Skip to content

You’re on the glow test network (Solana devnet). Tokens have no value. Time runs fast: 1 day = 10 minutes.

glowglow

Legal

Privacy Policy

Privacy at a glance

This summary is here to help you read the policy. It is not part of the binding policy. If it conflicts with the numbered sections, the numbered sections apply.

  • We never hold your private keys. You either connect your own Solana wallet or use an embedded wallet provided by Privy. You can export the keys of an embedded wallet.
  • Sign-in reads your username, and that is all we use. When you sign in with a social account, we ask the platform for your username, plus the display name and photo we show you so you can confirm the account. We revoke our access right after reading the username. We never post for you and never read your messages.
  • The blockchain is public and permanent. Anything recorded on Solana cannot be changed or deleted by us or anyone else. This includes nominated usernames and the wallet you claim fees to.
  • If someone nominated your account: we never contact you. Your username is shown with the token, and it stays visible after the claim window ends or after you decline. You can block future nominations of your account.
  • We do not sell your personal data and do not use it for advertising.
  • You have rights over your data, including access, correction, deletion and objection, subject to the limits of public blockchains. See Sections 13 and 14.
  • Questions or requests: [Legal Email].

1. Who we are and what this policy covers

1.1 Controller. [Company Legal Name], a company registered at [Registered Address] ("glow", "we", "us" or "our"), is responsible for the personal data described in this policy. Under the EU and UK General Data Protection Regulation ("GDPR" and "UK GDPR") we are the "controller". Under Türkiye's Law No. 6698 on the Protection of Personal Data ("KVKK") we are the "data controller" (veri sorumlusu).

1.2 Scope. This policy explains how we handle personal data when you:

(a) visit or use our website at https://www.glowlink.fun and the web application on it (together, the "Service");

(b) connect a wallet, launch a token, trade, or claim or decline creator fees through the Service;

(c) sign in with a social account to claim, decline or block nominations;

(d) contact us, or report a token or content to us; or

(e) are a person whose social username a launcher has entered in a nomination, even if you have never used the Service (see Section 15).

1.3 What this policy does not cover. This policy does not cover how the following handle your data: the Solana network and its validators; Meteora and its Dynamic Bonding Curve and DAMM v2 programs; the social platforms you sign in with; Privy's own services; block explorers; other websites; or wallet software you install yourself. Each of these has its own terms and privacy practices. Our on-chain programs are smart contracts: once we deploy them, they run on the public blockchain, and data written to them is public by design (see Section 5).

1.4 Relationship to our Terms. This policy should be read with our Terms of Service at https://www.glowlink.fun/legal/terms (the "Terms"). It explains how we handle personal data; it is a notice to you, not a contract. Words defined in the Terms have the same meaning here unless this policy defines them differently.

2. Key terms

In this policy:

(a) "Launcher" means a person who creates a token through the Service.

(b) "Nomination" means a launch in which the Launcher names a social account on X, TikTok, Instagram, YouTube, Kick or GitHub, by username only, as the intended recipient of the creator fee.

(c) "Nominee" means the person who holds the nominated username on that social platform. A Nominee was not asked, is not affiliated with the token, and did not create or endorse it.

(d) "Claimer" means a person who signs in with the nominated username during the claim window and claims the creator fee.

(e) "Holder" means a wallet that holds a token launched through the Service.

(f) "On-chain data" means data recorded on the Solana blockchain, including data written by our programs.

(g) "Personal data" means information about an identified or identifiable individual. It includes "personal information" as defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), and "kişisel veri" under KVKK.

3. The personal data we collect

We collect only what we need to run the Service, keep it secure and meet our legal obligations. The categories are listed below, together with where the data comes from.

3.1 Wallet and on-chain data

(a) Wallet addresses. These are the public addresses of wallets you connect or create through the Service. They come from you, when you connect a wallet, or from our wallet provider, when you create an embedded wallet.

(b) Transactions and program activity. This covers launches, first buys, trades, fee claims, declines, "stop receiving" actions, buyback and burn transactions, and holder distributions. We read this data from the public blockchain and our indexing systems.

