Skip to main content
Last updated 29 July 2026

Privacy Policy

How we collect, use, and protect your data. If you have questions, contact us at hello@chaintax.co.uk.

1. Who we are

ChainTax is a UK-based tax calculation tool for crypto and DeFi transactions. For the purposes of UK data protection law, the data controller is ChainTax Ltd (company number NI739302, registered in Northern Ireland), contactable at hello@chaintax.co.uk.

Governing jurisdiction: Northern Ireland.

2. What data we collect

We collect the minimum data necessary to provide the service. We never sell your data to third parties.

  • Email address: Used for account creation, authentication, and transactional emails (welcome, purchase confirmation).
  • Wallet addresses: Public blockchain addresses you provide, along with chain (e.g. Ethereum, Arbitrum) and optional label. Used to fetch your on-chain transaction history.
  • On-chain transaction data: Transaction hashes, timestamps, and decoded event logs fetched from public blockchains. This data is already publicly available on-chain.
  • Tax calculations: Gains, losses, income, and cost basis figures derived from your transaction data. These are computed by ChainTax, not provided by you.
  • Payment and contract information: Processed by Stripe. ChainTax stores the customer/session references, tax year, tier, amount, purchase/refund dates, and versioned checkout consent needed to provide access, meet accounting obligations, and evidence the contract. We never see or store your card details.
  • Tax preferences: Your selected tax band (basic/higher) and optional salary figure, used to refine income tax estimates.
  • Cookies & first-party storage: Essential session cookies keep you signed in, and small first-party preferences remember UI choices and whether you allow anonymous analytics. PostHog analytics are off by default; if you enable them, events use memory-only identifiers and are never tied to your ChainTax account ID or email. Vercel Analytics and Speed Insights are cookieless.
  • IP address: Used for ephemeral rate limiting (via Upstash) and not associated with your account. When a shared report link is opened, a salted, irreversible hash of the visitor’s IP (never the raw IP) is stored so we can detect abuse and show the report owner access counts.

3. Why we process your data

Under UK GDPR, we must have a lawful basis for processing your personal data. Our bases are:

  • Contract performance (Art. 6(1)(b)): Processing your wallet data, sorting transactions, calculating tax, and generating reports, which is the core service you signed up for.
  • Legitimate interest (Art. 6(1)(f)): Rate limiting, fraud prevention, and maintaining service security and availability.
  • Legal obligation (Art. 6(1)(c)): Retaining minimum accounting, tax, and transaction records where UK law requires us to do so.
  • Consent (Art. 6(1)(a)): Optional anonymous PostHog analytics. They remain off unless you allow them, and you can switch them off again at any time.

We do not currently send marketing emails. If we do in future, we will obtain your explicit consent first.

Your email and the source data needed for a calculation are required to create and perform the contract. If you do not provide them, we cannot create an account or generate the requested report. ChainTax does not make solely automated decisions that produce legal or similarly significant effects: automated classifications and calculations are working outputs for you to review.

4. How we use your data

  • Fetching on-chain transaction history for wallets you provide
  • Classifying transactions (on-chain DeFi and exchange CSV imports) primarily using deterministic protocol-specific rules. When enabled, an AI-assisted fallback may review unresolved public on-chain context; its output is always marked low confidence and requires review.
  • Calculating UK capital gains tax, income tax, and HMRC matching (Section 104, same-day, bed-and-breakfast)
  • Generating tax reports (PDF and CSV) and SA108 box mappings
  • Processing payments via Stripe
  • Sending transactional emails (welcome email, purchase confirmation)
  • Rate limiting to protect service availability
  • Running Concierge syncs on your behalf when you request one via hello@chaintax.co.uk

Concierge sync: if you request a manual sync via hello@chaintax.co.uk, you authorise ChainTax to access on-chain transaction history for the public wallet addresses you supply, in order to generate your HMRC report. We never request private keys, seed phrases, or exchange API keys you have not explicitly granted. Concierge data is stored on a dedicated internal service account and can be deleted on request once the report has been delivered and the 14-day support window has closed. If the service account is separate from your self-serve account, request its deletion separately so we can verify the relevant portfolio before removing it.

5. Third-party processors

We use the following third-party services to operate ChainTax. We share only the data necessary for each service's function.

ServicePurposeData sharedLocation
SupabaseDatabase & authenticationEmail, all stored dataEU
StripePayment processingEmail, payment detailsUS/EU
AnkrBlockchain data APIWallet addressesUS
InfuraBlockchain RPCWallet addresses, tx hashesUS
AlchemyBlockchain RPC (fallback)Wallet addresses, tx hashesUS
ResendEmail deliveryEmail addressUS
VercelHostingStandard web server logsUS
UpstashRate limiting and background sync-job queue (QStash)IP address (ephemeral, rate limiting); account & wallet IDs (sync queue)US
AnthropicOptional AI-assisted review of transactions unresolved by deterministic rulesPublic wallet address, destination contract, method signature and decoded token flows; no email, ChainTax account ID or tax totalsUS
PostHogOptional anonymous product analytics (custom events only)Aggregate actions with memory-only event identifiers; no ChainTax user ID or emailEU
SentryError monitoring onlyScrubbed error diagnostics and stack traces; no session replay or performance tracingEU
Vercel Analytics + Speed InsightsCookieless web & performance analyticsAggregate usage, no personal dataUS

Price and token-safety data services (DefiLlama, CoinGecko, Kraken, GoPlus) receive no personal data, only token or contract addresses and dates, used for historical price lookups and spam/scam screening.

