Privacy Policy
How the B420 interface at b420.io handles personal data: what it collects, where that data goes, what is permanently public because it lives on a blockchain, and what you can ask us to change or delete.
- We never hold your funds or your keys. Every transaction is signed in your own browser by your own wallet. No B420 server holds a private key or seed phrase for your wallet, or any key that could move your funds or sign a blockchain transaction.
- Your login and wallet come from Privy. We receive a Privy user identifier, your wallet addresses, and, if you use them, your X handle and profile picture or your email address.
- Your profile is public by default. Username, avatar, bio, follows, theses, launches, and your positions, trade activity, PnL and leaderboard rank are visible to anyone unless positions are set to private.
- Onchain data cannot be deleted. Swaps, launches, stakes, token names, images and descriptions are written to the Base blockchain permanently, by you, not by us.
- We do not sell personal data and run no advertising. B420 itself sets one cookie, carrying only a referrer's public username. Named third parties embedded in the interface, including Privy, Cloudflare Turnstile and Stripe, set their own.
- We record your acceptance of the Terms. When you pass the pre-login gate, the version you accepted and a server timestamp are stored on your profile, including your attestation that you are not a US person.
- Card payments and identity checks are handled by Stripe. Card numbers and identity documents never reach B420.
This box is a reading aid, not a binding summary. Only the numbered sections below state what we actually do. Where the two seem to differ, the full text governs.
01Who we are and what this covers
B420 is a trading and launch interface for B20 tokens on the Base network, available at https://b420.io. It is operated by CC0 COMPANY [LEGAL ENTITY NAME AND REGISTERED ADDRESS TO BE COMPLETED] ("we", "us", "our"). For data protection law in the EU and the UK, CC0 COMPANY is the controller of the personal data described here.
This policy applies to the b420.io website, its installable web app, the public read API documented at /docs, and the indexing service that keeps the trading data in the interface up to date.
What this policy does not cover
- The Base blockchain and the smart contracts. Once a transaction is confirmed it is public and permanent. Nobody, including us, can change or remove it. See section 6.
- Third-party services you use through the interface, including Privy for login and wallets, Stripe for card purchases, Relay for bridging, and any external wallet you connect. Each runs under its own privacy policy.
- Tokens launched by other people, the websites and social links their creators wrote onchain, and any site you reach from a link on this interface.
- Tokenized stocks, which are issued and administered by third parties. We do not issue them and do not hold them on your behalf.
Read this together with the Terms of Service. Governing law and venue are set out there: [GOVERNING LAW AND VENUE TO BE COMPLETED WITH COUNSEL].
02Summary in plain language
The short version of sections 3 and 4. It is a reading aid, not a substitute for them.
- A Privy user identifier and the wallet addresses linked to it.
- Your X handle, X user id and profile picture if you log in with or link X, and your email address if you log in by email on desktop.
- The profile you write: username, display name, bio, avatar image.
- Public chain activity for your wallets, indexed into our database: balances, positions, cost basis, trades, PnL, portfolio history, staking and launches.
- What you publish: theses, follows, and token metadata you write onchain at launch.
- Push subscriptions if you turn notifications on, and a referral relationship if you arrive through a referral link.
- Your acceptance of the Terms: the version accepted and a server timestamp, recorded when you pass the pre-login gate.
- Ordinary technical data: request logs at our hosting provider, and aggregate page view and performance metrics.
- Private keys, seed phrases or wallet passwords. No server-side key that could move your funds or sign a transaction exists anywhere in this product.
- Card numbers, bank details or identity documents. Card purchases run inside Stripe's own widget.
- Government identity data. We run no KYC of our own.
- Advertising identifiers or cross-site tracking data. There are no ad networks, no ad pixels and no third-party advertising cookies on this site.
- Precise location, contacts, camera or microphone data. The interface does not ask for them.
03The data we collect
Grouped by where it comes from. Each item names the actual mechanism in the product.
3.1 Account data, through Privy
Login and wallet infrastructure are provided by Privy. On a phone (viewport 760px or narrower) the only login method offered is X, and an embedded wallet is created for accounts that do not already have one. On desktop you can also log in with email or by connecting an external wallet.
