Cryptonite, LLC — Privacy Policy
Effective Date: May 11, 2026
Cryptonite LLC (“Cryptonite,” “Company,” “we,” “our,” or “us”) respects your privacy and is committed to protecting the personal information collected through our website, platform, and related services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you access or use the Services, and describes the rights you may have under applicable U.S. state privacy laws. By accessing or using the Services, you acknowledge that you have read this Privacy Policy. We do not rely on your silence or inactivity as consent to material changes.
1. About Cryptonite
Cryptonite operates an online e-commerce platform where customers can purchase approved digital assets using debit or credit cards. Customers provide transaction information, complete identity verification and payment authentication, and purchased digital assets are delivered directly to the customer’s designated non-custodial wallet. Cryptonite does not custody customer digital assets or control customer private keys. Certain payment processing, identity verification, sanctions screening, fraud monitoring, and digital asset fulfillment functions are performed by integrated third-party service providers, including BlockWyre and related partners.
2. Information We Collect
We may collect the following categories of personal information:
A. Identifiers and Contact Information
- Full legal name
- Email address
- Phone number
- Residential address
- IP address and device identifiers
B. Sensitive Personal Information
Some of the information we collect is treated as “sensitive personal information” under California law and as “sensitive data” under other state privacy laws, including:
- Date of birth
- Government-issued identification (e.g., driver’s license, passport)
- Social Security Number or taxpayer identification number
- Selfie images and biometric identifiers used for identity verification
- Precise geolocation
- Financial account and payment card information
We collect and process sensitive personal information solely for the purposes of providing the Services, verifying your identity, complying with anti-money laundering, sanctions, and other legal obligations, detecting and preventing fraud, and securing your account. We do not use sensitive personal information for advertising, profiling that produces legal or similarly significant effects, or any purpose beyond the limited business purposes permitted by Cal. Civ. Code § 1798.121 and comparable state laws.
C. Biometric Information
To verify your identity, our third-party identity verification providers may collect a selfie image and derive a biometric template for comparison with your government-issued identification. We do not sell, lease, trade, or otherwise profit from your biometric information. Biometric identifiers are retained only for the period required to satisfy the purpose for which they were collected and our legal record-keeping obligations, and in any event no longer than five (5) years after your last interaction with the Services, unless a longer period is required by law. By using the Services, you provide written consent to the collection, storage, and use of your biometric information as described in this Policy, including by our identity verification providers.
D. Transaction Information
- Purchase amounts
- Digital asset type
- Wallet destination addresses
- Payment authorization status
- Fraud or risk indicators
- Transaction timestamps
E. Automatically Collected Information
- Browser type and version
- Device information and operating system
- IP address
- Referring URLs
- Pages viewed and interaction data
- Cookies and similar first-party technologies
3. Sources of Personal Information
We collect personal information from the following sources:
- Directly from you, when you register, transact, contact support, or otherwise interact with the Services;
- Automatically, when you access the Services, through cookies and similar first-party technologies;
- From third-party service providers, including identity verification, sanctions screening, fraud, and payment partners, who provide information necessary to onboard and service your account; and
- From government, regulatory, and public sources, including sanctions and watchlist databases.
4. How We Use Your Information
We use personal information for the following business purposes:
- Providing and operating the Services and processing transactions;
- Verifying your identity and conducting Know Your Customer (“KYC”) procedures;
- Fraud prevention, risk management, and detecting unauthorized activity;
- Sanctions, anti-money laundering, and counter-terrorist financing screening;
- Customer support and account communications;
- Transaction monitoring and regulatory reporting;
- Compliance with legal and regulatory obligations, including record-keeping under the Bank Secrecy Act;
- Maintaining the security and integrity of the Services;
- Improving the Services, including through first-party analytics; and
- Enforcing our Terms of Service and other agreements.
We may use information in aggregated or de-identified form for analytics, operational, and business purposes. Where we maintain information in de-identified form, we commit to maintaining and using it in de-identified form and not to attempt to re-identify it, except as permitted by law.
5. KYC, Compliance, and Regulatory Screening
Cryptonite maintains anti-money laundering (“AML”) and compliance procedures designed to comply with applicable laws and regulations, including the Bank Secrecy Act, USA PATRIOT Act, and OFAC sanctions requirements. As part of these obligations, our service providers and we may:
- Verify your identity.
