web3radar · Stakecito
Privacy Policy
Last updated: 2026-06-03
This policy explains what personal data web3radar collects, why, who we share it with, and your rights under the EU GDPR and equivalent regimes. We try to keep it short and specific. If you have questions: contact@stakecito.com.
1. Who we are (Controller)
2. What we collect, why, and our legal basis
The full list, in plain language:
- Email address
- Collected
- When you subscribe to alerts at /alerts, or sign in at /account.
- Purpose
- To deliver the alerts you subscribed to and to authenticate you on your account.
- Legal basis
- Performance of contract (you asked us to send these emails) and explicit consent (double opt-in confirmation).
- Retention
- Until you unsubscribe or delete your account; then deleted within 30 days.
- Browser-issued IP address
- Collected
- On every request, but only stored as a SHA-256 hash.
- Purpose
- Rate-limiting, abuse prevention, and an audit trail for sensitive actions (login attempts, admin operations, submission spam).
- Legal basis
- Legitimate interest in keeping the service operational and secure. We never store or process the plaintext IP.
- Retention
- Hashes are retained alongside the audit-log row that referenced them — typically indefinitely as part of the security audit trail, unless we delete your account.
- Stripe customer & subscription IDs
- Collected
- When you upgrade to Pro.
- Purpose
- To grant Pro features, surface the billing portal, and revoke access on cancellation.
- Legal basis
- Performance of contract.
- Retention
- Until you cancel; the linked IDs are deleted within 30 days of account deletion. Stripe itself retains transaction records per their own retention policy.
- Keplr-signed wallet address (Cosmos / Injective / Sei bech32)
- Collected
- Only if you choose to verify delegator status at /account/keplr.
- Purpose
- To check your delegation to the Stakecito validator and grant free Pro tier if you qualify.
- Legal basis
- Explicit consent (you click a button and sign a message). We do not poll the chain otherwise.
- Retention
- Stored on your User record; deleted within 30 days of account deletion.
- Slack / Telegram / Discord webhook URLs
- Collected
- Only if you add a Pro-tier channel at /account/channels.
- Purpose
- To deliver alerts to that channel. We POST the alert JSON to the URL you provided and store nothing about the delivery body.
- Legal basis
- Performance of contract.
- Retention
- Until you remove the channel or delete your account.
- Submission contents (hack reports, chain requests)
- Collected
- Only if you fill out /submit or /request-chain.
- Purpose
- Editorial review — these are direct inputs into the public incident database.
- Legal basis
- Performance of contract (you submitted to be reviewed) and legitimate interest in editorial accuracy.
- Retention
- Retained indefinitely as part of the editorial audit trail. Email address you provided for follow-up is deleted on request.
- Server-side error telemetry
- Collected
- On every uncaught application error.
- Purpose
- Diagnosing and fixing bugs. Sent to our error-tracking provider (Sentry — see §4). HTTP cookies and Authorization headers are stripped before transmission.
- Legal basis
- Legitimate interest in operating a stable service.
- Retention
- 30 days at Sentry; aggregate counters longer.
- Session and theme preferences (cookies & localStorage)
- Collected
- When you sign in or change your theme.
- Purpose
- To keep you signed in (httpOnly session cookie) and remember your light/dark choice (localStorage).
- Legal basis
- Strictly necessary for the service you requested — no consent banner required.
- Retention
- Session: 30 days from last use, or until logout. Theme: until you clear browser data. See /cookies for the full list.
3. What we do NOT collect
- No advertising trackers, no third-party analytics that profile you across sites.
- No browser fingerprinting.
- No social-graph data, no contact-list uploads.
- No payment-card numbers — Stripe handles those; we receive only an opaque customer ID.
- No plaintext passwords (admin auth uses bcrypt; user sign-in uses magic-link tokens with hashed storage).
- No plaintext IP addresses, ever.
4. Sub-processors
- Resend
Transactional email delivery (alert + confirmation + sign-in links).
Jurisdiction: USA / EU. · Their privacy policy
- Stripe
Subscription payments. We never see your card; Stripe returns an opaque customer / subscription id.
Jurisdiction: USA, with EU data residency available. · Their privacy policy
- Sentry
Server-side error tracking. Authorization headers and cookies are stripped before transmission.
Jurisdiction: USA, with optional EU data residency. · Their privacy policy
- Upstash
Rate-limit counters (hashed IPs only).
Jurisdiction: USA / EU. · Their privacy policy
- DefiLlama
Incident data source + chain logos. We make outbound GETs only.
Jurisdiction: N/A — we don't send personal data to DefiLlama. · Their privacy policy
5. Where data is stored
6. Your rights
- Access the personal data we hold about you — request a copy via contact@stakecito.com.
- Rectify inaccurate data — same email, or correct it directly from /account.
- Erase your personal data — use the "Delete my account" button on /account, which removes your User record, channels, delegator verifications, and the corresponding alert subscription. The hashed-IP audit trail referenced earlier is retained for legitimate security purposes for as long as the audit log itself.
- Restrict or object to processing — email us; we'll discuss the specifics.
- Export your data in a machine-readable format — email request.
- Withdraw consent — unsubscribe from any alert email using the one-click link in the email footer, or hit "Delete my account".
- Complain to a supervisory authority. In the EU, find yours at edpb.europa.eu.
7. Security
sameSite=strict (admin) / sameSite=lax (user). Admin passwords stored as bcrypt hashes; magic-link and session tokens stored as SHA-256 hashes. Backups are restorable and drill-tested quarterly. Sub-processors named above are independently SOC 2 / ISO 27001 certified.8. Children
9. Changes
10. Contact
See also: Terms of Service · Cookies · Methodology