Skip to main content
bitgo
PlatformControl modelTechnical overviewDownloads
Language
01Platform02Control model03Technical overview04Downloads
Language
Back to homepageData protection

Privacy Policy

This Policy explains how personal data connected with the public website presented under the bitgo brand and related communications may be handled, including rights available in the EEA, the United Kingdom, Switzerland and other jurisdictions.

Effective and last updated: August 24, 2026
Privacy contact
privacy@bitgowallet.com
Scope
Public website and inquiries
Brand
bitgo
On this page
Who we areScope and important exclusionsPersonal data we may handleSources of personal dataPurposes and legal basesWhen data is requiredCookies and device storageRecipients and disclosuresSale, sharing and targeted advertisingInternational transfersRetentionSecurityEEA, UK and Swiss rightsComplaints and supervisory authoritiesRights in other jurisdictionsCanada and other jurisdictionsAutomated decisions and profilingBlockchain data and sensitive informationChildrenHow to exercise a rightPolicy changes and regulatory referencesContact

This document covers the public website only. Binding agreements, provider notices and mandatory local law may apply separately and control where they conflict. bitgo is the public-facing brand; no legal, licensing, regulatory, asset-safeguarding or financial-service status should be inferred from this website.

01

Who we are

The website is presented under the bitgo brand. The legal entity that determines why and how personal data is processed must be identified in the applicable corporate, contractual or privacy notice. If that identity is not shown for your interaction, request it from legal@bitgowallet.com; privacy questions and rights requests may be sent to privacy@bitgowallet.com.

Controller identity can differ for a separately contracted product, employment process, event, provider integration or regional activity. The notice and agreement presented in that context identify the responsible entity and take priority for that processing; brand presentation alone does not establish controller status.

02

Scope and important exclusions

This Policy covers visits to https://bitgowallet.com, cookie choices, direct website inquiries and related business communications. It does not by itself govern authenticated products, client onboarding, wallets, transactions, APIs, employment applications, provider platforms or services delivered under a separate privacy notice.

Public blockchains operate independently of this website. Data written to a public network may be visible globally and may not be capable of alteration or deletion by us.

The contact form does not submit data to a website server. It prepares a draft locally; we receive the content only if you send it through your email provider.

03

Personal data we may handle

The data involved depends on how you interact with the site. We seek to collect only what is relevant to the stated purpose.

CategoryExamplesTypical source
Identity and contactName, business email, organization, country or regionYou or your organization
Inquiry and relationshipRequest type, subject, message, prospective or existing relationshipYou
Technical and usageIP address, browser, device, referral URL, timestamps, requested pageHosting, security and network logs
Preference and consentLanguage, cookie and motion settings, policy version, save and expiry datesYour browser choices
Security and complianceFraud indicators, abuse reports, sanctions or legal-request records where applicableYou, systems, advisers or authorities
Public or blockchain dataPublic address or transaction reference you voluntarily includeYou or public networks
04

Sources of personal data

We may obtain personal data directly from you; from the organization you represent; automatically from browsers, hosting and security infrastructure; from authorized service providers; from public sources; and from authorities or counterparties where lawful.

If you provide another person's information, you should have authority to do so and give that person any notice required by law. Do not include client or employee data that is not necessary for the inquiry.

05

Purposes and legal bases

Where the GDPR, UK GDPR or a similar framework applies, we use the legal bases below according to the purpose. A legal basis may change if the context changes, but we will not use data for an incompatible purpose without an appropriate basis and notice.

PurposeData involvedTypical legal basis
Respond to inquiries and evaluate a requested business relationshipContact, organization and inquiry dataSteps at your request before a contract; legitimate interests in business communication
Provide client support or route a requestContact, relationship and message dataContract performance; legitimate interests in service administration
Protect the website and investigate abuseTechnical, usage and security dataLegitimate interests in security, fraud prevention and resilience; legal obligations
Meet legal, regulatory and rights-request obligationsIdentity, request, compliance and audit dataLegal obligation; public interest where applicable
Remember accessibility and privacy choicesPreference and consent recordsRequested service; legal obligation; legitimate interests in demonstrating choices
Optional analytics or marketingIdentifiers and usage data listed in the Cookie PolicyConsent where required; otherwise another basis only where law permits

Our legitimate interests are balanced against your rights and expectations. You may ask for information about that assessment or object where applicable.

06

When data is required

Fields marked required are needed to prepare a coherent request and route it to the correct team. You do not have to send the prepared email, but without contact details and enough context we may be unable to respond.

