This policy describes exactly what ABEBIT collects, why, who it goes to, and how to have it removed. It covers the platform at abebit.com, operated by ABEBIT LLC, a limited liability company registered in Georgia, Tbilisi, Georgia.
ABEBIT LLC is the data controller for the personal data described below.
Data protection contact: [email protected].
1. What we collect
1.1 Account data
- Email address — used to sign in, to send the one-time codes that complete every login, and to contact you about your account.
- Username.
- Password — stored only as a PBKDF2-SHA256 hash. We cannot read it and cannot recover it for you.
- Email verification status and the timestamps of one-time codes.
1.2 Technical data
- IP address — recorded on login attempts, on administrative actions, and when you accept a legal document. Used for rate limiting, account lockout after repeated failures, fraud prevention, and as proof of consent.
- Browser user agent string, recorded alongside consent records.
- Session identifier, so you stay signed in.
- Server logs — requested URLs, status codes and timestamps, retained for security investigation and debugging.
1.3 Product data you provide
- Watchlist — which assets you follow.
- Portfolio holdings — asset and quantity, if you choose to enter them. These are figures you type in; we have no access to any exchange or wallet of yours.
- Risk settings — declared account equity, risk percentage per trade, maximum daily and weekly loss limits, maximum concurrent positions, assumed fee and slippage levels. Used to personalise position-sizing arithmetic and Guardian risk alerts.
- Alert and notification preferences.
- Telegram chat ID, if you link the Telegram bot.
- Web push subscription token, if you enable browser notifications.
- Community content — signals you publish, votes, comments and discussion messages.
- Support tickets and their contents.
1.4 Payment data
- Invoice identifier, cryptocurrency, amount, status, and timestamps.
- Payments are processed by a self-hosted BTCPay Server instance. We never see or store card numbers or bank details — there are none; payment is in cryptocurrency only.
- Any wallet address or extended public key you provide for payouts is encrypted at rest and decrypted only in memory when a payout is being prepared.
1.5 Behavioural data
- Which signals you view, and personalisation scores derived from that, used to rank what you are shown.
- Login history — time, IP, and whether the attempt succeeded.
We do not use third-party advertising or analytics trackers, and we do not build advertising profiles.
2. Why we collect it, and on what basis
| Purpose | Data used | Basis |
|---|---|---|
| Providing the service you signed up for | Account, product, payment data | Performance of a contract |
| Signing you in securely (2FA codes) | Email, IP | Performance of a contract |
| Preventing abuse, fraud and account takeover | IP, login history, user agent | Legitimate interests |
| Proving you accepted the legal documents | IP, user agent, timestamp | Legal obligation / legitimate interests |
| Personalising which signals you see first | Behavioural data | Legitimate interests |
| Sending signal alerts you asked for | Email, Telegram ID, push token | Consent |
| Product announcements and price-change notices | Performance of a contract | |
| Optional newsletter | Consent — withdrawable at any time |
We use your data only for the purposes listed above. If we ever needed it for a genuinely new purpose, we would tell you first and, where the law requires it, ask for your consent.
3. Who your data is shared with
We do not sell your personal data. We do not rent it, and we do not share it for anyone else’s marketing. Data reaches the following third parties only as needed to run the service:
| Recipient | Role | What reaches them |
|---|---|---|
| Cloudflare | CDN, DDoS protection, bot check (Turnstile) | Your IP address and request metadata for every page you load |
| Telegram (Telegram FZ-LLC) | Bot delivery of alerts, if you link it | Your Telegram chat ID and the alert contents |
| [EMAIL PROVIDER] | Sending login codes and account email | Your email address and the message contents |
| [HOSTING PROVIDER] | Server hosting | All platform data, at rest on their infrastructure |
| Web push services (Apple / Google / Mozilla) | Delivering browser notifications, if enabled | Your push token and the notification contents |
Market, news and macroeconomic data is fetched from Binance, CoinGecko, Etherscan, alternative.me, ForexFactory, CoinMarketCal, CoinDesk, CoinTelegraph, Decrypt, Bitcoin Magazine, BBC, Reuters and Al Jazeera. No personal data is sent to any of them — these are one-way reads of public information.
We may also disclose data where legally compelled to do so, or to establish or defend legal claims.
4. Cookies
We use a small number of first-party cookies. None are advertising cookies.
- Session cookie — keeps you signed in. Strictly necessary.
- CSRF token cookie — protects forms against cross-site request forgery. Strictly necessary.
- Cloudflare Turnstile — sets a short-lived cookie while verifying that a login or registration is not automated. Strictly necessary for security.
