1. Introduction
This Privacy Policy describes how Cropr Labs Limited (“Cropr”, “we”, “us” or “our”), a company incorporated in the British Virgin Islands, processes personal information that we collect through our website at www.cropr.finance, our decentralised finance (DeFi) platform, and any related digital properties, applications, social media pages, and other services that link to this Privacy Policy (collectively, the “Service”).
Cropr is a DeFi portfolio management and aggregation platform that enables users to connect multiple cryptocurrency wallets across various blockchains, execute DeFi transactions (including swaps, lending, borrowing, staking, and bridging), and monitor portfolio performance through a unified dashboard. Users access the Service by connecting their cryptocurrency wallets; there is currently no traditional account registration process.
As a British Virgin Islands company, Cropr is subject to the British Virgin Islands Data Protection Act, 2021 (the “BVI DPA”). This Privacy Policy is designed to comply with the BVI DPA and, where applicable, with the data protection laws of other jurisdictions from which users may access the Service.
For clarity, this Privacy Policy does not apply to any decentralised aspect of the blockchain networks that we do not control due to the inherently decentralised nature of blockchain technology. Information recorded on public blockchains is outside the scope of this Privacy Policy and our control.
European Users: Please see Section 13 (“Notice to European Users”) below for additional information applicable to individuals located in the European Economic Area (“EEA”) or the United Kingdom (“UK”), which we collectively refer to as “Europe”.
2. Personal Information We Collect
2.1 Information You Provide to Us
Personal information you may provide to us through the Service or otherwise includes:
- Contact data, such as your name, email address, and any information you provide when contacting us through any communication channel.
- Communications data, based on our exchanges with you, including when you contact us through the Service, social media, or otherwise.
- Wallet and blockchain activity data, such as your cryptocurrency wallet addresses, transaction hashes, transaction sender and recipient details, transaction amounts, transaction history, and information relating to other on-chain activity associated with your connected wallets, including your interactions with DeFi protocols (e.g., liquidity pools, lending protocols, staking contracts, and decentralised exchanges) across supported blockchains such as Ethereum, Polygon, Base, Avalanche, BNB Chain, Arbitrum, Optimism, and Linea.
- Financial data, such as your digital asset balances, portfolio valuations, yield and return calculations, and other associated financial information derived from your connected wallets and DeFi positions.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
2.2 Information from Third-Party Sources
We may combine personal information we receive from you with personal information we obtain from other sources, such as:
- Public sources, including public blockchains, government agencies, public records, and other publicly available sources.
- Blockchain data providers and analytics services that aggregate and provide on-chain data.
- Service providers that provide services on our behalf or help us operate the Service or our business.
- Third-party wallet providers or linked services that you use to connect to or interact with the Service. This data may include your wallet address and other data made available based on the permissions you grant.
2.3 Automatic Data Collection
We, our service providers, and our business partners may automatically log information about you, your device, and your interaction with the Service, our communications, and other online services, such as:
- Device data, such as your device’s operating system type and version, browser type, screen resolution, IP address, unique identifiers, language settings, and general location information such as city, country, or geographic area.
- Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Service, navigation paths between pages, information about your activity on a page or screen, access times, and duration of access.
- Communication interaction data, such as your interactions with any emails or other communications we may send you (e.g., whether you open and/or click links within them), which we may track through pixel tags or similar technologies.
3. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect some of the automatic data described above and to support the operation of the Service.
3.1 What Are Cookies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work more efficiently, as well as to provide reporting and analytics information.
3.2 Types of Cookies We Use
- Strictly necessary cookies: These cookies are essential for the Service to function and cannot be switched off. They are usually only set in response to actions you take, such as setting your privacy preferences or connecting your wallet.
- Analytics and performance cookies: These cookies allow us to count visits and traffic sources so we can measure and improve the performance of the Service. They help us understand which pages are the most and least popular and how visitors navigate the Service. We may use third-party analytics services, such as Google Analytics, for this purpose. You can learn more about Google Analytics and opt out at: https://tools.google.com/dlpage/gaoptout.
- Functional cookies: These cookies enable the Service to provide enhanced functionality and personalisation, such as remembering your preferences and settings.
3.3 Managing Cookies
Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all or some cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, some parts of the Service may become inaccessible or not function properly.
Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals. We currently do not respond to “Do Not Track” signals. To find out more, please visit http://www.allaboutdnt.com.
