Skip to main content

Legal document

Privacy Policy

Last updated: Version 3.1.0

Coinbox Ltd (company no. 517137105)

The terms set out below present the main points of the privacy policy of Coinbox Ltd (hereinafter: "the Company" or "Coinbox"), which operates a website at https://www.coinbox.co.il and a trading platform for digital currencies (hereinafter: "the Site" or "the Services"). As a financial services provider supervised by the Capital Market, Insurance and Savings Authority, Coinbox is committed to high standards of information security and compliance with the law. The purpose of this policy is to set out the manner in which Coinbox, as the controller of the information, collects and uses information provided to it or collected by it in the course of the user's browsing and use of the Services.

By using the Site and the Services offered on it, you give your express consent to the Company's use of information about you as set out in this privacy policy. This privacy policy is to be regarded as an integral part of the Site's terms of use https://www.coinbox.co.il/en/legal/terms (hereinafter: "the Terms of Use"), and the two documents should therefore be read together. Unless the context requires otherwise, terms defined in the Terms of Use and not defined differently in this policy apply as they are for the purposes of this privacy policy as well. The masculine form is used in this document for convenience only, and it addresses and refers to all genders equally; anything stated in the singular also refers to the plural, and vice versa.

1. What information will be collected about you when you use the Site?

In the course of your use of the Site and the Services, the following data may be collected about you (together: "the Data" or "the Information"), depending on the manner and the extent of the uses you make of the Site or through it:

  1. Identification and contact details: full name, ID number, date of birth, marital status, gender, residential address, email address and telephone numbers. These details are required for unique identification and in order to meet the regulatory requirements for opening an account.

  2. Financial information and activity data: data about your financial position, in order to meet identification, know-your-customer and anti-money-laundering obligations, including declarations of sources of income and wealth. This information includes details of the operations carried out in your account (purchase, sale, conversion and transfer of digital currencies), balances and the history of your financial activity on the platform.

  3. Payment details: bank account details; credit card details, which are processed solely through an external and insured acquirer certified to the PCI-DSS standard; and the history of payments, deposits and withdrawals of funds.

  4. Technical information and usage data: when you use the Site and/or the trading platform, technical data is collected automatically, including the IP address, the device type, the operating system, unique device identifiers, location data (subject to specific permission), actions carried out on the Site or on the trading platform, pages viewed and the time spent on them, and the like.

  5. Records of communications: recordings of telephone calls with the Company's representatives, email correspondence, chat messages and enquiries made through digital "contact us" forms or through any other means of communication with the Company.

As a rule, you are not obliged to provide your personal information to the Company's databases, and providing it is a matter of your own will and consent. However, for opening an account and carrying out financial transactions there is a legal and regulatory obligation to provide identifying details and financial data. This obligation arises, among other things, from the Prohibition on Money Laundering Law, 5760-2000, from the Prohibition on Money Laundering Order applying to financial services providers, and from the directives of the Capital Market Authority, which require the Company to carry out identification and know-your-customer procedures and to record certain details as a condition for providing the service.

In all other cases, where there is no express legal obligation, the information is required in order to perform the contractual engagement and to supply the Services properly. In those cases, although providing the information depends on your consent, failure to provide the details, in whole or in part, may limit the manner or the scope of the Services supplied to you, or may prevent the Company from opening an account for you, from carrying out transactions, or from providing you with the requested service, in whole or in part. Your use of the Site and the Services and your provision of the details constitute consent to the use of the information for the purposes set out in this policy, both where the law requires it and where the information is needed for operational and business purposes.

2. What uses will be made of the information about you?

The information will be used solely in accordance with this privacy policy or under the provisions of any law, and for the purposes set out below:

  1. Providing digital-currency trading services and day-to-day operation: so that you can use the Site and the trading platform, including the receipt and execution of purchase, sale, conversion and storage operations for digital currencies, the management of balances, the making of deposits and withdrawals of funds, and the ongoing running of your account.

  2. Managing your personal account (the personal area) and tailoring the service: in order to present a full picture of your personal account, to analyse your activity patterns and to tailor the Services to your needs.

  3. Operational and service communications: sending essential messages and alerts in connection with the Services (SMS, WhatsApp or email), such as updates on the status of transactions, alerts about account balances, and changes to the Terms of Use.

  4. Marketing and personalised offers: in order to approach you and offer you new products or services of the Company, all subject to the provisions of the law regarding direct mailing and only after your express consent has been obtained. This information may also be used for segmentation (profiling) and marketing targeting.

