Privacy Policy

Last updated: 2026-09-06

This privacy policy (the "Policy") describes how P2P Companion ("we", "us", "our", or the "Company") collects, uses, stores, shares, and protects personal information obtained from users ("you", "your") of our website (p2pcompanion.com) and the P2P Companion mobile application (the "App") distributed via Google Play. We are committed to transparency, data minimization, and user control in compliance with global privacy regulations, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.

1. Definitions

For the purposes of this Policy:

  • Personal Data means any information relating to an identified or identifiable natural person (e.g., name, email address, online identifiers, location data).
  • Processing means any operation performed on personal data, such as collection, recording, storage, alteration, retrieval, use, disclosure, or deletion.
  • Data Controller means the entity that determines the purposes and means of processing personal data. For this Service, P2P Companion is the Data Controller.
  • Data Processor means a third party that processes personal data on behalf of the Data Controller (e.g., cloud hosting providers, analytics services).
  • Cookies are small text files stored on your device when you visit a website, used to remember preferences or track activity.

2. Information We Collect

P2P Companion is designed as a privacy-conscious utility. We do not require traditional account registration (username/password) or KYC document uploads to access our public P2P rate comparison terminal, arbitrage calculators, or market data feeds. However, certain features may involve the collection of limited personal data as detailed below.

2.1 Information You Provide Directly

We may collect the following categories of personal data when you voluntarily interact with specific features:

  • OTC Nexus Listings & Telegram Authentication: To publish a peer-to-peer trade order or access community listings, you authenticate via the official Telegram Login Widget. We receive your public Telegram user ID, username, first name, and avatar URL. When you create a trade listing, the details of that listing (including your Telegram username) are stored in our secure database and broadcast to our linked Telegram channels.
  • Communications: If you contact us via email (support@p2pcompanion.com or support@p2pcompanion.com) or through Telegram, we may retain copies of your correspondence, including your contact details and the content of messages.
  • Preferences & Configuration: You may choose to set default fiat currencies, crypto filters, dark mode, and custom price alerts within the App or website. This data is stored locally on your device (see Section 2.2) and is not transmitted to our servers unless you explicitly synchronize (which we do not currently offer).

2.2 Information Stored Locally on Your Device

Our website and App store certain configuration data locally on your device using browser LocalStorage or mobile AsyncStorage. This data never leaves your hardware and is not accessible to us. It includes:

  • UI Preferences: Selected fiat currency, cryptocurrency filters, exchange selections, theme (dark/light), and layout preferences.
  • Custom Price Targets: Thresholds for spread or price alerts that you define.
  • Session Tokens: Encrypted authentication tokens when logging in via Telegram (these are cleared upon logout or token expiration).

Your local UI settings and custom price alerts remain on your device and are not synced to our servers. Clearing your browser cache or app data will permanently delete this information.

2.3 Information Collected Automatically (Server Logs & Analytics)

When you access our services, our servers automatically record certain technical data. This information is necessary for security, performance monitoring, and troubleshooting. It may include:

  • HTTP Request Data: IP address, browser type and version, operating system, referral URL, pages visited, timestamps, and request/response status codes.
  • Device Information: Device type, screen resolution, mobile carrier, and approximate geographic location (derived from IP address, not GPS).
  • Usage Analytics: Aggregated event data collected by third-party analytics services (see Section 5) such as pages viewed, features used, session duration, and crash reports.

This automatically collected data is generally not linked to your identity unless you are logged in via Telegram, in which case some analytics events may be associated with your public Telegram ID for internal analysis (e.g., feature popularity).

2.4 Cookies and Similar Technologies

We use cookies and similar tracking technologies (e.g., local storage, pixels, web beacons) to enhance your experience, analyze usage, and deliver relevant advertisements. For detailed information, please see Section 5 of this Policy.

