Privacy
Privacy Policy
1. Who we are (data controller)
This site is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], unified social credit code (USCC) [USCC / REGISTRATION NUMBER], registered under the State Administration for Market Regulation of the PRC (“we”). We are the data controller for information submitted through the report form.
Data protection contact (DPO): [DPO EMAIL].
We are not affiliated with, endorsed by, or connected to BitMart or any of its group entities.
2. What we collect
Required: your BitMart account identifier (UID), a contact (email, Telegram, WhatsApp or Twitter), country of residence, the approximate amount affected, the date you first could not withdraw, and at least one screenshot as evidence.
Optional: a name or handle to address you by, transaction IDs / wallet addresses, and free-text notes.
Security metadata: a salted, irreversible hash of your IP address (never the address itself), your browser user-agent, and the time of submission.
We never ask for your password, seed phrase, private key, 2FA codes, or API keys. Anyone asking for these is attempting fraud.
3. Why, and our lawful basis
We collect this to record and document claims arising from the BitMart withdrawal crisis. Where you consent, the materials are passed to [RECIPIENT — LAW FIRM] and selected experts, solely to assess and potentially pursue this matter.
Registering does not create an attorney–client relationship, does not make you a party to any legal action, and is not a promise of recovery. Whether any group or class action proceeds, and who is included in it, is decided by a court.
Our lawful basis is your separate, explicit consent under Article 13 of the PRC Personal Information Protection Law (PIPL), given via the checkboxes on the form. You may withdraw consent at any time (see section 7).
4. Cross-border transfer
Your data is processed on Cloudflare infrastructure in Singapore (APAC region), outside mainland China. This is a cross-border transfer of personal information under PIPL.
For this transfer we rely on: [CROSS-BORDER MECHANISM — CAC security assessment / filed Standard Contract (SCC) / counsel confirmation that the data is not “important data”]. You give separate consent to this transfer via a dedicated checkbox on the form.
5. Who we share it with
We share submissions only with [RECIPIENT — LAW FIRM], [RECIPIENT ADDRESS], and with regulators or law enforcement where relevant, and only where you gave the sharing consent. We do not sell your data or use it for advertising.
Our processors act on our behalf under contract: Cloudflare (D1 database and R2 object storage, Singapore region).
6. Storage and retention
Structured fields are stored in Cloudflare D1; screenshots in a private Cloudflare R2 bucket, never accessible by public link.
We keep submissions for 365 days from the date of submission, after which they are automatically and permanently deleted, including all uploaded images. We may retain a submission longer only where required for active legal proceedings, and only for as long as that requires.
7. Your rights
You may request access to, correction of, or deletion of your data, withdraw consent, and lodge a complaint with a supervisory authority. To exercise any of these, contact [DPO EMAIL]. We respond within 15 working days. On an erasure request we permanently delete your report and all its screenshots.
8. Children
This site is not intended for anyone under 18, and we do not knowingly collect their data.
9. Changes
We may update this policy; the “last updated” date will change. Material changes will be noted on the site.
10. Contact
[LEGAL ENTITY NAME] — [DPO EMAIL] — [POSTAL ADDRESS].
Not legal advice. This site is based on public reports and user submissions and is not affiliated with BitMart.