REWARDS EARNED

Privacy Policy

Last updated: [DATE]

This policy says what C-Suite Fun, LLC ("we", "us") collects when you use the C-Suite site at csuite.fun, why, who else sees it, how long we keep it, and what you can ask us to do. It is written to be read, so it is short. If something you want to know is not here, ask: [CONTACT EMAIL].

The one thing to understand first: most of what the site shows is on a public blockchain, which we do not control and cannot edit. Your wallet address, every transaction it makes, every seat it holds, every payout it receives and every redemption it makes are public, permanent, and visible to anyone with a block explorer. That is true whether or not you ever use this site. This policy is about the smaller set of things we hold ourselves.

1. Who is responsible

C-Suite Fun, LLC, a Delaware company, is the controller of the personal data described here. Contact: [CONTACT EMAIL]. [COUNSEL: whether an EU or UK representative is required (GDPR Art. 27 / UK GDPR Art. 27) once the entity and its user base are known.]

2. What we collect, and why

We run no advertising, no third-party analytics, no tracking pixels and no fingerprinting. What follows is the whole list.

2.1 Your wallet address (when you sign in)

Signing in is a signature, in your wallet, over a sentence the site shows you. We check the signature and record your wallet address as your account. That is the only identifier the site has for you: no name, no email, no password. We keep the address and what the chain says the address holds.

Why: to show you your seats, your payouts, your drafts and your rewards, and to let you act on them. Basis: performing the agreement you make with us by using the site. [COUNSEL: Q4 — whether a wallet address is personal data for us at all; this policy assumes it may be.]

We do not keep the signed sign-in message or the signature. The single-use nonce lives in memory for ten minutes and is then gone.

2.2 The session cookie and three preference cookies

See the Cookie Policy. In one line: a signed session cookie (24 hours, renewed while you use the site), a theme cookie, a "you have seen the intro" cookie, and a referral cookie that remembers whose invite link brought you here for 30 days. We set nothing else.

2.3 How people use the site (our own measurement)

Our own server records, in our own database, three kinds of event: a page view of a token's page, a wallet connected, and a mint started. Each row holds: the time; the kind of event; which token; the path on our site; the page you came from (the referrer URL); any campaign tags (utm_…) in the link you arrived by; the wallet address in the invite link you arrived by, if any; the wallet address your browser reported as connected, if any; your account, if you were signed in; whether this was your first page of the visit; a yes/no "looks like a robot" flag; and, for some events, a small set of extra fields the event type defines.

We do not store your IP address or your browser's user-agent string in these rows. Both are read at the moment of writing — the user agent to set the robot flag, the IP address to rate-limit the endpoint — and then dropped. There is no visitor identifier: nothing ties your visits together beyond the wallet address you connect.

Once per launch, we record each seat holder's coin balance one hour after the pool opens, against their account. The balance is public on the chain; the row ties it to the account.

Why: to see whether a launch works, which links bring people, and where the mint loses them. Basis: our legitimate interest in understanding our own product, balanced against the low intrusiveness of first-party counting with no identifier. [COUNSEL: Q4 — lawful basis and retention; Q5 — the invite-link address on rows for visitors who never mint.]

2.4 Rate limiting and security

Our API reads the connecting IP address of every request to limit how often one client may write to it. The address is held in the API's memory for the length of the limit's window (up to one hour) and is never written to the database. [REVIEW: DevOps to confirm what Cloudflare and AWS keep in their own logs — request logs at the edge and in the hosted backend ordinarily include IP addresses and user agents — and for how long; this paragraph then names it. Packet flag 4.]

Why: to keep the service up and to stop abuse. Basis: our legitimate interest in security.

2.5 If you launch a token (creators)

We keep what you type and upload in the launch form: the Stock Token or pair token you chose, the collection's name and symbol, the coin's name and ticker, your theme text, your links, up to 4 reference images, which step of the form you reached, and the Telegram group you connect (its Telegram chat id and title). We keep the images our pipeline generates from your theme and references, the record of each generation run and what it cost, and the payment quotes you were issued with the transaction hashes that paid them.

