OBEX Privacy Policy
Effective date: August 30, 2026 Policy version: 2026-08-30
This Privacy Policy explains how the individual operator of ObiDoge Exchange (the "Operator") collects, uses, discloses, retains, and protects information through OBEX, exchange.obidoge.xyz, and related services (collectively, the "Service"). ObiDoge Exchange is an independently operated service and is not a separate legal entity. Privacy requests may be submitted through the Contact page.
1. Information collected
The Service may collect:
- Account information: email address, account status and role, password hash, email-verification status, and policy acceptance records. The Service does not store your plaintext password.
- Security information: session and CSRF tokens, API-key hashes and metadata, Authenticator configuration in protected form, recovery-code hashes, authentication events, login attempts, IP address, user agent, timestamps, and security notifications.
- Exchange activity: balances, ledger entries, orders, fills, trades, fees, funding requests, deposits, withdrawals, wallet addresses, blockchain transaction identifiers, confirmations, and related audit history.
- Communications: information you submit through contact, support, account, or listing forms and related delivery or handling records.
- Technical information: request metadata, service logs, errors, rate-limit events, security alerts, node and wallet health, device/browser characteristics sent by standard web requests, and essential browser-storage state.
- Public blockchain information: addresses, transactions, token transfers, amounts, block data, and other information available from supported public networks.
Do not submit passwords, one-time codes, recovery codes, private keys, or seed phrases through the Contact page or any support communication.
2. How information is used
Information may be used to:
- create, verify, authenticate, secure, and administer accounts;
- process orders, deposits, withdrawals, ledger entries, fees, and other requested actions;
- detect fraud, abuse, sanctions risk, account compromise, technical failures, and prohibited conduct;
- reconcile wallets and liabilities, maintain backups, investigate incidents, and preserve audit evidence;
- communicate security codes, transaction notices, operational updates, support responses, and policy changes;
- comply with legal obligations, lawful requests, recordkeeping duties, and dispute resolution;
- enforce the Terms and protect users, the Service, networks, and third parties; and
- improve reliability, accessibility, security, and functionality using aggregated or appropriately minimized information.
The Service does not use account information for third-party behavioral advertising and does not sell or rent personal information for money. If these practices materially change, the policy will be updated and any consent required by law will be requested before the new use.
3. How information may be disclosed
Information may be disclosed only as reasonably necessary:
- to infrastructure, hosting, email-delivery, security, anti-abuse, blockchain-node, backup, and other service providers that support the Service;
- to Cloudflare Turnstile or comparable security services on pages where that protection is displayed;
- to supported public blockchains when a transaction or address is created or used;
- to a destination exchange, wallet provider, or counterparty as inherent in a transaction you request;
- to professional advisers, auditors, insurers, or incident-response providers under appropriate duties;
- to authorities, courts, or other parties when required by law or reasonably necessary to protect rights, safety, assets, or the integrity of the Service; or
- in connection with a permitted transfer of the Service, provided the recipient assumes applicable privacy obligations.
Public blockchain transactions are visible globally and may permanently reveal addresses, amounts, timing, token contracts, and transaction relationships. The Operator cannot delete or control information written to a public blockchain or independently collected by third parties.
4. Retention
Information is retained only as long as reasonably necessary for the purposes described above, including account operation, security, fraud prevention, dispute handling, backup integrity, tax and financial records, and legal compliance. Retention periods differ by record type.
Completed ledger entries, blockchain records, policy acceptances, administrative audit events, and security evidence may be retained for an extended period or permanently when alteration would undermine financial integrity, security, or legal evidence. Backups may preserve deleted information until safely rotated. Account closure does not require deletion of records that must be retained or that are necessary to establish, exercise, or defend legal claims.
5. Security
The Service uses measures designed to protect information, including encrypted transport, hashed passwords and API credentials, protected authentication data, access controls, service isolation, rate limits, audit records, wallet protections, and backups. No system, storage method, email service, device, or blockchain is completely secure. The Operator cannot guarantee that unauthorized access, loss, or disclosure will never occur.
You are responsible for protecting your email, devices, passwords, Authenticator, recovery codes, API credentials, private keys, and seed phrases. Contact the Service promptly if you suspect compromise.
6. Browser storage and third-party content
The Service uses essential session and CSRF cookies and may store interface preferences in local browser storage. Contact and listing forms may use Cloudflare Turnstile for abuse prevention. Asset logos or other static resources may be delivered from identified third-party hosts. Details appear in the Cookie Policy.
Third-party websites, wallets, exchanges, explorers, or services have their own privacy practices. This Policy does not control them, even when the Service links to them.
7. Your choices and requests
Depending on applicable law, you may request access to, correction of, or deletion of certain personal information; object to or restrict certain processing; or obtain information about disclosures. Submit a request through the Contact page. The Operator may require reasonable verification before acting and may deny or limit a request where an exception applies, including financial-record integrity, security, fraud prevention, legal obligations, or the rights of others.
You can control cookies and local storage through your browser, but blocking essential storage can prevent sign-in, security validation, or preferences from working. You may unsubscribe from optional communications if offered; account, security, legal, and transactional communications cannot be disabled while the relevant account or activity remains active.
8. Children
The Service is not directed to anyone under 18, and people under 18 may not create or use an account. If you believe a minor provided information, submit a report through the Contact page.
9. Geographic processing
Information may be processed where the Service, its infrastructure, or its providers operate. Those locations may have different data-protection laws. The Operator applies this Policy to information under the Operator's control and uses reasonable safeguards where required.
10. Policy changes
This Policy may be updated prospectively. The current effective date and policy version will be displayed. Material changes may require notice or affirmative reacceptance. Earlier versions and recorded acceptances may be retained as legal and security evidence.
11. Contact
Use the Contact page on OBEX for privacy questions or requests. Do not submit authentication secrets, private keys, or seed phrases.