Opening your world…
METAHUB
Privacy Policy
Draft prepared 30 September 2026. Effective date: [TO BE CONFIRMED].
Draft for review. Company, jurisdiction, contact, and any marked operational details must be completed before publication as an effective policy.
Read alongside the Terms of Use.
1. General Provisions
1.1. This Privacy Policy explains how information relating to Users of METAHUB (the “Platform”) is collected, used, stored, disclosed, and otherwise processed.
1.2. The controller responsible for processing under this Policy is [LEGAL COMPANY NAME], registered at [REGISTERED ADDRESS], [COUNTRY OF INCORPORATION] (the “Company”). Privacy requests may be directed to [PRIVACY CONTACT EMAIL].
1.3. This Policy covers the website, wallet connection, project participation, referrals, position NFTs, marketplace, support correspondence, and related Company-controlled systems. Independent wallet providers and other third parties have their own privacy practices.
1.4. This Policy is a notice of processing. Visiting the Platform or connecting a wallet does not constitute consent to every use of data; separate consent shall be requested where required.
2. Wallet Identity and Public Blockchain Data
2.1. The ordinary registration flow identifies the User by a public wallet address rather than an email-and-password account. A wallet address and its associated activity may constitute personal data when linked or reasonably linkable to a person.
2.2. The Platform reads and indexes public blockchain records, including addresses, transaction hashes, amounts, timestamps, registration and sponsor relationships, matrix placements, position ownership, reward allocations, and marketplace activity.
2.3. On-chain records are publicly accessible and may be copied, analyzed, or linked to other information by independent parties. The Company cannot erase or alter confirmed records on the public blockchain.
2.4. The Company remains responsible for its own processing and off-chain copies of personal data. Blockchain immutability is not a blanket exemption from obligations relating to information under its control.
3. Information Processed
3.1. Participation data includes the connected wallet address, user and referral identifiers, sponsor wallet or sponsor position, program and board identifiers, NFT ownership, allocation history, balances, and transaction status.
3.2. Authentication data includes wallet-signature messages and signatures submitted for verification, single-use authentication challenges, wallet addresses, chain identifiers, and short-lived session credentials. These are distinct from private keys and seed phrases, which the Platform does not request or store.
3.3. Technical information includes request and connection details used to serve the website and API, such as IP address, request time, requested resource, and diagnostic information. Where configured, a trusted hosting provider’s country result is used to enforce regional restrictions.
3.4. If the User contacts the Company, the Company processes the contact details, correspondence, complaint information, and transaction references the User provides. Users should not send private keys, seed phrases, or unnecessary identification documents.
3.5. The current profile-photo feature saves the selected image in the User’s browser for the associated wallet. That feature does not upload the image to the Platform’s backend.
4. Sources of Information
4.1. Information is obtained directly from the User, from the connected wallet and authentication requests, from public blockchain records, and from operation of the website and related infrastructure.
4.2. Referral identifiers supplied through links and recorded sponsor relationships are used to associate participation with the applicable referral structure.
4.3. Hosting, network, and wallet-connection providers may process technical information when providing their services. The extent of their independent processing depends on the service selected and its own notice.
5. Purposes and Applicable Legal Grounds
5.1. Wallet, participation, and transaction information is processed to provide requested functionality, display positions and history, attribute referrals, and support execution and reconciliation of program activity. Where applicable law recognizes it, necessary processing relies on performance of the User agreement.
5.2. Authentication and technical information are processed to verify wallet control, enforce permissions, prevent replay and abuse, diagnose failures, and protect the service. Where permitted, the Company relies on legitimate interests in operating a secure service after considering the User’s rights, or another applicable lawful ground.
5.3. Correspondence is processed to respond to questions, investigate complaints, and handle rights requests. Processing may be necessary to perform the agreement, meet a legal obligation, or pursue a legitimate interest where recognized by applicable law.
5.4. Information is processed to comply with binding legal requirements where such requirements apply. Reliance on a legal obligation is limited to an obligation actually applicable to the Company.
5.5. Where consent is required, it shall be requested for the specified purpose and may be withdrawn. Contractual necessity or legitimate interests are not treated as universally available grounds in jurisdictions that do not recognize them.
6. Public Visibility and Automated Program Operations
6.1. Wallet-associated positions, sponsor relationships, NFT ownership, transactions, and rewards may be visible through public blockchain explorers and the Platform’s public read interfaces. Connecting a pseudonymous wallet does not ensure anonymity.
6.2. Program code automatically determines placement, allocation, and eligibility outcomes using recorded activity, ownership, and configured conditions. This can affect whether a reward is paid to the User or directed elsewhere under the program rules.
6.3. Users may ask the Company for an explanation of relevant processing and raise an apparent error. Where applicable law provides rights concerning solely automated decisions with legal or similarly significant effects, the Company shall address those rights. A review cannot itself undo an immutable blockchain transaction.
7. Disclosure and Service Providers
7.1. The Company uses infrastructure and technical providers as necessary to host the Platform, serve blockchain queries, maintain its database, and secure operations. Providers acting on the Company’s behalf shall be subject to appropriate data-processing, confidentiality, and security obligations.
7.2. Wallet connectors, including WalletConnect where selected and configured, and wallet applications may independently receive wallet and technical information necessary for the chosen connection. Blockchain query providers receive the queries sent to them and associated connection information.
7.3. The Company may disclose relevant information to professional advisers and competent authorities where necessary and legally justified, including for claims, legal obligations, or investigation of unlawful activity. Requests are not treated as automatically valid merely because they are received.
