Privacy Policy for Open FX Rates
Last updated: 31 Dec 2025
Introduction
Welcome to Open FX Rates' privacy policy. Open FX Rates respects your privacy and is committed to protecting your personal data. This privacy policy explains how we look after your personal data when you visit our website — openfxrates.com — and informs you of your privacy rights and how the law protects you.
Please refer to the Glossary (Section 10) to understand the meaning of some of the terms used in this privacy policy.
1. Important information and who we are
Purpose of this privacy policy
This privacy policy gives you information on how Open FX Rates collects and processes your personal data through your use of openfxrates.com, including any data you may provide when you visit, create an account, subscribe, or purchase a product or service.
This website is not intended for children, and we do not knowingly collect data relating to children.
You should read this privacy policy alongside any other privacy or fair processing notices we may provide to ensure you fully understand how and why we use your data. This policy supplements other notices and is not intended to override them.
Controller
Open FX Rates is the controller and is responsible for your personal data (referred to in this privacy policy as "Open FX Rates", "we", "us", or "our").
We have appointed a Data Privacy Manager responsible for overseeing questions related to this Privacy Policy. If you wish to exercise your legal rights or have questions, please contact us using the details below.
Contact details
- Legal entity: Open FX Rates
- Email: legal@openfxrates.com
Changes to this policy and your duty to update us
We review our privacy policy regularly.
Please keep your personal data up to date and inform us of any changes during your relationship with us.
Third-party links
openfxrates.com may include links to third-party websites, plug-ins, and applications. Clicking on these may allow third parties to collect or share your data. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.
2. The data we collect about you
We may collect, use, store, and transfer different kinds of personal data, including:
- Identity Data — first name, last name, title, username.
- Contact Data — billing address, delivery address, email address, phone numbers.
- Financial Data — bank account details, partial payment card details (if provided).
- Transaction Data — payment details, order history, product/service purchases.
- Technical Data — IP address, login data, browser information, time zone, device information, operating system, and platform.
- Profile Data — username, password, preferences, interests, feedback, survey responses.
- Usage Data — behaviour and interaction with our website.
- Marketing & Communications Data — preferences for receiving marketing from third parties or us.
We also collect aggregated data, which does not directly identify you.
We do not collect Special Categories of Personal Data (such as race, religion, health data, or political opinions) nor information relating to criminal convictions.
If you fail to provide personal data
If we require personal data by law or to fulfil a contract with you and you fail to provide it, we may be unable to deliver products or services and may need to cancel your order.
3. How your personal data is collected
We collect data through:
Direct interactions
You may provide data when you:
- Sign up for an account
- Subscribe to our services
- Request marketing
- Contact us
- Fill out forms
Automated technologies
We collect Technical Data through:
- Cookies
- Server logs
- Analytics tools
Third parties
We receive data from:
- Analytics providers (e.g., Google, AWS)
- Search providers (e.g., Google, DuckDuckGo)
- Payment processors (e.g., Stripe)
- Email and customer support platforms (e.g., SendGrid, HelpScout)
- Identity databases such as Companies House or the Electoral Register
4. How we use your personal data
We will only use your data when legally permitted, including:
- To perform a contract with you
- For legitimate interests, where your rights do not override ours
- To comply with a legal obligation
We do not rely on consent unless needed for third-party marketing.
Purposes for processing
We process your personal data for various purposes including:
- Account registration and management
- Processing and delivering orders
- Managing payments and fees
- Collecting debts
- Providing customer support
- Notifying you of changes to terms or policies
- Improving our website and services
- Measuring and understanding customer engagement
- Delivering relevant marketing communications
- Making recommendations based on your interests
- Protecting against fraud and security threats
5. Disclosures of your personal data
We may share your data with:
- Service providers (UK, EU, US)
- Professional advisers
- HMRC or other regulators
- Potential buyers or business partners during mergers and acquisitions
We require all third parties to respect and safeguard your data.
6. International transfers
Your information may be transferred to, stored, or processed in countries other than your country of residence. In such cases, we take appropriate steps to ensure that your personal data is protected in accordance with applicable data protection laws, including the use of adequacy decisions, standard contractual clauses, or other legally recognized safeguards.
7. Data security
We implement security measures to protect your data from loss, misuse, or unauthorized access. We restrict access to employees and third parties who need it and have confidentiality obligations.
We have procedures for handling suspected data breaches and will notify you and regulators where legally required.
8. Data retention
We do not retain any of your data. Once you delete your profile from the Open FX Rates dashboard, it is deleted permanently from our system.
9. Your legal rights
You have the right to:
- Access your data — Request copies of your personal data
- Correct inaccurate data — Request correction of incomplete or inaccurate information
- Request erasure — Request deletion of your personal data
- Object to processing — Object to the processing of your personal data
- Restrict processing — Request restriction of processing your personal data
- Request data transfer — Request transfer of your data to another organization
- Withdraw consent — Withdraw consent where we rely on consent to process your data
We may require identity verification before fulfilling requests.
We aim to respond within one month.
10. Glossary
Lawful Basis
Legitimate Interest means the interest of our business in conducting and managing our business to enable us to provide you with the best service/product and the most secure experience. We ensure we balance your rights and interests against our legitimate interests before we process your personal data.
Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
Legal Obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.
If you have any questions about this Privacy Policy, please contact us at legal@openfxrates.com.