A product provider may request additional identity, compliance or contractual information under a separate onboarding notice. Do not send that material through this public contact experience unless an authorized secure channel asks for it.

07

Cookies and device storage

This site stores your selected language, cookie and motion preferences in browser local storage. Optional analytics, functional and marketing categories are disabled by default and no optional provider is enabled in this build.

The Cookie Policy lists each current key, purpose and duration and explains how to withdraw a choice.

Read the Cookie PolicyOpen contact options
08

Recipients and disclosures

If personal data is processed, the responsible operator should disclose it only where relevant to a legitimate purpose and subject to appropriate safeguards. Depending on the actual interaction, potential recipients may include:

  • The entity responsible for the interaction and any documented affiliate involved in the product or region you ask about.
  • Hosting, network, security, communications, customer-support and professional-service providers selected for the interaction and acting under contract.
  • Auditors, insurers, banks, lawyers and other advisers subject to professional or contractual duties.
  • Authorities, courts or counterparties when disclosure is required by law or reasonably necessary to protect rights and safety.
  • A successor or transaction participant in a merger, financing, reorganization or sale, subject to confidentiality and lawful-use restrictions.
09

Sale, sharing and targeted advertising

This website build does not sell personal data for money, share personal data for cross-context behavioral advertising, or use sensitive personal data to infer characteristics. It also does not enable optional advertising technology.

If those practices change, we will update this Policy and provide any required notice, opt-out link and recognition of browser-based opt-out preference signals before the change applies.

10

International transfers

The website operator and relevant providers may process personal data in countries outside the country where you are located. Those countries may not offer equivalent statutory protections, so the required transfer mechanism must be assessed for the relevant origin, destination and recipient.

Where a restricted transfer occurs, the responsible operator must select and document a lawful mechanism. Depending on the transfer, that may include an adequacy decision, European Commission Standard Contractual Clauses, the UK Addendum or another approved mechanism, together with any supplementary measures required by the risk assessment. You may request information about the applicable safeguard at privacy@bitgowallet.com.

European Commission international transfersRequest transfer information
11

Retention

The responsible operator should keep personal data only for the shortest period reasonably necessary for its purpose, then delete or anonymize it unless law, a litigation hold, security needs or a binding agreement requires longer. The website itself uses the periods below; records created after an email is sent require an operator-approved schedule.

RecordGeneral period or criterion
Cookie preference record180 days in your browser, then renewed or deleted
Language and motion preferencesUntil you change them or clear browser site data
General business inquiryUntil routed and resolved, then under the operator's documented communications schedule
Website security and diagnostic logsThe shortest period required by the active hosting and security configuration; extended only for a documented incident, claim or security need
Privacy requests, objections and legal noticesFor the period needed to complete the request and demonstrate compliance under applicable limitation periods
Contract or separately provided service recordsUnder the applicable service retention schedule and legal obligations

Before launch, the operator must confirm these criteria against the actual hosting, email, ticketing, backup and legal-hold systems. A longer period should apply only where a documented legal, security or contractual reason requires it.

12

Security

The responsible operator should select risk-based administrative, technical and organizational measures appropriate to the data and systems in use. Actual measures, such as access controls, encryption in transit, logging, vendor review, resilience practices and incident procedures, must be confirmed for the deployed environment.

No internet transmission or system is perfectly secure. Do not send private keys, seed phrases, passwords, authentication codes, API secrets or unnecessary identity documents. Report a suspected vulnerability or impersonation to security@bitgowallet.com, without exploiting or accessing data beyond what is necessary to demonstrate the issue.

Email the security team
13

EEA, UK and Swiss rights

Subject to conditions and exceptions in applicable law, you may exercise the following rights. We will explain any lawful refusal or restriction.

  • Access personal data and receive information about its processing.
  • Correct inaccurate data and complete incomplete data.
  • Request deletion or restriction in qualifying circumstances.
  • Receive data you provided in a portable format where processing is automated and based on consent or contract.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Withdraw consent prospectively without affecting earlier lawful processing.
  • Not be subject to a solely automated decision with legal or similarly significant effects, where that right applies.
14

Complaints and supervisory authorities

Please contact privacy@bitgowallet.com first if you believe personal data has been handled incorrectly so we can investigate. You also have the right to complain to the data-protection authority where you live, work or believe an infringement occurred.

UK visitors may contact the Information Commissioner's Office. EEA visitors can identify their national authority through the European Data Protection Board. Contacting us does not limit your right to approach an authority or court.

