Privacy Policy
How BitcoinMargin handles your data: what our server stores, what stays in your browser, the services we rely on, and your rights under the GDPR.
1. Introduction
This Privacy Policy explains how BitcoinMargin ("we", "us", "our") collects, uses, and protects information when you visit our website at bitcoinmargin.com. We are committed to safeguarding your privacy and ensuring transparency about data practices in compliance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
Data Controller: MN Media s.r.o., a limited liability company registered in the Czech Republic (IČO 24045764; Commercial Register of the Municipal Court in Prague, file C 437414), with its registered seat at Varšavská 715/36, Vinohrady, 120 00 Praha 2, Czech Republic, operating bitcoinmargin.com under the name BitcoinMargin. For privacy requests, write to that address, email info@bitcoinmargin.com, or use the contact page.
2. Information We Collect
We may collect the following types of information:
- Usage data — the pages you visit, the page you came from, your browser and operating-system family, device type and screen size, the site language you use and the country your connection resolves to. How this is collected is described under Analytics data and in section 3.
- Cookies & local storage — we set no cookies. Your browser's local storage keeps a few preferences (your consent choice, theme, display currency, favourite coins) and, after you accept analytics, a per-tab session identifier; see section 3.
- Analytics data — we run two analytics systems on our own server. Plausible (self-hosted, cookieless) counts page views for every visitor from the page address, referrer, browser and operating-system family, device type and country; it derives a visitor identifier from your IP address and browser signature with a secret that changes every day, and never stores the address itself. Our own event log (page views, scroll depth, reading time, searches on the site, clicks on partner links) runs only after you accept analytics in the consent prompt and stores no IP address. Clicks on partner links are also counted without any identifier (page, partner, country).
- IP addresses (sentiment voting) — when you vote in a community sentiment poll, your IP address is stored with the vote to enforce one vote per coin per day. Vote records are not shared with third parties.
- IP addresses (geo-blocking) — when you visit the site, our content delivery network determines the country of your connection and passes it to our server, which decides whether the site may be shown in that country. If a request reaches our server without that information, the server looks the address up with a third-party geolocation service (ip-api.com, with ipapi.co as a fallback). The result is held in the server's memory for up to five minutes, keyed by the address, so that repeated requests are not looked up again; the address is not written to a database or log for this purpose.
- IP addresses (rate limiting) — our server keeps per-address request counters in memory to limit request rates and prevent abuse. They exist only in memory, for the length of the rate window, and are never written to a database or log.
- Contact form data — if you use the contact form, we store your name, email address, subject and message together with the IP address the message was sent from. The address is used to limit sending to three messages per address per hour and to ignore an identical message repeated within a minute. A copy of the message is emailed to our inbox. How long messages are kept is described in section 4.
- Reports and diagnostics — when you use the Report issue control, we store what you type, the address of the page, your browser's identification string, viewport size and language, and a salted one-way hash of your IP address (never the address itself). The wrong-location form on the regional-restriction page is described in section 7. If a page fails to render in your browser, the page itself may send us an automatic report with the same technical details and the same hashed address.
We do not collect payment details, government IDs, or sensitive personal information. We do not report any user data to tax authorities or regulatory bodies.
3. Cookies & Local Storage
We set no cookies. The website keeps the following items in your browser's storage; none of them is sent to third parties:
- Essential — required for the website to function (your consent choice, your theme).
- Functional — remember your preferences (display currency, favourite coins, preview text size).
- Analytics — help us understand traffic and usage patterns. Recorded only with your consent.
| ชื่อ | ประเภท | Purpose | Expiry |
|---|---|---|---|
| cookie-consent | Essential | Stores your consent choice (necessary, analytics). | Persistent |
| theme | Essential | Remembers your light/dark theme preference. | Persistent |
| preferred-currency | Functional | Remembers the display currency you selected. | Persistent |
| favorite_coins | Functional | Remembers your favourite coins so they appear at the top of your watchlist on every visit. | Persistent |
| previewSize | Functional | Remembers the text-size setting on the design-preview pages only. | Persistent |
| am_sid | Analytics | A random identifier for our own analytics, created only after you accept analytics, so that the page views in one tab count as one visit. | Session |
You can change your consent at any time via the Cookie Preferences link in the website footer, or clear the site's data in your browser settings.
