Privacy policy
A readable overview of data handling in the current development version, with the remaining publication requirements kept visible.
Scope of this notice
This page describes the current Coinkun development interface. It is not a statement that the product is ready to process customer payments, nor a substitute for a reviewed policy for the actual operating entity and hosting environment.
Data in the application
Account creation stores an account identifier, creation metadata, credential digest and related vault records. Key preparation and address generation add public derivation and ownership records. Scanners store matching transaction IDs, block references, observation and absence-check times, input references, known conflicting TXIDs, output indexes and integer amounts, plus the last processed block. History reads those observations. The raw Transfer Key is returned once and must be kept private by its holder. This flow does not ask for an email address or customer billing details.
Payment and notification records
The application stores transfer intents, recipient addresses, amounts and fees, idempotency keys, input reservations and signed transaction bytes for safe retry. Callback records include callback destinations, merchant-supplied data, receipt payloads and HTTP attempts with bounded response bodies and headers. These are server-side records, not browser preferences. Their access, backup and retention rules need to be reviewed for the actual deployment; no automatic deletion policy is promised here.
Data in your browser
The dashboard uses session access and remembers public Account IDs. The documentation can remember a theme preference. The public widget builders do not submit their configuration or collect customer information; they are presentation-only previews.
See the browser-storage inventoryInfrastructure and logs
Rails and deployment components may create operational logs. The production host, subprocessors, access controls, backup handling, retention schedule and any international transfers must be documented for the selected deployment. No blanket promise of anonymous use or zero data collection is made here.
Information still to be published
- The legal operator, registered address and privacy contact.
- Processing purposes and the applicable legal basis for each purpose.
- Retention and deletion rules, including operational backups.
- Actual service providers and any cross-border data arrangements.
- A verified process for privacy requests and complaints.
Questions and requests
A public privacy-request channel has not been configured. Do not send identity documents, secrets or payment credentials through a guessed email address. The contact page will need a verified channel before the service is made available to customers.
Contact informationYour next step starts here.
Explore the dashboard, learn the API and develop with local test coins.