Privacy Policy
Last updated: August 28, 2026
This privacy policy describes how DYOR.tax ("we", "us", "our") collects, uses, and protects information when you use our crypto tax calculation service at dyor.tax.
1. Information we collect
CSV transaction data. When you upload a CSV file from Coinbase, Binance, or Kraken, the file contents are sent to our server for processing. This data includes your transaction history (dates, amounts, asset types, prices) as exported from your exchange.
Wallet addresses. If you choose to scan on-chain wallets, you provide public blockchain addresses (EVM, Solana, or Bitcoin). We use these addresses to query public blockchain data through third-party APIs.
Payment information. Payments are processed through Stripe. We do not store your credit card number, CVV, or other payment card details. Stripe handles all payment data in accordance with PCI DSS standards. We receive only a payment confirmation and session identifier from Stripe.
Email address. If you voluntarily provide your email through our opt-in form, we store it for product updates. Email is never required to use the service.
Technical data. Our hosting infrastructure (Cloudflare) may log standard request data such as IP addresses, browser user agents, and request timestamps for security and operational purposes.
Advertising measurement data. If you consent to advertising measurement, Cloudflare Zaraz may activate Google Ads conversion measurement. The events may include the completed action, page path, country, tax year, selected source or report mode, a server-verified purchase amount and currency, a unique Stripe Checkout Session identifier, and Google advertising or click identifiers available in your browser. We do not send CSV rows, wallet addresses, report contents, email addresses, or payment-card details to Google Ads.
2. How we use your information
- To parse and analyze your transaction data and generate tax reports
- To process payments through Stripe
- To deliver your generated PDF report
- To send product updates if you opted in to email communications
- To monitor and maintain service reliability and security
- With your consent, to measure preview and purchase conversions and attribute them to advertising
3. Data storage and retention
CSV files. Your uploaded CSV data is processed in memory and is not stored permanently on our servers. CSV content is used only for the duration of your analysis session.
Wallet scanning. Wallet scanning is read-only. We query only public blockchain data using your addresses. We do not request, store, or have access to private keys, seed phrases, or wallet signing capabilities.
Generated reports. PDF and CSV reports you purchase are stored encrypted on Cloudflare R2 (S3-compatible object storage). Reports are retained for 12 months from the date of generation, after which they are automatically deleted by our cleanup process.
Preview data. Raw preview inputs, including uploaded CSV content and wallet addresses, are stored temporarily in private Cloudflare R2 object storage so checkout and paid report delivery read the exact analyzed input. We delete this input after successful report generation. If that immediate deletion fails or checkout is never completed, an automatic lifecycle rule deletes the input within 7 days.
4. Data sharing
We do not sell, rent, or trade your personal information or transaction data to third parties.
We share data with the following service providers to operate the service and, where you have consented, to measure advertising conversions:
- Stripe - payment processing
- Cloudflare - CDN, DNS, and report storage
- Plausible Analytics - privacy-friendly, cookieless web analytics (data policy)
- Google Ireland Limited - Google Ads conversion measurement and attribution, only when you consent to advertising measurement. See Google's privacy policy.
- Crisp - live chat support widget. Crisp may set session cookies to maintain your chat conversation. See Crisp's privacy policy for details.
- Third-party data providers - public blockchain and market data (read-only, no personal data shared)
5. Security
We take reasonable measures to protect your data:
- All data transmission uses HTTPS/TLS encryption
- Generated reports are stored encrypted at rest
- API authentication is required for all server requests
- Payment sessions are verified server-side with Stripe before report delivery
- Data integrity is verified using SHA-256 fingerprints during the checkout process
6. Cookies
Our site uses browser storage. We use sessionStorage to maintain calculator state
during a session. Cloudflare Zaraz stores consent choices in a first-party cookie. Google Ads
conversion measurement is disabled by default and is activated only after you opt in to the
advertising-measurement purpose. You can refuse or later withdraw that consent without losing
access to the calculator.
Analytics. We use Plausible Analytics, a privacy-friendly service that does not use cookies or collect personal data. Plausible processes aggregate page view counts and referral sources without identifying individual visitors. Plausible analytics data is not shared with advertisers. See Plausible's data policy for details.
Google Ads. With advertising-measurement consent, Google Ads may use cookies or similar identifiers to measure and attribute the preview and purchase events described above. Consent Mode v2 defaults advertising storage and advertising user data to denied. We keep ad personalization disabled in this setup. Google's handling and retention of data is governed by its privacy policy and our Google Ads settings.
Live chat. We use Crisp for live chat support. When you interact with the chat widget, Crisp may set session cookies to maintain your conversation state. These cookies are functional (not used for advertising or cross-site tracking). You can review Crisp's privacy policy for full details on how they handle data.
7. Your rights
Since we do not permanently store CSV data and do not require accounts, there is generally no persistent personal data to delete. If you provided your email for updates, you can request removal by contacting us at [email protected].
8. Children
DYOR.tax is not intended for use by individuals under 18 years of age. We do not knowingly collect data from minors.
9. Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Where consent is required, a policy update does not replace your consent choice.
10. Contact
If you have questions about this privacy policy or your data, contact us at [email protected].