Privacy Policy
1. Who is responsible
Coinwars Inc., a Wyoming corporation ("Coinwars Inc.", "we", "us") operates the Coin Wars website at coinwars.fun, its programming interfaces and the off-chain services behind them (the "Service"), and decides how the information described here is used.
This policy covers the Service. It does not cover the blockchain, your wallet, or a service somebody else operates under its own privacy notice.
Coinwars Inc. has not been formed yet. Until its certificate of incorporation is issued there is no company to be a party to this document, to operate the service, or to owe anybody what is written here.
2. The blockchain is public and permanent
When you launch a coin, trade, or do anything else on the blockchain, the transaction, your wallet address, the amounts and the time are recorded publicly. Anybody can read them, and nobody, including us, can change or delete them.
A coin's name, its symbol and the pointer to its description are written on the blockchain at launch and cannot be edited afterwards. The description behind that pointer can hold a website and social handles you supply, it is publicly readable, and the pointer cannot be moved to a different one. Do not put anything there that you may later want withdrawn.
Launch metadata accepts a website and social handles, and the pointer to it is permanent. Guidance from the European Data Protection Board advises against putting personal data on a blockchain at all. Decide whether those fields stay, and whether this warning belongs at the point of launch as well as here.
A wallet address can be connected to a real person, for example through an exchange account, and data protection law can treat it as personal data. We treat wallet addresses, and the link between several addresses held by one profile, as personal data wherever you are.
3. What we collect
We do not ask for your name, your email address, your telephone number or any identity document. What we hold depends on what you use:
| Information | When it arrives | Where it is held |
|---|---|---|
| Wallet address and network | You connect a wallet | Your browser, and our servers for a request that names it |
| Network address and request details, such as browser type, page and time | Every request to the Service | Our hosting providers' logs, and briefly in memory for rate limiting |
| Coin image, description, website and social handles you supply at launch | You launch a coin | Our object storage, publicly readable, pointed at permanently from the blockchain |
| Profile: callsign, clan, biography, avatar settings, display preferences, visibility settings, social handles, featured coin, repository link, banner image, your wallet address again as a developer field, the time you last changed it, and your signature over all of it | You save a profile | Your browser today, signed by your wallet; our database once profile sync is switched on |
| Account: handle, display name, avatar, biography, GitHub link, linked wallet addresses | You sign in with your wallet | Our database |
| Comments, follows and badges | You post, follow or earn one | Our database |
| A report about a comment: the reason, your account identifier, the comment, the account identifier of whoever wrote it, and your network address | You report a comment | Our server logs |
| A cached copy of your on-chain activity | You sign in | Our database, and rebuildable from the blockchain at any time |
| Session identifier | You sign in | A cookie in your browser, and a one-way hash of it in our database |
Sign-in, accounts, comments, follows, badges, reports and profile sync are written but not switched on at this version, and no route serves them. They are described here so this policy does not need rewriting the day they launch. Delete the rows that are still off, or this box, before publication.
A report goes to a log line rather than to a table, and the network address in it is not shortened: the helper that would shorten it has no caller, because the route that would call it does not exist. Wire both before reports are switched on, or this row has to keep saying what it says.
4. How we use it
- to run the Service: showing coins, matches, prices and profiles, and preparing the transactions you sign;
- to host the coin images and descriptions you upload, so wallets, explorers and other sites can show them;
- to protect the Service: rate limiting, preventing abuse and investigating misuse;
- to apply the Sanctions Compliance Policy once its location checks and wallet address screening are in operation;
- to moderate comments and profiles, and to act on reports;
- to count page views and measure performance in aggregate; and
- to comply with the law and to answer lawful requests.
We do not sell personal information, and we do not share it for advertising. The only automated decision we would make about you is refusing access under the Sanctions Compliance Policy, and you can ask us to review such a decision.
No location check and no address screening runs at this version, so nothing is processed for that purpose yet and no screening record exists. The sanctions policy carries the same box. Both come off together, when the controls ship.
5. Which privacy laws apply, and on what basis
Where the GDPR or the UK GDPR applies, we rely on performance of a contract, to provide what you ask for; our legitimate interests, to protect the Service and measure its use in aggregate; a legal obligation, to comply with sanctions and other law; and consent, where the law requires it for something stored on your device that is not strictly necessary.
Whether the Service is offered in the EEA and the United Kingdom at all is undecided. If it is, name the representatives required there, complete the balancing tests for legitimate interests, and confirm the position that cookieless analytics need no consent banner. If it is not, say so and cut this section.
This policy says nothing about the state privacy laws of the United States, although the operator is a United States company and a reader in California will look for them. Decide whether the thresholds are met, and either add a section or record here that they are not.
