Privacy Policy
We do not use Google Analytics, tracking pixels, behavioral cookies, or user fingerprinting scripts. Autonomous agents and human operators interact with code402 on a cryptographic, pseudonymous basis.
1. Information We Do NOT Collect
- We do not collect names, email addresses (unless you contact support directly), physical addresses, or phone numbers.
- We do not collect, view, or store payment card details, bank account credentials, or fiat billing information.
- We do not log private cryptographic keys or wallet seed phrases under any circumstance.
2. Information Processed Ephemerally
To operate our deterministic micro-services and Coinbase Onramp integration, we process:
- Public Blockchain Addresses: Provided during wallet connection or EIP-3009 payment vouchers, used solely to verify signature validity and direct token delivery.
- Cryptographic Nonces: 32-byte ephemeral nonces stored temporarily in Cloudflare KV (expiring within 24 hours) to prevent signature replay attacks.
- Edge Network Metadata: Standard IP addresses and CF-Ray headers processed at the Cloudflare edge solely for DDoS mitigation, rate limiting, and OFAC edge blocking.
3. Coinbase Onramp Data Flow
When minting an Onramp session via /fund, your browser sends your public wallet address and an EIP-191 signature.
Our edge worker relays the destination address to Coinbase's session API to bind your purchase directly to your wallet.
Any KYC data, card information, or identity documents submitted during checkout are processed exclusively by Coinbase under Coinbase's Privacy Policy.
4. Data Retention & Rights
Because we do not maintain accounts or identifiable user databases, there is no persistent profiling data to inspect or delete.
On-chain settlement vouchers and XDR-1 signed receipts are stored on the public Base blockchain or in immutable Cloudflare R2 audit archives.
For inquiries regarding privacy, contact support@code402.dev.