We use tracking technologies for site analytics and, if you allow it, for non-personalized advertising. These are two separate choices and neither one is required to use the site.Analytics and advertising cookies are optional and separate. Privacy Policy
No eligible rate right now
This page explains what information exchange.et collects, why we collect it, how long we keep it, and the rights you have over it.
This page is available in English and Amharic.
Last updated: September 15, 2026.
Account registration: when you create an account, we collect your name, email address, and a securely hashed password. API key registration: when you register for an API key, we collect an application name, your email address, and optionally your website and use case. Analytics: we use Google Analytics 4 to understand how the site is used and to improve performance. Analytics events are tied to a per-device identifier, and our Google Analytics configuration keeps advertising storage and ad personalization disabled. Advertising is described separately below. Cookies and local storage: we set a functional `exchange_et_locale` cookie (one year) to remember your language preference, and we store a small set of keys in your browser's local storage: `exchange-et-locale` (your language preference), `et_exchange_cookie_consent` (your analytics consent choice), `et_exchange_advertising_consent` (your advertising consent choice, separate from analytics), `et_exchange_visitor_id` (a pseudo-anonymous visitor id), `et_exchange_consent_receipts` (receipts of your recorded consent decisions), and `et_prior_visit` (a prior-visit marker). Server logs: our hosting providers record standard server logs (such as IP address, request time, and user agent) to operate, secure, and troubleshoot the service. Alerts without an account: you can set a rate alert without registering. If you do, we store a random per-browser identifier (kept as `exchange-et-alert-device:v1:guest` in your browser's local storage, and on our servers only as its SHA-256 digest), the alert you set, and the browser push subscription that delivers it, which is a push service URL and two encryption keys. We do not ask for an email address on this path.
We use the information we collect to provide and maintain your account and API keys, to serve exchange-rate data, to analyse aggregate site usage so we can improve the service, and to communicate with you about your account or API keys. We do not sell your personal data.
We process personal data on the following legal bases: performance of a contract, to provide and maintain your account and API keys; legitimate interests, to secure the service, prevent abuse, and understand aggregate site usage; consent, for analytics tracking, which you may withdraw at any time; and compliance with a legal obligation where required by law.
We rely on the following processors, which receive only the data needed for their role. Google Analytics 4 (Google LLC) provides site analytics; Supabase provides the managed Postgres database that holds accounts, API keys, consent records and alert subscriptions; Netcup (Vienna, Austria) hosts the application server that runs our API and serves API requests; Vercel hosts the website and its server-rendered pages, pinned to Vercel's Frankfurt (fra1) region; Cloudflare provides DNS for exchange.et and the reverse proxy, TLS and security filtering in front of our API; Resend delivers our transactional email (account verification, password resets, plan notices and rate alerts) to the address you gave us; Sentry receives error reports from the website's front end, in Sentry's EU region, which may include your IP address and the page you were on; the browser push services (Google, Mozilla, Apple and Microsoft) deliver rate-alert notifications to your browser, and receive the notification content and the push endpoint your browser gave us; and Chapa (chapa.co) processes payments. When you purchase an API plan, Chapa receives your name, email address, the ETB payment amount, and the transaction reference (tx_ref) needed to create, complete, and reconcile the payment. We do not collect or store your card details. They are handled directly by Chapa. Data-processing agreements with each of these processors are being finalised and will be executed in line with Article 28 GDPR and Ethiopia's Personal Data Protection Proclamation No. 1321/2024.
To provide the service we rely on processors located outside Ethiopia. Netcup (application hosting, Vienna, Austria), Supabase (database hosting, Ireland), Vercel (website hosting, from its Frankfurt fra1 region) and Sentry (error monitoring, in its EU region) keep data in the European Union. Google Analytics 4 (Google LLC) and Resend, which delivers our transactional email, are based in the United States. Cloudflare provides DNS and the reverse proxy in front of our API through a global network, and is a United States company. Where personal data is transferred out of Ethiopia or the European Economic Area, the mechanism we rely on is the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Cross-border transfer authorisation under Ethiopia's Personal Data Protection Proclamation No. 1321/2024 is pending.
Account and API-key data is kept while your account or key is active and deleted when you ask us to. One-time account tokens, such as email-verification and password-reset links, are deleted after about 30 days. Our application request logs are deleted after about 90 days. Records of the consent choices you make on this site are kept for about 13 months, after which they are deleted. Analytics data is retained according to Google Analytics retention settings. Our hosting and network providers keep their own standard server logs under their own retention policies. Rate alerts set without an account, and the browser push subscriptions that deliver them, are removed about 180 days after they can no longer be delivered to anyone, for example after you clear your browser data, or immediately when you remove them from the browser that set them. You may request deletion at any time via the contact details below.
Under the GDPR and Ethiopia's Personal Data Protection Proclamation No. 1321/2024, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. To exercise any of these rights, email support@keydama.com.
exchange.et is operated by Keydama Software, which is the data controller for the personal data described in this policy. To exercise any data-subject right, raise a privacy question, or contact our data-protection contact, email support@keydama.com. Our registration as data controller under Ethiopia's Personal Data Protection Proclamation No. 1321/2024 is pending; until registration is complete, no postal address is published, so please use the support email above. We respond within the timeframes required by applicable law.
Questions, requests, or complaints about your data can be sent to support@keydama.com.
Under the GDPR and Ethiopia's Personal Data Protection Proclamation No. 1321/2024, if you believe we have not handled your personal data properly, you have the right to lodge a complaint with a competent supervisory authority. In Ethiopia, complaints may be lodged with the supervisory authority established under Proclamation No. 1321/2024. Under the GDPR, you may complain to the data protection authority of the country in which you reside, work, or where the alleged infringement occurred. We invite you to contact us first at support@keydama.com so we can try to resolve your concern, but this does not limit your right to complain to a supervisory authority at any time.
This policy is governed by the laws of the Federal Democratic Republic of Ethiopia, including the Personal Data Protection Proclamation No. 1321/2024.
Advertising on this site is opt-in and non-personalized. Google’s advertising code is loaded only after you grant advertising consent, and only on English pages. Analytics consent and advertising consent are separate: granting one never grants the other, and declining analytics does not withdraw advertising consent. If advertising is not enabled on this deployment, no advertising code is loaded at all.
When ads are served they are requested as non-personalized, so Google does not use your visits to this site or to other websites to choose the ad you see. Google and its advertising partners still receive limited information needed to deliver and measure the ad and to prevent fraud, such as your IP address, browser and device details, the page visited, and your interactions with the ad. Non-personalized ads may still use cookies for frequency capping, aggregated reporting and fraud prevention.
You can manage or opt out of personalized advertising through Google Ads Settings and the participating vendors in the Digital Advertising Alliance choice tool. Your browser can also delete or block existing cookies, including cookies from earlier visits. These external choices are separate from the settings on this site: your analytics and advertising choices can each be changed or withdrawn at any time using Cookie Settings in the footer.
We do not use a certified consent management platform. The consent controls on this site are our own: they record your analytics and advertising choices separately, and either one can be changed or withdrawn at any time using Cookie Settings in the footer, without losing access to any part of the site.