Privacy Policy
This policy explains what personal data Zoide NFT processes, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
Who is responsible
Zoide Inc, trading as Zoide NFT, is the data controller. You can reach us for anything in this policy at [email protected].
Read this first: the blockchain is public and permanent
Zoide NFT operates on the Bitcoin SV public blockchain. Every mint, purchase, sale, transfer and listing is a transaction recorded on a public ledger that we do not own and cannot modify. Once something is on chain it is visible to anyone, worldwide, forever, and neither we nor you can delete it. Your wallet address and its full history are public by design.
This has a consequence you should understand before you use the platform: the rights described further down — erasure in particular — apply to our own records, not to the blockchain. We can delete your account and what we store about you. We cannot delete a transaction.
What we process, and why
| Data | Why | Legal basis |
|---|---|---|
| Wallet public keys and addresses | They are your identity on the platform: they are how we know which pieces are yours and how you sign in. | Performance of a contract |
| Username, avatar, bio, country, social handles | Your public profile, as you choose to fill it in. | Performance of a contract |
| Email address | Optional. Only used to verify the address and send you the notifications you have turned on. You can use the platform without giving us one. | Consent |
| Activity on the platform | Purchases, sales, listings, bids, tips, claims and subscriptions — the record that makes your wallet, your history and the public rankings work. | Performance of a contract |
| Where you came from | The campaign or referring site of your first visit, so we know which channels work. Aggregated for our own reporting; never sold, never shared. | Legitimate interest |
| Server logs: IP address, browser, requested page | Security, abuse detection and diagnosing failures. This is standard web server logging. | Legitimate interest |
| Last access and last seen | Session handling and the online-presence indicator. | Performance of a contract |
What we never hold: your private keys
Your wallet's private keys are generated in your browser and stored there, encrypted with your password. They never reach our servers. We cannot spend your funds, we cannot move your pieces, and we cannot recover your wallet for you if you lose your password and your backup. That is a deliberate trade-off: it costs us the ability to help you recover, and it buys you a platform that cannot be compelled to hand over what it does not have.
Who else sees your data
| Recipient | What reaches them |
|---|---|
| The Bitcoin SV blockchain | Everything on chain: addresses, transactions, inscriptions. Public and permanent, as explained above. |
| GorillaPool | Our on-chain data provider and content gateway. We query it with wallet addresses and inscription identifiers, and your browser fetches each piece's artwork directly from it — so your IP address reaches it whenever a page shows pieces. |
| WhatsOnChain | Wallet balances and transaction lookups, queried from our servers. Wallet addresses reach it; your IP does not. |
| Our email provider | Your email address and the message, when we send you one. |
| Your browser's push service | If you enable browser notifications, delivery goes through the push service of your browser vendor. Turning notifications off ends this. |
We do not sell personal data, we do not share it for advertising, and we do not run third-party analytics or tracking. Some of the recipients above operate outside the European Economic Area; where that is the case, the transfer relies on the safeguards those providers make available.
How long we keep it
Account and profile data for as long as your account exists. Activity records for as long as they are needed to show your history and settle what is owed. Server logs for a limited period, as a rolling window. On-chain data, as explained, is not ours to delete.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. Write to [email protected] from the address linked to your account, or from the account itself if you have not given us an email. If you think we have handled your data badly you can complain to the data protection authority of your country of residence.
Two honest limits on the right to erasure. First, the blockchain: we cannot remove transactions or inscriptions from it. Second, some records must survive an account deletion in aggregate form — a sale involves a counterparty who is entitled to their own history.
Storage on your device
What we store in your browser, why, and how to remove it, is covered in detail in our Cookie Policy. Short version: only what is strictly necessary, no analytics, no tracking, no banner.
Changes
If we change how we handle your data we will update this page before the change takes effect. It is worth re-reading if you have been away for a while.