LEGAL PRIVACY POLICY

EFFECTIVE 2026-09-10

What the Coin Wars service collects, who receives it, how long it is kept, and how to get a copy or have it erased.

DRAFT V0.1.0, NOT REVIEWED BY A LAWYER, DO NOT RELY ON IT AND DO NOT ACCEPT USERS AGAINST IT

1. Who is responsible

Coinwars Inc., a Wyoming corporation ("Coinwars Inc.", "we", "us") operates the Coin Wars website at coinwars.fun, its programming interfaces and the off-chain services behind them (the "Service"), and decides how the information described here is used.

This policy covers the Service. It does not cover the blockchain, your wallet, or a service somebody else operates under its own privacy notice.

NOT SETTLED // NEEDS AN OPERATOR DECISION

Coinwars Inc. has not been formed yet. Until its certificate of incorporation is issued there is no company to be a party to this document, to operate the service, or to owe anybody what is written here.

2. The blockchain is public and permanent

When you launch a coin, trade, or do anything else on the blockchain, the transaction, your wallet address, the amounts and the time are recorded publicly. Anybody can read them, and nobody, including us, can change or delete them.

A coin's name, its symbol and the pointer to its description are written on the blockchain at launch and cannot be edited afterwards. The description behind that pointer can hold a website and social handles you supply, it is publicly readable, and the pointer cannot be moved to a different one. Do not put anything there that you may later want withdrawn.

NOT SETTLED // NEEDS COUNSEL

Launch metadata accepts a website and social handles, and the pointer to it is permanent. Guidance from the European Data Protection Board advises against putting personal data on a blockchain at all. Decide whether those fields stay, and whether this warning belongs at the point of launch as well as here.

A wallet address can be connected to a real person, for example through an exchange account, and data protection law can treat it as personal data. We treat wallet addresses, and the link between several addresses held by one profile, as personal data wherever you are.

3. What we collect

We do not ask for your name, your email address, your telephone number or any identity document. What we hold depends on what you use:

What we collect, when it reaches us, and where it is held
InformationWhen it arrivesWhere it is held
Wallet address and networkYou connect a walletYour browser, and our servers for a request that names it
Network address and request details, such as browser type, page and timeEvery request to the ServiceOur hosting providers' logs, and briefly in memory for rate limiting
Coin image, description, website and social handles you supply at launchYou launch a coinOur object storage, publicly readable, pointed at permanently from the blockchain
Profile: callsign, clan, biography, avatar settings, display preferences, visibility settings, social handles, featured coin, repository link, banner image, your wallet address again as a developer field, the time you last changed it, and your signature over all of itYou save a profileYour browser today, signed by your wallet; our database once profile sync is switched on
Account: handle, display name, avatar, biography, GitHub link, linked wallet addressesYou sign in with your walletOur database
Comments, follows and badgesYou post, follow or earn oneOur database
A report about a comment: the reason, your account identifier, the comment, the account identifier of whoever wrote it, and your network addressYou report a commentOur server logs
A cached copy of your on-chain activityYou sign inOur database, and rebuildable from the blockchain at any time
Session identifierYou sign inA cookie in your browser, and a one-way hash of it in our database
NOT SETTLED // NEEDS AN OPERATOR DECISION

Sign-in, accounts, comments, follows, badges, reports and profile sync are written but not switched on at this version, and no route serves them. They are described here so this policy does not need rewriting the day they launch. Delete the rows that are still off, or this box, before publication.

NOT SETTLED // NEEDS AN OPERATOR DECISION

A report goes to a log line rather than to a table, and the network address in it is not shortened: the helper that would shorten it has no caller, because the route that would call it does not exist. Wire both before reports are switched on, or this row has to keep saying what it says.

4. How we use it

  • to run the Service: showing coins, matches, prices and profiles, and preparing the transactions you sign;
  • to host the coin images and descriptions you upload, so wallets, explorers and other sites can show them;
  • to protect the Service: rate limiting, preventing abuse and investigating misuse;
  • to apply the Sanctions Compliance Policy once its location checks and wallet address screening are in operation;
  • to moderate comments and profiles, and to act on reports;
  • to count page views and measure performance in aggregate; and
  • to comply with the law and to answer lawful requests.