European supervisory authoritiesUK Information Commissioner's Office
15

Rights in other jurisdictions

Depending on the law applicable to the processing, you may have rights to know about or access personal data, correct it, delete it, receive a portable copy, object to or restrict processing, withdraw consent, or opt out of certain sale, sharing or targeted-advertising activities. Applicable law may also protect you against discriminatory treatment for exercising a right.

You or an authorized representative may submit a request to privacy@bitgowallet.com. We may verify identity, authority and relevant location proportionately to the request. This website currently declares no sale, cross-context sharing or targeted-advertising activity; a legally binding browser preference signal will be addressed if an activity subject to such a signal is introduced.

  • Requests are evaluated under the law that applies to the requester and processing.
  • Certain data and uses are exempt, including where needed for security, legal compliance or a transaction you requested.
  • Where available, appeal instructions will be included if a request is denied.
OECD Privacy Guidelines
16

Canada and other jurisdictions

Where Canadian private-sector privacy law applies, we follow accountability, identified purposes, meaningful consent, limiting collection and use, accuracy, safeguards, openness and individual-access principles. You may challenge compliance through privacy@bitgowallet.com and, where appropriate, the relevant privacy commissioner.

Visitors in other jurisdictions may have comparable access, correction, deletion, objection, consent or complaint rights. We will assess a request under the law that applies rather than requiring you to name a statute.

Canada PIPEDA fair information principles
17

Automated decisions and profiling

This public website does not make decisions based solely on automated processing that produce legal or similarly significant effects. It does not use website behavior to determine eligibility for a separately contracted product or service.

A product onboarding or risk process may use automation under a separate notice, with the information and safeguards required for that context.

18

Blockchain data and sensitive information

Public blockchain addresses and transaction data can sometimes be linked to an individual and treated as personal data. Public networks are replicated across independent participants, and we generally cannot alter or erase data written to them.

Do not include private keys, recovery phrases, passwords, government identifiers, financial-account credentials, special-category data or information about another person unless specifically requested through an authorized secure channel.

A private key or recovery phrase should never be shared with us. Anyone who obtains it may be able to control the associated assets.

19

Children

The public website is intended for business and professional audiences and is not directed to children. We do not knowingly collect website inquiry data from anyone under 18.

If you believe a child submitted personal data, contact privacy@bitgowallet.com. We will investigate and delete it where required, subject to any legal duty to preserve a limited record.

20

How to exercise a right

Send a request to privacy@bitgowallet.com or select Privacy request on the Contact page. Describe the right and the relevant interaction. Do not send identity documents with the initial request. If verification is necessary, we will provide a proportionate and secure method.

We aim to respond within the period required by applicable law. Complex or numerous requests may allow an extension with notice. We ordinarily do not charge a fee, but may do so or refuse where a request is manifestly unfounded, excessive or repetitive and the law permits.

Prepare a privacy requestEmail the privacy team
21

Policy changes and regulatory references

We may update this Policy when processing, services, providers or law changes. The effective date will be revised, and material changes will receive additional notice or consent where required. Earlier versions should be retained for governance purposes.

The official materials below informed this international structure. Their inclusion does not mean every law applies to every processing activity.

EU General Data Protection RegulationEuropean Commission transfer safeguardsOECD Privacy GuidelinesCookie Policy
22

Contact

Privacy inquiries and rights requests: privacy@bitgowallet.com. Security reports: security@bitgowallet.com. Legal questions: legal@bitgowallet.com. Registered-office details are available from legal@bitgowallet.com. Request and verify current registered-office details and the permitted delivery method before sending formal correspondence.

If another entity is identified in a product notice or agreement, direct requests about that product to the contact stated there so they reach the correct controller.

Privacy emailContact directory
Back to top
bitgo

Policy-driven infrastructure for confident digital asset operations.

Control digital assets with confidence.bitgo public website

Products

Wallet operationsPolicies & approvalsTransaction workflowsIntegrations

Solutions

Asset managersExchangesProtocolsEnterprise treasury

Resources

DownloadsSecurityContactTechnical overview

Legal

Privacy PolicyTerms & ConditionsCookie Policy
hello@bitgowallet.combitgowallet.com — online servicebitgowallet.com

Digital assets involve risk and may fluctuate in value. Product availability and client eligibility vary by jurisdiction. Nothing on this website constitutes legal, tax or investment advice.

© 2026 bitgo. All rights reserved.Safe by design. Ready to move.