  5. Targeted advertising and campaign optimisation: use of contact details (such as an email address) and basic activity data (such as the fact that a registration was made, that a verification process was completed, or that an initial deposit was made) in order to create "Custom Audiences" and in order to make advertising campaigns on third-party platforms (such as Google, Meta, X) more efficient and better optimised. To protect your privacy, contact data is transferred only after a one-way hashing process (Hashing), with the information transferred reduced to the necessary minimum and without disclosing exact deposit amounts.

  6. Service improvement and business development: in order to analyse the use of the Site and the trading platform, produce insights, improve the user experience, develop new services and streamline internal work processes.

  7. Regulatory compliance and risk management: in order to fulfil the legal and regulatory obligations that apply to a financial services provider, including the directives of the Capital Market Authority, risk management, anti-money-laundering and counter-terrorism-financing procedures, and reporting to the competent authorities to the extent required by law.

  8. Information security and fraud prevention: in order to protect the sensitive information held in the Company's systems, to detect and prevent unauthorised access, and to prevent financial fraud, money laundering or misuse of the Services.

  9. Statistical analysis: carrying out anonymous analyses and market segmentation (aggregation) that do not identify you personally, for the purpose of improving the Company's activity and for internal research.

  10. Legal defence: in order to protect the rights, interests and assets of the Company, to defend against legal claims, and to enforce the Terms of Use.

The legal basis for processing the information, by main purpose:

3. Will information be disclosed to third parties, and on what terms?

Keeping your information confidential and protecting your privacy are important to us, and we undertake not to trade in personal information about you and not to transfer it to third parties, other than to the parties listed below and for the following purposes only:

  1. Service providers in the field of digital currencies: transfer of the required information to digital-currency exchanges, liquidity providers, custody and clearing service providers, banks and financial institutions. This transfer is necessary in order to carry out your transactions, clear deals and manage deposits and withdrawals of funds. It is clarified that these entities may act as the controllers of independent databases, and their use of the information is subject to their own privacy policies and their own responsibility.

  2. Identification, verification and payment service providers: transfer of information to service providers that assist in identifying and verifying customers and in clearing payments, in accordance with the requirements of the law and in order to carry out transactions you have requested. Sumsub (identity verification/KYC), the Population Authority interface for checking ID numbers, and the credit card companies (Cal, Max and Isracard).

  3. Service providers and data processors: to third parties that provide the Company with services in connection with the Site, the platform and its day-to-day activity, including cloud services, CRM systems, information security, mailing and backup services, and also legal advisers, accountants and external call-centre services. Such a transfer will be made under appropriate confidentiality undertakings.

  4. Business partners and licensed marketers: the Company may disclose basic identifying details regarding the opening of your account or your receipt of the service to third parties defined as licensed marketers who were involved in referring you to the Company, for the purpose of calculating, paying and recording commissions in accordance with the commercial agreements with the Company.

  5. Advertising platforms and social networks: we may share information (such as technical identifiers, hashed email addresses and indications that conversion events took place) with advertising partners (such as Google, Meta, X). This sharing is carried out securely (for example through the Conversions API) and is intended for measuring the effectiveness of advertising, for optimisation and for displaying relevant ads. This information may be processed on the servers of those companies outside Israel (including in the United States), and it is subject to their privacy policies and to the data processing agreements (DPAs) that the Company has signed with them.

  6. With your consent or at your request: any information disclosed in accordance with your express consent, or as part of a process you asked to initiate.

  7. Court order and regulatory demand: if the Company receives a court order or a demand from a competent authority, such as the Capital Market, Insurance and Savings Authority, the Israel Money Laundering and Terror Financing Prohibition Authority, the Israel Police or any other authority empowered by law, directing it to disclose the information.

  8. Legal proceedings: in any dispute, allegation, claim, demand or legal proceedings, if any, between you and the Company or anyone on its behalf.

  9. Security and fraud prevention: in order to safeguard and protect the rights, assets and property of the Company or of third parties, and in order to prevent financial fraud or misuse of the Services.

  10. Structural change: in any case in which the Company sells, assigns or transfers its activity (in whole or in part) to a third party, or in the event of a merger, an acquisition or insolvency proceedings.

In addition to the parties listed above, the Company may transfer to third parties aggregate and statistical information that does not identify you personally, for the purposes of research, marketing and improvement of the Services.

