1. Who is responsible
Chatple ("we") is responsible for personal information collected through Chatple. This policy is intended to meet the New Zealand Privacy Act 2020 and, where they apply to you, the EU and UK General Data Protection Regulation (GDPR) and similar laws.
2. On-chain data is public and permanent
Your wallet address, every transaction you sign, token metadata you launch (name, ticker, image link, description) and on-chain records of beneficiaries and payouts are written to the public Solana blockchain. Anyone can see them, link them to other activity, and copy them. We do not control the blockchain and cannot change or delete on-chain data, including in response to a deletion request. Think about this before linking a wallet to your identity.
3. What we collect
- Wallet data: public wallet addresses you connect or register for payouts, the signed sign-in message that proves you control them, and your transactions with Chatple pools (which we also read from the blockchain), and periodic samples of the $CHATPLE balance of those wallets (also public on-chain), used to work out holder tiers, fee rebates and the caller bond.
- Social account data: when you sign in with or verify an account on X, Twitch, YouTube/Google, TikTok, Kick, Instagram, Threads, Discord, Telegram, GitHub, Reddit or another supported platform, we receive that platform's account identifier, handle, display name and profile picture. We do not receive your password, and we request only the scopes needed to confirm identity. We also store handles that launchers name as beneficiaries, even if the owner has never used Chatple.
- Content: chat messages, calls and their comments, token names, images and descriptions, reports you file, and translations we generate of messages.
- Referral data: the caller or invite code in a link you opened, and the resulting attribution of your trades.
- Technical data: IP address and the country derived from it (used for regional restrictions and abuse prevention), device and browser type, request logs, and error reports.
- Cookies and local storage: a session cookie, a referral cookie, a language preference and interface settings. See the Cookie Notice.
- Correspondence: what you send us by email or support channels, including any proof of identity or rights for takedown, claim or do-not-pay requests.
We do not ask for government ID for normal use. If the law later requires identity verification for payouts, we will tell you before collecting it.
4. How we use it
- to provide the Service: sign you in, show rooms and chat, build transactions for you to sign, and display your activity (performance of our contract with you);
- to calculate, verify and pay creator shares and caller rewards, including checking that a named account belongs to the person claiming it (contract and legitimate interests);
- to prevent fraud, spam, market abuse, self-referral and impersonation, enforce our Terms, and apply regional and sanctions restrictions (legitimate interests and legal obligation);
- to translate chat messages on request, and to keep the Service secure, reliable and improving (legitimate interests);
- to meet legal, tax, accounting and regulatory obligations and respond to lawful requests (legal obligation); and
- to send service messages, and, where you have opted in, Telegram notifications (consent, which you can withdraw).
We do not sell personal information and do not use it for third-party advertising.
6. International transfers
Our providers may store or process information outside your country, including in the United States. Where required, we rely on safeguards such as standard contractual clauses, or on the comparable protection that applies under New Zealand's Privacy Act 2020 (Information Privacy Principle 12).
7. How long we keep it
- Account, wallet and linked-account records: while your account is active, then up to [RETENTION PERIOD — e.g. 2 years] after it closes.
- Payout, fee and ledger records: as long as tax and accounting law requires (generally [e.g. 7 years]).
- Chat messages: while the room exists, unless removed earlier by you, moderation, or a valid deletion request.
- IP addresses and request logs: up to [e.g. 90 days], longer only when needed to investigate abuse.
- Abuse, sanctions and enforcement records: as long as reasonably needed to prevent repeat abuse or meet legal duties.
On-chain data is permanent and outside this retention policy.
8. Your rights
Depending on where you live, you may have the right to:
- ask whether we hold information about you and get a copy (access);
- ask us to correct information that is wrong (correction);
- ask us to delete information, subject to legal retention duties and the limits of the blockchain (erasure);
- object to or ask us to restrict certain processing, and withdraw consent where we rely on it;
- receive information you gave us in a portable format; and
- complain to a regulator — in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz); in the EU or UK, your local data protection authority or the UK ICO.
To make a request, email hello@chatple.com. We may need to verify your identity, for example by asking you to sign a message with your wallet or sign in with the linked account. We aim to respond within 20 working days (New Zealand) or one month (GDPR), and will tell you if we need longer.
9. Security
We use reasonable technical and organisational measures, including signed session cookies, separated operational keys and access controls. No system is completely secure. We never ask for your seed phrase or private key; anyone who does is not us. If a breach is likely to cause you serious harm, we will notify you and the relevant regulator as the law requires.
10. Children
The Service is not for anyone under 18. We do not knowingly collect information from children and will delete it if we learn we have.
11. Changes
We will post updates here with a new version number and effective date, and give notice in the Service for material changes.
12. Contact
Chatple, not applicable (no registered office; contact us by email). Email: hello@chatple.com.
Privacy officer: [PRIVACY OFFICER NAME].