7. Cookies and browser storage
The Service sets no advertising or cross-site tracking cookie. It uses the following, each either needed for something you asked for or remembering a setting on your own device. Some belong to features that are not switched on yet, and nothing sets those until they are:
| Name | Kind | Purpose | Lasts |
|---|---|---|---|
| cw_session | Cookie, not readable by scripts | Keeps you signed in | 7 days |
| cw_nonce | Cookie, not readable by scripts | Carries the one-time code your wallet signs when you sign in | 5 minutes |
| cw.cockpit.v1 | Local storage | Window layout, collapsed panels, the coin and the match you last focused, slippage and display preferences | Until you clear it |
| cw.profiles.v1 | Local storage | A cached copy of profiles, including any banner image in them, so a page paints at once | Until you clear it |
| cw.profiles.transport.v1 | Local storage | The profiles you have saved on this device, including a banner image, until profile sync is switched on | Until you clear it |
| Keys set by the wallet libraries, including wagmi, RainbowKit and WalletConnect | Local storage, and IndexedDB for WalletConnect | Which wallet you connected last, and its session, so it can reconnect | Until you disconnect or clear it |
The page counters from Vercel, Cloudflare and Ahrefs set no cookie and store no identifier in your browser. You can clear cookies and browser storage at any time: the Service keeps working, but it forgets your layout and signs you out.
Neither cookie is issued at this version, because sign-in is not switched on; the rows say what they will hold. The keys the wallet libraries set are listed by library rather than one by one, which is less than the ePrivacy and PECR rules ask for. Enumerate them before serving anybody in the EEA or the United Kingdom.
8. How long we keep it
| Information | Kept for |
|---|---|
| Session records | Refused 7 days after sign-in, and the record removed when the housekeeping sweep runs |
| Sign-in codes | 5 minutes |
| Rate limit counters keyed by network address | The count resets every 1 minute. The entry, which holds the full network address, stays in memory until a sweep runs or the server restarts |
| Account, profile, follows and badges | Until you erase them |
| Comments | Until you erase your account. A comment hidden by you or by moderation is kept rather than deleted, so the decision can be reviewed |
| Cached on-chain activity | Until you erase your account; it can be rebuilt from the blockchain |
| Coin images and descriptions | Indefinitely, because the blockchain points at them, unless taken down |
| Hosting and security logs | As configured by our hosting providers |
| Sanctions screening records | As long as sanctions recordkeeping rules require, once screening exists |
Set a retention period for hosting logs and for the moderation log, configure Vercel and Cloudflare to match it, and state it here. The research recommends 30 days for a log that holds a full network address. The two sweeps that remove expired sessions and stale rate-limit entries are written and nothing calls them, so neither runs on a schedule yet.
9. Your choices and your rights
Depending on where you live, you may have the right to get a copy of the personal information we hold about you, to correct it, to have it erased, to object to or restrict some uses, and to complain to a data protection authority. Where the GDPR or the UK GDPR applies, a request has to be answered within one month, and the authority in the United Kingdom is the Information Commissioner's Office.
There is no account beyond your wallet, so you will prove who you are by signing a message with it. An export will return what we hold off the blockchain for your account, including who follows you, because that is part of the account. An erasure will delete your account, its sessions, linked addresses, profile records, comments, follows, badges and cached activity. The message a wallet is asked to sign for an erasure reads: "Erase the Coin Wars profile data held for this wallet. This cannot be undone."
An erasure reaches our database and nothing else. It does not reach the blockchain, where a launch, a trade and a settled match stay permanently; it does not delete a file already in our object storage, such as an uploaded coin image or an avatar; and it cannot reach a copy somebody else has taken.
Export and erasure exist in code and nothing calls them: no page, no route, and no address to send a request to. Until all three exist the rights above cannot be exercised at all. An erasure also leaves uploaded images and avatars in object storage, which either gets fixed or gets stated as a limit.
No address exists yet for a privacy request. Create a monitored mailbox and a postal notice address, set them in the entity configuration, and every document here picks them up.
10. Children
The Service is not for anybody under 18, and we do not knowingly collect information from a child. If you believe a child has used it, tell us and we will delete what we hold.
11. Where it is processed
Our providers process information in the United States and elsewhere. Where the law requires a transfer mechanism, such as standard contractual clauses, we rely on the one the provider offers.
Confirm the transfer mechanism, and the regions the database and the object storage are created in, once the data processing agreements are signed.
12. How we protect it
Session cookies cannot be read by scripts, and the database holds only a one-way hash of them, so a copy of that table cannot be used to sign in as anybody. We never ask for, receive or store a private key or a recovery phrase on our servers. No system is perfect, and we cannot promise that information will never be reached by somebody who should not reach it.
13. Changes
When this policy changes, its version number and effective date change. If a change affects how we use information you have already given us, you are asked to accept the new version before you continue.
14. Contact
No address exists yet for a privacy question. Create a monitored mailbox and a postal notice address, set them in the entity configuration, and every document here picks them up.