1. Introduction
GroveX (“GroveX”, “we”, “our”, “us”) is committed to protecting your privacy and safeguarding your personal information.
This Privacy Policy explains how we collect, use, disclose, store, and manage personal information when you access or use our website, platform, mobile application, and related services (collectively, the “Services”).
We aim to comply with applicable privacy and data protection laws and regulatory requirements.
Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take reasonable steps to delete it unless we are required or permitted by law to retain it.
By using our Services, you acknowledge you have read this Privacy Policy. If you do not agree, you should not use our Services.
This Privacy Policy should be read together with our Terms and Conditions, which are available via the Services or on our website.
2. Key Concepts
In this Privacy Policy:
- Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- Sensitive Information is a special category of personal information that may receive additional protection under applicable privacy law and may include biometric information used for automated biometric verification in some circumstances.
- De-identified Data means data that has been processed so individuals are no longer reasonably identifiable.
- Where this Policy refers to including, it means including without limitation.
3. Notification at Collection (Collection Notice)
When we collect personal information, we take reasonable steps to notify you (or ensure you are aware) of collection matters at or before the time of collection, or as soon as practicable after collection, including:
- What information we collect and why we collect it.
- Whether information is collected from third parties.
- The main consequences if you do not provide requested information (for example, we may not be able to provide account access, deposits, withdrawals, trading, support, or verification).
- The types of third parties we disclose information to (including overseas recipients where applicable).
This Privacy Policy works together with any in-app or web collection notices shown during signup, verification, deposits/withdrawals, support interactions, or other collection points.
4. Information We Collect
We collect information that identifies you or can reasonably identify you, and information that relates to your use of the Services.
4.1 Personal information you provide
We may collect:
- Identity data, such as full legal name, date of birth, residential address, nationality, and other identity details.
- Contact data, such as email address and phone number.
- Account data, such as login identifiers, account settings, security settings, and account status.
- Transaction data, such as trading history, order details, deposits, withdrawals, internal ledger activity, and interactions within the Services.
- Verification data (KYC/AML), such as government-issued identification, proof of address, and information required to verify your identity and meet AML/CTF obligations.
- Financial data, such as bank details or payment method details if you use supported fiat rails (if applicable).
- Support and correspondence data, such as emails, chats, complaint records, and other communications.
4.2 Information we collect automatically
When you use our Services, we may collect:
- Device and network data, such as IP address, device identifiers, browser type, device model, operating system, and mobile network information.
- Usage data, such as pages accessed, features used, clickstream data, timestamps, logs, and referring URLs.
- General location data derived from IP address.
- Push notification tokens or similar identifiers used to send notifications.
4.3 Cookies and similar technologies
We may use cookies, pixels, web beacons, SDKs, and similar technologies to:
- Enable core platform functionality and security.
- Remember preferences and improve user experience.
- Analyse and improve performance and reliability.
- Support marketing where permitted and consistent with your choices.
You can control cookies through your browser/device settings. Disabling certain cookies may impact functionality.
4.4 Information from third parties
We may collect personal information from third parties where reasonably necessary, including:
- Identity verification and KYC providers.
- Payment processors and banking/fiat partners (if applicable).
- Fraud prevention, cybersecurity, sanctions/PEP screening, and compliance monitoring providers.
- Analytics and communications providers.
- Public sources and blockchain networks, where relevant to your use of the Services (for example, wallet addresses and transaction details visible on public blockchains).
- Other Users or third parties where they provide information as part of a transaction or interaction (for example, beneficiary details for a transfer, account holder names for fiat rails, or authorised representatives for entity accounts).
Blockchain notice: Blockchain transactions and wallet activity may be public and immutable. GroveX cannot alter or delete information recorded on a public blockchain.
4.5 Unsolicited personal information
If we receive personal information we did not request, we will assess whether we are permitted to retain it under applicable privacy law. If we are not permitted to retain it and it is lawful and reasonable to do so, we will destroy or de-identify it as soon as practicable.
5. Sensitive Information and Biometrics
We generally avoid collecting Sensitive Information unless necessary and permitted by law.
In some cases, identity verification may involve biometric processing (for example, liveness checks or automated facial verification). Where biometric or other Sensitive Information is collected or processed:
- We do so only where required or permitted by law, or with consent where required.
- We use it for verification, fraud prevention, security, and compliance.
- We apply additional safeguards and restrict access.
- Where required, we will obtain your express consent for biometric processing and provide a notice at the point of collection.
You may withdraw consent for biometric processing by contacting us (where applicable). However, if biometric verification is necessary for compliance or security, withdrawing consent may mean we are unable to provide certain Services that require verification (including deposits, withdrawals, and account access).