When you log in, we store in our own database:
- your Privy user identifier (in the form did:privy:...), used as your profile id;
- each wallet address linked to your account, stored in lower case, with a flag recording whether it is a Privy embedded wallet, and the date it was linked;
- your X handle, X user id and a verification flag, and the profile picture URL from X, which becomes your default avatar, if you log in with or link X;
- your primary wallet address, used to attribute onchain activity to your profile.
- your acceptance of the Terms of Service and this policy, stored on your profile as terms_accepted_at (a timestamp set by our server, not by your browser) and terms_version (the version string of the documents you accepted). This is written when you pass the pre-login gate, where you must tick, as separate deliberate acts, that you accept these documents and that you are not a US person. The record is the evidence of that agreement and of that attestation. Accepting a newer version overwrites the record with the newer one.
Privy holds the identity record itself, including your email address if you log in by email, the X OAuth connection, and the key material for embedded wallets. Our servers verify your Privy access token and read back the fields listed above. We do not receive or store your email address in our own database unless a future feature says otherwise.
3.2 Profile data you choose to provide
- Username: 3 to 20 characters, letters, numbers and underscores only, stored in lower case and unique across the platform. If you do not choose one, we generate anon plus four digits on first login. It appears in your profile URL and everywhere your account is shown, and it doubles as your referral code.
- Display name and bio: free text you write. Both are public.
- Avatar: either a URL you paste, or an image file you upload. Uploaded files are pinned to IPFS through Pinata and we store the resulting public gateway URL. See the warning in section 6 about permanence.
There is no review or moderation of usernames, display names, bios or avatars before they are published.
3.3 Public blockchain activity we index
So the interface can show a portfolio, a PnL figure and a leaderboard, an indexing service reads the public Base chain for the wallet addresses linked to your account and writes the results into our database. This includes:
- Positions: token address and symbol, raw balance, decimals, average cost, remaining cost, realized and unrealized profit and loss (all time, 30 days, 7 days and 24 hours), current value in dollars, and staked amounts.
- Trades: one row per transfer leg, holding the transaction hash, your wallet, the token and symbol, the side (buy, sell, receive or send), the amount, the dollar value and the timestamp.
- Portfolio snapshots: point in time portfolio value and total profit and loss. The profile page serves up to 90 days of this history.
- PnL rollups: realized, unrealized and total figures per window, plus your leaderboard rank.
- Launches: for every token created through B420, the creator address, token name, symbol, image, description, paired quote token, supply, pool details, any dividend vault, the block and transaction hash.
- Indexing state: the last block processed for each wallet.
Transfer history and balances are discovered through third-party chain data providers (Alchemy, Etherscan, Blockscout and public Base RPC endpoints), and dollar values come from third-party market data providers. See section 7. When a swap you make in the interface confirms, the site also writes a swap event row (wallet, profile id, side, token, symbol, dollar value, timestamp) so the indexer can refresh your position quickly and so the trade can be pushed to your followers.
The indexing service runs outside the website codebase. Its hosting provider and its own data handling: [INDEXING SERVICE HOSTING AND SUBPROCESSOR TO BE COMPLETED].
3.4 Content you publish
- Theses: a plain-text case for a position, up to 280 characters, one per token. Stored with your profile id, the token address and timestamps. Shown publicly on that token's holders list and on your profile. There is no review queue and no profanity filter.
- Token metadata at launch: name (up to 48 characters), symbol (up to 12 characters, upper cased), image (uploaded or a URL, pinned to IPFS), description (up to 500 characters), and website, X, Telegram and Discord links (up to 200 characters each). All of this is written into the token contract on Base by your own wallet and is permanent. The launching wallet is recorded as the creator and is shown in the launches feed.
Token pages also display memos, which are messages emitted onchain by arbitrary callers. They are not written by us, we do not verify them, and the only filter applied is that memos containing a link are hidden.
3.5 Social graph
When you follow another profile we store the pair of profile ids and the time. Follower and following lists are publicly readable through the profile API.
3.6 Push notification subscriptions
If you turn on notifications and grant your browser's permission, we store one row per browser or device: the push endpoint URL issued by your browser vendor, the p256dh and auth encryption keys, your profile id and the creation time. These are used to send you a notification when someone follows you and when an account you follow makes a trade, which means a notification can describe another user's trading activity.