(c) Token details. These are the name, symbol, image and any other metadata a Launcher gives for a token, and the Launcher's choices at launch (creator fee tier, claim window, fallback). This data may contain personal data if a Launcher includes it. It is published at launch and cannot be changed afterwards (except that the fallback can switch under the liveness rule in the Risk Disclosure, Section 12.5).

3.2 Social sign-in data

When you sign in with X, TikTok, Instagram, YouTube, Kick or GitHub through our official sign-in (OAuth), we receive:

(a) the social platform and your username. We use these to check whether your account matches a Nomination, and to record a claim, decline or do-not-nominate request; and

(b) your display name and profile photo. We show these to you only so that you can confirm you signed in with the right account.

See Section 6 for how we limit what we request and how we revoke access.

3.3 Nomination data (about Nominees)

When a Launcher creates a Nomination, the Launcher gives us a social platform and a username. We did not collect this data from the Nominee. We store it in the Nomination record on-chain, where it becomes public and permanent (Section 5). We also display it on the token's page on our website. See Section 15 for what this means for Nominees.

3.4 Embedded wallet and email data

If you create an embedded wallet using a passkey or email sign-in, the wallet is provided by Privy. If you choose email sign-in, we process your email address to create and access that wallet. We never receive or store your private keys, seed phrase or passkey secrets.

3.5 Device, IP and security data

When you use the Service, we and our providers automatically collect:

(a) your IP address and the approximate location derived from it (country or region, not your precise location);

(b) device and browser data, such as browser type and version, operating system, language, screen size and time zone;

(c) log data, such as pages requested, time of request, referring page, response codes and error details; and

(d) error reports, which our error-monitoring provider (Sentry) captures when something breaks.

We use this data to run the Service and keep it secure, to prevent fraud and abuse, and to apply the sanctions and location checks described in Section 3.6.

3.6 Compliance data

(a) Location checks. We use your IP address to block access from sanctioned and restricted jurisdictions, including [Restricted Jurisdictions].

(b) Wallet screening. We send wallet addresses that interact with the Service to [Sanctions Screening Provider]. It checks them against sanctions lists and related risk data and returns a result, such as a risk score or a list match.

(c) Age confirmation. We ask you to confirm that you are at least 18.

We do not currently ask for identity documents.

3.7 Cookies and analytics data

We use a small number of cookies and similar technologies for your sign-in session and your preferences. We also use privacy-friendly analytics that produce aggregate statistics. See Section 17.

3.8 Support messages and reports

When you contact us, or report a token or content (for example, impersonation, minors, intellectual property or illegal content), we collect what you send us. This typically includes your contact details, your message, the token or account concerned, any attachments, and our replies.

3.9 Data we do not collect

We do not collect:

(a) private keys, seed phrases or passkey secrets;

(b) passwords for your social accounts;

(c) your social posts, direct messages, contacts, followers or other content from your social accounts;

(d) identity documents (see Section 3.6);

(e) precise geolocation; or

(f) special categories of personal data, such as health, religion or biometric data.

Please do not send us any of these. No one from glow will ever ask you for a seed phrase or private key. Anyone who does is not us.

4.1 The table below lists what we use personal data for. It also lists our legal basis under the GDPR and UK GDPR (Article 6) and under KVKK (Article 5).

