Legal

Privacy Policy

Last updated April 28, 2026

This is a starter document. Have a privacy specialist review against GDPR / CCPA / your jurisdiction before relying on it. Replace placeholder fields (in italics) with your actual entity, DPO contact, and retention windows.

1. Plain-English summary

TokenGate links a Telegram user identity to a cryptocurrency wallet address so we can re-check token holdings hourly and kick wallets that no longer qualify. To do that we need to store: your Telegram user id, your wallet address, and the signature you produced to bind them.

We do not collect your real name, your IP address (beyond what Cloudflare needs to serve a page), your phone number, or your Telegram messages. We do not custody funds. We do not run advertising trackers.

2. Who we are

The Service is operated by TokenGate Operator Ltd., registered in Norway. For privacy-related requests, contact [email protected].

3. What we collect, and why

From end users (members of gated groups)

  • Telegram user id and username: required to identify which group member maps to which wallet
  • Wallet address: required to read on-chain balances
  • Signature, nonce, and signed-message timestamp: cryptographic evidence that you authorized the binding
  • On-chain transaction history of the bound wallet, scoped to relevant assets: we read public chain data (Transfer events on the gated tokens) to verify holding age and balance, this is public information; we cache it so we don't hit RPCs every hour

From subscribing group owners

  • Wallet address(es) linked to subscriptions and group ownership on-chain
  • Group metadata you enter (display name, Telegram chat id, handle)
  • Email address, only if you contact support

Server logs

  • Cloudflare logs (IP, user agent, request path) Cloudflare retains these per their retention policy for DDoS/abuse protection. We don't separately store IPs.
  • Application logs (request method, path, response code, latency, error stack traces) used for debugging. Retained 30 days.

We do not collect: real name, phone number, date of birth, government identifiers, location, payment-card data (we don't accept cards, payments are on-chain), or contents of Telegram messages.

4. How we use the data

  • To run gating: evaluate your bound wallet's holdings against group rules, kick if you fail
  • To bill subscriptions: identify on-chain payments to the GatingHub contract and grant the corresponding plan duration
  • To support you: respond to questions, debug errors you report
  • To prevent abuse: rate-limit requests, detect anomalies in chain interactions

We do not sell, rent, or share your data with third parties for marketing. We don't run analytics trackers or advertising pixels.

5. Where the data lives

  • Postgres database, hosted on Neon (USA / EU regions). Tg-↔-wallet bindings, kick-queue, gating rules, group metadata.
  • VPS (operated by us, Frankfurt region): application code, transient logs, in-memory caches.
  • Cloudflare: TLS termination, DDoS protection, edge caching.
  • Public blockchains: smart-contract state (subscriptions, group registrations, member payments) is public by nature.

6. Your rights (GDPR / CCPA)

If you are in the EU, UK, or California, you have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to erasure")
  • Export your data in a portable format
  • Object to processing for legitimate-interest purposes
  • Withdraw consent (where we rely on it)

Note: on-chain data cannot be deleted it is publicly written by you when you sign transactions. We can delete our local cache and your TG-↔-wallet binding from our servers; the public blockchain state remains.

To exercise these rights, email [email protected] from the email tied to your account, or sign a message from your bound wallet proving control.

7. Retention

  • TG-↔-wallet bindings: kept while the binding is active; deleted within 90 days after you request unbinding
  • Kick-queue rows: 90 days after processing
  • Application logs: 30 days
  • Cached on-chain state: kept until rule configuration changes (then re-derived from public chain)

8. Security

The verification flow uses SIWE-style signatures so we never see your private key. Database is encrypted at rest, TLS everywhere in transit, including the Cloudflare-tunnel connection from edge to origin. We rotate operational secrets periodically and follow standard server hygiene.

See the Security page for technical detail.

9. Children

The Service is not directed at children under 13 (or 16 in the EU). If you believe a child has provided personal data, contact us and we will remove it.

10. Changes to this policy

We may update this policy. Material changes are announced via the dashboard at least 14 days in advance. The "Last updated" date at the top reflects the current version.

11. Contact

Privacy questions: [email protected]

General contact: /contact