4. How We Use Your Personal Information
Under the BVI DPA, we process your personal information on the basis of your consent or, where applicable, because such processing is necessary for the performance of a contract with you, for compliance with a legal obligation, or for the protection of your vital interests. We may use your personal information for the following purposes or as otherwise described at the time of collection:
4.1 Service Delivery and Operations
We may use your personal information to provide, operate, and maintain the Service; to enable security features of the Service; to facilitate your wallet connections and interactions with supported DeFi protocols and blockchain networks; to communicate with you about the Service, including Service-related announcements, updates, security alerts, and support messages; and to respond to your requests, questions, and feedback.
4.2 Service Personalisation
We may use your personal information to understand your needs and interests, personalise your experience with the Service, and remember your selections and preferences as you navigate the Service.
4.3 Service Improvement and Analytics
We may use your personal information to analyse your usage of the Service, improve the Service and our business, understand user activity (including which pages and features are most and least used), and develop new products and services.
4.4 Communications
If we introduce communication features (such as a newsletter or service announcements) in the future, we may use your personal information to send you relevant communications. Where required by applicable law, we will obtain your consent before sending any marketing communications. You will always have the ability to opt out of any such communications.
4.5 Compliance and Protection
We may use your personal information to comply with applicable laws, lawful requests, and legal process; to protect our, your, or others’ rights, privacy, safety, or property; to audit our internal processes for compliance; to enforce the terms and conditions that govern the Service; and to prevent, identify, investigate, and deter fraudulent, harmful, unauthorised, unethical, or illegal activity.
4.6 Aggregated and Anonymised Data
We may create aggregated, de-identified, and/or anonymised data from your personal information by removing information that makes the data identifiable to you. We may use and share this data for our lawful business purposes, including to analyse and improve the Service and promote our business.
5. How We Share Your Personal Information
In accordance with the BVI DPA’s disclosure principle, we will not disclose your personal information for any purpose other than the purpose for which it was collected (or a directly related purpose), or to any party other than the categories of third parties described below, unless we have obtained your consent. We may share your personal information with the following parties or as otherwise described in this Privacy Policy:
- Affiliates. Our corporate subsidiaries and affiliates.
- Service providers. Third parties that provide services on our behalf or help us operate the Service or our business, such as hosting, information technology, customer support, email delivery, analytics, and website performance services.
- Third parties designated by you. We may share your personal information with third parties where you have instructed us or provided your consent to do so, for example, third-party DeFi protocols or wallet providers you interact with through the Service.
- Professional advisors. Professional advisors such as lawyers, auditors, and insurers, where necessary in the course of the professional services that they render to us.
- Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for compliance and protection purposes.
- Business transferees. We may disclose personal information in the context of actual or prospective business transactions (e.g., investments in, financings of, or the sale, transfer, or merger of all or part of our business, assets, or shares), including to an acquirer, successor, or assignee as part of any such transaction, and/or in the event of an insolvency, bankruptcy, or receivership.
- Blockchain networks and the public. Due to the nature of blockchain technology, any data relating to your on-chain transactions or interactions with public blockchains will be visible to other users and the public. This information can be seen, collected, and used by others, and we are not responsible for any such use. It may be possible for third parties to identify you through your public wallet addresses using external information sources.
6. Data Retention
We generally retain personal information for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes. In accordance with the BVI DPA, personal information processed for any purpose will not be kept for longer than is necessary for the fulfilment of that purpose.
To determine the appropriate retention period for personal information, we consider factors such as the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal information we have collected about you, we will either delete it, anonymise it, or isolate it from further processing.
7. Security
We employ technical, organisational, and physical safeguards designed to protect the personal information we collect from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration, or destruction. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information. Cropr does not hold custody of your digital assets. Private keys remain under your control at all times; the Service only requests the permissions necessary to provide its functionality.
8. Your Choices
Under the BVI DPA and other applicable laws, you may have certain rights in respect of your personal information, including:
- Right of access. You have the right to request access to the personal information we hold about you.
- Right of rectification. You have the right to request that we correct any personal information that is incomplete, incorrect, misleading, or not up to date.
- Right to prevent direct marketing. You have the right to require us to stop processing your personal information for the purposes of direct marketing.
- Wallet disconnection. You may disconnect your wallet from the Service at any time through the Service interface or through your wallet provider. Disconnecting your wallet will prevent Cropr from accessing further data from your wallet, but will not affect data already collected or information already recorded on public blockchains.
- Cookies. You may manage your cookie preferences through your browser settings as described in Section 3.3 above.
- Declining to provide information. You are not obligated to provide personal information to us. However, if you do not provide information we identify as required (such as connecting a wallet), we may not be able to provide certain aspects of the Service to you.
- Third-party linked services. If you connect a third-party wallet or service to the Service, you may be able to use the settings of that third-party service to limit the information we receive. If you revoke our ability to access information from a third-party service, that choice will not apply to information we have already received.
