Legal

Privacy Policy

Last updated 5 September 2026

Prospr (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the Prospr platform, website, and services (collectively, the “Services”). By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.

Prospr is pre-launch. Today we hold at most an email address for people who sign up, together with the technical data needed to run the site, such as security logs and cookie choices. Interface preferences stay in your browser. The wider categories described below set out what the live product is designed to collect once the relevant features exist. They are not a description of what is collected now.

The product being built is a non-custodial interface: you connect a wallet you already control, and Prospr does not hold your keys or your assets. That shapes what we collect. A wallet address is the primary identifier for a live session, and identity documents on a fiat leg are intended to be handled by the licensed partner providing it rather than by us.

GDPR Compliance and User Consent

We comply with the European Union’s General Data Protection Regulation (GDPR) and applicable privacy laws. If you are located in the EU or EEA, we will implement explicit consent mechanisms for processing your personal data. This includes clear opt-in confirmations for things like account registration, marketing communications, and cookie usage. You have the right to withdraw consent at any time. We will not process sensitive personal data without your explicit consent, except as allowed by law or necessary for providing the Services (for example, for fraud prevention or compliance obligations).

  • Legal Basis for Processing: We only collect and process personal data when we have a lawful basis to do so under GDPR and other laws. The legal bases include: your consent, the necessity to perform a contract (e.g., our Terms of Service) or provide the Services you request, compliance with legal obligations (such as anti-money laundering laws), and our legitimate interests (such as improving our Services and ensuring security) balanced with your data protection rights.
  • Opt-In for EU Users: Users from the EU will be presented with clear opt-in choices for any data processing that is not strictly necessary for providing the Service. For example, you may be asked to tick a box agreeing to our terms and privacy policy, or to opt-in to marketing emails. We maintain records of consents as required by GDPR. We also provide cookie consent banners on our websites for EU users, allowing you to accept or reject non-essential cookies.

Information We Collect

We collect information to provide and improve the Services, to meet legal obligations where they apply, and to keep the platform secure and functional. Collection today is limited as stated above. The categories the live product is designed to collect are:

  • Contact information: An email address, and where you give one, a name and phone number. This is what we hold for waitlist signups, newsletter subscribers, and people who contact us.
  • Wallet and on-chain information: The public address of a wallet you connect, and public on-chain activity associated with it. A wallet address is public by design, but where we can link it to you it is personal data and we treat it as such. Prospr never receives your private keys or seed phrase, and no legitimate part of the Services will ever ask for them.
  • Screening results: Where sanctions or risk screening applies to a wallet address or to you, we may hold the outcome of that screening and the reason for it.
  • Identity verification status: Where a fiat on-ramp or off-ramp is used, identity checks are intended to be performed by the licensed partner providing that service. In that case the partner handles the documents and biometric checks under its own privacy terms, and Prospr expects to receive and store the outcome — verified or not verified, and any restriction that follows — rather than the underlying documents. Where we are required to collect identity documents directly, we will tell you at the point of collection.
  • Entity information: Where access is provided to a company or other entity, documentation about that entity and the individuals connected to it, including directors, officers, and beneficial owners, may be required.
  • Activity data: Records of what you do in the interface, including orders you submit and their outcome, settings and preferences, and features you use. Where trading occurs on a third-party venue, that venue also holds its own record under its own terms.
  • Payment information: Where a fee is payable, our payment providers collect the payment details. We do not store full card numbers; we may hold provider-issued references and a record of what was charged and when.
  • Technical and security data: IP address, device and browser information, session and connection logs, and access timestamps, used for security, fraud prevention, abuse detection, and troubleshooting.
  • Communications: Messages you send us, support requests, feedback, and anything you post in a community feature, retained so we can respond and improve the Services.
  • Cookies and similar technologies: Used to remember preferences and understand how the site is used. You can control cookies through your browser, and where the law requires it we ask for consent before setting non-essential ones.