- Screen your information against sanctions and watchlists;
- Review and monitor transaction activity;
- Investigate suspicious or prohibited conduct;
- Request additional information or documentation; and
- Retain records required by law.
Transactions may be delayed, restricted, canceled, or reported to regulators or law enforcement where required by law.
6. Third-Party Service Providers
Cryptonite relies on third-party service providers to support operation of the Services. These providers may assist with:
- Payment processing;
- Identity verification and biometric matching;
- Fraud detection;
- AML and sanctions screening;
- Cloud hosting and infrastructure;
- Customer support;
- First-party analytics and monitoring; and
- Digital asset fulfillment and settlement.
Service providers are contractually limited to processing personal information for the specific business purposes for which it was disclosed and are prohibited from using it for their own commercial purposes, selling it, or sharing it for cross-context behavioral advertising.
We may also share information with regulated financial institutions, banking partners, merchant processors, and compliance vendors where reasonably necessary to provide the Services or comply with legal obligations.
7. Sharing and Disclosure of Information
We do not sell your personal information for money or other valuable consideration, and we do not share your personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, as amended (“CCPA/CPRA”), or under comparable state privacy laws. We have not sold or shared personal information in the preceding twelve (12) months and have no current plans to do so.
Subject to that limitation, we may disclose personal information:
- To service providers and vendors performing functions on our behalf;
- To payment processors and financial institutions;
- To compliance, identity verification, and fraud-monitoring providers;
- To regulators, government authorities, or law enforcement;
- To comply with subpoenas, court orders, or other legal process;
- To investigate fraud, security incidents, or unlawful activity;
- To protect the rights, property, or safety of Cryptonite, our customers, or the public;
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case personal information may be transferred to the successor entity; and
- With your consent or at your direction.
We may also disclose aggregated or de-identified information that does not reasonably identify you.
8. Blockchain Transactions
Blockchain transactions are generally public and permanently recorded on distributed ledgers. Wallet addresses and blockchain transaction information may become publicly visible and may be associated with transaction activity outside of Cryptonite’s control. Cryptonite cannot modify, reverse, or delete blockchain transactions once completed. Users are responsible for verifying the accuracy of wallet addresses and transaction details prior to submission.
9. Cookies, Tracking Technologies, and Opt-Out Signals
We use cookies and similar first-party technologies to:
- Operate and secure the Services;
- Authenticate users and maintain sessions;
- Detect and prevent fraud;
- Analyze first-party website traffic and performance;
- Improve user experience; and
- Remember your preferences.
We do not currently use third-party advertising cookies, marketing pixels, or cross-context behavioral advertising trackers on the Services. If we ever do, we will update this Policy and treat that activity as a “sale” or “share” under applicable law and provide a corresponding opt-out mechanism.
Global Privacy Control.
Where required by applicable law, we endeavor to recognize Global Privacy Control (“GPC”) signals. If you visit the Services with GPC enabled, we will treat your visit as an opt-out request for the browser and device used.
Do Not Track.
Some browsers offer a “Do Not Track” (“DNT”) feature. Because there is no industry standard for how DNT signals should be honored, the Services do not respond to DNT signals. We do, however, honor GPC as described above.
You may adjust your browser settings to disable cookies; however, some features of the Services may not function properly.
10. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services, comply with legal and regulatory obligations, resolve disputes, and enforce our agreements. Retention periods vary by category of information:
- Identifiers and contact information: for the duration of your account and for up to five (5) years after closure, or longer where required by law.
- Sensitive personal information used for KYC (government ID, SSN/TIN): retained for at least five (5) years after the date of the last transaction, as required by the Bank Secrecy Act and applicable AML regulations.
- Biometric identifiers and templates: retained only for the period required to satisfy the purpose for which collected, and in any event no longer than three (3) years after your last interaction with the Services, unless a longer period is required by law.
- Transaction information: retained for at least five (5) years after the date of the transaction, as required by applicable financial recordkeeping laws.
- Automatically collected information (cookies, device, log data): retained for up to twenty-four (24) months, except where required for fraud, security, or legal purposes.
When we no longer have a business or legal need to retain personal information, we will delete, destroy, or de-identify it in accordance with our retention schedule.
11. Data Security
We implement commercially reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, loss, misuse, alteration, or disclosure. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. You acknowledge that internet-based services inherently involve security risks.
