- Home
- Privacy policy
Privacy policy
This is a reference website. There are no accounts, no logins, no comment system and no advertising network. The data we handle is minimal, and this page explains all of it.
Last updated 2 September 2026.
Who is responsible
BitcoinETF Directory operates the website at bitcoinetf.directory and is the controller of any personal data described in this policy. You can reach us at contact@bitcoinetf.directory about anything on this page, including a request to exercise your rights.
What we collect
Very little, and none of it deliberately identifying. This site has no user accounts, no login, no newsletter sign-up, no comment section and no form that asks you for personal details.
Server logs
Like any website, our hosting provider records technical information when your browser requests a page: your IP address, the date and time, the page requested, the HTTP status returned, the referring page if your browser sends one, and your browser's user-agent string. These records exist so that the site can be operated and defended — diagnosing errors, understanding load, and identifying abusive traffic. They are not used to build a profile of you, they are not combined with any other source, and they are not sold.
Analytics
If we operate analytics, it is limited to aggregate measurement of which pages are read and how visitors arrive. We do not use analytics tools that build cross-site advertising profiles, and we do not deploy advertising or retargeting pixels of any kind. If we introduce an analytics provider that sets cookies, we will present a consent request before doing so and update this page.
If you write to us, we hold your email address and whatever you chose to put in the message, for as long as we need it to deal with your enquiry and to keep a record of corrections. We do not add correspondents to any mailing list.
Cookies
This site sets no advertising cookies and no cross-site tracking cookies. It is built as static pages and does not require a cookie to function. Your browser may store technical items such as cached files, which are not cookies and carry no identifier we can read.
Third-party sites you reach by clicking an outbound link will apply their own cookie and privacy practices, over which we have no control. If we ever introduce cookies that are not strictly necessary, we will ask for your consent first and record that choice.
Outbound and commercial links
Some links on this site are commercial. If you follow one and open an account, the operator of that service may pay us a referral fee, and may record that the visit originated here — usually through a parameter in the link or a cookie set on their own domain once you arrive.
We do not receive your name, email address, account details, balances, transactions or any other personal information from those partners. What reaches us is aggregate: how many people followed a link and how many opened an account. Once you leave this site, that operator's own privacy policy governs your data, and you should read it.
Why we are allowed to process this data
Where the UK GDPR or the EU General Data Protection Regulation applies to you, our lawful bases are as follows. Server logs are processed under our legitimate interests in operating and securing the site — a limited, expected and low-impact use of data. Email correspondence is processed under legitimate interests in responding to you, or under consent where you have volunteered information. Any non-essential cookies would be processed only with your consent.
How long we keep it
Server logs are retained for a short operational period, typically no more than a few months, and then deleted or aggregated. Aggregate analytics contain no identifier and may be retained indefinitely. Email correspondence is kept while it remains relevant — corrections correspondence is generally kept as part of our editorial record — and deleted on request unless we are required to retain it.
Who we share it with
We do not sell personal data. We do not share it for anyone else's marketing. The only parties who may process data on our behalf are the technical suppliers who make the site work — our hosting provider, our content delivery network and our email provider — each acting under contract and only for that purpose. We may disclose information if we are legally compelled to, or where it is necessary to establish or defend a legal claim.
International transfers
Our suppliers may process data in countries outside your own, including the United States. Where such a transfer is subject to the UK or EU GDPR, it takes place under an appropriate safeguard, such as the European Commission's standard contractual clauses or an adequacy decision.
Your rights
Depending on where you live, you may have the right to ask what personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, to receive a copy in a portable format, and to withdraw consent where our processing relies on it. Residents of California and several other US states have comparable rights, including the right to know, to delete, and to opt out of any sale or sharing of personal information — we do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising any right.
To exercise any of these, email contact@bitcoinetf.directory. We will respond within the period the applicable law requires. Because we hold so little, it is often the case that we hold nothing about you at all beyond a short-lived server log entry, and we will tell you if that is so.
If you are in the UK you may complain to the Information Commissioner's Office; if you are in the EEA you may complain to your national supervisory authority. We would rather you raised it with us first.
Children
This site is intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Security
The site is served over HTTPS and delivered as static files, which removes most of the attack surface a database-driven site carries. No system is perfectly secure, but the practical consequence of our design is that there is very little about you here to lose.
Changes to this policy
If we change how we handle data — for example by adding an analytics provider or a newsletter — we will update this page and change the date at the top. Material changes will be described rather than quietly folded in.
See also our terms of use and our disclaimer.