#PurposeMain data usedGDPR / UK GDPR basisKVKK basis
1Providing the Service: connecting wallets, launching tokens, building transactions for you to sign, showing balances, prices and token pagesWallet and on-chain data, token details, device dataPerformance of a contract (Art. 6(1)(b))Art. 5(2)(c): necessary for a contract
2Running Nominations: storing and displaying nominated usernames, running claim windows, claims, declines and "stop receiving"Nomination data, social sign-in data, wallet addressesContract, for Launchers and Claimers. Legitimate interests (Art. 6(1)(f)), for Nominees who have not signed in (see Section 15)Art. 5(2)(c). Art. 5(2)(d), data made public by the data subject. Art. 5(2)(f), legitimate interest
3Verifying sign-in and co-signing claims and declines with our attester keySocial platform, username, wallet addressContractArt. 5(2)(c)
4Enforcing product rules, for example that a Launcher cannot claim the creator fee of a token they launched, and that Claimers are 18+Wallet addresses, on-chain data, sign-in data, age confirmationLegitimate interests (keeping the Service fair and lawful). ContractArt. 5(2)(c), (f)
5Honouring do-not-nominate requestsSocial platform, usernameLegitimate interests (respecting account owners' wishes). ContractArt. 5(2)(c), (f)
6Running fallbacks: buyback and burn, and holder distributions, including eligibility checks based on balances and holding time, exclusion of pools and vaults, our own accounts, the Launcher and wallets they funded, listed exchanges, wallets on the sanctions screening list we use and wallets that cannot receive SOL, and publishing each distribution round's datasetPublic on-chain data about Holders and walletsLegitimate interests (carrying out the fallback the Launcher selected at launch)Art. 5(2)(d), (f)
7Sanctions screening and location blockingIP address, approximate location, wallet addresses, screening resultsLegal obligation (Art. 6(1)(c)) where sanctions law applies to us. Otherwise legitimate interests (avoiding sanctioned activity)Art. 5(2)(ç): legal obligation. Art. 5(2)(f)
8Security, fraud and abuse prevention, error monitoring, protecting our keys and programsIP, device, log and error data, wallet addressesLegitimate interests (a secure and reliable Service)Art. 5(2)(f)
9Moderation: reviewing reports and hiding tokens from our websiteReport contents, token details, nomination dataLegitimate interests (a safe Service; protecting the rights of others). Legal obligation where the law requires actionArt. 5(2)(ç), (e), (f)
10Support: answering your messages and requestsContact details, messages, relevant account dataContract. Legitimate interestsArt. 5(2)(c), (f)
11Aggregate analytics to understand and improve the ServiceAggregate usage dataLegitimate interests. Consent where the law requires it (see Section 17)Art. 5(2)(f). Explicit consent (Art. 5(1)) if required
12Remembering your preferencesPreference cookiesLegitimate interests. Consent where the law requires itArt. 5(2)(f)
13Complying with law, responding to lawful requests, and establishing, exercising or defending legal claimsAny relevant dataLegal obligation. Legitimate interestsArt. 5(2)(ç), (e)
14Business transfers, for example a merger or sale of assetsAny relevant dataLegitimate interestsArt. 5(2)(f)

4.2 Where we rely on legitimate interests, we have weighed our interests against your rights. You can ask us for more information about this balancing test and can object at any time (see Section 13).

4.3 Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before it.

4.4 If you do not provide data. Some data is needed to use the Service. For example, you cannot trade without a wallet address, and you cannot claim without signing in with the nominated username. If you do not provide it, you cannot use the affected feature.

4.5 No advertising, no sale. We do not use personal data for targeted advertising. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

5. Public and permanent on-chain data

5.1 The blockchain is public. The Service runs on the Solana blockchain. Transactions and program data are visible to anyone. They are copied across many independent computers around the world and indexed by third parties such as block explorers and analytics sites. Neither we nor anyone else can change or delete data once it is recorded on-chain.

5.2 What becomes public through the Service. Using the Service can publish the following data permanently:

(a) your wallet address and every transaction it signs, including launches, trades, claims and declines;

(b) token names, symbols, images and metadata;

(c) the nominated social platform and username, which are stored in the Nomination record and emitted in our program events;

(d) the status of a Nomination, for example whether it was claimed, declined or expired, or switched to "stop receiving", and the fallback that applies;

(e) the wallet a Claimer chooses to receive fees. A claim publicly links that wallet to the nominated username;

(f) holder distribution payouts to Holders' wallets; and

(g) the dataset of each holder distribution round. Before a round is paid, we publish its dataset, which lists the eligible and excluded wallet addresses, their weights and amounts, and a reason code for each exclusion (for example, that a wallet was funded by the Launcher or belongs to an exchange). We record the dataset's hash on-chain so that anyone can check it.

