1. Scope and Controller
This Privacy Policy explains how LCX Liberty Labs Inc. ("LCX Liberty," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use the Services, visit our websites, contact us, participate in a beta or testnet, use an Account or developer credential, connect a Wallet, use our hosted interfaces, or opt in to communications.
This Policy applies to the Services made available through https://defi.lcx.com, https://chain.lcx.com, and https://explorer.lcx.com, related mobile applications and developer interfaces, and any other LCX Liberty website, application, or service that links to this Policy. The canonical legal hub for the Services is https://defi.lcx.com/legal.
LCX Liberty Labs Inc. is a Delaware corporation and is the controller or business responsible for the personal information described in this Policy, except where a separate product notice identifies another controller. Our business and mailing address is 111 NE 1st St, 8th Floor, Suite 89334, Miami, FL 33132, United States. Contact privacy@lcx.com for privacy questions or requests.
This Policy does not govern public blockchain networks, independent protocols, token issuers, third-party wallets, app stores, on-ramps, off-ramps, identity providers, market makers, bridges, websites, or other third parties. Their privacy practices are governed by their own notices.
2. Self-Custody and Information We Do Not Need
For non-custodial Wallet functions, your private keys, seed phrase, and Wallet password are intended to be generated or stored on your device or in a signing method you control. We do not ask you to send them to us and do not intentionally collect or store them. We generally cannot recover a Wallet if you lose control of its signing credentials.
You may use some public, non-custodial, and informational features without providing your name, email address, government identifier, or payment information. Other features, including support, security communications, developer access, issuer tools, compliance-gated features, or fiat services, may require additional information.
3. Categories of Personal Information We Collect
3.1 Information you provide
• Contact and profile information, such as name, business name, job title, email address, mailing address, telephone number, username, and preferences.
• Support, complaint, and correspondence information, including the content of messages, attachments, troubleshooting details, and records of our response.
• Account, developer, issuer, and business information, including API or RPC credentials, project details, entity information, beneficial-owner information, representatives, documentation, billing contacts, and contractual records.
• Optional identity and eligibility information for compliance-gated features, such as date of birth, government identification, residence, nationality, tax information, source of funds, investor status, ownership and control information, and verification results.
• Communications preferences and consent records, including email subscriptions, SMS opt-in source, date, time, telephone number, program, message history, HELP and STOP requests, and withdrawal of consent.
• Payment and transaction information for paid Hosted Services, such as billing records, invoices, subscription status, payment method tokens, and digital-asset payment records.
3.2 Public blockchain and Wallet information
When you connect a Wallet, request a quote, submit a transaction, search the Explorer, use a bridge, or interact with Chain infrastructure, we may process public Wallet addresses, transaction hashes, token identifiers, balances, amounts, smart-contract interactions, signatures or messages submitted to infrastructure, block data, chain IDs, and related public blockchain information.
Blockchain data can become personal information when it is reasonably linked to an individual, device, Account, support request, or other identifying information. Public blockchain data is created and maintained by the relevant network, not by LCX Liberty alone.
3.3 Device, network, and usage information
• Device and browser information, including operating system, browser or app version, language, device type, crash logs, diagnostic data, and similar technical attributes.
• Internet and network information, including IP address, timestamps, requested endpoints, referring pages, RPC requests, response codes, latency, rate-limit events, and security logs.
• Approximate location inferred from IP address or device settings, used for security, sanctions, jurisdictional restrictions, localization, and compliance. We do not collect precise geolocation unless a feature clearly asks for it and you authorize it.
• Usage and interaction information, such as pages or screens viewed, buttons or features used, Wallet-connect events, quote requests, route choices, errors, preferences, and engagement with communications.
• Security and risk signals, including wallet-risk scores, sanctions or illicit-finance exposure, device or network anomalies, phishing or malware indicators, authentication events, and results from third-party screening providers.
3.4 Cookies and local technologies
We and our providers may use strictly necessary cookies, localStorage, software development kits, pixels, and similar technologies to operate the Services, remember preferences, maintain security, prevent abuse, measure performance, and understand use. Where required by law, optional analytics or advertising technologies are used only after consent.
Our Services are not currently designed to respond to a browser Do Not Track signal. Where legally required, we recognize opt-out preference signals such as Global Privacy Control for the browser or device that sends the signal.
4. Sources of Personal Information
We collect personal information from you, your device and browser, public blockchains, persons or organizations that authorize you, LCX Group companies when appropriate and lawful, service providers, identity and compliance providers, security and blockchain-analytics providers, data providers, public sources, and third parties with which you interact through the Services.