3.7 Referral attribution
Opening a link of the form b420.io/r/<username> sets a cookie named b420_ref holding the referrer's username. If you then create a profile, we store that referrer as a permanent referred by field on your profile, so eligible trades can apply the discounted routing fee and pay the referrer their onchain cut. Which trades are eligible is set out in section 9 of the Terms of Service. Full cookie details are in section 12.
3.8 Storage on your own device
These values stay in your browser and are cleared when you clear site data. None of them is sent to our servers, with one exception noted below: the acceptance recorded in b420.terms is also written to your profile once you authenticate.
- b420.terms: the version of the Terms and this policy you accepted at the pre-login gate, the time you accepted on this device, and the not-a-US-person flag. It stops the gate reappearing on every click. The record that counts is the one written to your profile, described in 3.1.
- b420.terms.pending: a marker that an acceptance made on this device has not yet been written to your profile, because you were not authenticated at the time. It is cleared once the write succeeds.
- b420.qb: your preferred quick-buy amount on the markets screen.
- b420.watchlist: your watchlist. It exists only on this device and is never synced to us.
- b420.install.dismissed: records that you dismissed the install prompt.
- b420.chart.v2: your chart engine preference.
- A push prompt key: records that you have already seen the notifications prompt.
- b420_ref_seen in session storage: shows the referral banner once per browsing session.
3.9 Technical and usage data
- Request logs. Our hosting provider (Vercel) and our database provider (Railway) process ordinary request metadata including IP address, user agent, timestamps and requested URLs, in order to serve and protect the service. Retention is set by those providers: [HOSTING AND DATABASE LOG RETENTION TO BE CONFIRMED].
- Aggregate analytics. Vercel Analytics measures page views and Web Vitals performance metrics across the site. It is not used for advertising and does not build a cross-site profile of you.
- IP address for card purchases. When you start a card purchase, our server reads your IP address from the request headers and passes it to Stripe as the customer IP for Stripe's fraud and compliance checks. We do not store it in our database.
- Network-level exposure. Every RPC endpoint, market data API and third-party service your browser calls will see your IP address as the connecting client. That is inherent to using the web and to reading a blockchain.
04What we never collect or hold
- Private keys and seed phrases. B420 is non-custodial. Every state-changing action, including swaps, launches, staking, claims and vault operations, is signed in your browser by your own wallet. No B420 server holds any key that can move your funds or sign a blockchain transaction. Our servers do hold ordinary application secrets, including third-party API credentials and a private key used to sign browser push notification requests, but none of those can touch a wallet, an asset or the chain. For embedded wallets, the key material sits with Privy. If you export your key, it is rendered inside Privy's own isolated window; it never passes through B420 code and we never store it.
- Card numbers, bank details, and identity documents. The card purchase path runs inside Stripe's embedded onramp widget. Stripe collects the payment instrument and performs its own identity checks. We create the session, lock the destination to your connected wallet, and never see card or identity data.
- Your funds. We do not custody tokens, stocks or fiat at any point. Tokenized stocks held as staking rewards or dividends sit in the relevant smart contract, not in an operator wallet.
- Advertising and cross-site tracking data. No ad network, no advertising pixel, no third-party marketing cookie is loaded by this site.
05How we use data, and our legal basis
The legal bases in the right-hand column apply to readers in the EU, the UK and other places with equivalent law. Readers elsewhere can read the column as a plain statement of why we process each item.
- Run your accountContract
- Authenticate you through Privy, create and maintain your profile, link your wallets, and show you your own portfolio, positions, activity and rewards.
- Execute what you ask forContract
- Build swap, launch, staking, claim and vault transactions for you to sign, quote bridge routes, and start card purchase sessions. We build; your wallet signs.
- Public profiles and social featuresContract and legitimate interests
- Publish profiles, holders lists, theses, follows, the leaderboard and shareable PnL images. Our legitimate interest is operating a public, verifiable trading venue where traders can see each other's track records. You can object: see section 11.
