Privacy Policy
What CryptX actually stores about you, why each item exists, who else ever sees it, and what you can ask us to do with it. This page describes the real database behind the service — not a generic template. If something is not listed here, we do not collect it.
- Scope, and who we are
- What we actually hold
- What we do not collect, and cannot do
- Why each item exists
- Cookies and browser storage
- Your exchange API keys
- Who else your data reaches
- Where the data is stored
- How long we keep it
- Disconnecting, and asking us to delete
- Security, stated honestly
- Your rights, and how to use them
- Age
- Changes, and how to reach us
1Scope, and who we are
CryptX is a product of WealthX Technologies Pvt. Ltd. (“WealthX”, “we”, “us”). This policy covers the CryptX website, the client portal at /app, and the automated execution service behind them. It forms part of the Terms of Service.
It does not cover Delta Exchange India, Razorpay, or any other company you deal with directly. Your exchange account is governed by Delta’s own privacy policy; a card or UPI payment is governed by Razorpay’s.
2What we actually hold
Everything below is a real field in the CryptX database. Nothing else about you is stored.
Because you signed up
| Item | Detail |
|---|---|
| First and last name | As you typed them. Used to address you and on invoices. |
| Email address | Your login identity, and where verification codes, invoices and service notices go. |
| Mobile number | An Indian mobile, stored in +91XXXXXXXXXX form. Used to deliver the verification code over WhatsApp, and for support. |
| Password | Stored only as a salted one-way hash. The plain password is never written to disk and cannot be recovered by us — only reset. |
| Verification codes | Stored as a hash, never in the clear, with an attempt counter, an expiry and two flags recording whether the email and WhatsApp sends succeeded. |
| Password-reset requests | Your user id, the email, and whether the request is open or done. |
Because you connected an exchange account
| Item | Detail |
|---|---|
| Delta API key and secret | Encrypted at rest with Fernet (AES) before they touch the database. Decrypted in memory only to place, manage and close orders on your account. See section 6. |
| Connection settings | The exchange endpoint, a label for the connection, your size multiplier and minimum size, whether auto-adjust is on, and whether the connection is active or disconnected. |
| Last wallet balance read | A single USD figure, refreshed from Delta, used to size positions in proportion to your balance and to show your dashboard. |
Because the algorithm traded
| Item | Detail |
|---|---|
| Execution ledger | One row per order we send for you: the option symbol, buy or sell, size in contracts, the status (placed, dry-run, skipped or failed), the exchange order id, the fill price, any error the exchange returned, and the timestamp. |
| Billing windows | Start and end of each window, the gross realised P&L inside it, any deficit carried in or out, the fee percentage, and the fee in USD and INR. |
| Invoices | Amount in INR, the gross profit the fee was computed on, open or paid, the Razorpay order and payment references, and the created and paid timestamps. |
Technical
- A signed session cookie holding your user id, so you stay logged in. Nothing else is kept in it.
- Your light/dark preference, stored in your own browser as cx-theme. It never reaches our server.
- Web-server logs. TO CONFIRM: what our web server and hosting provider log (IP address, user agent, request line), how long those logs are kept, and whether that retention should be published here
3What we do not collect, and cannot do
- No card, UPI or bank details. Payment instruments are collected by Razorpay on their own page. We receive a payment reference and a success signature — never the instrument.
- No KYC documents. We do not ask for or store PAN, Aadhaar, passport, address proof or bank statements. Your identity verification happens with Delta Exchange, not with us. TO CONFIRM: whether PAN or GSTIN must be collected for tax invoices, and if so what changes here
- No advertising or analytics trackers on these pages. There is no Google Analytics, no Meta pixel, no advertising network, no third-party cookie and no cross-site tracking on the public CryptX site.
- No location, contacts, camera, microphone or device fingerprinting.
- No sale of your data. We do not sell, rent or trade personal data, and we do not share it for anyone else’s marketing.
- No access to your exchange account beyond the key. We cannot read your Delta login, your KYC file or your bank details, and the key you issue cannot withdraw funds.
4Why each item exists
- To run the service you asked for. Name, email, phone, password hash and API credentials exist so an account can be created, verified, logged into and traded.
- To show you what happened. The execution ledger is what produces your positions, your P&L and your notifications. It is also the audit trail if a fill is ever disputed.
