Legal
Privacy Policy
Last updated April 28, 2026
1. Plain-English summary
TokenGate links a Telegram user identity to a cryptocurrency wallet address so we can re-check token holdings hourly and kick wallets that no longer qualify. To do that we need to store: your Telegram user id, your wallet address, and the signature you produced to bind them.
We do not collect your real name, your IP address (beyond what Cloudflare needs to serve a page), your phone number, or your Telegram messages. We do not custody funds. We do not run advertising trackers.
2. Who we are
The Service is operated by TokenGate Operator Ltd., registered in Norway. For privacy-related requests, contact [email protected].
3. What we collect, and why
From end users (members of gated groups)
- Telegram user id and username: required to identify which group member maps to which wallet
- Wallet address: required to read on-chain balances
- Signature, nonce, and signed-message timestamp: cryptographic evidence that you authorized the binding
- On-chain transaction history of the bound wallet, scoped to relevant assets: we read public chain data (Transfer events on the gated tokens) to verify holding age and balance, this is public information; we cache it so we don't hit RPCs every hour
From subscribing group owners
- Wallet address(es) linked to subscriptions and group ownership on-chain
- Group metadata you enter (display name, Telegram chat id, handle)
- Email address, only if you contact support
Server logs
- Cloudflare logs (IP, user agent, request path) Cloudflare retains these per their retention policy for DDoS/abuse protection. We don't separately store IPs.
- Application logs (request method, path, response code, latency, error stack traces) used for debugging. Retained 30 days.
We do not collect: real name, phone number, date of birth, government identifiers, location, payment-card data (we don't accept cards, payments are on-chain), or contents of Telegram messages.
4. How we use the data
- To run gating: evaluate your bound wallet's holdings against group rules, kick if you fail
- To bill subscriptions: identify on-chain payments to the GatingHub contract and grant the corresponding plan duration
- To support you: respond to questions, debug errors you report
- To prevent abuse: rate-limit requests, detect anomalies in chain interactions
We do not sell, rent, or share your data with third parties for marketing. We don't run analytics trackers or advertising pixels.
5. Where the data lives
- Postgres database, hosted on Neon (USA / EU regions). Tg-↔-wallet bindings, kick-queue, gating rules, group metadata.
- VPS (operated by us, Frankfurt region): application code, transient logs, in-memory caches.
- Cloudflare: TLS termination, DDoS protection, edge caching.
- Public blockchains: smart-contract state (subscriptions, group registrations, member payments) is public by nature.
6. Your rights (GDPR / CCPA)
If you are in the EU, UK, or California, you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your data ("right to erasure")
- Export your data in a portable format
- Object to processing for legitimate-interest purposes
- Withdraw consent (where we rely on it)
Note: on-chain data cannot be deleted it is publicly written by you when you sign transactions. We can delete our local cache and your TG-↔-wallet binding from our servers; the public blockchain state remains.
To exercise these rights, email [email protected] from the email tied to your account, or sign a message from your bound wallet proving control.
7. Retention
- TG-↔-wallet bindings: kept while the binding is active; deleted within 90 days after you request unbinding
- Kick-queue rows: 90 days after processing
- Application logs: 30 days
- Cached on-chain state: kept until rule configuration changes (then re-derived from public chain)
8. Security
The verification flow uses SIWE-style signatures so we never see your private key. Database is encrypted at rest, TLS everywhere in transit, including the Cloudflare-tunnel connection from edge to origin. We rotate operational secrets periodically and follow standard server hygiene.
See the Security page for technical detail.
9. Children
The Service is not directed at children under 13 (or 16 in the EU). If you believe a child has provided personal data, contact us and we will remove it.
10. Changes to this policy
We may update this policy. Material changes are announced via the dashboard at least 14 days in advance. The "Last updated" date at the top reflects the current version.
11. Contact
Privacy questions: [email protected]
General contact: /contact