Privacy Policy
ASX Capital · Effective September 7, 2026
This document is provided in English. The English text is the version that governs.
1. Who we are
This Privacy Policy explains how ASX Limited, a company incorporated in the British Virgin Islands with company number 2137221 and registered office at Rodus Building, P.O. Box 3093, Road Town, Tortola, British Virgin Islands, VG1110 (“ASX”, “we”, “us”), collects and uses information when you visit asxapp.com and its subdomains, connect a wallet, sign in, subscribe to email updates, or take part in the ASX Capital Partner Program (together, the “Services”).
ASX is the controller of the personal data described here. You can reach us at [email protected].
This Policy is written to be read. Where it says we do not do something, we do not do it. If we start, we will change the Policy first.
2. What we collect
Wallet and blockchain data. When you connect a wallet we receive its public address. When you mint, buy, sell, stake or transfer ASX tokens, that activity is recorded on BNB Smart Chain, a public blockchain that we do not control and cannot edit. We run our own indexer that reads those public records and keeps a copy of ASX-related transfers, balances and the wallets involved so that we can show you your holdings and operate the Services.
Sign-in and account data. Social sign-in is provided by Privy, Inc. If you sign in with email, Google, X, Discord or another supported provider, Privy gives us your verified email address, the identifier of the account you used, and a Privy user id. Privy also creates the embedded wallet attached to that sign-in. Its private key is split cryptographically and ASX never holds any share of it; Privy’s handling of the key is governed by its own privacy policy.
Email address. If you sign in socially, the email you signed in with is added to our subscriber list. If you connect an external wallet such as MetaMask and type an email into our form, we store it as unverified and send one welcome message with a confirmation link; nothing further is sent until you confirm. Every email we send carries an unsubscribe link.
Email engagement. Our email provider, Resend, reports delivery, bounce, open and click events back to us and we keep them, so that we can stop sending to addresses that do not want mail and understand which messages are useful.
Site usage. We run our own first-party analytics rather than a third-party tracking script. For each page view we record the path, the referring website’s domain, any campaign or referral tag in the URL, the connected wallet address if one is connected, and a visitor identifier. That identifier is a one-way hash of your IP address and browser signature mixed with a secret and the current date, so it changes every day and cannot be turned back into your IP address. Raw IP addresses are not written to our database.
Partner Program. If you apply to the Partner Program we collect your display name, the platform and handle you promote on, other profiles you list, a description of your audience, your country, and a payout wallet address. We record your acceptance of the Partner Terms, including the version you accepted, your wallet signature and a salted hash of your IP address. We record clicks on your referral link (a salted IP hash, a hash of the browser signature, landing page and referrer) and the wallets that are bound to your code.
Server logs. Like every web server, ours records the IP address, requested page, timestamp and browser user agent of each request in access logs. These are kept for a short period for security and troubleshooting and then rotated out.
Approximate location. Cloudflare, which sits in front of our servers, tells us the country each request comes from. We use this only to pick the language the site first renders in. We do not store it.
Correspondence. If you email us, we keep the email and our reply.
3. What we do not collect
- We do not collect your name, date of birth, government identification or address for using the site, connecting a wallet or buying tokens. Identity verification, where required by law or by a payment provider, is carried out by that provider under its own policy.
- We do not hold private keys or seed phrases, for any wallet, ever.
- We do not use third-party advertising or analytics cookies, and we do not sell or rent personal data.
- We do not build advertising profiles or share data with data brokers.
4. How we use it
We use the information above to:
- operate the Services: show your balances, process your transactions, pay yield to token holders, and run the Partner Program including calculating and paying commissions;
- keep you informed: send transactional messages about your wallet and holdings, distribution and yield updates, and newsletters, each with an unsubscribe link;
- understand and improve the site: see which pages and campaigns bring people in and where they get stuck;
- keep the Services safe: rate limiting, abuse and fraud prevention, and defending against automated traffic;
- meet legal obligations, including record-keeping, sanctions compliance and responding to lawful requests.
Where a legal basis is required, we rely on performance of our agreement with you (operating the Services and the Partner Program), our legitimate interests (security, analytics, keeping you informed about a product you signed up for), your consent (unverified email addresses, newsletters where you opted in) and compliance with law.
5. Who we share it with
We share personal data only with service providers that need it to run the Services, and only the data each needs:
- Privy, Inc. – authentication, social sign-in and embedded wallets.