5.3 Nominee names stay visible. A nominated username stays visible on-chain and on our website after the claim window ends and after a decline. This is part of the token's permanent public record.

5.4 Hiding from our website. We can hide tokens and related information from our own website, for example after a report. Hiding does not remove anything from the blockchain or from third-party sites.

5.5 Linking wallets to you. A wallet address does not reveal your name on its own. However, anyone may be able to link a wallet to you by combining public on-chain data with other information. For example, a claim links a wallet to a nominated username. Consider this before you use a wallet that is already linked to your identity.

5.6 Our role. We are responsible for the on-chain data our programs are designed to record. We cannot control how third parties copy, index or analyse public blockchain data.

6. Social sign-in: what we request and how we limit it

6.1 Why we use social sign-in. Social sign-in is only for:

(a) claiming or declining a Nomination;

(b) choosing "stop receiving" after a claim; and

(c) blocking future Nominations of your account ("do-not-nominate").

You do not need a social account to launch or trade.

6.2 We ask for as little as possible. We ask the social platform for your username. The sign-in screen may also return your display name and profile photo, which we show you so that you can confirm the account. Some platforms only offer permission sets that technically allow more than this, such as a basic profile or read permission. When that happens, we still use the access only to read your username.

6.3 We revoke access straight away. As soon as we have read your username, we revoke the access token the platform gave us. We do not keep that token. We never post, like, follow, send messages or read your messages, posts, contacts or followers.

6.4 Matching is by username only. A claim is matched only to the username the Launcher typed. If a username changes hands, its current holder can claim. We do not check who held the username at launch.

6.5 Checking permissions yourself. You can review and remove app permissions in each platform's account settings, for example the "connected apps" or "security" section. For YouTube and Google, see Section 7.4.

6.6 Our attester. After checking your sign-in, our attester key co-signs your claim or decline so that our on-chain escrow program can process it. It co-signs only after our systems confirm that the signed-in username matches the Nomination and that the other checks in our Terms (such as eligibility and sanctions screening) are met.

7. YouTube API Services

7.1 We use YouTube API Services. When you sign in with YouTube, the Service uses YouTube API Services to read your channel handle. By signing in with YouTube, you agree to the YouTube Terms of Service: https://www.youtube.com/t/terms. Google's handling of your data is governed by the Google Privacy Policy: https://policies.google.com/privacy.

7.2 What we access, store and use.

(a) Accessed: your YouTube channel handle. The sign-in may also return your channel's display name and profile image, which we show you so that you can confirm the account.

(b) Stored: the channel handle, together with any claim, decline, "stop receiving" or do-not-nominate record you create.

(c) Not accessed: your videos, comments, subscriptions, subscribers, playlists, analytics, watch history or any other YouTube or Google account data. We never upload, post or change anything on your channel.

(d) Use: only to check that you control the nominated handle, and to record your choice.

7.3 Sharing.

(a) We do not sell YouTube API data or share it with advertisers.

(b) We do not let third parties serve content or advertisements through our use of YouTube data, or place cookies through it.

(c) Internally, the handle is used by our sign-in service and our attester.

(d) The handle that appears on-chain is the one the Launcher typed when creating the Nomination.

7.4 Revoking access. We revoke our access token right after reading your handle. You can also check and remove the Service's access at any time in your Google security settings: https://security.google.com/settings/security/permissions. To ask us to delete stored YouTube API data, email [Legal Email]. We will delete it within [7 days], except where Section 14 explains we cannot or must not.

7.5 Google API Services User Data Policy. Our use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including its Limited Use requirements.

8. How we share personal data

8.1 Service providers (processors). We share personal data with the providers below. Each processes it for us under a written contract that requires confidentiality and security.

