← Back to AMLRadar

Privacy Policy

Last updated: June 26, 2026

1. Who We Are

AML Radar ("we", "us", "our") is a crypto AML compliance intelligence platform operated as an independent service. Our website is available at aml-radar.com.

For any privacy-related enquiries, you can contact us at: info@aml-radar.com

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: email address and, optionally, your full name — provided when you register for an account.
  • Authentication data: hashed password (we never store your password in plain text).
  • Usage data: number of wallet screenings performed, timestamps of API calls, and subscription tier.
  • Technical data: IP address at the time of registration or login, used for security purposes.

We do not collect payment card data directly. Payments are processed by Stripe, which acts as an independent data controller under its own privacy policy.

3. How We Use Your Data

We use your personal data for the following purposes:

  • To provide the service: account creation, authentication, and access to wallet screening tools.
  • To manage subscriptions: processing payments and enforcing plan limits via Stripe.
  • To send transactional emails: email verification, password reset, and account notifications via Resend.
  • To prevent abuse: bot detection using Cloudflare Turnstile during registration and login.
  • To improve the service: anonymous, aggregated analytics via Plausible Analytics (no cookies, no cross-site tracking).

4. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:

  • Contract (Art. 6(1)(b) GDPR): processing your email, name, and usage data is necessary to provide the service you signed up for.
  • Legitimate interests (Art. 6(1)(f) GDPR): IP-based bot detection and security logging to protect the platform and our users.
  • Legal obligation (Art. 6(1)(c) GDPR): retaining transactional records where required by applicable law.

5. Cookies and Tracking

AML Radar uses Plausible Analytics for website analytics. Plausible is a privacy-first analytics tool that does not use cookies, does not collect personal data, and does not track users across websites. No consent banner is required.

Cloudflare Turnstile is used on registration and login forms to detect automated bots. It may use minimal browser signals (not persistent cookies) to assess whether a visitor is human.

We do not use Google Analytics, Facebook Pixel, or any other third-party tracking cookies.

6. Data Sharing and Third Parties

We share your data only with the following processors, under appropriate data processing agreements:

  • Stripe — payment processing (EU-compliant, Standard Contractual Clauses apply).
  • Resend — transactional email delivery.
  • Cloudflare — bot detection (Turnstile) and DNS/CDN infrastructure.
  • Hetzner Online GmbH — server infrastructure, located in the European Union.

We do not sell your personal data to third parties. We do not share your data with advertisers.

7. Data Retention

  • Account data is retained for as long as your account is active. If you delete your account, your data is deleted within 30 days.
  • Usage logs (screening counts, timestamps) are retained for 12 months for rate-limit management.
  • Security logs (IP at registration/login) are retained for 90 days.

8. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to erasure: request deletion of your account and personal data.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at info@aml-radar.com. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority. In Italy, this is the Garante per la protezione dei dati personali.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Passwords stored using bcrypt hashing — never in plain text.
  • All data in transit encrypted via TLS (HTTPS enforced).
  • Database access restricted to the application server only.
  • Server infrastructure hosted within the European Union (Hetzner, Germany).

10. International Transfers

Your data is stored on servers located in the European Union. Some of our third-party processors (such as Stripe and Resend) may transfer data outside the EEA. Where this occurs, appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions).

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The date at the top of this page reflects the most recent update.

12. Contact

For any questions about this Privacy Policy or your personal data, contact us at: info@aml-radar.com

Read our Terms of Service →