DRAFT — NOT LEGAL ADVICE. Prepared as a starting point for CryptoBuddy sCAN and must be reviewed and finalized by a licensed attorney before publication. Privacy obligations differ by jurisdiction (e.g., GDPR in the EU/UK, CCPA/CPRA in California) and depend on facts only you know (where you operate, what you actually collect, and which processors you use). Complete every [PLACEHOLDER] and verify the "what we collect" list against the Service's real behavior before relying on this.
Effective date: [EFFECTIVE_DATE] Data controller: [ENTITY], [ENTITY_ADDRESS]. Contact / privacy requests: [PRIVACY_CONTACT_EMAIL].
This Policy explains what CryptoBuddy sCAN (the "Service") collects, why, and your choices. It is part of, and incorporated into, our Terms of Use.
We try to collect as little as possible and to keep your workspace yours. We do not sell your personal information. Sensitive personal content you store in the Service (your vault documents and captures) is stored under your account, and passwords are stored only as salted Argon2 hashes — never in plain text.
a) Account information. Your username and a hashed password. If you use a third-party sign-in:
b) Optional profile information. Anything you choose to add — display name, role, bio, links, and your linked X handle. You separately choose whether your X handle is shown to other users; when shown, others see a small icon next to your name that reveals your handle and, if clicked, opens your public profile on the third-party platform in a new tab.
c) Community content and social activity. Posts, comments, events, real-time community chat messages, "good deeds" submissions (including a required location and required proof — either an image you upload or a link to your own social-media post — which you choose to keep private or to show publicly), likes and comments on deeds, votes, points/tickets activity, referral counts, and leaderboard standing. We also record your social connections — who you follow and who follows you — and list your username in a member directory that other members can search. Much of this is, by design, visible to other users (see Section 5).
d) Profile media. An avatar you select from our built-in mascot images and a short bio, stored under your account so they appear on your public profile.
e) Wallet connection (optional). If you connect a crypto wallet, we read the wallet address you choose to share in order to display it and to let you claim token-purchase notifications. The connection is read-only — we never request, and never receive, permission to move funds, sign transactions, or otherwise act on your wallet. Today the address is stored locally on your device, not on our servers. [ATTORNEY/ENG: confirm before launch whether any wallet data becomes server-stored — e.g., once on-chain purchase-claiming goes live — and update this section and retention accordingly. A wallet address is personal data when tied to an account.]
f) Workspace and vault content. Your saved layout, preferences, documents, and captures, stored server-side under your account so your workspace follows you across devices.
g) Technical and usage data. Basic information needed to run and secure the Service, such as request metadata and rate-limiting signals. Your browser also stores local data (e.g., a "remember this device" flag, your connected-wallet choice, and workspace state) on your own device.
h) Communications. Anything you send us for support.
i) Moderation records. If an operator/moderator takes action on your account or content (e.g., hiding or removing content, or suspending an account for a stated reason), we retain a record of that action to operate the Service safely.
To create and secure your account; to operate community, workspace, and vault features; to run and administer promotions you choose to enter; to prevent fraud, abuse, and manipulation; to provide support; to comply with law; and to improve reliability. We rely on the legal bases of performing our contract with you, our legitimate interests in operating and securing the Service, your consent where required (e.g., optional handle display), and legal obligation, as applicable.
[LIST PROCESSORS — hosting, database, email, analytics, etc.]We do not sell personal information or share it for cross-context behavioral advertising.
The Service uses your browser's local storage (and, if any, essential cookies) to keep you signed in when you choose "remember this device" and to persist your workspace. We do not use third-party advertising trackers. [Confirm the exact cookie/local-storage inventory and add a cookie notice/banner if you later add any non-essential cookies.]
We keep account and content data while your account is active and as needed for the purposes above and legal requirements, then delete or anonymize it. You can ask us to delete your account (see Your Rights).
We use measures including hashed passwords (Argon2), server-side storage of vault content, encrypted transport [confirm HTTPS/TLS in production], rate limiting, and access controls. No system is perfectly secure; we cannot guarantee absolute security.
Depending on where you live, you may have rights to access, correct, delete, port, or restrict/object to processing of your personal information, to withdraw consent (e.g., turn off handle display or unlink X at any time), and to not be sold (we don't sell). California residents have rights under CCPA/CPRA; EU/UK residents have rights under GDPR and may lodge a complaint with a supervisory authority. To exercise any right, contact [PRIVACY_CONTACT_EMAIL]. We will verify and respond as required by law and will not discriminate against you for exercising a right.
The Service is not intended for anyone under 18, and we do not knowingly collect their information. If you believe a minor has provided data, contact us and we will delete it.
We may process information in [COUNTRY/REGION]. If we transfer personal data across borders, we use safeguards required by applicable law [e.g., Standard Contractual Clauses for EU/UK transfers].
We may update this Policy; material changes will be posted with a new effective date. Continued use after an update means you accept it.
Privacy questions or requests: [PRIVACY_CONTACT_EMAIL], [ENTITY], [ENTITY_ADDRESS].