ProviderWhat they do for usPersonal data involved
PrivyEmbedded wallets (passkey and email) and wallet authenticationEmail (if used), wallet address, device and session data
HeliusSolana RPC: sending transactions and reading blockchain dataIP address, wallet addresses, transaction data in requests
Amazon Web Services (AWS)Hosting and key management, including our attester keyData stored or processed on our servers
[Hosting Provider]Website hosting and content deliveryIP address, device and request data
SentryError monitoringError reports, device data, IP address (masked where possible)
[Email Provider]Sending and receiving support and service emailsEmail address, message content
[Sanctions Screening Provider]Wallet sanctions and risk screeningWallet addresses, screening results
[Analytics Provider]Privacy-friendly aggregate analyticsAggregate usage data (see Section 17)

8.2 Social platforms. When you sign in, you are sent to X, TikTok, Instagram (Meta), YouTube (Google), Kick or GitHub. The platform learns that you are signing in to the Service. Each platform handles your data under its own privacy policy.

8.3 The public. Data recorded on-chain is public (Section 5). Token pages on our website also show public information, such as nominated usernames and Nomination status.

8.4 Legal and safety reasons. We may disclose personal data when we believe in good faith that it is needed to:

(a) comply with law, a court order or a lawful request from a public authority;

(b) enforce our Terms;

(c) protect the rights, property or safety of users, the public or us; or

(d) report illegal content where the law requires it.

8.5 Business transfers. If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. It will remain subject to this policy or to protections at least as strong.

8.6 Professional advisers. We may share personal data with our lawyers, auditors and insurers where needed. They are bound by confidentiality.

8.7 With your direction. We share personal data in any other way you ask us to.

8.8 What we do not do. We do not sell personal data, rent it, or share it for advertising.

9. International transfers

9.1 Our providers and the social platforms process data in several countries, including the United States. These countries may not offer the same level of protection as where you live.

9.2 When we transfer personal data out of the European Economic Area, the United Kingdom or Türkiye, we use a lawful transfer mechanism, such as:

(a) an adequacy decision, including the EU-U.S. Data Privacy Framework and the UK Extension where the recipient is certified;

(b) the European Commission's Standard Contractual Clauses;

(c) the UK International Data Transfer Agreement or Addendum; and

(d) for Türkiye, the standard contracts under KVKK Article 9, notified to the Personal Data Protection Authority as required, or another basis permitted by that Article.

You can ask us for a copy of the relevant safeguards at [Legal Email].

9.3 Blockchain. By its nature, on-chain data is replicated to nodes worldwide. This is unavoidable when you choose to transact on a public blockchain.

10. How long we keep personal data

10.1 We keep personal data only as long as we need it for the purposes in Section 4, including to meet legal, tax, accounting and dispute-resolution needs. The proposed default periods are below.

DataRetention period
Social access (OAuth) tokenNot stored. Revoked immediately after reading the username (Section 6.3)
Display name and profile photo shown at sign-inNot kept after the sign-in session
Sign-in session cookieAbout 30 minutes, or until you sign out
Preference cookies[12 months]
Social platform and username linked to a claim, decline or "stop receiving" recordFor as long as the Nomination and its fee arrangement exist, plus [6 years] for legal, tax and dispute records
Do-not-nominate recordUntil you ask us to lift the block
Email address (Privy email sign-in), as held by usUntil you ask us to delete your embedded wallet login, plus [30 days]. Privy's own retention applies to what Privy holds
Server and security logs, including IP address and device data[30 days]. Up to [12 months] where linked to a security incident, fraud investigation or report
Sanctions screening and location-check results[5 years] after the screening
Error monitoring data (Sentry)[90 days]
Analytics data[26 months]. Aggregate statistics that cannot identify you may be kept indefinitely
Holder distribution eligibility calculations and payout records[6 years]
Support messages and reports[3 years] after the case is closed
BackupsOverwritten on a rolling [35-day] cycle
On-chain dataPermanent. We cannot delete it (Section 5)

10.2 We may keep data for longer where the law requires it, or where we need it to establish, exercise or defend legal claims (for example, under a legal hold). When a retention period ends, we delete or anonymise the data.