If you do not wish to complete verification steps that are necessary for compliance or security, we may be unable to provide certain Services.
6. How We Use Your Information
We use personal information for purposes related to operating and protecting the Services, including:
- Service delivery and operations, such as account creation, platform access, processing trades, deposits, and withdrawals, and issuing service notifications.
- Account management and support, such as assisting with access, troubleshooting, disputes, and complaints.
- Compliance and regulatory obligations, including AML/CTF and sanctions screening, record-keeping, audits, and responding to lawful requests.
- Security and fraud prevention, including detecting and preventing suspicious activity, account compromise, unauthorised access, and misuse.
- Platform integrity and risk management, including enforcing our Terms and preventing abusive or unlawful activity.
- Research, testing, analytics, and service improvement.
- Marketing and promotions where permitted by law and consistent with your preferences.
We may create and use De-identified Data and aggregated data for analytics, security, fraud prevention, research, and improving Services. De-identified Data is not used to identify you.
7. Automated Decision-Making and Human Review
We may use automated systems (including algorithms and AI tools) to help operate the Services and manage risk, including:
- Fraud detection and prevention.
- Risk scoring and transaction monitoring.
- Compliance screening and monitoring.
- Security controls and account protection.
These systems may contribute to outcomes such as reviews, limits, delays, holds, or restrictions.
You may request human review of certain decisions by contacting us at AdminGroveX@GroveX.io and providing relevant details. We may be limited in what we can disclose due to security, compliance, and legal constraints.
7.1 Additional information about automated decisions
Where we arrange for a computer program to use Personal Information to make decisions that could reasonably be expected to significantly affect your rights or interests, we will include in this Privacy Policy (or a linked notice within the Services) information about:
- the types of decisions the program makes (for example, fraud/security holds, transaction monitoring flags, account risk reviews, verification outcomes, or limits/restrictions), and
- the kinds of Personal Information typically used (for example, identity/verification data, transaction and wallet activity, device/network identifiers, and security signals).
We will keep this information up to date as our systems change.
8. Disclosure of Personal Information
We may disclose personal information as reasonably necessary to provide the Services and comply with law.
8.1 Service providers and partners
We may disclose information to trusted providers who help us operate, including:
- KYC and identity verification providers.
- Hosting and cloud infrastructure providers.
- Security, fraud, risk, and compliance providers.
- Analytics providers.
- Customer support and communications providers.
- Payment processors and banking/fiat partners (if applicable).
We take reasonable steps to ensure providers handle information in a manner consistent with this Policy.
8.2 Legal and regulatory disclosures
We may disclose information where required or authorised by law, including to regulators and law enforcement, and where necessary to:
- Comply with legal obligations or lawful requests.
- Protect GroveX, our Users, and the public.
- Establish, exercise, or defend legal rights.
8.3 Business transitions
If GroveX undergoes a merger, acquisition, restructure, or asset sale, personal information may be transferred as part of that transaction, subject to appropriate protections and notices where required.
9. Cross-Border Disclosure (Overseas Transfers)
Some service providers may be located in jurisdictions different from your location or the jurisdiction in which GroveX operates, and may store or access information across borders.
Where we disclose personal information to a recipient in another jurisdiction, we take reasonable steps to ensure appropriate handling of personal information, for example through contractual safeguards, security requirements, and due diligence, subject to applicable privacy law.
Where required by applicable law, GroveX may remain accountable for the handling of personal information by recipients in other jurisdictions.
Where practicable, we will identify the countries where our overseas recipients are likely to be located in this Policy and/or in relevant collection notices within the Services.
For example, our service providers may operate or host data in jurisdictions such as the United States (e.g., cloud/hosting), the European Union (e.g., analytics), and Singapore (e.g., compliance tools). This list is non-exhaustive and may change over time.
10. Direct Marketing
We may send marketing communications where permitted by law and consistent with your preferences.
Where we use personal information for direct marketing:
- We will provide a clear opt-out method (for example, unsubscribe links, settings, or contacting us).
- We will honour opt-out requests within 5 working days.
- Our unsubscribe facilities will be functional for at least 30 days after we send a marketing message.
- Our opt-out method will not require you to create/log in to an account or provide additional personal information, and will not charge a fee.
Even if you opt out of marketing, we may still send essential service messages (such as security alerts or transaction notifications).
11. Government Identifiers (Including TFN)
We do not adopt, use, or disclose government-related identifiers (such as a Tax File Number) as our own identifier for you, except where required or authorised by law.
If we collect tax-related identifiers where legally required, we apply additional safeguards and limit access.
12. Data Security
We maintain technical and organisational measures designed to protect personal information, which may include:
- Encryption in transit and, where appropriate, at rest.