- Referrals and fee discountsContract and legitimate interests
- Read the referral cookie, record who referred you, apply the discounted routing fee to eligible trades and pay the referrer their onchain share.
- Push notificationsConsent
- Send device notifications for new followers and for trades by accounts you follow. Processed only after you opt in, and only until you withdraw consent.
- Linking X or emailConsent
- Show a verified handle and profile picture on your profile. You can unlink X in profile settings at any time, unless it is the only login method on your account, which is the case for accounts created on a phone, where X is the only method offered. You must link another login method first.
- Keep the service working and safeLegitimate interests
- Server logs, error diagnostics, abuse and fraud prevention, and protecting the interface and its users from attack and misuse.
- Understand usage in aggregateLegitimate interests
- Page view counts and Web Vitals, used to see which pages are used and where the interface is slow. Not used to profile individuals.
- Comply with lawLegal obligation
- Respond to valid legal requests, meet record-keeping duties that apply to us, and enforce the Terms of Service.
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not build advertising profiles.
06Blockchain data is public and permanent
Read this section before you trade, launch a token, or write anything into the interface. A public blockchain has no delete button, and neither do we.
Every swap, launch, stake, unstake, claim and transfer you make is a transaction on the Base network. It is broadcast to a public, permissionless ledger, replicated by thousands of independent parties, indexed by block explorers and analytics firms we have no relationship with, and retained indefinitely. Your wallet address is a persistent public identifier: anything that ties it to your name, whether by you here or anywhere else, ties it to your whole trading history.
Token metadata you write at launch, including the name, symbol, image reference, description and social links, is stored inside the token contract itself. It cannot be edited, corrected or removed afterwards, by you or by us. Images pinned to IPFS remain retrievable by their content identifier once distributed, even if we stop pinning them.
Deleting your B420 account removes your profile from our database. It does not and cannot delete anything from the blockchain or from IPFS. What deletion achieves is removing the link we hold between your addresses and your name, avatar and social identity.
6.1 What is public by default in the interface
- Your username, display name, bio, avatar, and X handle if you link one.
- Who you follow and who follows you.
- Theses you write, on the token page and on your profile.
- Tokens you launched.
- Your positions, trade activity, profit and loss, up to 90 days of portfolio value history, and your leaderboard rank. The public setting for positions is switched on by default from the moment your profile is created.
- Server-rendered share images at the PnL card endpoint, which turn a named trader's position and percentage into a public PNG at a public URL.
The public read endpoints described at /docs need no authentication and are cached at the edge, so third parties can copy public profile, holder and leaderboard data at scale. Treat anything public here as permanently copyable.
6.2 Making your positions private
A per-profile setting controls whether your positions are public. It is enforced on the server for the profile endpoint, the single-position endpoint and the leaderboard. When it is off, your profile shows identity only, you do not appear with figures on the leaderboard, and share cards render with no data.
There is currently no control in the interface to change this setting yourself. To have it switched off, email legal@b420.io from an account we can tie to your profile, or ask from the wallet you use here. We will confirm when it is applied. [SELF-SERVE POSITIONS PRIVACY TOGGLE TO BE SHIPPED, OR THIS PARAGRAPH UPDATED]
Turning the setting off hides figures in our interface. It does nothing to the blockchain, where your address and its full history remain public.
07Who we share data with
We do not sell personal data and we do not share it for cross-context behavioral advertising. We disclose data to the service providers below, which process it to make the interface work, each under its own privacy policy.
- VercelHosting and analytics
- Serves b420.io and its API from the edge, so it processes every request: IP address, user agent, headers and URLs. Vercel Analytics additionally records page views and Web Vitals in aggregate.
- RailwayManaged database
- Hosts the PostgreSQL database that holds every table listed in section 3, reached over a public TCP proxy.
- PrivyLogin and wallet infrastructure
- Holds your identity record: X OAuth connection, email address if you log in by email, linked wallet addresses, and the key material for embedded wallets. Our servers send Privy your access token to verify it and read back your user record. Privy also uses Cloudflare Turnstile for bot checks during login.
- StripeCard to crypto purchases
- Receives your destination wallet address, the currency (USD or EUR), the amount and your IP address. Stripe collects payment details and runs its own identity checks inside its widget. Card and identity data never reach B420.