We limit collection to what is relevant and necessary for the purposes described. You can decline to provide information, but that may close off part of the Services — for example, a fiat path cannot open if the checks that path requires are not completed.

How We Use Your Information

  • Providing and improving the Services: We use wallet, activity, and technical data to maintain your session, route orders you submit, display your position and history, and operate the features you choose to use. We use aggregated usage data and analytics to improve the interface, the tools, and overall performance.
  • Compliance and verification: Where legal obligations apply, we use the information we hold to meet them. This includes sanctions and restricted-jurisdiction screening, holding the outcome of an identity check performed by a partner, and monitoring for indicators of fraud, market abuse, or other unlawful activity. Where checks are performed by a partner, that partner is responsible for how it conducts them.
  • Communication: We use your contact information (email, phone) to send you service-related notifications such as account alerts, transaction confirmations, security verifications (including multi-factor authentication codes), and updates about changes to our terms or policies. With your consent, we may also send promotional communications, newsletters, or market updates. You can opt out of marketing emails at any time by using the unsubscribe link or contacting us.
  • Payments and Subscription Management: We process your payment information to charge subscription fees or other fees owed for using the platform. For example, if you are on a paid monthly plan, our payment processor will charge your card or account on a recurring basis. We maintain records of your payments and subscription status. Payment information may also be used to detect and prevent fraudulent payments.
  • Risk management and security: Activity patterns, device identifiers, and IP addresses may be used to detect suspicious behaviour, to protect against unauthorised use of a session or a trading permission, and to detect anomalies or attempted abuse. These measures protect the platform and the people using it.
  • Aggregate Analytics: We may anonymize or aggregate personal data so it no longer identifies you and use it for analytical purposes, such as measuring user engagement, performance metrics of our algorithms, and business improvements. For example, we might analyze aggregated trading data to understand market trends or user success rates, but without reference to specific individuals.
  • Legal Obligations and Enforcement: In certain cases, we are legally obligated to use or disclose your information. This includes cooperating with regulators and law enforcement, complying with court orders or subpoenas, and fulfilling tax and reporting obligations. We also use personal information to enforce our own legal rights and agreements – for instance, to investigate potential violations of our Terms of Service, fraud, or security breaches. If you violate the Terms or engage in unlawful activity, we may use your information to take action (such as account suspension) and provide details to the appropriate authorities as required.

We do not use your personal data for any purpose that is incompatible with the purposes outlined above without first obtaining your consent. We do not sell your personal information to third-party marketers.

Data Sharing and International Transfers

We treat your personal information with care and confidentiality. However, in order to run our business and comply with laws, we sometimes need to share information with third parties or transfer it across international borders:

  • Service Providers: We may share the personal information a provider needs to perform a service on our behalf. This includes identity and sanctions screening providers, payment processors, cloud hosting, analytics, customer support tooling, and email or SMS delivery. Providers are contractually required to protect your data and to use it only to provide the service to Prospr.
  • Venue, fiat, and banking partners: Where you use a feature that depends on a third party — an execution venue, a fiat on-ramp or off-ramp, or a banking rail — we share the data that party needs to process the transaction, and that party handles it under its own privacy terms. No fiat rail is live today, and partners are named when they are contracted, not before.
  • Corporate Affiliates: If Prospr is part of a corporate group, we may share your information with our parent company, subsidiaries, or affiliates for purposes consistent with this Privacy Policy (for example, internal administration, platform enhancements, or consolidated regulatory compliance functions). Any such affiliates will honor the commitments made in this policy.
  • Legal and Regulatory Disclosure: We may disclose your information to government authorities, regulators, or law enforcement if required by law or if we, in good faith, believe such action is necessary to (a) comply with a legal obligation (such as responding to a lawful subpoena or court order), (b) protect our rights or property, (c) prevent fraud or abuse of our platform, or (d) protect the safety of our users or the public. For instance, as a financial services platform, we may be required to share customer information with financial regulators or financial intelligence units upon request.
  • Business Transfers: If Prospr is involved in a merger, acquisition, sale of assets, bankruptcy, or reorganization, your personal data may be transferred to the successor or acquiring entity as part of that transaction. We will ensure that any such entity is bound to respect your personal data in a manner consistent with this policy. We will notify you of any change of ownership or control of your personal information either through the website or via email.