- Access controls, logging, and monitoring.
- Multi-factor authentication for internal systems and restricted access on a need-to-know basis.
- Secure development and operational practices.
No system is 100% secure. You should also protect your account by using strong passwords, enabling 2FA, and staying alert for scams and phishing attempts.
If you believe you have found a security vulnerability or incident affecting GroveX or your account, please contact us immediately at AdminGroveX@GroveX.io with “Security Report” in the subject line.
If a data breach occurs that triggers notification obligations under applicable law, we will notify affected individuals and relevant authorities where required. Where practicable, our notifications will describe what happened, the kinds of information involved, and steps we recommend you take to reduce the risk of harm.
13. Data Retention
We retain personal information only for as long as needed to:
- Provide Services and manage your account.
- Meet legal and regulatory obligations (including AML/CTF record-keeping).
- Maintain security, prevent fraud, resolve disputes, and enforce agreements.
We will take reasonable steps to securely delete or de-identify personal information when it is no longer required, unless we are required or permitted by law to retain it.
Where AML/CTF laws apply, we retain relevant transaction and identification records for the period required by applicable law and regulatory requirements.
14. Data Quality
We take reasonable steps to ensure personal information we collect, use, or disclose is accurate, up-to-date, complete, and relevant.
You are responsible for ensuring information you provide is accurate and for updating it when it changes. We may request that you update or verify information from time to time.
15. Your Rights and Choices
Subject to applicable law, you may have rights to:
- Request access to personal information we hold about you.
- Request correction of inaccurate, incomplete, or out-of-date information.
- Request deletion of personal information where it is no longer required, noting we may need to retain data for compliance, legal, audit, or legitimate business purposes.
- Opt out of marketing communications.
15.1 Anonymity and pseudonymity
Where lawful and practicable, you may be able to interact with GroveX anonymously or using a pseudonym. However, for most exchange services (including account access, trading, deposits, withdrawals, and compliance checks) we must identify you, and anonymity or pseudonymity will not be available due to legal and operational requirements.
15.2 Access and correction process
You can request access or correction by emailing AdminGroveX@GroveX.io.
We may request information to verify your identity before processing your request.
We aim to respond within a reasonable period and, in most cases, within 30 calendar days.
We do not charge a fee to make an access or correction request. (If we ever charge for providing access, it will not be excessive.)
If we refuse a correction request, we will (where required) provide written reasons and information about how you can request that a statement be associated with the information indicating you believe it is incorrect.
16. Advertising and Targeted Promotions (If Applicable)
Where permitted and consistent with your settings, we may use limited information to measure marketing effectiveness and improve promotions.
- We may use cookies, device identifiers, or similar technologies for marketing measurement and attribution.
- You can control some advertising preferences through your device settings or browser settings, where available.
- GroveX does not sell personal information.
17. Do Not Track and Analytics Controls
Some browsers and devices offer “Do Not Track” signals or similar controls. Our Services may not respond to all such signals.
You can manage analytics and cookie preferences through your browser/device settings, and by adjusting permissions where offered in our Services.
18. Information You Provide About Others
If you provide personal information about another person to GroveX (for example, as part of a transaction, beneficiary details, authorised representative details, or payment information), you represent and warrant that:
- You have informed that person of the disclosure.
- You have obtained any consents required.
- The information is accurate to the best of your knowledge.
19. International Users
If you access our Services from a jurisdiction different from where GroveX or its service providers operate, you understand that:
- Your personal information may be processed in multiple jurisdictions where GroveX or its service providers operate.
- Your information will be handled in accordance with this Privacy Policy and applicable privacy requirements, subject to lawful cross-border access and processing.
By using the Services, you understand that your personal information may be transferred to and processed in multiple jurisdictions as described in this Privacy Policy, subject to applicable laws.
20. Complaints
If you believe we have breached this Privacy Policy or applicable privacy law:
- Contact us at AdminGroveX@GroveX.io with “Privacy Complaint” in the subject line.
- We will acknowledge your complaint within 5 business days and aim to investigate and respond within 30 days.
If you are not satisfied with our response, you may have the right to lodge a complaint with the competent privacy or data protection authority that has jurisdiction over your complaint.
21. Contact Us
For privacy questions, access or correction requests, deletion requests, or requests for human review of certain automated decisions, contact:
- Email: AdminGroveX@GroveX.io
- Support email: support@grovex.io
- Support tickets: https://grovexcom-help.freshdesk.com/support/tickets/new
22. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in practices, technology, and legal requirements.
We will update the “Last Updated” date and, where appropriate, provide notice through the Services or via email. Where practicable, material changes will be notified via email or an in-app/web notice at least 30 days before the changes take effect