Exomoni · Legal

Privacy Policy

What we collect, why we need it, who else sees it, where it lives, and how to make us erase all of it.

Effective
17 September 2026
Version
19 August 2026 — added §7's account of the Meta advertising pixel and how to opt out
Contents

The short version

We collect what is needed to pay you and to keep the books straight, and nothing to sell you things. This section is a summary; the sections below are the detail.

  • There is no KYC. We do not ask for or hold identity documents, passports, selfies or proof of address.
  • There is one advertising tracker: the Meta (Facebook) pixel. It runs on this customer site only, it reports what you do here to Meta so we can measure our advertising, and §7 tells you exactly what is sent and how to switch it off. There is no Google Analytics, no session recorder and no heat map.
  • We never sell your data. The only marketing sharing we do is the Meta pixel described in §4 and §7 — measuring our own ads. Nobody else’s.
  • Your bank details are relayed to our payout team over Telegram so your rupees can be sent. §5 explains exactly what is sent.
  • Your data is stored on servers in France (the European Union).
  • You can have everything erased — genuinely erased, not archived. §9.

Exomoni is operated by RUPEXO PRIVATE LIMITED (UEN 199700383G), a company incorporated in Singapore, with its registered office at 160 Robinson Road, #14-04, Singapore 068914. We are the controller of the personal data described here.

What we hold about you

Things you give us when you register: your name, email address and phone number. Optionally, a Telegram username and a profile picture if you upload one.

Things you add so we can pay you: Indian bank accounts — account number, IFSC and account holder name, plus a label if you set one — and TRC-20 wallet addresses you save for withdrawals.

Things created by using the platform: your deposit instructions, your orders and their status history, your withdrawals, every entry in the balance ledger that moves your money, the bank references (UTRs) for rupees paid to you, and notifications sent to you.

Things recorded for security: your sign-in sessions, each with the IP address and browser user-agent it was created from; the IP address recorded against administrative actions affecting your account; and one-time codes sent to your email, stored hashed.

If you turn on notifications for a device: the notification address your browser creates for that device — a web address issued by its push service, with two encryption keys — and the device’s browser user-agent. Nothing is collected unless you switch notifications on.

Secrets, which we cannot read: your password and your transaction PIN are stored only as one-way hashes. Nobody at Exomoni can see either, and we cannot tell you what yours is.

Blockchain data: transfers to our master wallet, including the sending address, amount, transaction hash and block time. This is public information that exists on the Tron network whether or not you use Exomoni.

What we do not hold: no identity documents of any kind, no card numbers, no rupee balance, and no location data beyond what an IP address implies.

Why we hold it

  • To run your account and pay you — the name, email, phone, bank accounts and wallet addresses exist for this and nothing else. Without them we cannot send you rupees.
  • To keep the money record correct — every balance movement is written to an append-only ledger so your balance can always be re-derived and checked. This is what makes it possible to answer “where did my money go”.
  • To keep the account secure — sessions, IP addresses and one-time codes exist to detect and limit unauthorised access, and to let you be signed out everywhere if something is wrong.
  • To meet legal obligations and to establish, exercise or defend legal claims, including a dispute about whether a payment was made.
  • To tell you what happened — order and deposit notifications, and security emails about your own account. Order and deposit notifications appear in the app, and on your phone too if you turn that on.

Where the law that applies to you frames this in terms of a legal basis: we rely on performance of our contract with you for running the account and paying you, on our legitimate interests in operating a secure and financially accurate platform, and on legal obligation where one applies. We do not rely on consent for any of it, because none of it is optional to the service — except your profile picture and Telegram username, which you may add or remove freely, and phone notifications, which reach only a device you switched them on for and stop the moment you switch them off.

We do not use your data for automated decision-making or profiling, and we do not send marketing email.

The companies that help us run this

We use a small number of third parties. Each one gets only what it needs, and none of them is permitted to use your data for its own purposes.

  • Resend — sends our email (your one-time codes, password resets, account notices). It receives your email address and the content of that email.
  • TronGrid — lets us read the Tron blockchain to confirm deposits. It receives the wallet addresses we query. It is not told who you are.
  • Your browser’s push service — delivers phone notifications, and only if you turn them on: Google (Firebase Cloud Messaging) for Chrome and the Exomoni Android app, Mozilla for Firefox, Apple for Safari. Each message is encrypted on our server for your device, so the push service carries it without being able to read it; it sees the device address and when a message was sent.
  • Telegram — carries operational messages to our own staff groups. See §5, because this one involves your bank details.
  • Razorpay’s public IFSC directory — when you add a bank account, our server looks up the branch for the IFSC code you typed so we can show you the bank name. Only the IFSC code is sent. It is a public branch identifier, it is not personal to you, and the request comes from our server, so your device and IP address are never exposed to them.
  • Contabo — hosts the servers the platform runs on. See §6.
  • Meta Platforms (Facebook) — measures our advertising. This is the one processor on the list that receives data for MARKETING rather than to run the service, so it is described in full in §7 and it is the one you can switch off.

We will also disclose data where we are legally required to, or where it is necessary to investigate fraud or to establish or defend a legal claim.

Your bank details and our payout team

This is worth spelling out because most privacy policies would not. Exomoni pays your rupees by hand, from our own banking. To do that, the people making the payment need your bank details, and they receive them in a private Telegram group that only authorised staff can join.

When you place an order, the following is posted into that group:

  • the order’s reference (for example GM-KCCYKD);
  • the account holder name, account number and IFSC you selected;
  • the rupee amount to send, and the bank references of payments already made.

