AllSwap processes information needed to complete swaps and protect its website. This includes assets, networks, amounts, the generated deposit address, the destination and optional refund addresses entered by the user, as well as IP addresses, User-Agent data, and access times. Swap requests and order-status records are retained for up to 12 months. The standard consumer flow does not collect private keys, seed phrases, KYC documents, or bank card details, but transactions recorded on a public blockchain are permanent and cannot be deleted.
What information does AllSwap process?
The information should be considered according to the context in which it is produced. It is not all equivalent to verified identity data.
| Context | Information that may be processed | Main purpose |
|---|---|---|
| Creating and executing a swap | Source and destination assets, source and destination chains, amount, slippage preference, the deposit address generated for the order, the destination receiving address entered by the user, and an optional refund address | Generate a quote and order, complete settlement, display status, and handle a failure or refund |
| Visiting the website | IP address, User-Agent data—the basic browser and device information sent to a website—and access time | Website security, rate limiting, troubleshooting, and service operation |
| Cookies and basic analytics | Necessary cookies for language, theme, and time zone; security cookies used for CSRF protection and rate limiting; limited anonymous page-view counts | Save basic preferences, prevent forged requests or abuse, and understand page usage |
| Contacting support voluntarily | The order ID, transaction hash, contact details, explanation, and redacted evidence supplied by the user | Verify an order and investigate a dispute, missing payment, or refund request |
According to the [AllSwap Privacy Policy][privacy], its analytics are limited to anonymous page-view counting and it does not use third-party advertising trackers. A cookie is a small piece of data stored by a browser or sent with a request. CSRF protection helps prevent another party from misusing the browser to submit a request, while rate limiting controls abnormally frequent traffic. Blocking every necessary or security cookie may affect saved preferences, security checks, or normal use of the website.
Support is different from automated order creation. AllSwap receives contact details, chat content, or evidence selected by the user only when that user voluntarily asks for help. Before submitting a screenshot, hide unrelated balances, email addresses, phone numbers, and other orders. For payment verification, the most useful initial details are usually the order ID, source-chain transaction hash or TxID, deposit address, asset, amount, and time. Never send a private key, seed phrase, wallet password, or one-time password to anyone claiming to be support.
Which sensitive details are not collected during a normal swap?
AllSwap's current standard consumer flow has no identity-based account or KYC upload form. The ordinary order process therefore does not collect:
- private keys, seed phrases, wallet passwords, or other credentials that control and can move assets;
- identity documents, selfies, facial scans, or other biometric information;
- bank card numbers, bank accounts, or fiat payment-account details; or
- legal names, identity document numbers, residential addresses, or phone numbers.
Not collecting KYC documents does not make a swap completely anonymous. A wallet address usually does not display a natural person's name, but a third party may still attribute it to someone if it has interacted with an identity-verified exchange, a publicly identified address, or other traceable on-chain activity. Using a dedicated receiving address can reduce direct address reuse between different activities, but it cannot guarantee that a user is unidentifiable. It also does not remove on-chain compliance screening or the user's legal obligations. See the [AllSwap no-KYC swap explanation][no-kyc] for the boundaries of its account-free model.
Does AllSwap associate an IP address with a wallet address?
AllSwap states that it does not proactively establish an association between IP addresses and wallet addresses. This should be understood as a stated data-processing principle, not as a guarantee that the fields could never be technically correlated. The service may process an IP address and User-Agent when someone visits the website, while order creation necessarily involves processing deposit and receiving addresses. Public information does not explain in enough detail whether or how those fields are related in the actual database, or how long separate access logs are retained.
The accurate privacy conclusion is therefore narrower: AllSwap does not require an identity-based account and says that it does not proactively use IP-to-wallet links to build identity profiles. Users should not infer that their visit leaves no technical record, that wallet activity cannot be traced, or that all technical metadata is completely isolated from an order. A personal risk assessment should consider three distinct layers: the browser visit, the payment tool, and the public blockchain record. Users should also check the latest version of the [AllSwap Privacy Policy][privacy].
How long are swap records retained, and what cannot be deleted?
AllSwap's consumer privacy disclosure says that swap requests and order-status records are retained for up to 12 months for support verification, dispute handling, and legal compliance. After the applicable period, they are periodically destroyed or de-identified. The 12-month period must not automatically be applied to every access log, cookie, or document voluntarily sent to support because specific retention periods for all of those categories have not been published. This explanation also does not mix the separate data rules for API customers into the consumer order flow.
AllSwap's internal records must be distinguished from a blockchain ledger. Once a deposit address, receiving address, asset, amount, time, or transaction hash is included in an on-chain transaction, the relevant blockchain records it publicly and persistently. AllSwap can review a data request for information within its control, but it cannot rewrite or erase blockchain history. It also cannot force block explorers or other nodes that have synchronized the ledger to remove a transaction.
How can I request access, correction, or deletion?
Users may email [email protected] to request access, correction, deletion, an objection to processing, or data portability. The scope of a request is subject to Hong Kong's Personal Data (Privacy) Ordinance (PDPO), the GDPR where applicable, legal and dispute-resolution obligations, and technical feasibility. A deletion request does not mean every record must or can be removed immediately; public on-chain records are specifically outside AllSwap's ability to delete.
To avoid disclosing more information than necessary:
- Type
allswap.ioyourself and verify the privacy policy and official email address. Do not submit personal data through an unsolicited direct message, shortened link, or search advertisement. - Provide only the order ID, TxID, address, and explanation needed to identify the request. Redact unrelated information in screenshots.
- Specify which category of data you want to access, correct, or delete instead of sending an entire wallet history, exchange account, or complete transaction record.
- Keep the email and request reference. For an on-chain transaction, expect AllSwap to review copies within its control while the public blockchain entry continues to exist.
In short, AllSwap's account-free flow reduces the collection of identity documents and traditional account data, but it does not make a swap a data-free activity. Before paying, read the current privacy policy, never disclose any credential that controls assets, and treat network metadata, AllSwap's order records, and public blockchain history as three separate data layers.
Related help
- [Read the complete AllSwap Privacy Policy][privacy]
- [Understand AllSwap's account-free, no-KYC swap model][no-kyc]
- [Review AllSwap's eligibility and terms of service][terms]
[privacy]: https://allswap.io/privacy [no-kyc]: https://allswap.io/no-kyc-crypto-swap [terms]: https://allswap.io/terms