12. Geographic Scope
The Services are intended for users located in the United States. We do not knowingly offer the Services to, or solicit personal information from, individuals located outside the United States. If you access the Services from outside the United States, you do so on your own initiative, and your personal information will be processed and stored in the United States.
13. Children’s Privacy
The Services are not directed to, and we do not knowingly collect personal information from, individuals under the age of 18. In particular, we do not knowingly collect personal information from children under 13, consistent with the Children’s Online Privacy Protection Act (“COPPA”). If we become aware that we have collected personal information from a person under 18, we will take reasonable steps to delete it. If you believe a child under 18 has provided us with personal information, please contact us.
14. Your Privacy Rights
Depending on your state of residence, you may have some or all of the following rights regarding your personal information:
- The right to know or access the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the purposes for collecting it, and the categories of third parties to whom we have disclosed it;
- The right to request correction of inaccurate personal information;
- The right to request deletion of personal information, subject to legal exceptions;
- The right to data portability — to receive personal information in a portable and, to the extent technically feasible, readily usable format;
- The right to opt out of the sale or sharing of personal information (which we do not engage in);
- The right to opt out of targeted advertising and profiling that produces legal or similarly significant effects (which we do not engage in);
- The right to limit the use and disclosure of sensitive personal information to purposes necessary to provide the Services;
- The right to non-discrimination for exercising any of these rights; and
- The right to appeal a decision we make about your request, where required by law.
How to Submit a Request
To submit a request, contact us by email at support@cryptonite.club. You may also designate an authorized agent to submit a request on your behalf. We will require the agent to provide written authorization from you, and we may require you to verify your identity directly with us before processing the request.
Verification
To protect your information, we will take reasonable steps to verify your identity before responding to a request. The verification method will depend on the type of request and the sensitivity of the information involved, and may include matching information you provide against information we already maintain or, for sensitive requests, additional identity verification.
Appeals
If we decline to act on your request, you may appeal our decision within a reasonable period by contacting us by email at support@cryptonite.club and stating that you are appealing our decision. We will respond to your appeal within sixty (60) days, or such shorter period as may be required by applicable law, and will explain our decision. If your appeal is denied, you may contact the attorney general of your state or the applicable regulator.
15. State-Specific Privacy Notices
Residents of certain U.S. states may have additional privacy rights under applicable state privacy laws, which may include the right to access, correct, delete, or obtain a portable copy of personal information, as well as the right to opt out of certain processing activities such as targeted advertising, profiling, or the sale or sharing of personal information. Where required by applicable law, we will honor valid consumer privacy requests and provide any required appeal rights. Depending on your state of residence, you may also have the right to limit certain uses of sensitive personal information or to exercise your rights through an authorized agent.
We do not sell personal information for monetary consideration and do not share personal information for cross-context behavioral advertising.
To exercise any privacy rights available to you under applicable law, please contact us at support@cryptonite.club or through any contact methods provided in this Privacy Policy.
16. Third-Party Websites
The Services may contain links to third-party websites, applications, or services not operated by Cryptonite. We are not responsible for the privacy practices or content of third-party services. Your use of third-party services is governed by their own privacy policies and terms.
17. Changes to This Privacy Policy
Non-material changes. We may make non-material changes to this Privacy Policy from time to time — such as stylistic edits, clarifications, contact information updates, or changes that do not expand the categories of personal information collected, the purposes for which it is used, or the categories of third parties with whom it is shared. Non-material changes will be posted on this page with a revised “Effective Date.” Your continued use of the Services after the effective date of a non-material change constitutes acceptance of that change.
Material changes. We will not make material changes to this Privacy Policy on a passive basis. A “material change” includes any change that expands the categories of personal information we collect, the purposes for which we use it, the categories of third parties with whom we share or sell it, or that otherwise materially affects your rights or our obligations. Before any material change takes effect, we will (i) provide you with advance, conspicuous notice through the Services and, where we have your email address, by email. Where required by applicable law, we will provide additional notice or obtain consent prior to applying material changes. We will not treat your silence, continued use, or failure to object as consent to a material change.
18. Contact Information
If you have questions regarding this Privacy Policy or our privacy practices, or to exercise any of the rights described above, you may contact:
Cryptonite LLC
127 N Higgins Ave STE 307D #2142
Missoula, MT 59802
Email: support@cryptonite.club
Website: cryptonite.club