- Resend, Inc. – sending our emails and reporting delivery events.
- Cloudflare, Inc. – content delivery, DDoS protection, bot detection (Turnstile) and the country lookup described above.
- Hosting providers – the servers and database that run the site.
- Blockchain node providers (for example QuickNode, PublicNode, Ankr and thirdweb) – when the site reads or submits blockchain data, your wallet address and the request are sent to these nodes as part of how blockchains work.
- LI.FI – if you use the cross-chain funding option, your wallet address, chains and amounts are sent to LI.FI to quote and route the transfer.
- WalletConnect – if you connect a wallet through WalletConnect, its relay carries the session between the site and your wallet app.
- Google Fonts and the Trust Wallet asset CDN – your browser fetches fonts and token logos from these hosts, which see your IP address in the ordinary way any web request does.
- Payment and on-ramp providers, where offered – if you buy crypto with a card through the site, the provider collects and verifies your identity and payment details directly under its own policy. ASX receives confirmation of the transaction, not your card or identity documents.
We may also disclose information where the law requires it, to enforce our terms, to protect the rights, property or safety of ASX, our users or others, or as part of a corporate transaction. Anyone who acquires the Services will be bound by this Policy for the data it receives.
Blockchain data is public by design. Anything recorded on-chain, including the wallet addresses involved in a transaction, is visible to anyone and cannot be deleted by us.
6. Cookies and browser storage
We set a small number of first-party cookies and browser storage entries, none of them for advertising:
- NEXT_LOCALE – the language you picked, kept for one year.
- asx_ref – the Partner code from a referral link you arrived through, so that the partner can be credited if you later transact.
- Partner dashboard session – keeps you signed in to the partner dashboard.
- Browser storage (localStorage and sessionStorage) – remembers which wallet you connected with, whether you have dismissed a prompt, your first-touch campaign tag, and similar preferences. This stays in your browser and is not sent to us except as described in Section 2.
Third parties named in Section 5 may set their own cookies inside their components, for example Privy’s sign-in frame or Cloudflare’s bot check. Those are governed by their policies. You can clear or block cookies in your browser; the site will still work, but you may need to pick your language and reconnect your wallet again.
7. How long we keep it
- Subscriber records and email events – until you unsubscribe or ask us to delete them. Unsubscribed addresses are kept on a suppression list so we do not email them again.
- Partner records – for the life of your participation and for as long afterwards as we need to pay what is owed, resolve disputes and meet record-keeping obligations.
- Terms acceptance records – for as long as the agreement they evidence may matter.
- Page-view and referral-click records – kept in hashed form; the daily-rotating visitor identifier means they cannot be tied back to you after the day they were recorded.
- Server access logs – rotated on a rolling basis of roughly two weeks.
- Indexed blockchain data – indefinitely, as a copy of a public ledger.
8. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict its use, to receive a copy in a portable form, and to withdraw consent where we rely on it. You always have the right to stop receiving marketing email, by clicking unsubscribe in any message or writing to us.
To exercise a right, email [email protected] from the address on file, or include the wallet address concerned and a signature we can verify. We will respond within thirty days. We cannot delete information that is recorded on a public blockchain, and we may retain what the law requires us to keep.
If you are in the European Economic Area or the United Kingdom you may also complain to your local data protection authority. In the British Virgin Islands the relevant law is the Data Protection Act, 2021.
9. International transfers
ASX is established in the British Virgin Islands and our providers operate servers in the United States and elsewhere. Your information may be processed in countries whose data protection laws differ from those of your own. Where required, we rely on contractual safeguards with our providers for such transfers.
10. Security
We keep personal data on access-controlled servers reachable only over encrypted connections, with key-based administrative access and no private keys stored alongside the application. IP addresses in our analytics are hashed rather than stored. No system is perfectly secure, so please guard your own wallet credentials and email account; we will never ask for a seed phrase or private key.
11. Children
The Services are not directed at anyone under 18 and we do not knowingly collect information from them. If you believe a minor has provided us with personal data, contact us and we will delete it.
12. Changes
We will post any change to this Policy on this page and update the effective date above. If a change materially affects how we use information you have already given us, we will tell subscribers by email before it takes effect.
13. Contact
ASX Limited, Rodus Building, P.O. Box 3093, Road Town, Tortola, British Virgin Islands, VG1110. Email: [email protected].