11. Security

11.1 We use technical and organisational measures that are appropriate to the risk, including:

(a) encryption in transit;

(b) access controls based on least privilege;

(c) managed key storage (AWS key management) for our attester key;

(d) a multisignature wallet with a timelock for administrative functions of our programs;

(e) a separate emergency guardian key that can, at once, pause registrations, claims and declines, and fallbacks, revoke the attester and distributor keys, and cancel a holder distribution round (only the multisignature wallet can lift a pause or appoint keys);

(f) revocation of social access tokens right after use;

(g) monitoring and logging; and

(h) due diligence on our providers.

11.2 We do not hold your private keys. Keeping your wallet, keys, seed phrase, passkeys, devices and email account secure is your responsibility. Only sign in through our official website at https://www.glowlink.fun. Check the address before you sign any message or transaction.

11.3 No system is completely secure. We cannot guarantee the security of data sent over the internet, of the blockchain, or of third-party services. If a personal data breach occurs, we will notify the relevant authorities and affected people as the law requires.

12. Automated processing

12.1 Some decisions in the Service are made automatically:

(a) Sanctions and location checks can block access from certain locations or for certain wallets.

(b) The attester checks that the username you signed in with matches the Nomination before it co-signs a claim or decline.

(c) Holder distribution eligibility is calculated by our off-chain systems (our distributor key) from public on-chain data. Each holder's weight is their balance multiplied by the time they held it. The calculation excludes pools and vaults, our own accounts and keys, the Launcher and wallets the Launcher funded, listed exchanges, wallets on the sanctions screening list we use (their share goes to the other eligible holders) and wallets that cannot receive SOL. It also applies a minimum holding and minimum payouts. The rules are published and applied as published, and they may exclude any wallet. Each round's dataset, including the reason code for each exclusion, is published for a day before the round can be paid, so anyone can check it.

12.2 If you believe an automated check has affected you wrongly, for example that you were blocked in error, contact [Legal Email]. A person will review it. This does not mean that on-chain outcomes can be reversed. For example, a fallback that has already taken effect cannot be undone.

12.3 We do not use personal data to build advertising or marketing profiles.

13. Your rights

13.1 Everyone

Whatever your location, you can contact us at [Legal Email] to ask what personal data we hold about you, or to ask us to correct or delete it. We will respond in line with this Section and Section 14.

13.2 EEA and United Kingdom

13.2.1 If the GDPR or UK GDPR applies to you, you have the right to:

(a) access your personal data and receive a copy;

(b) correct inaccurate or incomplete data;

(c) erase your data in certain cases;

(d) restrict processing in certain cases;

(e) data portability, meaning you can receive data you gave us in a structured, machine-readable format, or have it sent to another controller;

(f) object to processing based on legitimate interests, including the processing of nominated usernames;

(g) withdraw consent at any time, where we rely on consent; and

(h) complain to a supervisory authority. In the EEA, this is the authority where you live, work or where the alleged infringement took place. In the UK, it is the Information Commissioner's Office (https://ico.org.uk).

13.2.2 We will respond within one month. We can extend this by two further months for complex or numerous requests, and if we do we will tell you.

13.2.3

13.3 Türkiye (KVKK)

13.3.1 If KVKK applies, you have the rights set out in Article 11 of KVKK. You may:

(a) learn whether your personal data is processed, and request information about it;

(b) learn the purpose of the processing and whether the data is used for that purpose;

(c) know the third parties in Türkiye or abroad to whom your data is transferred;

(d) request correction of incomplete or inaccurate data;

(e) request deletion or destruction under the conditions in Article 7;

(f) request that third parties who received your data be told of a correction or deletion;

(g) object to a result against you that arises only from automated analysis of your data; and

(h) claim compensation for damage caused by unlawful processing.

13.3.2 How to apply. You can apply to us in writing at [Registered Address]. You can also apply by registered electronic mail (KEP), secure electronic signature or mobile signature, or from the email address you have previously given us, to [Legal Email]. Your application should include:

(a) your name, surname and signature (for written applications);

(b) your identity details as required by law;

(c) your address or email for replies; and

(d) the subject of your request.

13.3.3 Our response. We will respond free of charge within 30 days. If responding involves a separate cost, we may charge the fee set by the Personal Data Protection Board. If you are not satisfied with our response, you can complain to the Board (https://www.kvkk.gov.tr) within the periods set by law.

