Privacy Policy
Version 0.1 · Effective 2026-05-11
What we collect
When you use the Service, the operator collects:
- The contract identifier, amount, deadline, condition, and the two party identifiers you submit.
- IP address and User-Agent for each request (Cloudflare access logs, retained for 30 days).
- Basic page analytics through Cloudflare Web Analytics if enabled by the operator. Cloudflare Web Analytics is cookie-free and does not collect cross-site advertising identifiers.
- Stripe PaymentIntent IDs and on-chain transfer hashes for any funding event.
- A one-time claim token issued at create-time. The raw token is returned once, then stored only as a SHA-256 verifier.
What we don't collect
- We do not collect your card number, bank account number, or any KYC document. Stripe collects and processes card details; Stripe's privacy policy applies.
- We do not run advertising trackers or marketing cookies.
How we use it
- To operate the Service: create contracts, observe signals, drive settles.
- To screen for OFAC compliance (sanctions screening of wallet addresses + counterparty identifiers).
- To diagnose operational issues.
We do not sell your data. We do not share it with third parties except:
- Stripe (for the card / Link funding path) - see https://stripe.com/privacy
- Cloudflare (operates the Worker) - see https://www.cloudflare.com/privacypolicy/
- Helius (Solana webhook delivery) and Alchemy (Ethereum webhook delivery) - see their respective privacy policies.
Your rights
If you are in the European Union or California, you have rights under GDPR or CCPA to request access to, correction of, or deletion of your data. Email hi@ronakdaya.com.
Retention
- Contract records are retained indefinitely while the Service is operational.
- Access logs are retained for 30 days.
- The operator may purge demo / test contracts at any time.
Security
The Service runs on Cloudflare Workers. Secrets (Stripe key, webhook secrets, master seeds for derived wallets) are stored as Cloudflare-managed secrets and are not accessible to the application code at rest. The operator follows reasonable security practices but does not warrant invulnerability.
Contact
hi@ronakdaya.com