Last updated April 2026

Privacy Policy

How we collect, use, and protect your data. If you have questions, contact us at hello@chaintax.co.uk.

1. Who we are

ChainTax is a UK-based tax calculation tool for crypto and DeFi transactions. For the purposes of UK data protection law, the data controller is ChainTax Ltd (company number NI739302, registered in Northern Ireland), contactable at hello@chaintax.co.uk.

Governing jurisdiction: Northern Ireland.

2. What data we collect

We collect the minimum data necessary to provide the service. We never sell your data to third parties.

  • Email addressUsed for account creation, authentication, and transactional emails (welcome, purchase confirmation).
  • Wallet addressesPublic blockchain addresses you provide, along with chain (e.g. Ethereum, Arbitrum) and optional label. Used to fetch your on-chain transaction history.
  • On-chain transaction dataTransaction hashes, timestamps, and decoded event logs fetched from public blockchains. This data is already publicly available on-chain.
  • Tax calculationsGains, losses, income, and cost basis figures derived from your transaction data. These are computed by ChainTax, not provided by you.
  • Payment informationProcessed entirely by Stripe. We store only your Stripe customer ID — we never see or store your card details.
  • Tax preferencesYour selected tax band (basic/higher) and optional salary figure, used to refine income tax estimates.
  • Authentication cookiesEssential session cookies for keeping you signed in. No analytics, advertising, or tracking cookies.
  • IP addressUsed for rate limiting only. Not stored persistently or associated with your account.

3. Why we process your data

Under UK GDPR, we must have a lawful basis for processing your personal data. Our bases are:

  • Contract performance (Art. 6(1)(b))Processing your wallet data, classifying transactions, calculating tax, and generating reports — the core service you signed up for.
  • Legitimate interest (Art. 6(1)(f))Rate limiting, fraud prevention, and maintaining service security and availability.

We do not currently send marketing emails. If we do in future, we will obtain your explicit consent first.

4. How we use your data

  • Fetching on-chain transaction history for wallets you provide
  • Classifying transactions (on-chain DeFi and exchange CSV imports) using deterministic protocol-specific rules
  • Calculating UK capital gains tax, income tax, and HMRC matching (Section 104, same-day, bed-and-breakfast)
  • Generating tax reports (PDF and CSV) and SA108 box mappings
  • Processing payments via Stripe
  • Sending transactional emails (welcome email, purchase confirmation)
  • Rate limiting to protect service availability

5. Third-party processors

We use the following third-party services to operate ChainTax. Each receives only the data necessary for its function.

ServicePurposeData sharedLocation
SupabaseDatabase & authenticationEmail, all stored dataEU
StripePayment processingEmail, payment detailsUS/EU
AnkrBlockchain data APIWallet addressesUS
InfuraBlockchain RPCWallet addresses, tx hashesUS
AlchemyBlockchain RPC (fallback)Wallet addresses, tx hashesUS
ResendEmail deliveryEmail addressUS
VercelHostingStandard web server logsUS
InngestBackground job processingWallet IDs, sync metadataUS
UpstashRate limitingIP address (ephemeral)US

Price data services (DefiLlama, CoinGecko) receive no user data — only token addresses and dates for historical price lookups.

6. International data transfers

Some of our processors are based in the United States. Where personal data is transferred outside the UK, transfers are protected by Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as applicable.

Blockchain data (wallet addresses and transaction hashes) is inherently public and available globally on-chain. Providing a wallet address to ChainTax does not create a new data transfer — we are reading data that is already publicly accessible.

7. Data retention and deletion

Your data is retained for as long as you maintain an active account.

Deleting your account permanently removes all associated data — wallets, transactions, tax events, tax year summaries, and purchase records. This deletion is irreversible. There is no soft-delete or recovery period. To request account deletion, email hello@chaintax.co.uk.

Anonymised service data (price cache entries, transaction enrichment data keyed by public transaction hash) is retained for service improvement and is not personally identifiable.

8. Your rights under UK GDPR

You have the following rights regarding your personal data:

  • AccessRequest a copy of the personal data we hold about you.
  • RectificationCorrect any inaccurate personal data.
  • ErasureDelete your account and all associated data.
  • PortabilityExport your data. CSV export is available in-app for tax reports.
  • ObjectionObject to processing based on legitimate interest.
  • RestrictionRestrict processing in certain circumstances.
  • Withdraw consentWhere processing is based on consent, withdraw it at any time.

To exercise any of these rights, email hello@chaintax.co.uk. We will respond within 30 days.

9. Cookies

ChainTax uses only strictly necessary cookies for authentication (maintaining your signed-in session). We do not use analytics cookies, advertising cookies, or tracking pixels.

Because we use only essential cookies, no cookie consent banner is required under UK PECR (Privacy and Electronic Communications Regulations).

10. Children

ChainTax is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.

11. Security

We take the security of your data seriously. Measures include:

  • All data encrypted in transit (TLS) and at rest
  • Authentication via Supabase Auth with PKCE flow — no passwords stored by ChainTax
  • Every API route enforces authentication, rate limiting, and input validation
  • Content Security Policy (CSP) headers on all responses
  • No raw SQL — all database access via Prisma ORM with parameterised queries
  • Service credentials never exposed to the client

12. Changes to this policy

We may update this privacy policy from time to time. The “Last updated” date at the top of this page will reflect any changes. Continued use of ChainTax after changes constitutes acceptance of the updated policy.

13. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

14. Contact

For any privacy-related questions or to exercise your data rights, contact us at hello@chaintax.co.uk.

Ready to get your crypto tax right?

Import from Coinbase, Binance, or Kraken — or connect your DeFi wallets. Review every classification with full working shown. Pay only when you download the report.