13.3.4 Collection method. We collect personal data by automated means: through the Service, social sign-in, our providers and the public blockchain. We process it on the legal bases in Section 4.

13.3.5

13.4 California (CCPA/CPRA)

13.4.1 This section applies to California residents where the CCPA applies to us.

13.4.2 Categories collected in the last 12 months.

CCPA categoryExamplesSourcesDisclosed for a business purpose to
IdentifiersWallet address, social platform and username, email address, IP addressYou, your device, Privy, social platforms, Launchers (for Nominees), the blockchainService providers listed in Section 8
Customer records (Cal. Civ. Code § 1798.80(e))Email address, support correspondenceYouEmail provider, hosting
Commercial informationLaunches, trades, claims, distributions receivedYou, the blockchainService providers; the public (on-chain)
Internet or network activityLog, device and error data; interactions with the ServiceYour deviceHosting, Sentry, analytics, RPC provider
Geolocation (approximate)Country or region derived from IPYour deviceSanctions-screening and hosting providers

We do not collect sensitive personal information as defined by the CCPA. We do not create inferences to profile consumers. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the last 12 months. We do not knowingly sell or share the personal information of consumers under 16. Retention periods are in Section 10.

13.4.3 Your rights. You have the right to:

(a) know what personal information we collect, use and disclose, and to access it;

(b) delete it;

(c) correct it;

(d) opt out of sale or sharing (we do neither);

(e) limit the use of sensitive personal information (we do not collect any); and

(f) not be discriminated against for exercising these rights.

13.4.4 Global Privacy Control. We treat a Global Privacy Control signal as a valid opt-out request.

13.4.5 Authorised agents. You can use an authorised agent. We may ask for proof of the agent's authority and may ask you to verify your identity directly.

13.4.6 Response time. We will respond within 45 days. We can extend this by a further 45 days, and if we do we will tell you.

13.5 Other jurisdictions

Other laws, including other US state privacy laws, may give you similar rights, such as the right to appeal our decision on a request. To use them, contact us at [Legal Email]. If we decline a request, we will explain how to appeal.

13.6 How to exercise your rights and how we verify you

13.6.1 Email [Legal Email] with the subject "Privacy request". Tell us your request and the wallet address or social username it concerns.

13.6.2 Wallet addresses and usernames are not proof of identity, so we will verify that the data relates to you before we act. We may ask you to:

(a) sign a message with your wallet. This is a free signature, not a transaction, and it never moves funds;

(b) sign in through our official sign-in with the social account concerned; or

(c) confirm your email address.

13.6.3 Verification never involves your seed phrase or private key, and we will never ask you for either.

13.6.4 We may refuse, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, as the law allows.

14. Deletion requests: what we can and cannot delete

14.1 What we can delete. On a valid request, we will delete or anonymise the personal data we hold off-chain, unless an exception below applies. This includes:

(a) support messages;

(b) email records we hold;

(c) logs and error data;

(d) analytics records that identify you; and

(e) sign-in records we no longer need.

14.2 What we cannot delete.

(a) On-chain data. This includes wallet addresses, transactions, token details, nominated usernames in Nomination records and program events, claim and decline records, and the wallet a Claimer chose. No one can change or delete it (Section 5).

(b) Copies held by others. This includes block explorers, analytics sites, social platforms, and anyone who has copied public data.

(c) Data held by Privy or other independent controllers. Contact them directly. We will pass on your request where we can.

14.3 What we may need to keep.

(a) Records we need to comply with law, including sanctions screening results.

(b) Records we need to establish, exercise or defend legal claims.

(c) Records needed to keep an existing arrangement working. For example, we need a claim record to keep paying future creator fees to a Claimer. We need a do-not-nominate record to keep honouring the block.

(d) Security and fraud records, for the periods in Section 10.

14.4 What we can do instead. We may be able to hide a token or related information from our own website (see Sections 5.4 and 15). We will tell you what we deleted, what we kept and why.

