Privacy Policy
Last updated: July 17, 2026
1. Overview
VEIL (“VEIL”, “we”, “us”, or “our”) is a privacy-focused, non-custodial cryptocurrency exchange aggregator available at veilexchange.is. This Privacy Policy explains what limited data is involved when you use our services (the “Services”), how it is used and shared, and the choices and rights you have. It should be read together with our Terms of Use and AML/KYC Policy.
Our guiding principle is data minimization: we collect as little information as possible, and we do not require accounts, identity verification (KYC), or personal registration to use the core swap service.
2. Scope
This Policy covers data processed through the VEIL website, interfaces, and any related communications with us (such as email or in-app support chat). It does not cover data collected by independent third-party providers, exchanges, payment processors, card issuers, bridges, or websites that you interact with or that are linked from the Services; those parties process data under their own policies.
3. Data We Collect
To operate the Services reliably and securely, we process a minimal amount of technical and transactional data:
- Technical and usage data — such as IP address and IP-derived request metadata, approximate region, user-agent, accept-language, browser or device type, timestamps, and diagnostic logs, used for security, abuse prevention, rate limiting, and reliability.
- Transaction metadata — the assets and networks involved, amounts, quotes, selected provider, Order and reference identifiers, transaction hashes, and the destination and refund addresses you enter, which are required to route and track a transaction.
- Optional account data — if you choose to create an account, the email address you supply and your related settings and Order history. An account is never required for the core swap service.
- Support and communications — if you contact support or use in-app chat, the messages, attachments, and contact details you provide, and, if you opt in, a push-notification token used solely to notify you of support replies.
We do not ask for unnecessary personally identifiable information (PII) such as your name, government ID, or physical address to perform a standard swap.
4. Data We Do NOT Collect or Sell
VEIL is non-custodial and privacy-first. We do not hold your funds or private keys, we do not require an account for the core service, and we do not collect KYC documents, real names, or other unnecessary personal data to use it. We do not sell, rent, or cede your data to third parties, we do not share it with data brokers, and we do not build advertising profiles about you. Any data we do hold is disclosed outside of executing your transaction only on an individual basis where required by law or valid legal process.
5. Features With Additional Data (Fiat, Cards)
Some optional features rely on regulated third parties that impose their own requirements. When you buy or sell Digital Assets for fiat, or issue or top up a prepaid card, the third-party payment processor, bank, or card issuer may collect identity and payment information (KYC) directly from you under its own privacy policy. That data is collected and controlled by the relevant provider, not by VEIL, and VEIL may have little or no access to it. Please review the provider’s policy before using such features.
6. How We Use Data
We use the limited data described above to: provide, operate, and maintain the Services; route Orders to providers and display their status; prevent fraud and abuse and keep the Services secure; screen against sanctions and comply with applicable legal obligations; respond to support requests; and improve reliability and performance. We do not use your data for behavioral advertising.
7. Legal Bases for Processing
Where data-protection laws such as the EU/UK GDPR apply, we process data on the following bases: performance of a contract (to provide the Services you request); our legitimate interests (security, abuse prevention, and improving the Services), balanced against your rights; compliance with legal obligations (including AML and sanctions); and, where relevant, your consent (for example, optional push notifications), which you may withdraw at any time.
8. Cookies and Local Storage
We use only essential cookies and browser local storage needed for the Services to function — for example, to remember your language preference, interface settings, session, and in-progress Order state. We do not use third-party advertising or cross-site tracking cookies. You can clear or block storage in your browser settings, though some features may then not work correctly.
9. Third-Party Providers and Data Sharing
Because transactions are executed by independent third parties, we share only what is necessary to complete what you request:
- Exchange providers and bridges — transaction details (assets, networks, amounts, destination and refund addresses) are shared with the provider you select so it can execute and settle the Order under its own privacy policy and compliance requirements.
- Fiat processors and card issuers — for buy, sell, and card features, the relevant regulated provider processes the payment and any KYC data directly.
- Infrastructure and support tools — hosting, security, logging, communications, and support-chat providers that process data on our behalf under appropriate safeguards.
- Legal and safety — we may disclose data where required by law, valid legal process, or to protect the rights, safety, and security of users, VEIL, or the public.
We do not control how providers process data once it is shared with them to execute your transaction.
10. AML and Sanctions Data
To keep the Services safe and compliant, transactions may be screened for sanctions and anti-money-laundering (AML) risk, including on-chain analysis of the addresses involved. Where a provider flags a transaction, it may request additional information such as source of funds or identity verification. This processing is described further in our AML/KYC Policy.
11. International Data Transfers
The Services are global, and the limited data we and our providers process may be transferred to and stored in countries other than your own, which may have different data-protection rules. Where required, we rely on appropriate safeguards for such transfers.
12. Data Retention
We retain the limited data described above only for as long as necessary for the purposes set out in this Policy — to provide the Services, support pending and recent transactions, maintain security, and comply with legal obligations. Diagnostic and security logs are kept for a limited period appropriate to those purposes and then deleted or anonymized. Transaction metadata may be retained longer where necessary to meet legal, tax, or anti-fraud obligations, or where a provider requires it. Optional account data is retained until you delete your account or it is no longer needed. Where you ask us to delete data we hold about a completed transaction, we will do so unless we are required to keep it.
13. Security
We take reasonable technical and organizational measures to protect the data we process against unauthorized access, alteration, and loss. However, no method of transmission or storage is completely secure, and you use the Services at your own risk. Because VEIL is non-custodial, you remain solely responsible for the security of your own wallets and private keys.
14. Your Rights
Depending on your jurisdiction (for example under the GDPR or CCPA), you may have rights to access, correct, delete, restrict, or object to the processing of personal data we hold about you, to portability, and to withdraw consent. You also have the right to lodge a complaint with your local data-protection authority. Because we collect so little data and generally do not require accounts, we may be unable to identify data associated with a particular individual; where we cannot verify or locate such data, we may be unable to action a request. To exercise any applicable right, contact us using the details below.
15. Children
The Services are not directed to, and may not be used by, anyone under 18 (or the age of majority in their jurisdiction). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
16. Automated Decisions and Do Not Track
Providers may apply automated risk scoring to transactions for AML and fraud-prevention purposes, as described in our AML/KYC Policy. VEIL itself does not use your personal data to make automated decisions that produce legal effects concerning you. Because we do not track you across sites, we treat all visits the same and maintain essential-only data practices regardless of any “Do Not Track” browser signal.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Changes become effective when posted on this page, and the “Last updated” date will be revised accordingly. Your continued use of the Services after any change constitutes acceptance of the revised Policy.
18. Contact
If you have any questions about this Privacy Policy or wish to exercise a right, contact us at support@veil.exchange. For confidential matters you may encrypt your message with our PGP key, available in the site footer.