4. Direct mailing, marketing messages and service communications

Subject to your express consent (if it is given), and in accordance with the provisions of the Communications Law (Telecommunications and Broadcasts), 5742-1982 (hereinafter: "the Communications Law") and the Protection of Privacy Law, 5741-1981 (hereinafter: "the Protection of Privacy Law"), the Company may use the contact details you provided, including your email address and your mobile telephone number, in order to send advertising material, offers of complementary products and services, information about benefits, newsletters and various updates. These approaches may be sent by email, text message (SMS), WhatsApp message, telephone call or any other digital means of communication, and they may be personalised to your characteristics (direct mailing) on the basis of the information held in the Company's databases.

A distinction must be drawn between marketing mailings and operational messages. Even if you have chosen not to receive advertising material, the Company will continue to send you the service and operational messages that are essential to the running of your account, such as updates on the status of transactions, notices of regulatory changes about which you must be informed, or confirmations that transactions were executed. These messages are sent as part of the Company's service obligation towards you and are not considered "advertising material".

You have the right to withdraw your consent to marketing approaches and direct mailing at any time. You can do so easily and free of charge by clicking the "unsubscribe" link that appears in the body of the mailing, by sending a reply message refusing further mailings, or by contacting the Company's service centre directly. Once your request is received, the Company will stop sending you advertising material, but your details will continue to be kept in the database for the purpose of managing the ongoing engagement, as stated.

5. Information collection technologies and content tailoring (Cookies)

When you use the Company's websites and applications, certain information about your activity is collected through various technological means, including cookies, tags and web beacons, and third-party tools. These technologies are used to analyse your activity, to tailor the services offered to you, to improve the user experience, for information security, for statistical measurement, and to display tailored content and advertisements on various platforms. Through these means, the information collected may include your IP address, the browser type and the operating system, the pages you viewed, the time spent on the Site, the actions carried out, unique identifiers of a device or an application, further technical information relating to the network connection, the communications provider, and the approximate geographic area.

If you are a customer of ours, we may combine that information with other information we hold, for internal analyses, for the tailoring of services and commercial offers, and for the monitoring and improvement of the service.

The analytics tools running on the Site. We operate Google Analytics 4 and Microsoft Clarity. Microsoft Clarity includes the recording of browsing sessions (Session Replay) and heat maps, which capture scrolling, clicks and movement on the page. The tool is configured on our side in strict masking mode (Strict Masking), which is intended to prevent the capture of text you have typed into fields. Both tools are subject to the consent mechanism (Google Consent Mode): as long as you have not given your consent to the analytics category, they operate without cookies and do not store persistent identifiers. You can change your choice at any time through the cookie settings on the Site, as set out in the Cookie Policy.

We do not sell personal information about you, and we do not transfer it to Data Brokers. To the extent that Apple's App Tracking Transparency programme applies, the sharing of identifiers from within the application will be carried out solely in accordance with the permissions of the operating system.

In addition, third parties such as Google and Meta (Facebook) may use cookies or similar technologies on the Company's site and applications in order to collect personal and/or statistical information regarding your activity on those sites and on other sites on the internet, in accordance with their privacy policies and terms:

Google

Meta/Facebook: cookies

You can configure how cookies are used through the settings of your browser or of your operating system, or through dedicated tools such as Ghostery, at your sole responsibility, including the full or partial blocking of cookies, their deletion, or receiving an alert before they are stored. Please note that some of the services may not be available, or may work in a limited way, if you choose to block required cookies.

For your convenience, you can also manage your cookie preferences individually for each browser using the instructions at the following links:

Google Chrome

Mozilla Firefox

Safari (macOS)

Microsoft Edge

In addition, you can opt out of Google Analytics using a dedicated browser add-on

6. Transfer of information outside the jurisdiction of the State of Israel

The Company may transfer information about you outside the borders of the State of Israel, for the purpose of providing the Services, carrying out your transactions through international providers, operating systems through affiliated companies, and for the purposes of cloud storage, system backup, information security and the management of operational processes through leading international technology providers.

The laws relating to information security and privacy protection in the destination countries may differ from the laws that apply in Israel. Nevertheless, the Company undertakes that any such transfer will be carried out in accordance with the provisions of the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001. To the extent that European law (GDPR) applies, a transfer of information outside the European Economic Area will be made under a recognised protection mechanism, such as Standard Contractual Clauses (SCCs) or an adequacy decision. The Company will take the legal and technological steps required in order to ensure that the level of protection of your information is adequate and in accordance with all applicable law. By using the Site, the platform and the Services, you give your express consent to the transfer of the information outside Israel as stated, for the purposes set out in this policy.

7. Links to external sites and third-party services

The Site and the platforms may contain links to external sites and services on the internet. Those sites are not operated by the Company, they are separately owned, and a different and separate privacy policy applies to them.

