Privacy Policy
Last updated September 28th, 2026
1. Introduction
Welcome to DexPal. Your privacy is important to us. This Privacy Policy explains how we collect, use, and protect your data when you use our platform.
2. Data We Collect
- Non-Personal Data: We may collect anonymized usage statistics, transaction metadata, and aggregated analytics.
- Personal Data: DexPal does not require personally identifiable information (PII) for use. However, if you voluntarily provide an email for early access or communications, we will store it securely.
3. How We Use Your Data
- To provide and improve our platform.
- To analyze usage trends and enhance user experience.
- To communicate important updates and announcements.
4. Third-Party Services
- We may use third-party analytics and marketing tools that collect anonymized data.
- We do not sell or share your data with third-party advertisers.
5. Blockchain Transparency
Transactions and activity on DexPal may be recorded on public blockchains. We cannot modify or delete blockchain data.
6. Security Measures
We take reasonable measures to protect your data but cannot guarantee complete security due to the decentralized nature of blockchain technology.
7. No Affiliation with DEXes
DexPal is an independent platform and is not affiliated with any decentralized exchange.
8. Events guide (events.dexpal.io) and Google Calendar
- Scope: This section covers DexPal’s side-events guide at events.dexpal.io, operated by DP Analytiques Inc., and its optional Sync and Google Calendar features. Without them, the guide keeps your saved events and plan only in your browser’s storage on your device.
- Sync: When you turn on Sync, or connect Google Calendar, which turns Sync on, the guide stores one document under a random ID: the IDs of the guide events you saved and the minutes you planned for them. Anyone who has that ID can read the document, so it holds nothing else: no addresses, no names and no contact details.
- What DexPal reads from Google Calendar: Connecting lets you import the guide events that are already on your main Google Calendar. The guide reads that calendar only when you import, within 15 minutes of signing in with Google to do so, and only events from that moment until just after the guide’s last conference week. It does not ask Google for event titles or for other guests’ email addresses. The locations and descriptions it reads are held in memory for that one request; DexPal’s server neither stores nor logs them. Events that are not in the guide are counted and otherwise ignored.
- What DexPal writes to Google Calendar: DexPal writes only to the DexPal Side Events calendar it creates in your Google account: the guide’s public details for each event you schedule in the guide, at the times you planned. Events you imported are not copied into it. It reads that calendar back to pick up planned times you change in it, and it never writes to your main calendar.
- What DexPal keeps: the connection record, with the refresh token Google issues for it (Google lets that token read your main calendar as well, but DexPal uses it only for its own DexPal Side Events calendar); your Google account ID, an identifier Google assigns to your account, so that your other devices join the same schedule when you sign in with the same account; and the IDs of the guide events you imported, so they are not added twice. For invite-only events, that list shows the host approved you. These records are encrypted and kept in a private store at DexPal’s hosting provider, Vercel. Google also sends your email address when you sign in; DexPal does not keep it. DexPal never keeps event addresses.
- Where addresses live: An approved invite can carry an event’s address, which hosts often show only to approved guests. The import sends those addresses to your device, which saves them, and any map points found for them, only in your browser’s storage on that device. They never go into the Sync document, the connection record, usage statistics or any page URL of DexPal’s. Apart from the optional map points below, they leave your device only when you ask for directions to one: picking a map app under Directions, such as Google Maps or Apple Maps, opens that app with the address, or its map point, as the destination, so that app alone receives it. Each device you import on keeps its own.
- Map points (optional): The route planner needs a map point, not an address. Only if you tick that option when reviewing an import does DexPal’s server send each imported address to Photon, an OpenStreetMap search service run by komoot, and return only the map point to your device. Photon receives the address and the centre of the conference city, never your IP address. DexPal’s server does not store or log the address.
- How long: DexPal keeps the connection record, your Google account ID and the list of imported events until you disconnect, and at the latest until 30 days after the guide’s last conference week ends. At that point it deletes them, deletes the DexPal Side Events calendar from your Google account, and removes its access.