- To bill you correctly. Billing windows and invoices exist so a fee can be calculated, evidenced and reconciled — see the fee terms.
- To keep the account secure. Verification codes and reset records exist to stop someone else claiming your email or phone.
- To answer you. Support correspondence is kept so a query has a history.
TO CONFIRM: the lawful basis to state for each purpose under the Digital Personal Data Protection Act, 2023 — consent versus legitimate uses — and the exact form of notice and consent the Act requires at signup
5Cookies and browser storage
There are exactly two things stored in your browser by CryptX, and neither of them tracks you.
Because we set no analytics or advertising cookies, there is no consent banner to click through. Clearing your browser storage logs you out and resets the theme; nothing else is affected.
6Your exchange API keys
This is the most sensitive thing you give us, so it gets its own section.
- Encrypted at rest. The key and secret are encrypted with Fernet before being written, using a master key held in the server environment and never stored in the database alongside the data it protects.
- Trade permissions only. We ask you to issue a key with withdrawals disabled. Delta enforces that on their side, so a compromise of our systems could not by itself move your money, provided the key you issued has withdrawals disabled as we ask.
- IP whitelisting. We publish the single execution IP in your portal so you can bind the key to it.
- Used for one thing. The credentials are decrypted only to read your balance and to place, manage and close positions on your own account.
- Destroyed on disconnect. When you disconnect a connection, the stored key and secret are overwritten in the database and the real credentials are gone. The connection row itself is kept, because your execution ledger and your invoices refer to it — see section 10.
8Where the data is stored
Your data sits in a single database on a server we control, reachable only over an encrypted connection.
TO CONFIRM: the hosting provider and the data-centre region to disclose, and the cross-border transfer statement required if that region is outside India
9How long we keep it
- Account details for as long as you have an account with us.
- API credentials only while a connection is live — they are destroyed the moment you disconnect.
- Execution ledger, billing windows and invoices are financial records. They are kept after you leave, so that a past invoice can be evidenced and reconciled.
- Verification codes expire in minutes and are stored hashed.
TO CONFIRM: the exact retention period for each category, and the statutory minimum that applies to invoices and financial records in India
10Disconnecting, and asking us to delete
Disconnecting is instant and self-serve. Remove the connection in the portal, or delete the key inside your Delta account, and execution on your account stops. The stored credentials are destroyed. Read section 9 of the Terms first if you have open positions — once the key is gone we can no longer close them for you.
Deleting your data is a written request. There is no self-serve delete button today. Email support@cryptxindia.com from your registered address and we will erase your personal details. We will keep the execution and invoice records we are required to keep, unlinked from your profile where we can. We would rather say this plainly than promise an erasure we cannot perform.
TO CONFIRM: the response time to commit to for an erasure request, and which records must be retained by law despite it
11Security, stated honestly
- Credentials are encrypted at rest; passwords and one-time codes are stored only as hashes.
- The site is served over HTTPS, and the session cookie is signed.
- The trading key cannot withdraw, and we ask you to whitelist a single IP for it.
- Payment instruments never reach our servers.
No system is perfectly secure, and we will not claim otherwise. The strongest protection in this design is not ours — it is that your money never leaves your own exchange account and the key we hold cannot move it. Use a unique password here, and revoke the key on Delta if you are ever concerned.
TO CONFIRM: the breach-notification commitment to publish — who we notify, within what period, and what the Digital Personal Data Protection Act, 2023 requires
12Your rights, and how to use them
- See what we hold. Ask, and we will send you your record.
- Correct it. Name, email and phone can be corrected on request; the execution ledger cannot be edited, because it is a record of what actually happened.
- Erase it. See section 10.
- Withdraw consent. Disconnect, and stop using the service.
- Complain. Write to us first; escalation details are on the Contact page.
All of these start at support@cryptxindia.com from your registered email address.
TO CONFIRM: the statutory list of data-principal rights and the grievance-redressal wording required by the Digital Personal Data Protection Act, 2023, including the right to nominate
13Age
CryptX is not for anyone under 18. We do not knowingly hold data about a minor; if we learn that we have, we will delete it and close the account.
14Changes, and how to reach us
If this policy changes materially we will email the address on your account and update the date at the top of this page. TO CONFIRM: notice period for a material change to this policy
WealthX Technologies Pvt. Ltd. — cryptx.wealthx.tech, support@cryptxindia.com, WhatsApp +91 91879 46508.