Your theme text, names and reference images are sent to the image-generation service we use to draw the collection (section 4). The collection's name, symbol, images and metadata are published on the chain and on the public site, where anyone can see them and we cannot recall them.

Why: to run your launch. Basis: performing the agreement you make with us as a creator.

2.6 If you link Telegram

If you connect a group as a creator, or join a token's group as a holder, you open a link to our Telegram bot and it records your Telegram user id against your account, so that it can admit you, name you, and remove you when your wallet no longer holds a seat. The bot posts in a token's group about the launch and about seat holders' buys; a buy post names the buyer by their Telegram name if they have linked one, otherwise by a shortened wallet address. Those posts are visible to every member of that group, and linking Telegram therefore connects your Telegram identity to your wallet in front of them. We keep the single-use link codes (ten minutes), the link, and the removal queue.

Telegram Inc. processes everything inside Telegram under its own privacy policy.

Why: to run the group. Basis: performing the agreement you make when you choose to link. [COUNSEL: whether naming a holder in a group post needs a separate consent, and what the join flow must say. Related to KB-08 B8.]

2.7 If you verify with X [REVIEW: this feature is scheduled for removal before launch (specs 205 and 207). Delete this section if it does not ship.]

If the site offers you verification through X (it is called activation on the site), you authorise our app on X once. We read two things: your X account id and the URL of your profile image. We download the image, compute a perceptual hash of it, and keep the X account id, the hash and the time of the check. We do not keep your handle, the image, its URL, or the access token, and we ask for no refresh token. A salted commitment to that evidence is written to the chain; the salt is stored encrypted and never published, so the on-chain record alone does not link your wallet to your X account. One X account can activate one wallet per collection, permanently.

X Corp. processes the authorisation under its own privacy policy.

2.8 If you contact us

If you email [CONTACT EMAIL], we keep the email and what you wrote for as long as we need to answer and to keep a record of it.

2.9 What we read from the chain

Our indexer reads the public chain and keeps a copy of what it finds about our contracts: every address that holds a seat, every mint, refund, payout, redemption, trade and referral, and their amounts and times. This is public data. We hold it so pages load and so our jobs know whom to pay.

2.10 What we do not collect

No name, email, phone number, postal address, date of birth, government id, payment card, location beyond what an IP address implies at the moment of a request, biometric, or contact list. No advertising identifiers. No third-party analytics. If any of that changes, this policy changes first.

3. Cookies and browser storage

The Cookie Policy lists every cookie and storage item, who sets it, why, and for how long. Your wallet software and WalletConnect keep their own connection state in your browser's storage; that is theirs, not ours.

4. Who else sees your data

We share personal data with nobody for marketing, and we do not sell it. The parties below process data for us, or receive it because you chose a feature that involves them.

4. Who else sees your data
PartyWhat they do for us, or with youWhat reaches them
Cloudflare, Inc.Hosts the web site (Workers), serves our domain (DNS, CDN), carries the API's tunnel, and guards the administrators' panel (Access)Every request to the site: your IP address, user agent and the pages you load, at the edge, under Cloudflare's own logging
Amazon Web Services (AWS), us-east-2 (Ohio)Hosts the API and the database (ECS Fargate, RDS Postgres), stores and serves published images (S3, CloudFront), holds our signing key (KMS)Everything in section 2 that we store, and the IP address of requests reaching the backend
The blockchain's RPC operatorsYour browser talks to the chain's public RPC endpoint directly to read balances and send transactionsYour IP address and the addresses and transactions you query. On Robinhood Chain the operator is Robinhood; on Base, Base's public endpoint
WalletConnect (Reown)Relays messages between the site and your wallet, only if you choose to connect through WalletConnectYour wallet address, the site's origin and the messages relayed; WalletConnect's own telemetry endpoint is reachable by its library
Relay (relay.link)Powers the optional cross-chain "any token" control on the mint page, only if you open itYour wallet address and the quote you ask for; Relay's terms apply to the swap
Telegram Inc.Runs the groups and the bot's messagesSection 2.6
The image-generation serviceDraws a collection's artwork from a creator's theme and references. Today that is Black Forest Labs (the FLUX API) when hosted [REVIEW: confirm the vendor in use at launch; the local development path uses a different tool]The creator's theme text and reference images
X Corp.Verification through X, if offered (section 2.7)Your one-time authorisation
The Stock Token's issuer and the chain's operatorThey do not receive data from us. They can see the chain like anyone else, and the issuer can act on any address (see the Risk Disclosure)Nothing from us
Professional advisers, and authorities where the law requiresLegal, accounting, and responding to lawful requestsWhat the matter needs
A successorIf we sell or transfer the businessThe data described here, under this policy