Because we operate internationally, the recipients mentioned above may be located outside of your home jurisdiction. Specifically, if you are an EU/EEA resident, your personal data may be transferred to countries that the European Commission has not determined to have an adequate level of data protection (for example, to the United States). In such cases, we take additional measures required by GDPR to protect your data, such as entering into EU Standard Contractual Clauses with the receiving party or, for U.S. recipients, relying on the EU-U.S. Data Privacy Framework where the recipient is certified. We also implement technical safeguards like encryption to protect data in transit. You can contact us to learn more about the safeguards we have in place for international transfers of personal data.

Data Retention and Deletion

We retain your personal information only for as long as necessary to fulfill the purposes we collected it for, including for legal, accounting, or reporting requirements.

  • Retention Periods: In general we keep your information while you are using the Services. After you stop, we may retain data for a further period where we have a legal or legitimate reason to. Financial-crime and record-keeping rules, where they apply to us, typically require identity and transaction records to be kept for a number of years after the relationship ends, and the exact period depends on the market and the obligation. We also retain data as needed to resolve disputes, enforce our agreements, and meet tax and other legal obligations.
  • Right to Deletion: We support your right to be forgotten in accordance with GDPR and other applicable laws. You may request that we delete your personal data from our systems at any time. Upon receiving a verified deletion request, we will delete or anonymize your personal information within a reasonable timeframe (generally within 30 days), provided that we are not legally required or have legitimate grounds to retain it. Please note that certain data cannot be deleted on request if we must keep it for legal compliance (e.g., records of transactions and identity verification already performed, which we may need to retain to satisfy anti-money laundering regulations or respond to law enforcement inquiries). We will inform you if such an exception applies when you make a deletion request.
  • Deletion Process: To request deletion of your data, you should contact us at the email or physical address provided in this policy (see “Contact Us” section below). For security, we may ask you to verify your identity before processing the request. Once your request is confirmed and applicable, we will remove your personal data from our active databases and put your account in a deletion queue. Backup or archival copies might be retained for a short period until their normal retention cycle is completed, but they will be securely isolated and eventually deleted as well.
  • Blockchain Data: Activity recorded on a public blockchain is permanent and outside anyone's control, including ours. We cannot edit, erase, or restrict a transaction recorded on a public ledger, and a deletion request cannot reach it. Off-chain personal data we hold about that activity can be deleted as described above. We do not write personal details on-chain; personal data is kept off-chain.

After the retention period expires or your deletion request is fulfilled, we will securely dispose of or anonymize your data so that it can no longer be associated with you. Anonymized aggregate data (which is no longer personally identifiable) may be retained indefinitely for analytics and business purposes.

Security Measures

We take the security of your data very seriously and implement a range of technical and organizational measures to protect it against unauthorized access, loss, misuse, or alteration. These measures include:

  • Encryption: Sensitive data is encrypted in transit and at rest. Our sites are served over HTTPS/TLS, and secrets are held in protected environments. Prospr never holds your private keys or seed phrase, so there is no store of them to protect.
  • Access controls: Access to personal data is restricted on a need-to-know basis to authorised personnel trained in data protection. Administrative access requires multi-factor authentication and is logged and audited. Sensitive actions are separated so that no single person can carry them out unsupervised.
  • Session security: We monitor for unusual session and connection activity and may end a session or require reconnection where something looks wrong. Because access is tied to a wallet you control, protecting that wallet, and revoking any permission you no longer want in place, is a control that sits with you.
  • Contract security: Contracts that handle value are intended to be independently audited before they do so, including ahead of any token generation event, and audit summaries will be published when they exist. These are design commitments until the relevant contracts are live.
  • Treasury controls: Movements of Prospr's own funds are designed to require multi-party approval. This concerns company funds, not customer assets, which Prospr does not hold.
  • Infrastructure security: Servers are protected by firewalls, network segmentation, and monitoring. Software and dependencies are kept patched, and vulnerability scanning is part of routine operation.
  • Independent review: External penetration testing and code review are planned before launch and on a recurring cycle after it. No formal security certification is held today, and we will name one only when it is held, with its scope. Where card payments are processed, they will be handled by a provider meeting the applicable card-network rules.