We do not sell personal information, and we do not share it for advertising. The only automated decision we would make about you is refusing access under the Sanctions Compliance Policy, and you can ask us to review such a decision.

NOT SETTLED // NEEDS AN OPERATOR DECISION

No location check and no address screening runs at this version, so nothing is processed for that purpose yet and no screening record exists. The sanctions policy carries the same box. Both come off together, when the controls ship.

5. Which privacy laws apply, and on what basis

Where the GDPR or the UK GDPR applies, we rely on performance of a contract, to provide what you ask for; our legitimate interests, to protect the Service and measure its use in aggregate; a legal obligation, to comply with sanctions and other law; and consent, where the law requires it for something stored on your device that is not strictly necessary.

NOT SETTLED // NEEDS COUNSEL

Whether the Service is offered in the EEA and the United Kingdom at all is undecided. If it is, name the representatives required there, complete the balancing tests for legitimate interests, and confirm the position that cookieless analytics need no consent banner. If it is not, say so and cut this section.

NOT SETTLED // NEEDS COUNSEL

This policy says nothing about the state privacy laws of the United States, although the operator is a United States company and a reader in California will look for them. Decide whether the thresholds are met, and either add a section or record here that they are not.

6. Who receives it

We share information with the providers that run the Service for us, with the third parties your own use of the Service reaches, and with authorities where the law requires it.

Who receives information, what reaches them, and why
RecipientWhat it receivesWhy
VercelRequests to the website, including your network addressHosting, and page counts that set no cookie
CloudflareRequests and network address, and the database and file storage behind accounts, comments and uploadsDelivery, database, object storage, and page counts where enabled
AhrefsPage, referrer and network address, from a script on each pagePage counts, with no cookie
DiceBearThe wallet address or seed an avatar is drawn from, and your network addressDrawing an avatar when a page shows one
Node providers for the chain the app servesBlockchain queries passed on by our server, which can include wallet addresses, but not your network address. If our relay fails, your browser may reach a provider directly, and it then sees your network addressReading the blockchain and submitting signed transactions
Public Ethereum node providers, currently BuidlGuidl and AlchemyQueries sent straight from your browser, with your network addressResolving names and prices on Ethereum
WalletConnectThe messages passed between the Service and your wallet, if you connect that wayConnecting a wallet
Block explorers you open from a linkThe coin, pool or wallet address in the link, your network address, and this site as the referring pageShowing a transaction, an address or a contract
Your wallet providerThe transactions and signatures you approveSigning, under its own notice
NOT SETTLED // NEEDS AN OPERATOR DECISION

No data processing agreement is in place with Vercel or with Cloudflare. Both publish standard terms, and neither is in force until somebody accepts them. Avatars are also fetched from DiceBear with a wallet address in the request, so a third party learns that address and your network address on every render; drawing them in the browser would delete that row.

7. Cookies and browser storage

The Service sets no advertising or cross-site tracking cookie. It uses the following, each either needed for something you asked for or remembering a setting on your own device. Some belong to features that are not switched on yet, and nothing sets those until they are:

Every cookie and browser storage key, its purpose and how long it lasts
NameKindPurposeLasts
cw_sessionCookie, not readable by scriptsKeeps you signed in7 days
cw_nonceCookie, not readable by scriptsCarries the one-time code your wallet signs when you sign in5 minutes
cw.cockpit.v1Local storageWindow layout, collapsed panels, the coin and the match you last focused, slippage and display preferencesUntil you clear it
cw.profiles.v1Local storageA cached copy of profiles, including any banner image in them, so a page paints at onceUntil you clear it
cw.profiles.transport.v1Local storageThe profiles you have saved on this device, including a banner image, until profile sync is switched onUntil you clear it
Keys set by the wallet libraries, including wagmi, RainbowKit and WalletConnectLocal storage, and IndexedDB for WalletConnectWhich wallet you connected last, and its session, so it can reconnectUntil you disconnect or clear it

The page counters from Vercel, Cloudflare and Ahrefs set no cookie and store no identifier in your browser. You can clear cookies and browser storage at any time: the Service keeps working, but it forgets your layout and signs you out.

