Privacy Policy
Last updated: May 2026
1. Who We Are
FHATAL operates FhatalX, a cryptocurrency market analytics and intelligence platform. We are the data controller responsible for your personal data processed through the Service.
For any privacy-related enquiries contact us at support@fhatal.com.
2. Information We Collect
2.1 Information you provide directly
- Account data — email address and password (hashed) when you register.
- Payment data — billing name, email, and payment method details. Card numbers are handled exclusively by Stripe and are never stored on our servers.
- Communications — any messages you send to our support team.
2.2 Information collected automatically
- Usage data — pages visited, features used, session duration, click patterns, and referring URLs.
- Device & technical data — browser type and version, operating system, IP address, time zone, and language preference.
- Log data — server logs including timestamps, request paths, and error codes for security and debugging.
- Analytics data — aggregated behavioural analytics via Google Analytics 4 (only with your consent — see Section 6).
2.3 Information from third parties
- Authentication providers — if you sign in via a third-party provider (e.g. Google OAuth), we receive your name and email from that provider.
- Stripe — subscription status, payment history, and customer ID to manage your billing.
3. How We Use Your Information
- Provide, operate, and maintain the Service and its features.
- Create and manage your account and subscription.
- Process payments and send billing-related communications.
- Send transactional emails (e.g. password reset, subscription confirmation).
- Respond to support requests and enquiries.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Analyse usage patterns to improve and develop new features (only with consent where analytics are involved).
- Comply with legal obligations.
We do not sell your personal data to third parties. We do not use your data for personalised advertising.
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal bases:
- Contract — processing necessary to fulfil the subscription contract with you (account management, billing, service delivery).
- Legitimate interests — fraud prevention, security monitoring, and improving service reliability.
- Consent — analytics cookies and any optional marketing communications. You can withdraw consent at any time.
- Legal obligation — when required by applicable law (e.g. retaining financial records).
5. Data Sharing & Third Parties
We share data only with trusted sub-processors as necessary to operate the Service:
- Supabase — database and authentication. Stores account data and usage records.
- Stripe — payment processing. Handles billing info and subscription status.
- Google Analytics 4 — usage analytics (only with your consent). Receives anonymised behavioural data.
- OpenAI — AI-powered analysis features. Receives query content only, no personally identifiable information.
- Hosting infrastructure — server deployment. Processes server logs only.
We may also disclose data when required by law, court order, or to protect the rights and safety of FHATAL, our users, or the public.
7. Data Retention
- Account data — retained while your account is active and for 30 days after deletion, then permanently erased.
- Billing records — retained for 7 years to comply with financial and tax regulations.
- Server logs — retained for 90 days for security and debugging, then automatically deleted.
- Analytics data — retained in Google Analytics for 14 months, then automatically deleted by Google.
- Support communications — retained for 2 years after the last interaction.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to legal retention requirements.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — withdraw consent for analytics at any time without affecting prior processing.
To exercise any of these rights, email support@fhatal.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Security
We implement industry-standard measures to protect your data, including:
- TLS/HTTPS encryption for all data in transit.
- Bcrypt password hashing — plaintext passwords are never stored.
- Row-level security (RLS) policies so users can only access their own data.
- Environment-variable isolation for all secrets — API keys are never committed to source code.
- Regular dependency audits and security patches.
10. International Data Transfers
FHATAL is based in Finland. Some of our sub-processors (including Stripe and Google) are based in or may process data in the United States or other countries outside the EEA. Where such transfers occur, they are governed by appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.
11. Children's Privacy
FhatalX is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us at support@fhatal.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “Last updated” date at the top of this page and, where required, notify you by email or in-app notification. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.
13. Contact
If you have any questions or concerns about this Privacy Policy or our data practices, please reach out:
© 2026 FHATAL. All rights reserved.
By using FhatalX, you acknowledge that you have read and agree to this Privacy Policy.