6. International data transfers

Some processors operate outside the UK. We rely on a UK adequacy regulation where one applies. Otherwise, we use an appropriate safeguard such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses together with the UK Addendum, as applicable, and assess supplementary protections where required.

Wallet addresses and transaction hashes can remain personal data even when they are public on-chain. When a processor receives them outside the UK, we treat that disclosure as an international transfer and apply the safeguards described above.

7. Data retention and deletion

Operational account data is normally retained while your account is active and deleted when you delete the account, subject to the exceptions below.

Deleting your account permanently removes your ChainTax login and application data (wallets, transactions, tax events, tax year summaries, report shares, and in-app purchase/refund records). This deletion is irreversible. There is no recovery period. Start deletion from Settings or email hello@chaintax.co.uk. ChainTax records a detached retry job while deletion is in progress so temporary Supabase or Stripe failures cannot be silently treated as success. Identifiers required for retries are erased on completion; the anonymous completion record is purged after 30 days.

We retain a detached minimum commercial record after account deletion: a pseudonymous account reference, Stripe session reference, tax year, tier, amount, purchase/refund date, and any versioned immediate-supply consent. It contains no email, wallet address, transaction history, or report. We normally retain it for six years after the relevant accounting period, and longer only where required by law or for an active legal claim. It is used only for accounting, tax, fraud-prevention, and legal-claims purposes.

Stripe may independently retain payment records under its own obligations. Shared price and token metadata may be retained where it is not linked to your account. If the loss-harvesting probe is legally approved and enabled, its public-wallet result cache expires after 24 hours. Wallet addresses and transaction hashes can still be personal data when linkable to an individual.

8. Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct any inaccurate personal data.
  • Erasure: Delete account data, subject to records we must retain by law or for overriding legal reasons.
  • Portability: Export your data. CSV export is available in-app for tax reports.
  • Objection: Object to processing based on legitimate interest.
  • Restriction: Restrict processing in certain circumstances.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email hello@chaintax.co.uk. We will respond within 30 days.

9. Cookies

ChainTax uses strictly necessary cookies for authentication (maintaining your signed-in session) and first-party storage for service/UI preferences. Optional PostHog analytics are off by default. If you allow them, ChainTax sends only explicitly defined aggregate actions using memory-only identifiers, with no account identification, autocapture, advertising, session replay, or cross-site tracking. Our web and performance analytics (Vercel Analytics and Speed Insights) are cookieless.

We also use Sentry for error monitoring. Session Replay and performance tracing are disabled, and error events are scrubbed of user, request, cookie, email, wallet, transaction, and session identifiers before sending.

Referral and campaign-attribution cookies are not set while the partner programme is paused. Any legacy ct_ref or ct_utm cookie is expired when it reaches the service.

We keep this footprint deliberately minimal and limited to first-party, privacy-respecting purposes. We do not sell or share this data, and it is never used for advertising. We keep our use of cookies and similar technologies under review under UK PECR (Privacy and Electronic Communications Regulations).

Anonymous product analytics

Off by default. If enabled, ChainTax records a small set of aggregate page and product actions without your account ID, email, session replay, advertising profile, or persistent analytics identifier.

Current setting: off.

10. Children

ChainTax is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.

11. Security

We take the security of your data seriously. Measures include:

  • Data is encrypted in transit with TLS; database and storage protections depend on the configured hosting providers and deployment controls
  • Authentication via Supabase Auth with PKCE flow; the ChainTax application does not receive or store plaintext passwords
  • API routes enforce the authentication or signed-token checks appropriate to their purpose; deliberately public endpoints expose only bounded public data or tools
  • Costly and sensitive endpoints use per-route rate limiting, with server-side ownership checks on user data
  • Content Security Policy (CSP) headers on all responses
  • Database access goes through Prisma; the small number of bulk or atomic SQL operations use parameterised tagged templates rather than unsafe string interpolation
  • Service credentials never exposed to the client

12. Changes to this policy

We may update this privacy policy from time to time. The “Last updated” date at the top of this page will reflect any changes. We will communicate material changes where appropriate. Optional analytics will remain governed by your saved choice and will not be enabled merely because this policy changes.

13. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

14. Contact

For any privacy-related questions or to exercise your data rights, contact us at hello@chaintax.co.uk.

Ready to review your crypto tax history?

Import Coinbase, Binance and Kraken; Crypto.com App (beta), or connect your DeFi wallets. Review every result with full working shown. Pay only when you download the report.