5. How We Use Personal Information
We use personal information to:
• provide, operate, maintain, secure, authenticate, troubleshoot, and improve the Services;
• connect Wallets, generate quotes and routes, relay requests, display blockchain data, operate Layer 2 and RPC infrastructure, provide support, and administer developer or issuer features;
• detect, prevent, investigate, and respond to fraud, phishing, abuse, illicit finance, sanctions exposure, security incidents, and violations of the Terms;
• verify identity, business status, beneficial ownership, eligibility, jurisdiction, source of funds, or other compliance information where a feature requires it;
• send operational, security, legal, support, authentication, account, SMS, and marketing communications in accordance with your choices and applicable law;
• measure performance, analyze use, improve user experience, develop new features, and create aggregated or de-identified statistics;
• administer contracts, subscriptions, fees, billing, audits, records, disputes, and business relationships;
• comply with law, legal process, regulatory requests, tax requirements, sanctions, and lawful investigations, and protect our rights and the rights and safety of users and others; and
• evaluate or complete a corporate transaction, financing, reorganization, merger, acquisition, or sale.
6. Legal Bases for EEA, UK, and Similar Laws
Where a law requires a legal basis, we rely on one or more of the following: performance of a contract or steps requested before a contract; compliance with legal obligations; our legitimate interests in providing, securing, improving, and protecting the Services and exercising legal rights; consent, including for optional cookies, certain marketing, and SMS; and establishment, exercise, or defense of legal claims. You may withdraw consent at any time, without affecting prior lawful processing.
7. Public Blockchains Are Transparent and Generally Permanent
Public blockchains are designed to make transaction and address information available to participants and the public. Once information is submitted to or recorded on a blockchain, LCX Liberty generally cannot change, hide, erase, or reverse it. Other parties may copy, index, combine, analyze, or retain it independently.
A privacy request cannot require LCX Liberty to alter a public blockchain that we do not control. We will apply a request to information in systems we control to the extent required by law.
8. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
• service providers and processors that provide hosting, cloud, communications, SMS, customer support, analytics, security, fraud prevention, blockchain infrastructure, RPC, identity verification, compliance screening, payments, document storage, professional, and other business services;
• LCX Group companies that help provide, secure, support, administer, or improve the Services, subject to appropriate access controls and legal safeguards;
• third parties you direct us to interact with, including Wallet providers, protocols, bridges, dApps, market participants, on-ramps, off-ramps, token issuers, identity providers, and business integrations;
• professional advisers, auditors, insurers, financing sources, and counterparties to a corporate transaction, subject to confidentiality obligations where appropriate;
• courts, regulators, law enforcement, tax authorities, sanctions authorities, and other persons when required or permitted by law, legal process, or to protect rights, security, users, or the public; and
• a successor or acquirer in connection with a merger, financing, reorganization, sale, bankruptcy, or transfer of all or part of our business or assets.
We may share aggregated or de-identified information that cannot reasonably be used to identify you, subject to applicable law.
9. Sale, Sharing, Targeted Advertising, and Global Privacy Control
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are defined by California law. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law.
If our practices change, we will update this Policy and provide required choices. Where legally required, we recognize browser-based opt-out preference signals, including Global Privacy Control, for the browser or device that sends the signal.
10. Data Retention
We retain personal information for the period reasonably necessary for the purposes described in this Policy, including security, legal, tax, accounting, dispute, and contractual requirements. Typical periods are:
• support, complaint, and general inquiry records: up to 24 months after closure;
• analytics and product-performance data: generally up to 14 months;
• routine IP, RPC, access, and operational logs: generally up to 7 days, unless needed longer for security, abuse, billing, reliability, or legal purposes;
• security, fraud, compliance, and incident records: generally up to 12 months after closure, and longer where required to establish, exercise, or defend legal rights;
• Account, business, issuer, developer, contractual, billing, tax, and due-diligence records: for the relationship and generally up to 7 years afterward, or longer if law requires;
• SMS consent, opt-out, HELP, and program records: generally at least 4 years after the relevant event to demonstrate consent and compliance;
• marketing contact information: until you unsubscribe or we determine that the information is no longer needed; and
• public blockchain data: for as long as it remains on the relevant blockchain or is lawfully retained in our systems.
We may retain de-identified or aggregated information for longer. Legal holds, investigations, disputes, and regulatory requirements may extend a retention period.
11. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information and risks, including access controls, encryption in transit where appropriate, logging, monitoring, vendor management, and incident-response practices. No system is completely secure, and we cannot guarantee security. If a security breach involving personal information occurs, we will investigate and provide notices or take other steps as required by applicable law.
You are responsible for securing your devices, Wallets, private keys, recovery information, telephone number, email account, and authentication methods. Public blockchain information may remain visible even if our systems are secure.
11.1 Hacks, Software Vulnerabilities, Security Incidents, and No Refunds
Wallet software, interfaces, smart contracts, bridges, sequencers, RPC endpoints, APIs, SDKs, open-source dependencies, telecommunications services, devices, browsers, operating systems, and third-party integrations may contain vulnerabilities or may be affected by hacking, malware, phishing, spoofing, SIM swapping, denial-of-service attacks, supply-chain compromise, credential theft, social engineering, or other malicious or accidental events.
