Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.
THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.
“we do not sell your personal information”
Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.
THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.
“service providers, partners, and affiliates”
How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.
THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.
“aggregated or de-identified information”
Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.
THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.
THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.
“you grant us a licence to use your content”
A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.
THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.
“Regarding the Travel Rule, we and other custodial exchanges and financial institutions share certain basic information about you.”
The identity they checked at signup is attached to individual crypto transfers and sent to the exchange on the other side. The recipients are not limited to that exchange: policies extend the sharing to regulators and other industry partners. This is required by anti-money-laundering rules in the US, UK and EU.
THE MOVE Which of your transfers carried your identity, and where it went, is theirs to answer. Their reply goes on your record.
“We may analyze public blockchain data, including timestamps of transactions, transaction IDs, transaction amounts, and wallet addresses.”
The public chain is read back into your account. Wallet addresses, amounts and times that look anonymous on their own are joined to the identity on your account and held as data about you.
THE MOVE What they have tied to your account from the public chain is theirs to answer. The reply, or the silence, goes on your record.
“As blockchains are networks we do not control, we are not able to erase, modify, or alter personal data on such networks.”
Some policies warn that on-chain transaction history sits outside the deletion right entirely. Only the copy the service holds off the chain can ever be removed; what is written to the public ledger stays.
THE MOVE Which parts of your record they can actually delete, and which are fixed on the chain, is theirs to answer. Their reply goes on your record.