Privacy Policy
Last updated:
The short version
We collect the minimum needed to run the Interface: your wallet address (when you connect), an optional Telegram username (if you enable notifications), any alerts or watchlist items you create, and technical logs (IP, browser, page views). We do not collect private keys or seed phrases. We do not sell data. You can request deletion at any time.
1. Introduction
This Privacy Policy describes how PolyScalping ("PolyScalping", "we", "our", or "us") collects, uses, discloses, and protects personal data when you access or use the polyscalping.org website, its subdomains, and any related services (collectively, the "Interface"). It applies in addition to our Terms of Use. By accessing or using the Interface, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for processing personal data collected through the Interface is PolyScalping. You can reach us with privacy questions, requests, or complaints at polyscalping@gmail.com. The Interface is intended for users outside the European Economic Area, the United Kingdom, and other jurisdictions listed as Prohibited Jurisdictions in our Terms of Use.
3. Information We Collect
We collect only the information necessary to operate the Interface and to provide its core features. Specifically:
- Wallet address. When you connect a wallet, we record the public blockchain address for the purpose of authentication, personalisation (e.g. portfolio view), and rate-limiting.
- Telegram identifier. If you opt into Telegram notifications, we store your Telegram username or chat ID to deliver alerts you have configured.
- User-created data. Price alerts, watchlists, saved filters, and similar preferences you create through the Interface.
- Technical data. IP address, approximate geolocation derived from IP, browser type and version, device type, operating system, referring URL, pages viewed, timestamps, and similar standard server-log information.
- Analytics data. Aggregated, pseudonymous performance and usage metrics collected via Vercel Analytics (page-view counts, load-time percentiles). No cross-site tracking cookies are used.
We do not collect or store wallet private keys, seed phrases, recovery files, or any sensitive credentials. We do not collect Polymarket account credentials or trading data outside of what is publicly available on the Polygon blockchain.
4. Legal Basis for Processing (GDPR)
Where the General Data Protection Regulation (GDPR) applies, our legal bases for processing personal data are:
- Performance of a contract (Art. 6(1)(b)) — to provide the Interface and the features you request (e.g. delivering an alert you configured).
- Legitimate interests (Art. 6(1)(f)) — to operate and secure the Interface, detect and prevent fraud and abuse, debug and improve the service, and enforce our Terms.
- Consent (Art. 6(1)(a)) — for optional features that require it (e.g. opt-in Telegram notifications). You may withdraw consent at any time without affecting prior lawful processing.
- Legal obligation (Art. 6(1)(c)) — to comply with sanctions screening, court orders, or other obligations under applicable law.
5. How We Use Your Information
We use the information described above to:
- Provide, maintain, and improve the Interface.
- Personalise content and features you see (e.g. portfolio view tied to your connected wallet).
- Deliver alerts and notifications you have configured.
- Monitor performance, debug issues, and protect against abuse, fraud, and unauthorized access.
- Comply with applicable law, regulation, court order, or governmental request, including sanctions screening obligations.
- Communicate with you about service updates, security notices, and other operational matters.
We never sell, rent, or trade your personal data. We do not share data with third parties for their own marketing purposes.
6. Data Sharing and Recipients
We share data only with the following categories of recipients, and only as necessary to operate the Interface:
- Infrastructure providers — Vercel (hosting and edge network), database providers, and Cloudflare (where applicable). These providers process data on our behalf under appropriate data-processing agreements.
- Third-Party Services you interact with — fun.xyz (cross-chain bridging), the Polymarket Gamma and CLOB APIs, the Polygon network, the Telegram API, and any wallet provider you connect. These services receive only the data necessary for the interaction you initiate and are independent data controllers under their own privacy policies.
- Sanctions and abuse screening providers — we may use blockchain-analytics services to screen wallet addresses against OFAC and similar sanctions lists.
- Legal and law enforcement — where required by law, regulation, court order, or to protect our rights, the rights of others, or to investigate fraud, abuse, or security incidents.
- Successors — in connection with a merger, acquisition, financing, or sale of all or part of our business, subject to standard data-protection commitments.
7. International Data Transfers
Our infrastructure providers may process data in regions outside your country of residence, including the United States. Where the GDPR or analogous law applies, transfers outside the European Economic Area or the United Kingdom are made on the basis of Standard Contractual Clauses, an adequacy decision, or an applicable derogation.
8. Data Retention
- Wallet address records — retained for up to twenty-four (24) months from the date of last activity, after which they are deleted or anonymised.
- Technical and analytics logs — retained for up to twelve (12) months, after which they are deleted or aggregated to non-personal form.
- User-created data (alerts, watchlists, saved filters) — retained until you delete it or for the lifetime of your account, whichever comes first.
- Records required by law — retained for the period required by applicable law (e.g. sanctions-screening records).
9. Your Rights
Subject to applicable law, you may have the following rights with respect to your personal data:
- Access — to obtain confirmation that we process your data and a copy of that data (GDPR Art. 15).
- Rectification — to correct inaccurate or incomplete data (Art. 16).
- Erasure — to request deletion of your data where no overriding legitimate interest or legal obligation applies (Art. 17).
- Restriction — to restrict processing in certain circumstances (Art. 18).
- Portability — to receive your data in a structured, commonly used, machine-readable format (Art. 20).
- Objection — to object to processing based on legitimate interests (Art. 21).
- Withdraw consent — to withdraw consent at any time for processing based on consent, without affecting prior lawful processing.
- Lodge a complaint — with your local data-protection authority.
To exercise any of these rights, contact us at polyscalping@gmail.com. We will respond within thirty (30) days. We may need to verify your identity (for example by asking you to sign a message from the wallet address in question) before acting on a request.
10. California Privacy Rights (CCPA / CPRA)
California residents have, in addition to the rights above, the right to know what categories of personal data we collect, the purposes for which it is collected, and the categories of third parties with whom it is shared; the right to delete; the right to correct; the right to opt out of the sale or sharing of personal data; and the right to non-discrimination for exercising these rights. We do not sell or share personal data within the meaning of the CCPA.
Note: California (United States) is currently a Prohibited Jurisdiction under our Terms of Use. This section is provided for transparency in the event you are entitled to CCPA rights by reason of residency notwithstanding any access through the Interface.
11. Children's Privacy
The Interface is intended for users aged eighteen (18) and over. We do not knowingly collect personal data from anyone under eighteen, and in no case from anyone under thirteen (13) as defined by the U.S. Children's Online Privacy Protection Act (COPPA) or under sixteen (16) as defined by the GDPR. If you become aware that a child has provided us with personal data, contact us and we will take steps to delete it.
13. Data Security
We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. All data in transit is encrypted using TLS 1.2 or higher. Access to production systems is restricted, logged, and reviewed. However, no system is perfectly secure, and we cannot guarantee the absolute security of your data. You are responsible for keeping your wallet credentials secure.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be reflected by the "Last updated" date at the top of this page. Material changes will be flagged by a notice on the Interface for at least seven (7) days. Your continued use of the Interface after the effective date of a revised Privacy Policy constitutes your acceptance of the revised terms.
15. Contact
Questions, complaints, or rights requests regarding this Privacy Policy or our handling of your personal data can be sent to: polyscalping@gmail.com
