RIXTO

Privacy Policy

Last updated: 22 July 2026

Covers the waitlist site and, when launched, the RIXTO product. Not legal or tax advice.

This Privacy Policy explains how RIXTO (“we”, “us”) processes personal data on rixto.co and related staging sites. It covers the current waitlist and the processing we intend when the full product launches. Cookie preferences are controlled separately via Manage Cookies; they are not part of the waitlist “agree to” covering Privacy Policy, Terms of use, and Disclaimer.

Controller

Controller:
SMIRNOV SERGEY
Partita IVA:
01866710096
Address:
VIA GUIDO ROSSA 26R,SAVONA (SV), 17100, Italia
Contact:
legal@rixto.co

What we process now (waitlist)

While the public site is waitlist-only, we process: (1) the email address you submit to join the waiting list; (2) UI locale / language preference needed to show the site; (3) a record of your cookie consent choices (Necessary Cookies / Analytics Cookies / Marketing Cookies) stored in your browser so we can honour them. Joining uses double opt-in: after you submit the form we send a confirmation email; your address is added to the active waitlist only after you confirm the link. Confirmed subscribers may receive a success email and later launch-related updates; every waitlist email includes an unsubscribe link. We do not collect passwords or tax transaction data at this stage.

Lawful bases

Waitlist email: consent (GDPR Art. 6(1)(a)) — you submit your email and agree to this Privacy Policy (together with Terms of use and Disclaimer) by continuing on the waitlist form. Necessary Cookies and local storage required to run the site and remember consent: legitimate interests in operating a secure, functional website (Art. 6(1)(f)), and/or necessity for the service you request. Optional Analytics Cookies and Marketing Cookies: consent only (Art. 6(1)(a)) via our cookie banner — never assumed from joining the waitlist. When the product launches, processing needed to provide your account and tax-reporting service will rely primarily on performance of a contract (Art. 6(1)(b)), with other bases where required by law.

What we will process when the product launches

When accounts are enabled, we expect to process: account email for authentication; imported transaction history (for example CSV exports); wallet settings; TaxProfile preferences (one profile per country); and calculation snapshots and related notifications — solely to provide crypto tax reporting for your chosen country module (Italy first). We do not use imported history to custody assets, execute trades, or file returns with tax authorities on your behalf. Material changes to this policy will be highlighted on this page.

Cookies and similar technologies

We use one strict cookie consent experience for all regions (no geo-softening). Optional categories are off by default. Non-essential scripts and cookies are not loaded until you opt in. We use Google Consent Mode v2 in Basic mode: Google Analytics and Google Ads tags are not loaded before the matching consent, and we do not send cookieless analytics or advertising pings before consent.

  • •Necessary Cookies (always on): session/locale preferences and storage of your cookie consent choice so the site and (later) your signed-in session can work. These cannot be switched off in Manage Cookies.
  • •Analytics Cookies (optional): Google Analytics 4, only if Analytics Cookies is enabled on our side and you grant Analytics Cookies consent. Used to understand aggregate site usage. Consent mapping: Analytics Cookies ON → analytics_storage granted.
  • •Marketing Cookies (optional): Google Ads (conversion / remarketing tag), only if Marketing Cookies is enabled on our side and you grant Marketing Cookies consent. Used to measure ad campaigns and, where applicable, show more relevant ads. Consent mapping: Marketing Cookies ON → ad_storage, ad_user_data, and ad_personalization granted.
  • •You can change or withdraw optional consent at any time via Manage Cookies. Reject All turns off Analytics Cookies and Marketing Cookies only; Necessary Cookies remain. Manage Cookies is a preference control — not part of the waitlist contractual “agree to” covering Privacy Policy, Terms of use, and Disclaimer.

Where data is stored

Waitlist and (when enabled) product cloud data are hosted with EU-region providers where we control the choice of region (see sub-processors). Preferences and consent may also be stored in your browser (local storage). Application logs are designed to avoid personal data where practicable.

Transfers outside the EU/EEA

Some providers may process data in the United States or other countries. In particular, if you grant Analytics Cookies and/or Marketing Cookies consent, Google Analytics and/or Google Ads may involve transfers to Google in the US under Google’s applicable transfer mechanisms. We do not enable those tags without the matching consent. Where EU Standard Contractual Clauses or equivalent safeguards apply to our contracts with providers, we rely on those.

Retention

Waitlist email retention (storage limitation): (1) Pending (not confirmed): we keep the address only while the confirmation link is valid (7 days from the last confirmation email). After the link expires we delete the pending record — we do not keep unconfirmed emails indefinitely. (2) Confirmed: kept until you unsubscribe, ask us to delete, we close the waitlist, or we migrate you to a product account with notice. (3) Unsubscribed: we retain the record for up to 30 days after unsubscribe for operational consistency, then hard-delete the email from the waitlist database. Cookie consent records in the browser: until you clear site data or change preferences; we may keep minimal records needed to demonstrate compliance. Product account data (when available): while the account is active; deleted from our cloud after account deletion (cascade), subject to short technical backups and any legal retention we must observe. To stop waitlist emails use the unsubscribe link in any waitlist message, or contact the controller email once published on this page to request earlier deletion.

Your rights (GDPR)

Where applicable you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent without affecting prior lawful processing. Waitlist: use the unsubscribe link in waitlist emails and/or email the controller contact to exercise rights (including deletion). Product accounts: Settings → delete account (cascade). You may lodge a complaint with your supervisory authority.

Sub-processors

We use: Vercel (web hosting and edge delivery); Supabase in an EU region (waitlist subscriber database now; authentication and product database when accounts are enabled); Resend (transactional waitlist email: confirmation, success, and related notices from addresses such as no-reply@rixto.co); Railway or an equivalent EU-hosted API (when the API is enabled); Google Analytics (only if Analytics Cookies is enabled and you consent); Google Ads (only if Marketing Cookies is enabled and you consent). We do not sell personal data. We do not claim certifications (for example SOC 2) or third-party products (Clarity, Mixpanel) that are not actually in use on the waitlist.

This page is product documentation, not legal advice. We may update this policy; material changes will be noted here.

RIXTO
Privacy PolicyTerms of useDisclaimer© 2026 RIXTO