- RelayBridging quotes
- Receives your wallet address (as both sender and recipient) and the amount, in order to quote a bridge of ETH from Ethereum mainnet to Base. You sign the resulting transaction yourself.
- Pinata (IPFS)Image pinning
- Receives the image bytes you upload for a token or an avatar, plus a file name label. Pinned content becomes publicly retrievable by content identifier through IPFS gateways and is effectively permanent.
- AlchemyChain data
- Receives wallet addresses in order to enumerate token balances. Alchemy is also the primary Base RPC endpoint your browser connects to, so it additionally receives your IP address as the connecting client, every chain read the interface makes on your behalf, and the contents of every transaction you broadcast through it, including swaps, launches, staking and claims.
- Etherscan and BlockscoutChain data
- Receive wallet addresses in order to return token transfer history used to build your portfolio.
- Base and Ethereum RPC providersChain access
- Public Base endpoints used as fallbacks behind the primary endpoint (currently mainnet.base.org and base-rpc.publicnode.com), and Ethereum mainnet endpoints used for the bridge leg. They see wallet addresses, balance queries and the contents of signed transactions, plus the IP address of whichever party makes the call. Our content security policy permits additional RPC endpoints, so the set of possible fallbacks is wider than the ones named here.
- KyberSwap and 0xSwap routing
- Receive the token pair, the amount and your wallet address as the sender or taker, in order to return a route and calldata for the swap you sign.
- CoinGecko, GeckoTerminal, DexScreenerMarket data
- Receive token and pool addresses for prices, charts and pair data. They do not receive your identity from us.
- Browser push servicesNotification delivery
- Google, Mozilla or Apple, depending on your browser. They receive the subscription endpoint and the encrypted notification payload in order to deliver it to your device.
- Google FontsTypography
- The Inter and Fraunces typefaces load from Google's font servers, so your browser makes a request to Google, including your IP address, on page load.
- Wallet connectorsExternal wallets
- If you connect an external wallet on desktop, that wallet's own infrastructure, which may include WalletConnect or Coinbase Wallet relays, sees your wallet address and connection metadata.
We may also disclose data where we are legally required to, where it is necessary to establish or defend legal claims or enforce the Terms of Service, and, if the business is ever transferred, to the acquiring party as part of that transfer. [BUSINESS TRANSFER AND LAW ENFORCEMENT DISCLOSURE POLICY TO BE CONFIRMED WITH COUNSEL]
08International transfers
The service is delivered from a global content delivery network and most of the providers listed in section 7 operate from the United States. Using B420 therefore involves processing your data outside your own country, including in countries whose data protection law differs from your own.
Where a transfer of personal data leaves the EEA or the UK, the transfer mechanism relied on for each provider is: [TRANSFER MECHANISM PER PROCESSOR, FOR EXAMPLE STANDARD CONTRACTUAL CLAUSES OR THE UK ADDENDUM, TO BE COMPLETED WITH COUNSEL].
Blockchain data is a separate case. Public chain data is replicated worldwide by design, by parties nobody selects or controls. No transfer mechanism can constrain it, and we cannot promise otherwise.
09How long we keep data
- Profile record
- Username, display name, bio, avatar, linked handles and the referral relationship are kept until you ask us to delete the profile. Deleting a profile also removes your wallet links and your PnL rollups.
- Indexed chain data
- Positions, trades, portfolio snapshots and swap events are kept for as long as the interface displays that wallet. Deleting your profile removes the link between your address and your identity; the address-level rows can remain, and the chain itself keeps everything regardless. [RETENTION WINDOW FOR ADDRESS-LEVEL TRADE AND SNAPSHOT ROWS TO BE SET]
- Terms acceptance record
- The version accepted and the server timestamp are kept for as long as the profile exists, because they are our record of the agreement you entered into and of the US-person attestation you made. Accepting a newer version replaces the record rather than adding to it.
- Theses
- Kept until you replace the thesis or ask us to remove it.
- Follows
- Kept until you unfollow, or until either profile is deleted.
- Push subscriptions
- Kept until you turn notifications off, revoke the permission in your browser, or the push service rejects the endpoint, in which case we drop the row.
