Privacy Policy
What we collect, why we hold it, how long we keep it and how to have it removed. Last updated 12 August 2026.
Vacuum Exchange operates the cryptocurrency exchange service at vacuum.exchange, its mirror at vacuum.click and its Tor address. We are established in the Republic of Seychelles and act as the controller of the personal data described here.
For anything in this policy, including a request to see or delete your data, write to [email protected].
To carry out an exchange we need the destination address you give us and the amount. That is the minimum, and it is all we require: no name, no document, no phone number.
If you give an email address we store it, send the order confirmation and status messages to it, and create an account so you can look up your history. Giving one is optional; every exchange works without it.
The blockchain tells us the rest. Your deposit transaction hash, the amount that arrived, and — when a refund is due — the address the funds came from, read from a public block explorer.
Technical records. The IP address the order was created from, the country reported by our network provider, and which of our domains you arrived on. Page visits are counted using a one-way hash of your address and browser, never the address itself.
If you contact us through the form on a stopped order, we keep the contact you leave and the message.
No identity documents. No selfies. No proof of address. No source-of-funds questionnaire. We do not ask, and we have nowhere to store them if you sent one.
We do not hold your funds. Each exchange is settled from the deposit that funds it and closed; there is no balance in your name.
The destination address and amount, because without them there is no exchange to perform.
Your email, because you asked for confirmations — and because an order that cannot be confirmed by email is not created at all, which protects you from a mistyped address.
Transaction data, because a refund can only go back to where the money came from, and establishing that requires the deposit transaction.
Technical records, to detect abuse, investigate a disputed order and understand where our visitors come from.
Four cookies of our own, none of them sold or shared:
- vx_account — keeps you signed in. Removing it signs you out.
- vx_lang — remembers your language.
- vx_ref — records that you arrived through a partner's link, so their share is credited. 400 days.
- vx_src — records which listing or site sent you.
Third-party analytics. We use Google Analytics, Microsoft Clarity and PostHog. Clarity and PostHog record how pages are used, which can include a replay of your session on the site. Google Analytics counts visits. Each sets its own cookies under its own policy.
Blocking cookies in your browser, or using an extension that blocks trackers, does not prevent you from exchanging. Only vx_account is needed, and only if you want to sign in.
Our payment gateway receives the destination address and the amount, because it executes the transfer. It cannot work without them.
Resend delivers our email and therefore sees your address and the message.
Cloudflare sits in front of the site and sees the requests, as any network provider does.
The analytics providers named above.
We do not sell data, we do not share it for advertising, and we do not pass it to anyone else unless we are legally compelled to.
Orders and financial records — five years. Exchange records are financial records and are retained accordingly.
Account and email — until you ask us to delete it, then removed within 30 days, except where an order it is attached to is still inside its retention period.
Support messages — one year.
Visit statistics — 14 months. These hold no address, only a hash.
Email delivery records — six months.
Write to [email protected] and you can ask us to: tell you what we hold about you; correct it; delete it; send it to you in a portable form; or stop sending you status emails, which you can also do from the unsubscribe link in any of them.
We answer within 30 days. If a request would require us to destroy a financial record we are obliged to keep, we will say so and explain what remains.
Traffic is encrypted in transit. Passwords are stored as scrypt hashes and cannot be read back, including by us. The key that authorises payouts is held by a single isolated process and is not available to the web server.
No system is beyond compromise. If a breach affects your data we will tell you at the address we hold, and say plainly what was exposed.
When this policy changes materially we update the date at the top and, where we have your address and the change affects you, we write to you. Continuing to use the service after a change means you accept it.