- Data deletion requests. If you wish to request deletion of personal information we hold about you, please contact us using the details in Section 14. Please note that due to the nature of blockchain technology, neither you nor Cropr may be able to delete transactions or other data already recorded on a blockchain.
- Withdrawal of consent. Where we process your personal information on the basis of your consent, you may withdraw that consent at any time by contacting us. Withdrawal of consent will not affect the lawfulness of processing carried out prior to such withdrawal.
To exercise any of the above rights, please contact us using the details in Section 14.
9. International Data Transfers
Cropr is incorporated in the British Virgin Islands and may use service providers that operate in various countries worldwide. Your personal information may be transferred to and processed in jurisdictions other than the jurisdiction in which you are located, including jurisdictions where privacy laws may not be as protective as those in your home jurisdiction.
Under the BVI DPA, personal information may not be transferred outside the British Virgin Islands without proof of adequate data protection safeguards or your consent. Where we transfer your personal information internationally, we take steps to ensure that appropriate safeguards are in place to protect your personal information in accordance with this Privacy Policy and applicable law.
10. Children
The Service is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe we have collected personal information from a child in a manner prohibited by law, please contact us. If we learn that we have collected personal information from a child without appropriate consent, we will take steps to delete the information as required by applicable law.
11. Third-Party Sites and Services
The Service may contain links to websites, mobile applications, DeFi protocols, and other online services operated by third parties. In addition, our content may be integrated into web pages or other services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control third-party websites, applications, or services, and we are not responsible for their actions or privacy practices. We encourage you to read the privacy policies of the third-party services you use.
12. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by updating the date of this Privacy Policy and posting it on the Service. Any modifications will be effective upon posting (or as otherwise indicated at the time of posting). Your continued use of the Service after the effective date of any modified Privacy Policy indicates your acknowledgement that the modified Privacy Policy applies to your interactions with the Service.
13. Notice to European Users
Applicability. This section applies only to individuals located in the EEA or the UK (“Europe”). References to “personal information” in this Privacy Policy should be understood to include “personal data” as defined in the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and the EU GDPR as it forms part of the laws of the United Kingdom (“UK GDPR”).
Controller. Cropr Labs Limited is the “controller” of your personal information for the purposes of the GDPR. See Section 14 for our contact details.
13.1 Legal Bases for Processing
Under the GDPR, we are required to have a “legal basis” for each purpose for which we process your personal information. Our legal bases are as follows:
- Contractual necessity: Where processing is necessary to deliver the Service to you or to take steps at your request prior to entering into a contract.
- Legitimate interests: Where processing is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. Our legitimate interests include operating, improving, and promoting the Service, ensuring security, and exercising or defending legal claims.
- Compliance with law: Where we need to comply with a legal or regulatory obligation.
- Consent: Where we have obtained your specific consent to carry out the processing in question. Where we rely on consent, you have the right to withdraw it at any time.
13.2 Your Rights Under European Data Protection Law
If you are located in Europe, you may have the following rights in relation to your personal information, in addition to the rights described in Section 8:
- Access: Obtain information about our processing of your personal information and receive a copy of it.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal information where there is no compelling reason for its continued processing.
- Data portability: Receive a machine-readable copy of your personal information which you have provided to us.
- Restriction: Request restriction of processing of your personal information.
- Objection: Object to our processing of your personal information where we rely on legitimate interests, including for direct marketing purposes.
- Withdrawal of consent: Where we rely on your consent, withdraw that consent at any time.
To exercise these rights, please contact us using the details in Section 14. We may request information to verify your identity before processing your request. We aim to respond to all legitimate requests within one month, though complex requests may take longer.
Right to lodge a complaint. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority. For users in the EEA, contact details can be found at https://edpb.europa.eu/about-edpb/board/members_en. For users in the UK, contact details can be found at https://ico.org.uk/make-a-complaint/.
13.3 International Transfers from Europe
Where we transfer your personal information outside Europe, we ensure that appropriate safeguards are in place, including through the use of Standard Contractual Clauses approved by the European Commission or UK Government (as applicable), transfers to countries with adequacy decisions, or reliance on applicable derogations under the GDPR. You may contact us for further information on the specific mechanisms used.
14. How to Contact Us
If you have questions about this Privacy Policy or our privacy practices, or if you would like to exercise any privacy-related rights that may be available to you under the BVI DPA or other applicable law, please contact us at:
Cropr Labs Limited
c/o Suite 5, Oleander Building, Port Purcell, Tortola, VG1110, British Virgin Islands
Email: privacy@cropr.finance
This Privacy Policy was last updated on .



