of doing that — for example to distinguish legitimate traffic from automated attack traffic. Those cookies belong to that provider, they serve the security and delivery of the site, and they are not used by us for measurement or marketing.

12.Children

EBCMX is for adults. The service is not directed at children, and we do not knowingly open accounts for them.

Verification is carried out by a person, who sees what you submit. If we learn that an account holder is a child, a member of our team will act on it — as with every other adverse action here, that is a decision a person takes, not an automated one. If you believe a child has created an account, write to support@ebcmx.com and we will look into it.

14.Changes to this notice

We will update this notice when what we do changes — for example if we begin using a new category of processor, or if a new product surface starts collecting something new.

When we update it, the revised notice is posted on this page with a new date. If a change materially affects how your personal data is used, we will tell account holders by email rather than relying on you to re-read the page. We do not make changes retroactively pretend to have always been there: the version in force is the one published here.

15.How to contact us

For anything about this notice, about the data we hold on you, or to make any of the requests listed above:

  • Email: support@ebcmx.com
  • Operator: ECA, Corp., operator of EBCMX (https://ebcmx.com)

Write in English or Persian; both are read. Tell us the email address on your account so we can find you, and say plainly what you want us to do. A person will answer.