1. Introduction
Vinance Coin ("VNC", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at vinancecoin.com, including our web application, APIs, wallet services, and all related services (collectively, the "Platform").
By accessing or using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our services.
2. Information We Collect
2.1 Personal Information (Provided by You):
- Account Registration: Full name, email address, phone number, password (hashed)
- KYC Verification: PAN card number & image, Aadhaar card number & images (front/back), selfie photograph
- Financial Information: Bank account details (for withdrawals), UPI ID, payment transaction references
- Wallet Information: Cryptocurrency wallet addresses, transaction histories
2.2 Automatically Collected Information:
- Device Data: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, timestamps, click patterns
- Cookies & Tokens: JWT authentication tokens, session data, preference cookies
- Transaction Data: Buy/sell orders, deposits, withdrawals, swap history, staking records
2.3 Third-Party Information:
- Payment gateway data (Razorpay, Cashfree, PayPal, Stripe transaction confirmations)
- Blockchain data (BSC transaction hashes, on-chain activity)
- Referral information from users who invite you
3. How We Use Your Information
We use collected information for the following purposes:
- Account Management: Creating and maintaining your account, authenticating logins
- Transaction Processing: Executing buy/sell/swap/transfer orders, processing deposits & withdrawals
- KYC/AML Compliance: Verifying identity as required by Indian regulations (PMLA, FEMA)
- Security: Detecting fraud, preventing unauthorized access, quantum-secure encryption
- Communication: OTP verification, transaction confirmations, security alerts, marketing (with consent)
- Platform Improvement: Analytics, performance monitoring, feature development
- Legal Compliance: Meeting regulatory requirements, responding to legal processes
4. Data Security
We implement industry-leading security measures to protect your data:
- Encryption: AES-256 encryption for data at rest, TLS/SSL for data in transit
- Quantum Security: CRYSTALS-Dilithium post-quantum cryptographic signatures for wallets
- Password Hashing: bcrypt with 12 salt rounds — passwords are never stored in plaintext
- Rate Limiting: API rate limiting to prevent brute-force attacks (500 requests/15 min)
- Helmet Protection: HTTP security headers to prevent XSS, clickjacking, and injection attacks
- Access Control: Role-based access (user/admin), JWT token authentication with expiry
- Withdrawal Whitelist: Users can whitelist approved withdrawal addresses for added security
5. Data Sharing & Disclosure
We do NOT sell your personal data. We may share information only in these cases:
- Payment Processors: Razorpay, Cashfree, PayPal, Stripe — to process your transactions
- Legal Obligations: When required by Indian law, court orders, or regulatory authorities (SEBI, RBI, ED, FIU-IND)
- Blockchain Networks: On-chain transactions on BSC are publicly visible by nature of blockchain technology
- Service Providers: Hosting providers, email services (for OTP and notifications) — under strict data processing agreements
- Business Transfers: In event of merger, acquisition, or asset sale — with user notification
6. Cookies & Local Storage
We use the following browser storage mechanisms:
- JWT Token: Stored in localStorage for authentication (expires after session)
- Preferences: Theme settings, notification preferences
- Analytics: Anonymous usage patterns to improve the platform
You can clear cookies and local storage through your browser settings. Note: clearing auth tokens will log you out.
7. Your Rights
Under applicable Indian data protection laws (IT Act 2000, Digital Personal Data Protection Act 2023), you have the right to:
- Access: Request a copy of your personal data we hold
- Correction: Update or correct inaccurate data via your profile settings
- Deletion: Request deletion of your account and associated data (subject to regulatory retention requirements)
- Withdraw Consent: Opt out of marketing communications at any time
- Data Portability: Request your data in a machine-readable format
- Grievance Redressal: File complaints about data handling practices
To exercise these rights, email us at privacy@vinancecoin.com or legal@vinancecoin.com.
8. Data Retention
- Account Data: Retained for the duration of your account + 5 years after closure (regulatory requirement)
- KYC Documents: Retained for 5 years after account closure as per PMLA guidelines
- Transaction Records: Retained for 8 years as per Income Tax Act requirements
- Log Data: Server logs retained for 90 days for security monitoring
- Marketing Data: Deleted within 30 days of opting out
9. Children's Privacy
Our Platform is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you are under 18, please do not register or use our services. If we learn that we have collected data from a user under 18, we will delete the account and associated data promptly.
10. International Data Transfers
Your data is primarily stored on servers in India. Some data may be processed by third-party services (payment gateways, email providers) that may have servers outside India. We ensure all international transfers comply with applicable data protection laws and include appropriate safeguards (encryption, contractual clauses).
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via:
- Email notification to your registered email address
- In-app notification on your dashboard
- Banner on the Platform homepage
Continued use of the Platform after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related inquiries, complaints, or data requests:
Grievance Officer: As required under Indian IT Act, our Grievance Officer can be reached at legal@vinancecoin.com. We will acknowledge your complaint within 24 hours and resolve it within 30 days.