- Referral cookie
- 30 days in your browser. The stored referrer on your profile is set once and stays with the profile until the profile is deleted.
- Launch records
- Kept indefinitely. They mirror permanent onchain events and deleting our copy would not remove anything from the chain.
- Logs and backups
- Held by our hosting and database providers under their own schedules. [LOG AND BACKUP RETENTION PERIODS TO BE CONFIRMED WITH VERCEL AND RAILWAY]
10Security, and its limits
What protects you here:
- No custody. No server-side key in this product can move your funds or sign a blockchain transaction, so a breach of our servers cannot move your funds. The server-side keys that do exist, such as third-party API credentials and the push notification signing key, have no access to a wallet or to the chain.
- Encrypted transport. The site and its API are served over HTTPS.
- Secrets stay server-side. Database credentials and third-party API keys are held in server environment variables and are never shipped to the browser.
- Verified sessions. Server routes that touch your profile verify your Privy access token before acting.
Where the limits are, stated plainly:
- Public endpoints are open. The read API needs no authentication and is not rate limited today, so anything shown publicly, including profile and leaderboard data, can be collected at scale by anyone. [RATE LIMITING TO BE ADDED]
- Our content security policy currently runs in report-only mode, so it reports violations rather than blocking them.
- Embedded wallets sign without a second prompt. For accounts using a Privy embedded wallet, a tap in the B420 interface is the only confirmation before a real transaction is sent. Protect the X or email account behind that wallet, because it is effectively the key to it.
- We cannot recover a lost wallet. We hold no key material. If you lose access to the login behind an embedded wallet and never exported the key through Privy, the funds are unrecoverable by us.
- No system is perfectly secure. We cannot guarantee that our systems, or those of our providers, will never be compromised.
Our process and timeline for notifying users and regulators of a personal data breach: [BREACH NOTIFICATION PROCESS AND TIMELINE TO BE COMPLETED WITH COUNSEL]. To report a security issue, email legal@b420.io.
11Your rights and how to use them
11.1 Rights in the EU, the UK and similar regimes
- Access: ask what personal data we hold about you and get a copy.
- Rectification: have inaccurate data corrected. Profile fields can be edited directly in the interface.
- Erasure: ask us to delete your profile and the data keyed to it, subject to the limits in 11.4.
- Restriction: ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
- Objection: object to processing we base on legitimate interests, including the public display of your positions and your leaderboard entry.
- Portability: receive the data you gave us, and the data we generated from your activity, in a machine-readable form.
- Withdraw consent: turn push notifications off in notification settings or in your browser at any time, and unlink X in profile settings, unless X is the only login method on your account, in which case another login method must be linked first. Accounts created on a phone have X as their only login method. Withdrawal does not undo processing that already happened.
- Complain: lodge a complaint with your local data protection supervisory authority. You do not need to contact us first, though we would prefer the chance to fix it.
11.2 California residents
If you live in California you have the right to know what personal information we collect and disclose, to request deletion, to request correction, to opt out of any sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so. We do not use sensitive personal information to infer characteristics about you. The categories we collect, the purposes, and the recipients are set out in sections 3, 5 and 7 respectively. Requests through an authorized agent: [AUTHORIZED AGENT VERIFICATION PROCESS TO BE COMPLETED].
Other US states. We do not offer the interface to US persons at all: see section 3 of the Terms of Service, which you must confirm before you can log in. Several other US states, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana, grant residents rights broadly equivalent to those above. Where such a regime nonetheless applies to you, we honour the equivalent rights through the same contact route in 11.3, on the same terms.
11.3 How to exercise a right
Email legal@b420.io and state the right you want to use and the profile or wallet address it concerns. Because accounts here are tied to wallets and social logins rather than to verified names, we may ask you to prove control of the wallet by signing a message, or to make the request from the linked social or email account.
There is currently no self-serve export or account deletion button in the interface. Requests are handled by hand. [IDENTITY VERIFICATION METHOD AND RESPONSE TIME TO BE COMPLETED] [SELF-SERVE EXPORT AND DELETION TO BE BUILT]
11.4 What we can and cannot delete
We can delete your profile row and the records keyed to it: username, display name, bio, avatar reference, linked handles, your wallet links, your PnL rollups, your theses, your follows and your push subscriptions.