No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security. You play a part too: protect your wallet and its recovery phrase, keep your devices and email secure, review what you are signing before you approve it, and tell us immediately if you suspect unauthorised access. Where a breach affects your personal data, we will notify you and the appropriate authorities as required by law.

Your Rights and Choices

Depending on your jurisdiction, you have certain rights over your personal data. Prospr is committed to honoring these rights and providing you with control over your information:

  • Access and Rectification: You may request a copy of the personal data we hold about you, and you have the right to correct or update any inaccuracies. Most of your basic account information can be reviewed and edited at any time by logging into your account settings. For any details not accessible online, contact us to exercise your access right. We will provide the information free of charge within the time frame required by law (typically within 30 days). If any data is incorrect or outdated, you can ask us to correct it, and we will do so promptly.
  • Deletion: As noted in the Data Retention section above, you may ask us to delete your personal data. See “Data Retention and Deletion” for details on how we handle those requests and the exceptions that may apply.
  • Objection and Restriction: You have the right to object to certain processing of your data, such as for direct marketing or if you believe our processing is based on a legitimate interest that isn’t sufficiently justified. You can also request that we temporarily restrict processing of your data (for instance, while we verify an accuracy claim or an objection you raised). We will honor such requests where required by applicable law.
  • Data Portability: Where applicable (e.g., under GDPR), you have the right to receive your personal data that you provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit that data to another service provider. For example, we can provide a CSV or JSON file of certain account data upon request. This right applies when processing is carried out by automated means and is based on your consent or on a contract.
  • Withdraw Consent: If we rely on your consent to process any personal data, you have the right to withdraw that consent at any time. For example, you can opt out of marketing emails by clicking “unsubscribe,” or disable certain data collection by adjusting your account settings or browser options (such as opting out of analytics cookies). Withdrawal of consent will not affect the lawfulness of any processing done prior to such withdrawal.
  • Complaints: If you have concerns about how we are handling your personal data, please let us know so we can address them. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection supervisory authority. For EU users, this is typically the authority in the country of your residence or where our business is established. We will provide details of the relevant authority upon request.

We will not discriminate against you for exercising any of these rights. Some rights may be subject to certain exceptions or limitations under law. When you contact us to exercise a privacy right, we may need to verify your identity to ensure we don’t disclose or modify information for the wrong person. This is for your security.

Children’s Privacy

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are under 18, please do not attempt to use our platform or send any personal data to us. If we learn that we have inadvertently collected personal information from a minor under 18, we will take steps to delete that information as soon as possible. Parents or guardians who become aware that their child has provided us with information should contact us immediately so we can remove the data and terminate any accounts if necessary.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will revise the “Last Updated” date at the top of this policy. If the changes are significant, we will provide a more prominent notice (such as by email notification to registered users or a notice on our website). We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Your continued use of the Services after any changes to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should stop using the Services and can request that your data be deleted as described above.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

Email: privacy@prospr.co (for privacy inquiries or GDPR data requests)

Support: support@prospr.co

We will respond to your inquiries as promptly as possible, and no later than required by applicable law. Your privacy is important to us, and we welcome your feedback on our privacy practices.

Legal library

Read the source, not a paraphrase.

Risk, privacy, custody and regulatory wording should be read at the source.

Regulatory statusTerms of Service