4. Legal Basis & Retention
We process the limited data described above on the following legal bases under GDPR:
- Legitimate interest (Art. 6(1)(f)) — IP addresses are processed for rate limiting, abuse prevention, the regional restrictions described in section 7 and one-vote-per-day enforcement; hashed addresses in reports let us recognise repeat submissions without keeping the address. Cookieless page-view counting (Plausible) also rests on this basis.
- Consent (Art. 6(1)(a)) — our own analytics events are recorded only after you opt in via the consent prompt.
- Contract performance (Art. 6(1)(b)) — contact form data is processed to respond to your inquiry.
Retention periods:
- Sentiment vote IPs — stored with the vote record to enforce one vote per coin per day. We do not currently delete vote records or the addresses stored with them automatically; you can ask us to delete yours (section 10).
- Contact form data — kept in our database and inbox for as long as we need them to answer you and to keep a record of our correspondence. We do not delete them automatically; you can ask us to delete your message at any time (section 10).
- Reports — problem reports, wrong-location reports and automatic error reports are kept while we work through them and afterwards as a record of what was fixed; they hold no address, only its salted hash, and are deleted on request.
- Rate limiting data — held only in the server's memory for the length of the rate window and then discarded; never written to a database. The contact form's hourly limit is counted from the stored messages instead.
- Geo-check IP lookups — the country result is held in memory for up to five minutes per address and then dropped. The third-party geolocation services we fall back to have their own retention policies.
- Analytics events — events recorded by our own analytics are deleted after one year by a daily clean-up job. Plausible's statistics contain no address and are kept as the site's history.
- Server logs — the web server's access logs (IP address, requested page, browser identification, time) are rotated automatically and deleted after at most 30 days. Our content delivery network keeps its own request logs under its own policy.
- Aggregated statistics — sentiment totals, click counts and similar aggregated metrics are kept indefinitely; they contain no personal data.
5. Sub-Processors & Third-Party Services
We use the following third-party services to operate the website:
| Service | Purpose | Data Processed |
|---|---|---|
| Hostinger | Hosting of our server — a virtual private server in Germany that we operate ourselves | Everything the site stores lives on this server: the database, server logs and our own analytics |
| Bunny.net | Content delivery network and edge protection in front of the site | Every request passes through it: IP address, requested page, browser identification. It determines the country of your connection and forwards it to our server. |
| Proton Mail | Email delivery of contact-form messages to our inbox, which is itself a Proton Mail mailbox | Name, email, subject, message (from contact form only) |
| ip-api.com / ipapi.co | IP geolocation, only when a request reaches our server without the CDN's country | Visitor IP address; the result is cached in our server's memory for up to five minutes |
| Market-data providers (Binance, Bybit, OKX, Kraken, KuCoin, CoinGecko, Coinglass, Alternative.me, exchange-rate and Ethereum node APIs) | Prices, funding rates, open interest, volumes, gas fees and similar market data | No user data sent — server-side API calls only |
Non-affiliate third-party references — such as CoinGecko, Bitcoin, Ethereum, and other cryptocurrency or platform names — appear for informational purposes only and do not imply any data-sharing arrangement between us and those entities.
6. Affiliate Links & Referral Tracking
Some links on this website are affiliate links, including links to cryptocurrency exchanges and trading platforms we work with (via our referral identifiers; every paid link is marked as described on our Advertising Disclosure page). When you click an affiliate link and register or trade on the partner platform, the platform may pay us a commission at no extra cost to you. Compensation can influence which platforms we work with and where their buttons and listings appear on this site; it does not change the market data, the calculators or the risk warnings.