3. Purpose and Legal Basis for Processing

We process personal data for the following purposes and rely on the corresponding legal bases under the GDPR:

PurposeLegal Basis (GDPR Art. 6)
Providing and maintaining core functionality (price comparisons, arbitrage calculations, OTC Nexus listings)Performance of a contract (implicitly accepted terms of service) and legitimate interests
Authenticating users via Telegram Login WidgetConsent (when you choose to log in) and legitimate interests (security, fraud prevention)
Sending local push notifications for price alerts (App only)Consent (you can disable at any time in device settings)
Analytics and service improvement (Google Analytics, Microsoft Clarity, Cloudflare)Legitimate interests (understanding usage patterns, optimizing UX) – you may object via opt-out tools
Displaying advertisements (Google AdSense, AdMob)Consent (for personalized ads) or legitimate interests (for non-personalized ads, if applicable)
Responding to user inquiries and support requestsLegitimate interests (customer service) and, where required, consent
Compliance with legal obligations (e.g., law enforcement requests, tax/audit requirements)Legal obligation

4. Sharing and Disclosure of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share data in the following limited circumstances:

  • OTC Nexus Listings: Your public Telegram username and trade listing details are publicly visible to other authenticated OTC Nexus users and are broadcast to our official Telegram channels to facilitate counterparty discovery.
  • Service Providers: We engage trusted third-party processors to operate our infrastructure and provide analytics, advertising, and security services. These providers only process data on our behalf and are contractually bound to data protection obligations. They include:
    • Google (Analytics, AdSense, AdMob, Firebase)
    • Cloudflare (CDN, security, web analytics)
    • Microsoft (Clarity session replay)
    • Telegram (Login Widget, bot integration)
  • Legal Compliance: We may disclose personal data if required by law, regulation, court order, or governmental request, or to protect the rights, property, or safety of P2P Companion, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, personal data may be transferred as part of the transaction, subject to this Policy continuing to apply.

5. Cookies, Analytics, and Advertising Technologies

We use cookies and similar technologies for the purposes described below. You can manage cookie preferences through your browser settings and opt-out tools provided by third parties.

5.1 Strictly Necessary Cookies

These cookies are essential for the website to function and cannot be switched off in our systems. They are usually set in response to actions you take, such as setting privacy preferences, logging in, or filling forms. Examples:

  • session_id – maintains your authenticated session with Telegram Login.
  • theme_preference – remembers dark/light mode selection.
  • cookie_consent – records your consent to non-essential cookies.

5.2 Analytics and Performance Cookies

We use third-party analytics services to measure website traffic and understand user behavior. These services may set cookies or use similar technologies. You can opt out of these using the links provided:

  • Google Analytics 4 (GA4): Uses first-party cookies (_ga, _ga_<ID>) to distinguish users and collect aggregated event data. We have enabled Google Signals to receive demographic and interest reports (based on Google account data) for signed-in users who have consented to personalized ads. Opt-out via browser add-on or Google Ad Settings.
  • Microsoft Clarity: Sets cookies to track user interactions and generate heatmaps/session recordings. Data is pseudonymized and no financial information is captured. You can opt out of Clarity tracking.
  • Cloudflare Web Analytics: Privacy-focused, cookie-free analytics that do not track individual users across sites. No opt-out necessary but you can block JavaScript if desired.

5.3 Advertising Cookies and Mobile Ad Identifiers

We display advertisements through Google AdSense (website) and Google AdMob (mobile app). These services may use cookies, device identifiers (e.g., Google Advertising ID on Android, IDFA on iOS), and similar technologies to serve ads that are relevant to your interests.

  • Personalized Advertising: By default, you may be shown personalized ads based on your browsing history and app usage. You can opt out of personalized ads at any time:
    • Web: Visit Google My Ad Center and disable ad personalization.
    • Android: Go to Settings > Privacy > Ads and enable "Opt out of Ads Personalization".
    • iOS: Go to Settings > Privacy > Tracking and disable app tracking, or reset Advertising Identifier.
  • Non-Personalized Ads: If you opt out, ads may still appear but will not be based on your interests. They may be contextual (based on the page content) or limited.
  • Third-Party Ad Networks: Google may share data with its partners for ad delivery and measurement. See Google's Privacy Policy for details.

5.4 Managing Cookies and Tracking

Most web browsers allow you to control cookies through their settings. You can typically find these options under "Privacy" or "Security" in your browser menu. To opt out of interest-based advertising from many companies, visit Digital Advertising Alliance or Your Online Choices (EU). Please note that disabling cookies may affect the functionality of our website.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required by law. Retention periods vary by data category:

  • Local device data: Stored until you clear your browser cache/app data or uninstall the App.
  • Telegram authentication tokens: Retained until you log out or the token expires (typically 30–90 days).
  • OTC Nexus trade listings: Stored until you delete the listing or your account is terminated; historical listings may be retained for up to 12 months for dispute resolution.
  • Analytics data (GA4, Clarity): Aggregated and anonymized data may be retained for up to 26 months (Google Analytics default) or as configured by the respective service. Individual session recordings in Clarity are retained for 30 days.
  • Server logs: Retained for 30–90 days for security and performance monitoring.
  • Email correspondence: Retained for up to 24 months after last contact, unless otherwise required.