Although we aim to link only to trustworthy sites, the Company does not control and is not responsible for the privacy policies, the information security procedures or the content appearing on those external sites. Accordingly, the Company will not bear liability for any damage, direct or indirect, caused to the user as a result of providing details on those sites or of using them.

We recommend reading carefully the terms of use and the privacy policy of every external site you reach, before you provide personal details on it, since this privacy policy applies only to information collected directly by the Company.

We use the Sumsub platform in order to verify the customer's identity in the KYC process. When you continue to use the Site and approve the privacy policy, you also approve Sumsub's terms of use. You can review Sumsub's privacy centre.

8. Information security

The Company regards the security of its customers' information as a paramount value and invests significant technological and organisational resources in protecting the confidentiality and the integrity of the information. The Company applies advanced information security systems and procedures on the Site and on the platform, in accordance with accepted standards and with the requirements of the law, including the Protection of Privacy Regulations (Data Security), 5777-2017. These measures are intended to reduce the risks of unauthorised intrusion, theft of information or its corruption.

Among other things, particularly sensitive information transmitted between your device and the Company's servers is encrypted using secure protocols, and access to the databases is restricted to authorised parties only, for the purpose of providing the service.

At the same time, it is important to clarify that absolute immunity from intrusions, cyber attacks or exposure of information cannot be assured. Accordingly, the Company does not undertake that the Services will be entirely immune to unauthorised access, and it will not bear liability for any damage caused by intrusion into the information or by its theft, provided that it took reasonable and accepted security measures.

In addition, information security depends on you as well: you must keep the login password to your account confidential, must not pass it to a third party, must change it from time to time, and must report to us immediately any concern about unauthorised use of your account.

9. Data retention and deletion

The Company retains personal information only for the period required in order to fulfil the purposes for which it was collected, or for a longer period to the extent that this is required by law. The main retention periods are set out below:

At the end of the relevant retention period, the information will be deleted or anonymised, unless its retention is required for an active legal proceeding or for a further legal obligation.

10. Account deletion

You can request the deletion of your account at any time by sending a written request to privacy@coinbox.co.il. Once the request is approved and your identity is verified, your account will be closed. Information that the Company is required to retain by law (such as KYC documents and transaction data) will be kept in accordance with the retention periods set out in Section 9, and at the end of those periods it will be deleted or anonymised. The remaining personal information will be deleted or anonymised within a reasonable period from the date on which the request is approved.

11. Your rights in the information

Under Section 13 of the Protection of Privacy Law, every person is entitled to review, in person, through a representative authorised in writing for that purpose, or through a guardian, information about them held in a database. Under Section 14 of the Protection of Privacy Law, a person who has reviewed information about them and found that it is not correct, complete, clear or up to date may apply to the owner of the database with a request to correct the information. Accordingly, if you wish to review the identified information stored about you, to the extent that it is held by the Company, or to update, change or correct it, please set out precisely the content of your request to us, using the contact details listed below.

In addition, to the extent that European law (GDPR) applies to you, you may have the following rights: the right of access; the right to rectification; the right to erasure ("the right to be forgotten"), subject to regulatory data retention obligations; the right to restrict processing; the right to object to processing based on a legitimate interest; and the right to data portability (receiving a copy of the information in a structured format). To exercise your rights, contact us at privacy@coinbox.co.il. We will reply to your request within the period prescribed by law, and we may be required to verify your identity before handling the request.

12. Minors

The Services are not intended for minors under the age of 18, and the Company does not knowingly collect personal information from minors. If the Company becomes aware that a minor's information has been collected, it will act to delete it as soon as possible. If you know, or suspect, that a minor has provided personal information to the Company, please contact privacy@coinbox.co.il.

13. Changes to the privacy policy

The Company reserves the right to update, change or amend the provisions of this privacy policy from time to time, at its sole discretion, for changing business needs or following technological and regulatory changes. Any change to the policy will take effect immediately upon its publication on the Site and on the platform, and the date of the last update will appear at the top of this document. Your continued use of the Services after the date of the update will constitute your full consent to the updated privacy policy. We recommend reviewing this page from time to time.

14. Contact us

For any question regarding this privacy policy, you can contact us by the following means:

Coinbox Ltd (company no. 517137105), 20 Lincoln St., Tel Aviv, Israel

Email for privacy matters: privacy@coinbox.co.il

General email: support@coinbox.co.il

Website: coinbox.co.il

© 2026 All rights reserved to Coinbox Ltd.