Trust
This page is maintained by the CCTRX team to answer common security and privacy questions about our product. It is editable app content, not an independent certification.
Sign-in supports email + password and Google sign-in. Email verification with a one-time code is required before sensitive actions. Optional 2FA over email is available in profile settings.
Sessions are issued and rotated by our authentication provider; signing out from your profile ends the session on this device.
Full card numbers and CVV are stored separately from your live card record and are only revealed on explicit request through an authenticated server-side flow. Other screens show a masked PAN.
Crypto deposits are credited only after the network confirms the transaction, the transfer event type matches the official USDT-TRC20 contract, and the destination address matches your assigned deposit address exactly.
All traffic to CCTRX is served over HTTPS. Database access is gated by row-level security policies — you can only read and modify rows that belong to your account, and security-sensitive fields cannot be changed by the account holder.
Live broadcasts of database changes are scoped to non-sensitive tables. Payment instrument fields, device fingerprints, and IP intelligence are never streamed to clients.
We use Lovable Cloud for hosting and authentication, Resend for email delivery, Tron public infrastructure for on-chain confirmations, and Pushover/Telegram for internal operational alerts. We do not sell account data.
Account data is retained while your account is active. Contact support to request deletion; we will remove your profile and personal records, retaining only what we are required to keep for legal, tax, or anti-fraud purposes.
If you believe you have found a vulnerability, please email security@cctrx.com with steps to reproduce. Please do not publicly disclose until we have had a chance to respond.
Last reviewed: June 2026. The CCTRX team owns and maintains this page.