This Policy is a privacy notice and is not a warranty of security, an insurance policy, a custody agreement, or a promise to recover assets or data. For applicable non-custodial features, LCX Liberty generally cannot reverse transactions, restore a Wallet, recover digital assets, or refund losses. Except where applicable law requires otherwise or separate written terms expressly provide otherwise, LCX Liberty has no obligation under this Policy to reimburse, compensate, or refund digital assets, fees, data, or value lost because of a hack, malicious activity, software defect or vulnerability, credential compromise, phishing event, or other security incident.
The Terms of Service at https://defi.lcx.com/legal/terms-of-service govern contractual risk allocation, releases, limitations of liability, and no-refund terms.
12. International Transfers
LCX Liberty operates from the United States, and personal information may be processed in the United States and other countries where we or our providers operate. Those countries may have different privacy laws. Where required for EEA, UK, or Swiss information, we use recognized transfer mechanisms, such as adequacy decisions, the EU Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, and supplementary safeguards as appropriate.
13. Your Privacy Rights
Depending on your location and subject to exceptions, you may have rights to access, know, confirm processing, obtain a copy, correct, delete, restrict, object, withdraw consent, opt out of sale or sharing, opt out of targeted advertising, opt out of certain profiling, limit certain uses of sensitive information, and obtain data portability. You may also have the right to appeal a decision and to complain to a privacy regulator.
To exercise a right, email privacy@lcx.com and describe the request. We may ask for information reasonably necessary to verify your identity and authority. You may use an authorized agent where law permits, but we may require proof of authorization and verification of your identity. We will not unlawfully discriminate against you for exercising a right.
If we deny a request and your law provides an appeal right, reply to the decision with the subject line "Privacy Appeal." We will explain the result and any right to contact a regulator.
EEA and UK residents may lodge a complaint with the supervisory authority in their country. California residents may contact the California Privacy Protection Agency or the California Attorney General.
14. California Notice at Collection
The table below summarizes categories of personal information we may collect, examples, purposes, and whether we sell or share them as defined by the California Consumer Privacy Act. We retain each category as described in Section 10.
• Identifiers (name, email, telephone number, IP address, Wallet address, account or device identifiers): Used to provide, secure, support, communicate about, and administer the Services. Not sold or shared for cross-context behavioral advertising.
• Customer records (contact, account, billing, business, issuer, and contractual information): Used for service delivery, compliance, records, and support. Not sold or shared.
• Commercial information (subscriptions, fees, support history, service use, quote or transaction interaction records): Used to operate, bill, support, and improve the Services. Not sold or shared.
• Internet or electronic network activity (browsing, app, device, RPC, API, access, interaction, diagnostic, and security logs): Used for operation, analytics, security, and abuse prevention. Not sold or shared.
• Geolocation (approximate location inferred from IP address): Used for security, localization, sanctions, and jurisdictional restrictions. Not sold or shared.
• Professional or employment information (employer, role, organization, and authority for business, issuer, or developer users): Used to administer business relationships and compliance. Not sold or shared.
• Inferences (risk, fraud, security, eligibility, and service-preference inferences): Used for security, compliance, and personalization. Not sold or shared.
• Sensitive personal information (government identifiers, hosted-account authentication information, nationality or residence information, and financial or compliance data, only when required for selected features — we do not collect Wallet private keys or seed phrases): Used for verification, security, compliance, and service delivery. Not sold or shared; not used for purposes requiring a right to limit.
• Contents of communications (support, complaint, and correspondence content sent to us): Used to respond, investigate, and maintain records. Not sold or shared.
We do not knowingly sell or share personal information of consumers under 16.
15. Children
The Services are not directed to children under 18, and we do not knowingly collect personal information from a child under 13. A person under the age required by the Terms may not use the Services. Contact privacy@lcx.com if you believe a child provided information to us.
16. Third-Party Links, Wallets, Protocols, and App Stores
A Service may link to or integrate with a third party. A third party may collect information directly from you or your device and may combine public Wallet activity with other information. Review the third party's privacy notice and security practices. LCX Liberty is not responsible for independent third-party processing.
17. Products and Entities Not Governed by This Policy
This Policy governs only personal information processing by LCX Liberty Labs Inc. for Services that link to or expressly incorporate it. It does not govern:
• the centralized LCX exchange;
• LCX AG;
• LCX Exchange USA Inc.; or
• any other LCX Group company or product, unless this Policy is expressly incorporated into the applicable product or service.
Those entities and products may collect, use, disclose, and retain personal information under separate privacy notices. Common ownership, branding, links, integrations, or referrals do not make LCX Liberty the controller of their independent processing.
18. Changes to This Policy
We may update this Policy to reflect changes in the Services, law, technology, or our practices. We will post the updated version with a new effective date and provide additional notice where required. Your continued use after the effective date is subject to the updated Policy, except where consent is legally required.
19. Contact
Privacy requests and questions may be sent to privacy@lcx.com or by mail to LCX Liberty Labs Inc., 111 NE 1st St, 8th Floor, Suite 89334, Miami, FL 33132, United States.