← Back to CoinHoldCoinHold

Privacy Policy

Last updated: 2 October 2026

This policy explains what personal data CoinHold Institutional Technologies AG ("we", "us") collects when you visit our website or use your wallet, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

1. Who is responsible for your data

Institutional Technologies AG, the operator of CoinHold, is the controller of the personal data described here. For any privacy question or to exercise your rights, contact our support team (open a ticket from the Support section of your wallet).

2. Data we collect

Data you give us

Data collected automatically

3. Why we use it and on what legal basis

PurposeLegal basis (GDPR / UK GDPR)
Creating and running your wallet, processing requests, providing supportPerformance of a contract
Identity verification, anti-money-laundering, sanctions screening, record-keeping, responding to authoritiesCompliance with legal obligations
Securing accounts, preventing fraud and abuse, rate-limiting sign-in attempts, keeping audit logsLegitimate interests (protecting our users and platform)
Remembering your cookie choice and any optional features you switch onConsent, or strict necessity for the service you request

We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not make decisions about you based solely on automated profiling.

4. Cookies & similar technologies

A cookie is a small text file stored by your browser. We currently set only strictly necessary cookies, which do not require consent under the EU ePrivacy rules and similar laws:

NameSet byPurposeLifetime
coinholderFirst partySession identifier: keeps you signed in and protects forms against cross-site request forgery. HttpOnly, Secure and SameSite=Lax.Until you close your browser (idle sessions also expire server-side after about 2 hours)
cc_consentFirst partyRemembers whether you accepted or rejected non-essential cookies on the cookie notice.180 days

We do not use advertising, tracking or analytics cookies. If that ever changes, we will ask for your consent first and update this table. When you are signed in, the wallet may also keep small interface-state items (for example, which notifications you have already seen) in your browser's local storage on your own device; this is not sent to us.

You can change your cookie choice at any time with the “Cookie preferences” link at the bottom of our pages, and you can delete or block cookies in your browser settings (blocking the session cookie will prevent you from signing in).

5. Third-party services used on our pages

To display the site we load some resources directly from third parties. When your browser requests them, the provider receives your IP address and standard request data, and may process it under its own privacy policy:

Some of these providers are located outside the European Economic Area and the United Kingdom. Where required, transfers rely on adequacy decisions or standard contractual clauses.

6. Who we share data with

7. How long we keep it

We keep account and transaction records for as long as your wallet is open and afterwards for the period required by anti-money-laundering, tax and accounting law (typically five to ten years depending on the jurisdiction). KYC documents are kept for the legally required period after the relationship ends and then deleted. Security logs are kept in a rolling window. Data we no longer need is deleted or irreversibly anonymised.

8. How we protect it

Connections use TLS. Passwords are hashed; KYC files and recovery phrases are encrypted at rest with keys held outside the public web directory; access to administrative functions is restricted, authenticated and logged; and the site sits behind a web application firewall with rate limiting. No system is perfectly secure, so please also protect your password and recovery phrase and never share them with anyone.

9. Your rights

Depending on where you live (for example under the GDPR, UK GDPR, the Swiss FADP or the California CCPA/CPRA) you may have the right to:

To exercise a right, contact our support team (open a ticket from the Support section of your wallet). We may need to verify your identity first, and we may be unable to delete data we are legally required to retain.

10. Children

CoinHold is for adults only. We do not knowingly collect data from anyone under 18, and we will delete it if we learn that we have.

11. Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed; material changes will be announced on the site or by notice in your wallet.

12. Contact

Questions about this policy: our support team (open a ticket from the Support section of your wallet).

See also our Terms of Use.
Privacy Policy Terms of Use Cookie preferences © 2026 CoinHold Institutional Technologies AG