Kebijakan Privasi
Terakhir diperbarui: 2026-08-12
Teks lengkap hanya diterbitkan dalam bahasa Inggris. Terjemahan menyusul setelah tinjauan hukum selesai.
1. The short version
We collect an email address and the exchange UIDs you choose to register. That is essentially all of it. We do not run identity checks, we never see your exchange credentials or your trading API keys, we do not build advertising profiles, and we do not sell anything to anyone.
The controller of this data is the loweef team. Privacy enquiries: [email protected].
2. What we collect
| Data | Why | Where it comes from |
|---|---|---|
| Email address, and either a password hash or a Google account identifier | Signing you in; sending service-critical notices | You |
| The exchange UIDs you register | Verifying referral attribution and settling payback | You |
| Payback ledger — accruals and settlements per UID | Calculating your payback and being able to prove it to you | The exchange's affiliate reporting |
| A single first-party session cookie | Keeping you signed in | Your browser |
| Self-reported estimated volume, if you enter one | Showing you an estimate. Never used for settlement | You |
| Ambassador attribution, if you arrived through an ambassador link | Paying the ambassador from our own share | Your first UID link |
3. What we deliberately do not collect
Identity documents and selfies: identity verification is the exchange's own procedure, carried out between you and the exchange. We never see it and never receive the result beyond, at most, whether an account exists.
We also do not collect private keys or seed phrases, trading API keys, deposits or withdrawals, external wallet addresses, precise location, contact lists, or any advertising identifier.
4. Analytics without cookies
We measure traffic on our own servers rather than through a third-party analytics service, and we do so without setting an analytics cookie and without storing your IP address.
For each page view we record the path, the language, the device class, the referring hostname, any campaign tags in the link, and the country code our network provider supplies. To count unique visitors without identifying them we compute a short one-way hash of the date, your IP address, your browser string, and a random value that is generated in memory, never written to disk, and replaced every day. The IP address itself is never stored, the hash cannot be reversed, and because the random value changes daily the same visitor cannot be followed from one day to the next.
This is deliberately a weaker measurement than the industry norm. It counts visits; it does not build a profile.
5. How we use it
- To operate the service: verifying UID attribution against affiliate reporting, calculating and settling payback, and showing you your dashboard.
- To detect and prevent fraud, self-referral and abuse.
- To send service-critical email — verification, security, and changes that affect your payback. We do not send marketing email to your account address unless you ask for it.
- To meet accounting, tax and audit obligations.
We do not sell personal data, do not share it with advertisers, and do not use it to train models.
6. Who we share it with
Exchanges: we match your UID against the exchange's affiliate reporting. The exchange already knows that UID — it issued it. We send exchanges no other personal data about you.
Service providers that process data on our behalf:
| Provider | Role |
|---|---|
| Vultr Holdings, LLC | Application hosting |
| Cloudflare, Inc. | DNS, TLS and reverse proxy |
| Google LLC | Sign-in with Google (OpenID Connect) — only if you choose it |
Authorities, where we are legally required to, and only to the extent required.
7. How long we keep it
- Account data: for as long as your account exists.
- Settlement ledgers: for 5 years, as required for accounting and audit. These records are what let us prove what you were paid, so they outlive account deletion.
- Traffic records: 400 days, in the reduced form described above.
You may delete your account at any time. When you do, we remove the personal data that is not required for the retained ledgers, and the ledger entries that remain are no longer linked to your email address.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or export it. Write to [email protected] from the address on your account and we will act on it.
If you are in a jurisdiction that grants statutory data rights — for example the GDPR in the EEA and the UK, or the CCPA in California — those rights apply in addition to the above, including the right to complain to your local supervisory authority.
9. Cookies
One first-party cookie, used to keep you signed in. It is not used for tracking, is not shared, and expires when your session ends or you sign out. We set no advertising cookies and no third-party cookies, and there is nothing here to consent to because there is nothing optional being set.
10. Security
Session secrets and affiliate API credentials are held server-side and never sent to browsers. UIDs are masked in every interface, including our own admin screens, and both of those properties are checked automatically on every build so that a regression fails the deployment rather than reaching you.
No system is perfectly secure. If you find a vulnerability, please report it to [email protected] before disclosing it publicly, and we will work with you.
11. Changes and contact
We post updates to this policy on this page with a new "last updated" date. Where a change materially affects what we collect or why, we say so in the dashboard as well.
Privacy enquiries: [email protected].
Lihat juga: Ketentuan Layanan · Pernyataan risiko