15. If your account has been nominated

15.1 How we got your username. A Launcher typed your social platform and username when creating a token. We did not collect it from you. We never contact Nominees. Launchers share a public claim link themselves. A Nomination does not mean you are affiliated with the token or endorse it.

15.2 What we process. We process:

(a) your social platform and username, exactly as the Launcher typed it;

(b) the token it relates to;

(c) the claim window, which the Launcher chose (3 to 21 days from launch); and

(d) the Nomination's status.

This data is public and permanent on-chain. It is also shown on our website, and it stays visible after the claim window ends or after a decline (Section 5.3).

15.3 Your choices.

(a) Do nothing. When the window closes, the creator fee goes permanently to the fallback the Launcher selected. We keep no further personal data about you beyond the Nomination record.

(b) Claim. You must be 18 or older. You sign in with the nominated account and choose a wallet. The wallet will be publicly linked to your username on-chain (Section 5.2(e)).

(c) Decline. You sign in with the nominated account. No wallet is needed.

(d) Stop receiving. After claiming, you can stop receiving fees. Fees already owed are paid first, in the same transaction, and later fees go to the fallback permanently.

(e) Block future Nominations. You can sign in and turn on do-not-nominate for your account.

(f) Report. You can report the token for impersonation, involvement of a minor, intellectual property infringement or illegal content. We may hide it from our website.

(g) Object or ask for erasure. See Sections 13 and 14. We will consider your request. On-chain records cannot be removed.

15.4 Username changes. Matching is by username only. If you give up or change your username and someone else later holds it, that person can claim any open Nomination of that username.

15.5 Legal basis and notice. We process nominated usernames on the basis of our legitimate interests, and those of Launchers and Nominees, in running the nomination and claim feature (Section 4). This policy is our notice to Nominees about data we did not collect from them.

16. Children

The Service is only for people aged 18 or older. It is not directed at children, and we do not knowingly process their personal data. If we learn that we hold off-chain personal data of someone under 18, we will delete it, subject to Section 14. If you believe a token nominates or depicts a person under 18, report it at [Legal Email]. We may hide the token from our website. We cannot remove on-chain records.

17. Cookies and analytics

17.1 What we use. We use cookies and similar technologies (such as browser local storage) only for the purposes below.

TypePurposeDurationSet by
Strictly necessaryKeeping you signed in during a social sign-in session, and security of that sessionAbout 30 minutesUs
PreferencesRemembering your settings on the Service[12 months]Us
Embedded wallet sessionKeeping your Privy embedded wallet session workingPer Privy's settingsPrivy
AnalyticsPrivacy-friendly aggregate statistics, such as page views and referrers[Session / none][Analytics Provider]

17.2 No advertising or cross-site tracking. We do not use advertising cookies, tracking pixels or cross-site tracking.

17.3 Analytics. [Analytics Provider] is configured to produce aggregate statistics without building profiles of individuals or tracking you across sites.

17.4 Your choices. You can block or delete cookies in your browser settings. If you block strictly necessary cookies, social sign-in will not work. Where the law requires your consent for any cookie, we will ask for it before setting that cookie, and you can withdraw consent at any time through [cookie settings link].

The Service links to, and relies on, third-party services. These include social platforms, Privy, Meteora, Solana block explorers and wallet software. We are not responsible for their privacy practices. Please read their privacy policies.

19. Changes to this policy

19.1 We may update this policy from time to time. We will post the new version at https://www.glowlink.fun/legal/privacy and change the "Last updated" date.

19.2 If a change is material, we will give notice on the Service before it takes effect. Where the law requires, we will also give notice by other means or ask for your consent.

19.3 Changes do not affect on-chain data already recorded.

20. Contact us

  • Controller: [Company Legal Name], [Registered Address]
  • Privacy requests and legal notices: [Legal Email]
  • Reports about tokens, nominations, minors or illegal content: [Legal Email]
  • General support and scam or phishing reports: [Contact Email]
  • EU representative: [EU Representative]
  • UK representative: [UK Representative]
  • KVKK applications: see Section 13.3.2
Questions about this document or about the test? Get support.