NOT SETTLED // NEEDS AN OPERATOR DECISION

Neither cookie is issued at this version, because sign-in is not switched on; the rows say what they will hold. The keys the wallet libraries set are listed by library rather than one by one, which is less than the ePrivacy and PECR rules ask for. Enumerate them before serving anybody in the EEA or the United Kingdom.

8. How long we keep it

How long each kind of information is kept
InformationKept for
Session recordsRefused 7 days after sign-in, and the record removed when the housekeeping sweep runs
Sign-in codes5 minutes
Rate limit counters keyed by network addressThe count resets every 1 minute. The entry, which holds the full network address, stays in memory until a sweep runs or the server restarts
Account, profile, follows and badgesUntil you erase them
CommentsUntil you erase your account. A comment hidden by you or by moderation is kept rather than deleted, so the decision can be reviewed
Cached on-chain activityUntil you erase your account; it can be rebuilt from the blockchain
Coin images and descriptionsIndefinitely, because the blockchain points at them, unless taken down
Hosting and security logsAs configured by our hosting providers
Sanctions screening recordsAs long as sanctions recordkeeping rules require, once screening exists
NOT SETTLED // NEEDS AN OPERATOR DECISION

Set a retention period for hosting logs and for the moderation log, configure Vercel and Cloudflare to match it, and state it here. The research recommends 30 days for a log that holds a full network address. The two sweeps that remove expired sessions and stale rate-limit entries are written and nothing calls them, so neither runs on a schedule yet.

9. Your choices and your rights

Depending on where you live, you may have the right to get a copy of the personal information we hold about you, to correct it, to have it erased, to object to or restrict some uses, and to complain to a data protection authority. Where the GDPR or the UK GDPR applies, a request has to be answered within one month, and the authority in the United Kingdom is the Information Commissioner's Office.

There is no account beyond your wallet, so you will prove who you are by signing a message with it. An export will return what we hold off the blockchain for your account, including who follows you, because that is part of the account. An erasure will delete your account, its sessions, linked addresses, profile records, comments, follows, badges and cached activity. The message a wallet is asked to sign for an erasure reads: "Erase the Coin Wars profile data held for this wallet. This cannot be undone."

An erasure reaches our database and nothing else. It does not reach the blockchain, where a launch, a trade and a settled match stay permanently; it does not delete a file already in our object storage, such as an uploaded coin image or an avatar; and it cannot reach a copy somebody else has taken.

NOT SETTLED // NEEDS AN OPERATOR DECISION

Export and erasure exist in code and nothing calls them: no page, no route, and no address to send a request to. Until all three exist the rights above cannot be exercised at all. An erasure also leaves uploaded images and avatars in object storage, which either gets fixed or gets stated as a limit.

NOT SETTLED // NEEDS AN OPERATOR DECISION

No address exists yet for a privacy request. Create a monitored mailbox and a postal notice address, set them in the entity configuration, and every document here picks them up.

10. Children

The Service is not for anybody under 18, and we do not knowingly collect information from a child. If you believe a child has used it, tell us and we will delete what we hold.

11. Where it is processed

Our providers process information in the United States and elsewhere. Where the law requires a transfer mechanism, such as standard contractual clauses, we rely on the one the provider offers.

NOT SETTLED // NEEDS COUNSEL

Confirm the transfer mechanism, and the regions the database and the object storage are created in, once the data processing agreements are signed.

12. How we protect it

Session cookies cannot be read by scripts, and the database holds only a one-way hash of them, so a copy of that table cannot be used to sign in as anybody. We never ask for, receive or store a private key or a recovery phrase on our servers. No system is perfect, and we cannot promise that information will never be reached by somebody who should not reach it.

13. Changes

When this policy changes, its version number and effective date change. If a change affects how we use information you have already given us, you are asked to accept the new version before you continue.

14. Contact

NOT SETTLED // NEEDS AN OPERATOR DECISION

No address exists yet for a privacy question. Create a monitored mailbox and a postal notice address, set them in the entity configuration, and every document here picks them up.

VERSION 0.1.0, EFFECTIVE 2026-09-10, UPDATED 2026-09-10, STATUS DRAFTCONTENT HASH sha256:336638cbc442bd158a76a02f84d18870539d7fffca610a64f600c93b12b95f34The hash identifies these exact words, and changes if any of them change.
GAS CHAIN Robinhood ChainBLOCK #LEGALNO WALLET