Last update: 28 April 2026
Privacy policy
How CCTRX collects, uses, stores, and protects your personal data and on-chain identifiers.
1. Who we are
CCTRX Labs ("CCTRX", "we", "us") is the controller of personal data processed in connection with the Service available at cctrx.com. Our Data Protection Officer can be reached at privacy@cctrx.com.
2. Data we collect
Identity data: full name, date of birth, nationality, country of residence, government-issued ID, selfie / liveness video, and source-of-funds documentation supplied during KYC and any later enhanced due diligence.
Contact data: email address, phone number, postal address.
Account & transactional data: deposit history, card activity, merchant names and MCCs, refunds, cashback, subscription tier, and support correspondence.
On-chain data: TRON addresses you deposit from, transaction hashes, and the risk scores returned by our blockchain-analytics providers.
Device & log data: IP address, user agent, language, device fingerprint, session ID, and access timestamps.
Marketing data: where you have opted in, your communication preferences and engagement with our emails and ads.
3. How we use it and the legal basis
Performance of a contract: opening and operating your account, issuing cards, processing deposits and spending, paying cashback, and handling support requests.
Legal obligation: KYC, AML, CTF, sanctions screening, tax reporting, scheme reporting, and responding to lawful requests from regulators or courts.
Legitimate interests: preventing fraud and abuse, securing the platform, debugging, improving the product, and informing our existing customers about closely related services. We balance these interests against your rights and you may object at any time.
Consent: optional marketing communications, non-essential cookies, and any processing for which we explicitly ask for opt-in. You can withdraw consent at any time without affecting prior processing.
We do not sell your personal data and we do not use it for automated decisions producing legal effects without a human in the loop, except where required by law (for example, hard sanctions blocks).
4. Sharing
Card issuers, processors and the card schemes (Visa, Mastercard) — to authorise, settle, and dispute transactions.
KYC / KYB and biometric verification providers — to verify your identity and assess risk.
Blockchain analytics providers — to assess the risk of incoming deposits and the addresses they originate from.
Cloud and infrastructure providers — to host the Service, store backups, and deliver notifications.
Professional advisers — accountants, lawyers, auditors — under duties of confidentiality.
Regulators, financial intelligence units, tax authorities, and law-enforcement — where we are legally required to disclose.
All processors are bound by written data-processing agreements requiring confidentiality, security, and processing only on documented instructions.
5. International transfers
Where personal data is transferred outside your country of residence, we rely on adequacy decisions, Standard Contractual Clauses, or your explicit consent, and we apply supplementary safeguards (encryption in transit and at rest, access controls, and minimisation) to maintain a level of protection equivalent to your local law.
6. Retention
Identity records, transaction records, and SAR documentation are retained for at least 5 years after account closure to satisfy AML record-keeping obligations, and longer where required by local law.
Marketing data is retained until you withdraw consent or three years of inactivity, whichever comes first.
Device and log data is retained for up to 12 months for security and abuse-investigation purposes.
7. Your rights
Subject to local law, you may: access your data; request correction of inaccurate data; request erasure ("right to be forgotten") where no legal retention duty applies; restrict or object to processing; port your data; and withdraw consent for processing that relies on consent.
You may also lodge a complaint with the data-protection authority of your country of residence. We would, however, appreciate the opportunity to address your concerns first — please contact privacy@cctrx.com from the email registered to your account.
8. Security
CCTRX uses TLS 1.2+ in transit and AES-256 (or scheme-equivalent) at rest, hardware-isolated key custody for hot wallets, role-based access with least-privilege and audit logging, mandatory 2FA for staff, and continuous monitoring and alerting. We perform regular vulnerability scans and engage independent security testers.
No system is perfectly secure. Please use a strong unique password, enable 2FA on your account, and never share verification codes with anyone — CCTRX will never ask you for your password or for an OTP.
9. Children
The Service is not intended for and is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact privacy@cctrx.com and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice in advance of the effective date.
