LiveRegime NEUTRALBTC $79,042.37 +1.1%Tide OK -0.074%/1hF&G 74 greedUpdated 14:14refresh in 0:30
Legal

Privacy Policy

What we know about you, why we know it, and how to make us forget it. Short and in plain language, because being straight with you is the whole point of this project.

Effective from: 16 August 2026

1. Who we are

charliedesk is an independent crypto media site at charliedesk.com (the "site"). We publish analyses, market data, exchange and coin overviews, regulation and tax coverage.

The site is operated by CAP-NET s.r.o., company ID 25466640, VAT ID CZ25466640, registered office at 1. máje 476/53, Liberec III-Jeřáb, 460 07 Liberec, Czech Republic, represented by its managing director Milan Litvan (referred to as "we" or "the operator"). We are the data controller.

For anything related to personal data, write to hello@charliedesk.com. We have not appointed a data protection officer, because we do not meet the conditions under which the GDPR requires one.

2. What we do not do

Without your consent, no analytics, no marketing tools and nothing that tracks you runs on the site. We do not sell or rent personal data and we do not carry out automated decision-making with legal effects. Anything beyond what the site strictly needs to work starts only after you consent in the cookie banner.

Google's analytics and marketing cookies (Google Analytics loaded through Google Tag Manager) are switched on only if you allow them in the cookie banner. Until you consent, no Google code loads on the page at all. You can withdraw your consent at any time via the "Cookie settings" link in the site footer.

If you simply read the site, do not sign in and do not allow cookies in the banner, we create no account for you and do not track you in any way. We only process the server logs described in section 3.

3. What data we process

Account and sign-in

You can create an account in four ways, and the data we hold depends on which one you pick:

  • E-mail (magic link): your e-mail address. The link carries a single-use token that we store only as a hash, valid for a short time and invalidated once used.
  • Wallet (Sign-In with Ethereum): the public address of your wallet. We never have access to your private key or to any funds.
  • Passkey: a public key and a credential identifier. Your biometrics or PIN never leave your device and we never see them.
  • Google account: your Google identifier, e-mail address, and name or profile picture if Google provides them.

For every account we also keep the creation date, the last sign-in date, the role and the membership tier. The creation date also weights your exchange ratings, so that freshly created accounts cannot easily skew the results.

Exchange ratings and comments

When you rate an exchange we store your scores, an optional comment and the link to your account. The rating is public but is shown without your e-mail address. Reports of inappropriate content are recorded for moderation.

Newsletter

If you subscribe, we store your e-mail address, chosen language and subscription status. You can unsubscribe at any time using the link in every e-mail or by writing to hello@charliedesk.com.

Paid membership

Payments are handled by the Stripe payment gateway. Card numbers never reach us. From Stripe we store only the customer and subscription identifiers, the subscription status and the end of the billing period, so that we can unlock the paid section for you.

Analytics and marketing (only with consent)

If you allow cookies in the banner, we use Google Analytics 4 to measure the pages you view, your approximate city-level location, your device and browser type, and where you arrived from. The consent also covers Google marketing features (Google Signals): aggregate demographic reports and campaign measurement. Google may link this data to your Google account under its own terms. Individual records are deleted after 14 months at the latest.

Server logs

The server and its protective layer keep ordinary technical access logs, which may contain an IP address, request time, page address and browser type. They serve only to keep the site running, to debug errors and to defend against attacks, and are deleted automatically within days to weeks.

4. Why we process it and on what legal basis

  • Running your account and unlocking the paid section: performance of the contract you enter into by accepting the terms of use.
  • Newsletter: your consent, which you can withdraw at any time.
  • Analytics and marketing cookies: your consent given in the cookie banner, which you can withdraw at any time in the site footer.
  • Exchange ratings, their moderation and abuse prevention: our legitimate interest in keeping ratings trustworthy.
  • Site security, attack and abuse prevention: our legitimate interest in secure operation.
  • Accounting and tax records for paid services: compliance with a legal obligation.
  • Answering your questions and complaints: our legitimate interest in communicating with readers, or compliance with a legal obligation.

5. Who we share data with

We do not sell personal data. We share it only with processors without which the site could not run, and only to the extent necessary:

  • Stripe: payment and subscription processing.
  • Resend: delivery of transactional e-mail, such as sign-in links.
  • Google: sign-in with a Google account if you choose it, and analytics and marketing tools (Google Analytics, Google Tag Manager, Google Signals) if you allow them.
  • The provider of the server infrastructure the site runs on.

Some of these processors are based outside the European Economic Area. Where that is the case, the transfer is covered by the European Commission Standard Contractual Clauses or another transfer tool permitted by the GDPR.

We may also disclose data to public authorities where the law requires it.

6. Cookies

Without your consent we use only cookies that are strictly necessary for the site to work. Google's analytics and marketing cookies are set only if you allow them in the cookie banner.

  • Session cookie: keeps you signed in. It is set only once you sign in.
  • Single-use security cookies for wallet and passkey sign-in: they prevent replay of a sign-in request and last only for the duration of signing in.
  • A language cookie, if you switch languages.
  • A cookie with your cookie-banner choice: it remembers it for 12 months so we do not have to ask you over and over.
  • Google's analytics and marketing cookies (only with consent): they distinguish visitors and visits and enable demographic reports and campaign measurement, lasting up to 2 years.

You can block the necessary cookies in your browser settings, but then you will not be able to sign in. You can withdraw your consent to the other cookies at any time via the "Cookie settings" link in the footer.

7. How long we keep data

  • Account data: for as long as the account exists. Once deleted, we erase or irreversibly anonymise it.
  • Sign-in tokens: minutes. They stop working once used or expired and are deleted continuously.
  • Exchange ratings: for as long as they are published. After account deletion we detach them from your identity so that the public rating keeps its meaning.
  • Newsletter: until you unsubscribe.
  • Accounting and tax records: for the period required by accounting and tax law.
  • Server logs: days to weeks.
  • Your cookie-banner choice: 12 months.
  • Analytics data: individual records for 14 months at most, aggregate statistics beyond that.

8. Your rights

In relation to your personal data you have the right:

  • to access your data and receive a copy,
  • to have inaccurate data corrected,
  • to erasure (the "right to be forgotten"),
  • to restriction of processing,
  • to data portability in a machine-readable format,
  • to object to processing based on legitimate interest,
  • to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before it.

Just write to hello@charliedesk.com. We will handle it within one month. You can also delete your account at any time in the Account section.

If you believe we are mishandling your data, you can lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with the supervisory authority in your country of residence. We would appreciate the chance to put it right first.

9. Security

The site is served exclusively over encrypted HTTPS. Sign-in tokens are stored only as hashes and we do not use passwords at all. Database access is limited to the necessary people and systems.

No measure is perfect. Should a security breach occur that poses a risk to your rights, we will notify the supervisory authority and you within the statutory deadlines.

10. Children

The site is not intended for children under 16 and we do not knowingly create accounts for them. If we find that we hold such an account, we delete it.

11. Changes to this policy

We may update this policy when the site or the law changes. We will always publish the new version with its effective date. For material changes we will notify registered readers by e-mail.