We cannot delete:
- anything recorded on the Base blockchain, including your transactions, tokens you launched, the name, symbol, image reference, description and links written into those token contracts, and onchain memos;
- images pinned to IPFS, which stay retrievable by their content identifier once distributed, even after we stop pinning them;
- copies that third parties already took from our public API, from block explorers, or from search engine and CDN caches;
- records we are required to keep by law.
12Cookies and device storage
B420 itself sets one cookie. Named third parties embedded in the interface set their own, which are listed at the end of this section. There are no advertising cookies, no analytics cookies of our own, no tracking pixels and no cross-site tracking of any kind. The table below lists everything B420 stores in your browser.
- b420_refCookie, 30 days
- Set when you open a referral link. Holds the referring user's public username, nothing else. Path /, SameSite Lax. It is deliberately readable by page scripts so the interface can apply the referral fee discount to an eligible trade.
- b420.termsLocal storage
- The version of the Terms and this policy you accepted at the pre-login gate, the time you accepted on this device, and the not-a-US-person flag. Stops the gate reappearing. The authoritative record is the one on your profile, described in 3.1.
- b420.terms.pendingLocal storage
- Marks an acceptance that has not yet been written to your profile. Cleared once the write succeeds.
- b420.qbLocal storage
- Your preferred quick-buy amount. Persists until you clear site data.
- b420.watchlistLocal storage
- Your watchlist. Stored on this device only and never sent to us. Persists until you clear site data.
- b420.install.dismissedLocal storage
- Records that you dismissed the install prompt so it stops reappearing.
- b420.chart.v2Local storage
- Remembers your chart engine preference.
- Push prompt keyLocal storage
- Records that you have already been shown the notifications prompt.
- b420_ref_seenSession storage
- Shows the referral banner once per browsing session. Cleared when you close the tab.
Third-party components embedded in the interface set their own storage under their own policies: Privy for your login session, Cloudflare Turnstile which Privy uses for bot checks, the Stripe onramp widget during a card purchase, and any external wallet connector you use. We do not control these and cannot list their keys here. [COOKIE CONSENT REQUIREMENTS FOR THE JURISDICTIONS SERVED TO BE ASSESSED WITH COUNSEL]
13Children
This service is not directed at children and may not be used by anyone under 18 years old, or older where the law where you live sets a higher age, as set out in section 3 of the Terms of Service. We do not knowingly collect personal data from anyone under that age.
If you are a parent or guardian and believe a child has created a profile here, email legal@b420.io. We will delete the profile and the data we hold for it. As with any deletion request, we cannot remove transactions or token metadata already recorded on the blockchain.
14Changes to this policy
The product changes, and this policy will change with it. When it does, we update the Last updated date at the top of this page. If a change materially affects how we handle your personal data, we will give notice in the interface before it takes effect: [NOTICE METHOD AND NOTICE PERIOD TO BE COMPLETED].
Continuing to use B420 after a revised policy takes effect means the revised policy applies to you. Where the law requires your consent for a change, we will ask for it rather than assume it. Earlier versions of this policy: [VERSION ARCHIVE LOCATION TO BE COMPLETED].
15Contact
For anything in this policy, including access, correction and deletion requests, privacy questions and security reports:
- Operator: CC0 COMPANY [LEGAL ENTITY NAME AND REGISTERED ADDRESS TO BE COMPLETED]
- Email: legal@b420.io
- Data protection contact: [DATA PROTECTION CONTACT OR REPRESENTATIVE TO BE COMPLETED] (an EU or UK representative, or a data protection officer, if one is required for the operator)
- Interface: https://b420.io. Terms: Terms of Service, where governing law and venue are set: [GOVERNING LAW AND VENUE TO BE COMPLETED WITH COUNSEL]
This policy describes the b420.io interface as it is built. It is written to be read by the people who use it, and it is not legal advice. If you need advice about your own situation, including how data protection, financial or tax rules apply to you, consult a qualified professional. Trading tokens carries risk, and nothing on this site is financial advice.