- Deleting it: Disconnect Google Calendar in the guide to delete these records and remove DexPal’s access to your Google account at once, for every device that shares your schedule. You can also remove DexPal’s access at myaccount.google.com/permissions; the records can then no longer be used, and are deleted when you disconnect or 30 days after the last conference week, whichever comes first. Disconnecting also deletes the DexPal Side Events calendar from your Google account. If you remove DexPal’s access at Google instead, DexPal can no longer delete that calendar, so it stays until you delete it in Google Calendar.
- Limited Use: DexPal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. DexPal never sells this data, never uses it for advertising, and shares it with no one except as this section describes. The guide’s usage statistics (Vercel Web Analytics) never include anything read from your Google Calendar.
9. Investor data room (investors.dexpal.io)
- Scope: This section covers DexPal’s investor data room at investors.dexpal.io, operated by DP Analytiques Inc., and applies to everyone who visits it. The Investor Docs and the Investor Deck are behind an email link: you enter your email, DexPal emails you a one-time link, and using that link lets you in.
- What DexPal records: Each time you ask for a link, DexPal stores one record in its database: the email address you entered, when you asked, when the link expires (30 minutes later), the page of the data room you were trying to reach, if any, so the link can take you there, and, once you use the link, when you used it. DexPal does not store the link itself, only a one-way fingerprint of it that lets DexPal check the link when you use it.
- Why: DexPal uses these records to send you the link and to know who asked for and who opened the data room. Nothing else uses them.
- The email: DexPal sends the link through Mailgun, an email delivery service. Mailgun receives your email address and the message, which contains your link, and handles them under its own privacy policy. DexPal limits how many emails it sends to one address in each hour; to count them, it keeps a counter under your address that deletes itself an hour after the last link asked for it. When a send fails or is held back, DexPal’s logs record only the first letter of your address and its domain.
- Your IP address: The data room is hosted on Vercel, and DexPal’s API, database and counters run on Railway. Like any web host, Vercel receives your IP address with every page you load and handles it under its own privacy policy. When you ask for a link or use one, the data room also passes your IP address to DexPal’s API, which uses it only to limit how often that can happen from one IP address: 10 link requests and 30 attempts to open a link every 10 minutes. The API holds it only in a counter that deletes itself 10 minutes after your last request, and does not store it with your email.
- Small web trackers (also known as cookies): Using your link adds two of them for investors.dexpal.io to your browser. dxi_access holds your email address and the date it expires, signed by DexPal so it cannot be changed or forged. It lets you come back for 90 days without asking for a new link. Your browser does not let the page’s scripts read it (it is HttpOnly), and the data room reads it only to check that it is valid. dxi_welcome holds nothing but the value 1, lasts at most 2 minutes, and exists only so the notice about the tracker shows once; the page deletes it when it shows the notice. The data room sets no other cookies and keeps nothing else in your browser’s storage. To remove them, clear the cookies for investors.dexpal.io in your browser; you will then need a new link to get back in.
- No analytics: The data room runs no analytics service. The deck notes which slides you view, for how long, the page you came from and your window size, but only in your browser’s memory while the deck is open: it sends this nowhere, and it is gone when you leave the deck. The only thing the data room loads from another company is the demo video on its Demo and links page, and only when you press play: the video then plays from YouTube (youtube-nocookie.com), which can then keep its own data in your browser under YouTube’s own privacy policy.
- How long: DexPal keeps these records while the data room is in use, and deletes yours when you ask at info@dexpal.io.
- No sale, no advertising: DexPal never sells these records, never uses them for advertising, and does not use your email for marketing.
10. Your Rights
- You may request data deletion where applicable.
- You can opt out of marketing communications at any time.
11. Updates to this Policy
We may update this Privacy Policy periodically. Continued use of DexPal after changes constitutes acceptance.
12. Contact Us
For any privacy-related inquiries, contact us at info@dexpal.io.
