We want to inform our customers of a change to our data-handling practices in connection with the security incident disclosed on July 30, 2026.

As many of you know, our standard practice has been to automatically blank customer records after 120 days, retaining only email addresses and country of residence. We have also offered customers the option to request accelerated blanking at any time after delivery.

Due to legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings, we have temporarily suspended our automated data-blanking process. This means that customer records that would otherwise have been blanked under our standard schedule will be retained until further notice. However, if you would like us to apply our existing retention policies to your data, we will exempt them from this protocol. Please confirm that you do not want us to preserve your data by contacting support@coinkite.com.

We understand that this is a departure from our published practices and that our customers value the privacy protections we have committed to. We want to be transparent about why this change has been made. We are required by law to preserve records that may be relevant to legal proceedings. This obligation applies regardless of our internal data-retention policies and overrides our standard deletion schedule.

During this period, all retained customer data will be stored securely and access will be restricted to authorized personnel. Retained data will not be used for any purpose other than compliance with legal obligations. We will resume our standard data-blanking practices as soon as we are legally permitted to do so.

If you have questions about this change, please contact support@coinkite.com.