Privacy Policy
Last updated: August 27, 2026
This Privacy Policy describes how ChainAttest (“we”, “us”, “controller”) collects, uses, and shares personal data when you use our website and application (“Service”). It is intended to meet transparency requirements under the EU GDPR and UK GDPR for a SaaS product. It is not legal advice.
Controller: ChainAttest (sole trader trading as ChainAttest). Privacy contact: [email protected] or the contact form. Payment-related personal data for purchases is also processed by Paddle as Merchant of Record (see their privacy policy).
1. Information we collect
- Account data: email address, optional display name, password hash, role, plan/credits status, portfolio limits, and usage counters.
- Service data: token contract addresses, chain/RPC settings you configure, scan jobs and results, pasted Solidity source (when you run a code audit), portfolio notes/metadata, and feedback you submit (including optional contact email).
- Payment data: pack purchases are handled by Paddle, our merchant of record. We receive payment/transaction status, pack identifiers, amounts, and Paddle customer/transaction IDs. We do not store full payment card numbers.
- Technical data: session tokens, security logs, and short-lived IP address use for rate limiting and abuse prevention. We do not currently run third-party product analytics SDKs on the site.
- Local device data: the app stores a session token and basic user profile in your browser’s
localStorageso you stay signed in. Checklist UIs may also store preferences locally on your device.
2. Why we process data (purposes & legal bases)
- Provide the Service (accounts, scans, audits, portfolio, credits) — contract (Art. 6(1)(b) GDPR).
- Process payments via Paddle and enforce pack limits — contract; tax/accounting records may also be legal obligation (Art. 6(1)(c)).
- Secure the Service, prevent fraud/abuse, debug incidents — legitimate interests (Art. 6(1)(f)).
- Respond to support and feedback — contract or legitimate interests.
- Improve product quality using AI/embeddings on content you submit for scans/audits — contract (to deliver the feature you requested) and, where we use it for broader improvement, legitimate interests. We do not sell personal data.
We do not currently send marketing emails. If we introduce marketing, we will rely on consent or soft opt-in where allowed and provide an unsubscribe option.
3. Sharing & processors
We share personal data only with providers needed to run the Service, under appropriate agreements where required:
- Paddle — payments, tax invoicing, and purchase-related support (Merchant of Record). See Paddle’s Privacy Policy.
- Hosting / infrastructure — cloud hosting, reverse proxy/TLS, and managed database for the application.
- AI / embedding providers — to generate or retrieve analysis when you run scans or code audits (content you submit may be processed by those providers for that purpose).
- Blockchain RPC / explorer providers — to fetch on-chain contract and related public blockchain data you request us to analyse.
We may disclose information if required by law or to protect rights, safety, and security. We do not sell your personal information.
4. Cookies and similar technologies
Authentication is primarily via a bearer token stored in localStorage (not a tracking cookie). On the billing page we load Paddle.js so you can complete checkout; Paddle may set cookies or similar technologies as described in their policies. We do not use advertising cookies. If we add non-essential analytics cookies later, we will present a consent choice where required by ePrivacy/GDPR rules.
5. Retention
We retain account and scan data while your account is active and for a reasonable period afterward for backups, abuse prevention, billing disputes, and legal obligations (for example, payment records related to Paddle transactions). You may request deletion of your account; we will delete or anonymise personal data we no longer need, except where retention is required by law or necessary for disputes/security.
6. Security
We use reasonable technical and organisational measures, including password hashing (bcrypt), session expiry, TLS in production, and access controls for administrative functions. No method of transmission or storage is completely secure.
7. International transfers
We and our processors may process data in countries outside your own (including outside the EEA/UK). Where required, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses with processors.
8. Your rights (EU/UK and similar laws)
Depending on your location, you may have rights to:
- access your personal data;
- rectify inaccurate data;
- erase data (“right to be forgotten”);
- restrict or object to certain processing;
- data portability (receive a copy in a common format);
- withdraw consent where processing is based on consent.
To exercise these rights, email [email protected] or use the contact form (choose Delete my account). We aim to respond within one month. You may also lodge a complaint with your local supervisory authority (in the UK: the ICO; in the EU: your member-state DPA).
Account deletion is processed manually by an administrator after we verify the request. We then remove the account, sessions, portfolio, and scan history. Anonymised purchase records may be retained for accounting and legal obligations.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information.
10. Changes
We may update this policy. The “Last updated” date will change when we do. Material changes will be communicated where appropriate (for example, a notice in the product or by email if we have a reliable address).
11. Contact
Privacy questions: contact form or [email protected].