7.4. If the business is transferred or reorganized, relevant information may be transferred to a successor subject to applicable safeguards and notice obligations.
7.5. The Company does not sell wallet-associated personal data. Public access to the blockchain is separate from disclosure by the Company.
8. International Processing
8.1. Hosting, wallet-connection, and blockchain infrastructure may operate in countries other than the User’s country. The Company shall confirm the locations and recipients used for the production service before this draft takes effect.
8.2. Where Company-controlled transfers require safeguards, the Company shall use the applicable lawful transfer mechanism, such as an adequacy arrangement or appropriate contractual safeguards, and supplementary measures where necessary.
8.3. Publication of this Policy and continued use of the Platform do not, by themselves, provide consent or another legal basis for a restricted international transfer. Information about applicable safeguards may be requested through the privacy contact.
9. Retention
9.1. Participation records and off-chain blockchain indexes are retained for as long as needed to provide active position and transaction-history functionality, reconcile records, and meet applicable recordkeeping obligations. Retention shall be reassessed when those purposes cease; public availability alone does not justify indefinite retention of every off-chain copy.
9.2. Authentication challenges expire after five minutes. They are removed upon successful use, and expired challenge records are cleared when new challenges are issued. Authenticated session tokens currently expire after fifteen minutes; expiry does not necessarily mean every browser copy is immediately erased.
9.3. Operational logs are retained according to the period necessary to investigate failures and misuse, taking account of the incident window and any binding preservation requirement. The production log-retention period is [LOG RETENTION PERIOD — TO BE CONFIRMED].
9.4. Support correspondence is retained until the request is resolved and for any additional period justified by applicable complaint, limitation, or legal recordkeeping requirements. Information subject to a specific legal hold is retained only as required for that hold.
9.5. Browser storage follows the controls described below. Public blockchain records may remain available indefinitely through independent nodes and services.
10. Browser Storage and Cookies
10.1. The Platform uses local and session storage for wallet-connection state, the optional profile photo, interface and animation state, and authorized sessions. Persistent browser data can remain until the User clears it or the relevant feature removes it.
10.2. A selected profile photo can be removed using the profile feature or browser site-data controls. Intro-animation state and administrator-session information use session storage; authenticated requests transmit the session token to the backend for verification.
10.3. Wallet software and connection libraries may use their own storage. Disconnecting a wallet does not necessarily delete stored site data or revoke token approvals. Users may manage site data in their browser and connections in their wallet.
10.4. The application currently has no integrated advertising or behavioral-analytics tracker identified in its own source. Production hosting and third-party services must be assessed separately. If optional tracking is introduced, the Company shall provide the required information and choices before it operates.
10.5. Disabling storage may affect wallet reconnection, authentication, profile photos, and remembered interface behavior.
11. Security
11.1. The Company shall maintain technical and organizational measures appropriate to the information and risks involved. Existing application controls include wallet-signature verification, expiring authentication credentials, permission checks, and request-rate limits.
11.2. No system provides absolute security. The Company shall assess and respond to security incidents and notify affected persons and authorities where applicable law requires.
11.3. The User should protect devices and wallets, review signature requests, and report suspected unauthorized access. User responsibilities do not replace the Company’s duties to protect information under its control.
12. User Rights and Requests
12.1. Depending on applicable law, the User may have rights to obtain information and access, correct inaccurate data, request erasure or restriction, object to processing, obtain a portable copy, and withdraw consent without affecting earlier lawful processing.
12.2. Requests should be sent to [PRIVACY CONTACT EMAIL], identifying the relevant wallet or interaction and the right being exercised. The Company may request proportionate evidence of control or identity, but shall not request a private key or seed phrase.
12.3. The Company shall respond within the period required by applicable law and explain any lawful refusal, limitation, or extension. Continued retention for a specific legal purpose does not justify refusing every aspect of a request.
12.4. The Company cannot delete immutable public blockchain records, but shall consider requests concerning its own database, logs, correspondence, and other controlled copies separately.
12.5. The User may complain to the competent data-protection authority and seek available remedies. The relevant authority and any locally required representative shall be identified once the Company’s establishment and service jurisdictions are confirmed.
13. Identity Verification and Children
13.1. The current ordinary participation flow does not collect identity documents, biometric verification, residential addresses, or proof of funds. If verification is introduced, the Company shall first identify the information, provider, purposes, lawful grounds, retention, and rights relevant to that processing.
13.2. The Platform is intended for adults meeting the eligibility requirements in the Terms of Use. It does not knowingly solicit children’s personal information.
13.3. If the Company learns that it holds a child’s information in circumstances that are not permitted, it shall take appropriate steps under applicable law, including restriction or deletion of controlled copies where required.
14. Changes to this Policy
14.1. The Company may update this Policy when functionality, providers, or legal requirements change. The effective date and material changes shall be communicated as required by law.
14.2. New processing that requires consent shall not be authorized solely by publishing a revised Policy. Where a new purpose requires further notice or another lawful ground, those requirements shall be met before the processing begins.
15. Contact Information
15.1. Data controller: [LEGAL COMPANY NAME]. Registered address: [REGISTERED ADDRESS]. Country of incorporation: [COUNTRY OF INCORPORATION]. Official website: [OFFICIAL WEBSITE URL].
15.2. Privacy requests and complaints: [PRIVACY CONTACT EMAIL]. General support: [SUPPORT EMAIL]. Data-protection officer or local representative, where required: [CONTACT DETAILS OR NOT APPLICABLE].