When personal data is no longer needed, we securely delete or anonymize it.

7. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption in transit using TLS 1.2+ (HTTPS) for all web and API traffic.
  • Firebase security rules restricting database access to authenticated users and authorized processes.
  • Telegram hash verification to ensure login integrity.
  • Regular security audits and vulnerability scanning of our infrastructure.
  • Access controls and the principle of least privilege for any internal data handling.
  • Secure storage of OTC Nexus data in Google Firebase (EU or US region) with redundancy.

Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

8. International Data Transfers

We are a global service, and our third-party processors may store and process data in countries outside your jurisdiction, including the United States, European Union, and Singapore. Where required by applicable law (e.g., GDPR), we ensure that such transfers are safeguarded by appropriate mechanisms, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • EU-US Data Privacy Framework (for transfers to the US where applicable).
  • Binding Corporate Rules or other legal instruments as required.

By using our services, you consent to the transfer of your data to these jurisdictions.

9. Your Rights and Choices

Depending on your location and applicable laws, you may have the following rights regarding your personal data:

9.1 GDPR Rights (EU/EEA Users)

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data, subject to legal retention obligations.
  • Right to Restriction of Processing: You can ask us to limit how we use your data.
  • Right to Data Portability: You can receive your data in a structured, machine-readable format and transfer it to another controller.
  • Right to Object: You can object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent: If processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
  • Rights Related to Automated Decision-Making: We do not make automated decisions with legal or significant effects.

9.2 CCPA/CPRA Rights (California Residents)

  • Right to Know: You can request disclosure of categories and specific pieces of personal data we collect, use, disclose, or sell/share.
  • Right to Delete: You can request deletion of personal data we have collected from you, subject to exceptions.
  • Right to Opt-Out of Sale/Sharing: We do not sell personal data, but we may share limited data for targeted advertising. You can opt out by using the mechanisms described in Section 5.3.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Correct: You can request correction of inaccurate personal data.
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information (as defined by CPRA).

9.3 How to Exercise Your Rights

To make a request, please contact us using the details in Section 11. We may need to verify your identity before processing the request. For GDPR requests, we will respond within one month. For CCPA requests, we will respond within 45 days. You also have the right to lodge a complaint with your local data protection authority.

10. Children's Privacy

P2P Companion is intended for users aged 18 and older. We do not knowingly collect personal information from individuals under 18. If we become aware that a minor has provided us with personal data, we will take immediate steps to delete such information and terminate the account (if any). If you believe a minor has submitted data, please contact us.

11. Financial and Non-Custodial Disclaimer

P2P Companion is strictly an independent market data aggregator, analytics engine, and community directory. We are not a broker, exchange, custodian, money services business, or financial advisor. We do not hold user balances, execute trades, custody assets, or facilitate fiat/crypto transfers. All transactions occur directly between users on third-party platforms (e.g., Binance P2P, OKX P2P) or via OTC Nexus peer-to-peer agreements. Users are solely responsible for conducting due diligence, verifying counterparty identities, and complying with local laws and regulations.

12. Third-Party Links and Integrations

Our services may contain links to external websites, APIs, and services operated by third parties (e.g., cryptocurrency exchanges, Telegram, Google). These third parties have their own privacy policies and practices. We are not responsible for the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of those third parties before providing any personal information.

Key third parties with links to their policies:

13. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or operational needs. We will notify you of any material changes by posting the updated Policy on this page with a revised "Last updated" date, and, where appropriate, by displaying a prominent notice on our website or App. We encourage you to review this page periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or data protection practices, please contact our Data Protection team:

For EU residents: You may also contact our EU Representative (if applicable) or lodge a complaint with your local supervisory authority. For California residents: You may exercise your CCPA rights through the contact channels above.

This Privacy Policy is provided for informational purposes and does not constitute legal advice. For specific legal guidance, please consult a qualified attorney.