Affiliate links contain a referral parameter that identifies bitcoinmargin.com as the source of the visit. We do not receive your name, email address or other contact details from a partner platform; what a platform reports to us concerns referral results and commissions. How a partner handles your data is governed by that platform's own privacy policy.
How paid links are marked, and what compensation does and does not influence, is set out in full on our Advertising Disclosure page.
7. Geo-Blocking & Access Restrictions
For regulatory compliance, we restrict access to the website from certain jurisdictions. When you visit the site, our content delivery network and, for some regions, a third-party geolocation service determine your approximate location from the network address of your connection. If you are in a restricted region, the server answers with an HTTP 451 page that states the location it detected instead of the requested content; no cookie is set and nothing about you is stored to make that decision. That page lets you report a wrong classification. A report contains the detected and claimed locations, the page you requested, a salted hash of your network address (never the address itself), your browser's language and time zone, any details you type, and an email address only if you choose to give one so that we can reply. We use reports solely to review the classification, and you may ask us to delete yours at any time by writing to info@bitcoinmargin.com.
No page content is sent to a restricted region: the restriction is applied on the server before anything is rendered. Your IP address is not stored as part of the location check — the country result is held in the server's memory for up to five minutes and then dropped; only a wrong-location report that you choose to send retains a salted hash of the address.
8. Tax Reporting
While our educational content discusses tax regulations (such as the EU's DAC8 directive), we do not report any user data to tax authorities, financial regulators, or government agencies. We are an informational website, not a crypto-asset service provider. Any tax reporting obligations rest with the exchanges and platforms you use directly.
9. Data Security
We implement the following security measures to protect your data:
- All data transmitted between your browser and our servers is encrypted via HTTPS/TLS.
- The database runs on our own server and accepts connections only from that server; it is not reachable from the internet, and your browser never talks to it directly.
- Every server endpoint validates its input and applies per-address rate limits.
- Contact-form and report inputs are validated, length-limited and screened for spam before they are stored.
- Operator tools — the message inbox and the analytics dashboard — are reachable only from allow-listed addresses.
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of data transmitted to our site.
10. Your Rights Under GDPR
If you are in the European Economic Area (EEA) or the United Kingdom, you have the following rights. To exercise any of them, write to MN Media s.r.o., Varšavská 715/36, Vinohrady, 120 00 Praha 2, Czech Republic, or email info@bitcoinmargin.com; we answer within one month, as the GDPR requires:
- Right of access (Art. 15) — you may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — you may request correction of inaccurate personal data.
- Right to erasure (Art. 17) — you may request deletion of your personal data ("right to be forgotten").
- Right to restriction (Art. 18) — you may request that we limit the processing of your data.
- Right to data portability (Art. 20) — you may request your data in a structured, machine-readable format.
- Right to object (Art. 21) — you may object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)) — you may withdraw your analytics consent at any time via the Cookie Preferences link in the footer.
- Right to lodge a complaint — you may file a complaint with your local Data Protection Authority (DPA), or with the authority that supervises us, the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz), if you believe your rights have been violated.
Requests about data held on our server — contact messages, votes, reports — are handled by us: write to the address above or use the contact page. Clearing your browser's site data removes only the preferences and identifiers kept in your browser (section 3), not records on our server.
11. International Data Transfers
The site runs on a server in Germany that we rent from Hostinger. Bunny.net delivers it through edge servers around the world, including outside the European Economic Area, which forward each request to our server. Contact-form messages are emailed through Proton AG in Switzerland, a country the European Commission recognises as providing adequate protection. The fallback geolocation services may process the IP address outside the EEA. Where personal data leaves the EEA, we rely on the safeguards of Chapter V of the GDPR (adequacy decisions or standard contractual clauses).
12. Children's Privacy
This website is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided data to us, please contact us and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically. Continued use of the website after changes constitutes acceptance of the updated policy.
Last updated: 5 September 2026