Strictly necessary cookies do not require consent, and the service cannot function without them. We set no analytics, advertising or cross-site tracking cookies, which is why you are not shown a tracking-consent banner. Some preferences are stored in your browser’s local storage (for example, which notices you have dismissed); this never leaves your device.
5. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Payment records | Retained after account deletion where accounting or tax law requires it |
| Legal consent records | Deleted together with your account |
| Login history and security logs | Up to 12 months |
| Signal outcome history | Indefinitely, but detached from your identity |
| News and market data | News for 30 days; market data as needed for analysis |
| Support tickets | 24 months after closure |
| Encrypted backups | Rotating, up to 14 days |
Deleted data persists in backups until those backups age out — at most 14 days beyond deletion.
6. Your rights
You can ask us to:
- Access — receive a copy of the data we hold about you.
- Correct — fix anything inaccurate. Most fields you can edit yourself in Settings.
- Delete — erase your account and personal data (see below).
- Restrict or object — to processing based on legitimate interests.
- Port — receive your data in a machine-readable format.
- Withdraw consent — for alerts or newsletters, at any time, without affecting the lawfulness of what came before.
How to request deletion
Email [email protected] from the address registered to your account, with the subject “Delete my account”. Alternatively, open a support ticket from within the platform.
We respond within 30 days. We will confirm before erasing, because the action cannot be undone. Deletion removes your account, profile, watchlist, portfolio, risk settings, alert preferences, community content, support history and your records of accepting these documents. Payment records are retained where accounting or tax law requires it, and are kept only for that purpose.
7. Security
- All traffic is encrypted in transit (TLS).
- Passwords are stored as salted PBKDF2-SHA256 hashes.
- Wallet addresses and other sensitive fields are encrypted at rest.
- Every login requires a one-time code sent to your email, in addition to your password.
- Repeated failed logins lock the account temporarily.
- Backups are encrypted with AES-256 before leaving the server.
- Administrative access is limited, requires a second authentication step, and is recorded in an audit log.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law.
8. Children
The service is not for anyone under 18. We do not knowingly collect data from children; if we learn that we have, we delete it and close the account.
9. Your rights by region
9.1 Georgia
The operator is established in Georgia and processes personal data under the Law of Georgia on Personal Data Protection. You may exercise the rights in section 6 by writing to [email protected], and you may lodge a complaint with the Personal Data Protection Service of Georgia.
9.2 European Economic Area and United Kingdom
Where you are in the EEA or the UK, the GDPR (and UK GDPR) applies to our processing of your data. The operator is the data controller.
- Legal bases are set out in the table in section 2: contract, legitimate interests, consent, and legal obligation.
- Your rights — access, rectification, erasure, restriction, portability, and objection — are described in section 6 and apply in full.
- Right to object. Where we rely on legitimate interests (abuse prevention, personalised ordering of signals) you may object at any time and we will stop unless we can show compelling grounds that override your interests.
- Withdrawing consent is as easy as giving it: turn alerts off in Settings, or email us. Withdrawal does not affect processing already carried out.
- No automated decision-making with legal or similarly significant effects is carried out on you. Signals are generated by an algorithm, but they are published to everyone on a tier and produce no decision about you.
- Response time — within one month, extendable by two further months for complex requests, in which case we will tell you why.
- Complaints may be made to your national supervisory authority, or in the UK to the Information Commissioner’s Office.
Georgia is not currently the subject of a European Commission adequacy decision. Where personal data is transferred from the EEA or UK to Georgia or to a service provider elsewhere, we rely on Standard Contractual Clauses or another lawful transfer mechanism, and apply the safeguards described in section 7.
9.3 United States
If you live in a U.S. state with a comprehensive privacy law — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah and Texas — the following applies in addition to section 6.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
- We do not use or disclose sensitive personal information beyond the purposes listed in section 2.
- We will not discriminate against you for exercising any privacy right — your subscription, pricing and service level are unaffected.
- You may authorise an agent to make a request on your behalf; we will ask for proof of that authorisation.
- If we decline a request we will tell you why, and you may appeal by replying to that decision. We respond to appeals within 45 days.
Exercise any of these rights at [email protected]. We verify identity by confirming control of the registered email address.
10. International transfers
Our infrastructure and service providers may be located outside your country. Where personal data is transferred internationally we rely on appropriate safeguards as required by applicable law.
11. Changes to this policy
We may update this policy. The version and date appear at the top of this page. Material changes are announced by email and by an in-product notice.
12. Complaints
Contact us first at [email protected] — most issues are resolved directly. If you are not satisfied you may complain to:
- the Personal Data Protection Service of Georgia, the operator's supervisory authority;
- the data protection authority of your own country, if you are in the EEA;
- the Information Commissioner's Office, if you are in the UK;
- your state attorney general, if you are in the United States.