Nothing from your account profile is sent. Not your name as registered, not your email address, not your phone number, not your balance, not what you sold or at what rate. The payout group sees a payment instruction and nothing else. This is enforced in the code by the query that builds the message, not by a staff instruction.

Telegram is an independent company and your data passes through its servers under its own privacy policy. We control who is in the group and can remove access at any time, and every action taken from it is recorded against the person who took it.

In practice

If you would rather your bank details did not travel over Telegram, the only way to avoid it is not to place an order — it is how the desk pays. We would rather tell you that than leave it out.

Where your data is stored

The platform runs on servers in France, within the European Union. Our company is registered in Singapore, and most of our customers are in India.

That means your personal data is transferred out of the country you are in and stored in the European Union. Our email, blockchain and messaging providers named in §4 may process data in other countries, including the United States.

Wherever it sits, it is protected the same way: encrypted in transit over HTTPS, access-controlled, with passwords and PINs stored only as one-way hashes and backups held encrypted.

Cookies and what runs in your browser

This site runs the Meta (Facebook) pixel. It is here so we can tell which of our advertisements bring people to Exomoni and which are wasted. It runs on this customer site only — the agent panel and the staff panel carry no tracking of any kind. There is no Google Analytics, no session recorder and no heat map.

What is sent to Meta. Two kinds of thing, and it is worth separating them:

  • What you did — that a page was viewed, that an account was created, that someone signed in, that a deposit was started or credited, that an order was placed or completed. Where an amount exists it goes too: the rupee value of an order, and the USDT amount of a deposit.
  • Who you are, in a form Meta can match but cannot read. Your email address and phone number are put through a one-way hash (SHA-256) on our server before they leave it, along with your Exomoni account ID. Meta compares those hashes to its own to see whether you are one of its users. We never send them in the clear.

Two of those events — a credited deposit and a completed order — are sent from our SERVER rather than from your browser, because they happen when you are not on the site. They carry the same hashed identifiers and nothing more.

Meta sets its own cookies through this pixel and uses what it receives under its own privacy policy, not ours, including for its own advertising purposes. That is the honest position and it is why the next paragraph exists.

How to stop it. Any of these works, and none of them affects your account, your balance or your ability to trade:

  • Turn on your browser’s tracking protection, or use an ad blocker — the pixel is a third-party script and they all block it.
  • Send a “Do Not Track” or opt-out request to info@exomoni.com and we will confirm it in writing.
  • Change your own Meta ad settings, which control what Meta does with anything it receives about you.

There is no cookie banner on this site. That is a deliberate choice by the operator, not an oversight, and we would rather say so here than pretend the question does not arise. If you would prefer not to be measured, the paragraph above is real and we will act on it.

What we set ourselves:

  • One session cookie, set when you sign in. It holds a random token, is marked HttpOnly so page scripts cannot read it, is sent only over HTTPS, and expires after seven days or when you sign out. It is strictly necessary — without it you cannot stay signed in.
  • One browser preference, exomoni-theme, kept in local storage so the site remembers whether you chose light or dark. It never leaves your device and identifies nothing.
  • A notifications helper (a service worker), installed only if you turn notifications on. It shows the notifications we send and opens the right page when you tap one. It stores nothing and caches nothing.

Signing out revokes the session on our side as well as clearing the cookie, so a copy of it cannot be reused.

How long we keep it

We keep your account data for as long as you have an account. Transaction records — deposits, orders, withdrawals and the ledger behind them — are kept while the account exists because they are the record of what happened to your money, and because we may need them to answer a question or defend a claim about a payment.

One-time codes expire within minutes and are consumed on use. Sessions expire and are revoked. Some records with a legal or accounting purpose may be kept after an account closes where the law requires it.

A device’s notification address is deleted when you switch notifications off, when the push service tells us the device no longer exists, or with your account.

We do not currently operate an automatic pruning schedule for notification records; they are removed when the account they belong to is deleted.

Your choices, and how to erase everything

You can ask us to:

  • Give you a copy of everything we hold about you. We can export your complete record — account, balances, banks, addresses, every deposit, order, bank reference, withdrawal and ledger row — as a spreadsheet file.
  • Correct anything wrong. Your name, phone and Telegram username can be changed from your profile; your email address cannot change, because it is your sign-in and your recovery route.
  • Delete your account.
  • Object to or restrict what we do with your data, and to complain to the data protection authority where you live.

Write to info@exomoni.com from the address on your account. We will respond within 30 days.

Deletion here means deletion. When an account is deleted we erase the profile, the bank accounts and wallet addresses, the deposits, orders, withdrawals, ledger rows, sessions, notifications and the audit records naming the account. We do not keep a shadow copy and we cannot restore it afterwards. Take your export first if you want one.

The one thing that survives, and why. Records of transfers that arrived on the blockchain are kept, with the link to you removed. Each blockchain transaction may only ever be credited once, and that record is what makes a second credit of the same transfer impossible. What remains is a fact about our own wallet — an amount, a hash and a time — with nothing identifying you attached.

In practice

Deleting your account is irreversible and it destroys your transaction history along with everything else. Withdraw or sell your balance first — an account with money in it or an open order cannot be deleted.

Children

The platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, write to info@exomoni.com and we will remove it.

Changes to this policy

If we change what we collect, who we share it with, or where it is stored, we will update this page and move the effective date at the top. Material changes will be notified to you in the platform or by email.

This policy should be read with the Terms and Conditions.

Who you are dealing with

Exomoni is operated by RUPEXO PRIVATE LIMITED (UEN 199700383G), a company incorporated in Singapore, with its registered office at 160 Robinson Road, #14-04, Singapore 068914.

Questions about this document go to info@exomoni.com.