[REVIEW: DevOps to confirm this table against docs/infrastructure.md and infra/environments.md at launch — in particular whether production runs where dev runs.]

5. International transfers

We are based in the United States and our servers are there (section 4). If you use the site from the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States. [COUNSEL: the transfer mechanism — the EU-US Data Privacy Framework if the entity certifies, otherwise standard contractual clauses with each provider — and whether Cloudflare's and AWS's data processing terms cover it.]

6. How long we keep things

  • Your account (the wallet address and settings): while you use the site, and then [COUNSEL: retention period] after your last sign-in.
  • The session cookie: 24 hours after your last request.
  • Measurement events (2.3): [COUNSEL: retention period — Q4 question 5; there is no deletion job until this is answered, and the job is one bounded delete by date once it is].
  • Creator drafts, submissions and generation records: while the token exists in our catalogue and [COUNSEL: retention period] after it is taken down or the draft is abandoned.
  • Telegram links: until you unlink, the group is disconnected, or your last seat leaves your wallet.
  • Emails to us: [COUNSEL: retention period].
  • What we read from the chain (2.9): indefinitely; it is a copy of a public record.

7. What you can ask us to do

You can ask us to tell you what we hold about your wallet address, to correct it, to delete it, to give it to you in a portable form, to stop using it for a purpose based on our legitimate interests, or to restrict how we use it. Where the law where you live gives you these rights, we honour them for everyone.

How to ask. Email [CONTACT EMAIL] from any address, naming the wallet address. Because the only identifier we hold is the wallet, we will ask you to prove you control it by signing a message we send you; we cannot act on a request for a wallet you cannot sign for. [COUNSEL: Q4 question 6 — what proof we may or must ask for.] We answer within one month, or tell you why we need longer.

What we cannot do. We cannot delete, change or hide anything on the blockchain: your address, its transactions, its seats, its payouts, and any commitment our contracts wrote. We cannot delete what you posted in a Telegram group. We cannot change a collection's on-chain record, including its pointer to its images and metadata, though we can stop showing the token on the site and stop serving its images from our storage.

If you are in the EEA or the UK you may also complain to your data-protection authority.

8. Children

The site is for adults. We do not knowingly collect personal data from anyone under 18, and never from anyone under 13. If you believe a child has used the site, tell us at [CONTACT EMAIL] and we will delete what we hold.

9. Security

The site is served over HTTPS. The session cookie is signed and cannot be read by page scripts. The salt behind any on-chain commitment is stored encrypted under a key that lives outside the database. Our signing key lives in a hardware-backed key service and can only pay gas; it holds no role on any contract and cannot move anyone's assets. No system is perfectly secure, and the blockchain's security is not ours to promise.

10. Do-not-sell and similar rights

We do not sell personal data and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. [COUNSEL: whether the CCPA/CPRA applies to us at all — we assume we are below its thresholds today (revenue, 100,000 consumers, 50% of revenue from selling or sharing) and this needs confirming as the entity and the numbers become known — and whether another state's law applies.]

11. Changes

We may change this policy. The date at the top is the current version's. A material change is posted on the site before it takes effect.

12. Contact

C-Suite Fun, LLC [CONTACT EMAIL]

Connect Wallet