Privacy Policy
Effective date: 04 May 2026 · OIT Coin
OIT Coin (“OIT Coin”, “we”, “our”, or “us”) operates a private membership investment platform. Protecting your personal data is fundamental to the trust our members place in us. This Privacy Policy explains what data we collect, why we collect it, how we use it, and the rights you have over it. It is written to align with internationally recognised data-protection standards including the EU GDPR principles of lawfulness, fairness, transparency, data minimisation, and purpose limitation.
1. Who we are
OIT Coin is the data controller for the personal information described in this policy. For all privacy-related enquiries, contact us via the secure form on the Contact page.
2. What information we collect
2.1 Information you provide
- Membership applications: full name, phone number, email (optional), city (optional), referral source (optional), and your free-text message.
- Contact form submissions: name, phone or email, subject, message body.
- Member portal: a securely hashed password (we never store your raw password), and any profile updates you make.
2.2 Information collected automatically
- Session cookies required to keep you logged in to the member portal or admin dashboard. These are first-party cookies, HTTP-only, and not used for advertising or cross-site tracking.
- Basic operational logs (timestamps, request paths, error reports) used to keep the service running and to investigate security incidents.
We do not use third-party advertising trackers, social media pixels, or behavioural profiling cookies on this site.
3. Why we use your information (legal bases)
- Performance of a contract: to evaluate your membership application, create and operate your member account, record OIT Coin allocations, and provide portal access.
- Legitimate interests: to maintain the security and integrity of the platform, prevent fraud and abuse, and improve the service.
- Consent: for any optional communications you opt into. You can withdraw consent at any time.
- Legal obligation: where we are required by applicable law to retain or disclose certain information.
4. How long we keep your information
We keep personal data only for as long as necessary for the purposes it was collected. Membership records are retained for the duration of your membership and for a reasonable period afterwards to comply with financial recordkeeping and dispute-resolution obligations. Contact messages are retained for up to 24 months and then deleted unless they are part of an ongoing matter.
5. Who we share information with
We do not sell your personal data. We share information only with:
- Authorised OIT Coin personnel who need it to operate the service (currently the CEO / Super Admin).
- Trusted infrastructure providers (hosting, database, transactional notifications) that process data on our instructions under appropriate data-protection terms.
- Authorities where we are legally required to disclose information.
6. International transfers
Our infrastructure providers may store and process data in jurisdictions outside Myanmar. Where this happens, we rely on providers that maintain internationally recognised security and privacy controls.
7. Security
We protect your data with industry-standard measures: TLS encryption in transit, password hashing with bcrypt, role-based access control, and the principle of least privilege for administrative access. No system is perfectly secure, but we take this responsibility seriously.
8. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data, subject to retention obligations;
- object to or restrict certain processing; and
- withdraw consent where processing is based on consent.
To exercise any of these rights, contact us through the Contact page. We will respond within a reasonable timeframe.
9. Children
OIT Coin is not directed at children. Membership requires applicants to be of legal age in their jurisdiction. We do not knowingly collect data from minors.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to members through the portal or via email where available. The effective date at the top of this page indicates the most recent revision.
11. Contact
For any privacy-related question, please write to us via the Contact page on this site. We aim to respond within seven business days.