BetaCoverage is expanding. Data is best-effort and may contain gaps or errors — report inaccuracies via About.
STAKECITO

web3radar · Stakecito

Privacy Policy

Last updated: 2026-06-03

This policy explains what personal data web3radar collects, why, who we share it with, and your rights under the EU GDPR and equivalent regimes. We try to keep it short and specific. If you have questions: contact@stakecito.com.

1. Who we are (Controller)

web3radar is published by Stakecito. Stakecito acts as the data controller for personal data processed through the service.

2. What we collect, why, and our legal basis

The full list, in plain language:

  • Email address
    Collected
    When you subscribe to alerts at /alerts, or sign in at /account.
    Purpose
    To deliver the alerts you subscribed to and to authenticate you on your account.
    Legal basis
    Performance of contract (you asked us to send these emails) and explicit consent (double opt-in confirmation).
    Retention
    Until you unsubscribe or delete your account; then deleted within 30 days.
  • Browser-issued IP address
    Collected
    On every request, but only stored as a SHA-256 hash.
    Purpose
    Rate-limiting, abuse prevention, and an audit trail for sensitive actions (login attempts, admin operations, submission spam).
    Legal basis
    Legitimate interest in keeping the service operational and secure. We never store or process the plaintext IP.
    Retention
    Hashes are retained alongside the audit-log row that referenced them — typically indefinitely as part of the security audit trail, unless we delete your account.
  • Stripe customer & subscription IDs
    Collected
    When you upgrade to Pro.
    Purpose
    To grant Pro features, surface the billing portal, and revoke access on cancellation.
    Legal basis
    Performance of contract.
    Retention
    Until you cancel; the linked IDs are deleted within 30 days of account deletion. Stripe itself retains transaction records per their own retention policy.
  • Keplr-signed wallet address (Cosmos / Injective / Sei bech32)
    Collected
    Only if you choose to verify delegator status at /account/keplr.
    Purpose
    To check your delegation to the Stakecito validator and grant free Pro tier if you qualify.
    Legal basis
    Explicit consent (you click a button and sign a message). We do not poll the chain otherwise.
    Retention
    Stored on your User record; deleted within 30 days of account deletion.
  • Slack / Telegram / Discord webhook URLs
    Collected
    Only if you add a Pro-tier channel at /account/channels.
    Purpose
    To deliver alerts to that channel. We POST the alert JSON to the URL you provided and store nothing about the delivery body.
    Legal basis
    Performance of contract.
    Retention
    Until you remove the channel or delete your account.
  • Submission contents (hack reports, chain requests)
    Collected
    Only if you fill out /submit or /request-chain.
    Purpose
    Editorial review — these are direct inputs into the public incident database.
    Legal basis
    Performance of contract (you submitted to be reviewed) and legitimate interest in editorial accuracy.
    Retention
    Retained indefinitely as part of the editorial audit trail. Email address you provided for follow-up is deleted on request.
  • Server-side error telemetry
    Collected
    On every uncaught application error.
    Purpose
    Diagnosing and fixing bugs. Sent to our error-tracking provider (Sentry — see §4). HTTP cookies and Authorization headers are stripped before transmission.
    Legal basis
    Legitimate interest in operating a stable service.
    Retention
    30 days at Sentry; aggregate counters longer.
  • Session and theme preferences (cookies & localStorage)
    Collected
    When you sign in or change your theme.
    Purpose
    To keep you signed in (httpOnly session cookie) and remember your light/dark choice (localStorage).
    Legal basis
    Strictly necessary for the service you requested — no consent banner required.
    Retention
    Session: 30 days from last use, or until logout. Theme: until you clear browser data. See /cookies for the full list.

3. What we do NOT collect

  • No advertising trackers, no third-party analytics that profile you across sites.
  • No browser fingerprinting.
  • No social-graph data, no contact-list uploads.
  • No payment-card numbers — Stripe handles those; we receive only an opaque customer ID.
  • No plaintext passwords (admin auth uses bcrypt; user sign-in uses magic-link tokens with hashed storage).
  • No plaintext IP addresses, ever.

4. Sub-processors

We use a small number of vetted providers to deliver the service. Each receives only what the function requires.
  • Resend

    Transactional email delivery (alert + confirmation + sign-in links).

    Jurisdiction: USA / EU. · Their privacy policy

  • Stripe

    Subscription payments. We never see your card; Stripe returns an opaque customer / subscription id.

    Jurisdiction: USA, with EU data residency available. · Their privacy policy

  • Sentry

    Server-side error tracking. Authorization headers and cookies are stripped before transmission.

    Jurisdiction: USA, with optional EU data residency. · Their privacy policy

  • Upstash

    Rate-limit counters (hashed IPs only).

    Jurisdiction: USA / EU. · Their privacy policy

  • DefiLlama

    Incident data source + chain logos. We make outbound GETs only.

    Jurisdiction: N/A — we don't send personal data to DefiLlama. · Their privacy policy

5. Where data is stored

Application data is stored in a PostgreSQL database hosted on a server controlled by Stakecito. Sub-processors store the data they receive on their own infrastructure as described in their privacy policies (§4).

6. Your rights

Under the GDPR and equivalent laws, you have the right to:
  • Access the personal data we hold about you — request a copy via contact@stakecito.com.
  • Rectify inaccurate data — same email, or correct it directly from /account.
  • Erase your personal data — use the "Delete my account" button on /account, which removes your User record, channels, delegator verifications, and the corresponding alert subscription. The hashed-IP audit trail referenced earlier is retained for legitimate security purposes for as long as the audit log itself.
  • Restrict or object to processing — email us; we'll discuss the specifics.
  • Export your data in a machine-readable format — email request.
  • Withdraw consent — unsubscribe from any alert email using the one-click link in the email footer, or hit "Delete my account".
  • Complain to a supervisory authority. In the EU, find yours at edpb.europa.eu.

7. Security

Encryption in transit (TLS 1.2+). Session cookies are httpOnly with sameSite=strict (admin) / sameSite=lax (user). Admin passwords stored as bcrypt hashes; magic-link and session tokens stored as SHA-256 hashes. Backups are restorable and drill-tested quarterly. Sub-processors named above are independently SOC 2 / ISO 27001 certified.

8. Children

web3radar is not directed at children under 16. We don't knowingly collect personal data from children. If you believe we have, email us and we'll delete it.

9. Changes

We may update this policy; the "Last updated" date at the top of this page changes when we do. Material changes (anything affecting what we collect or who we share it with) will be notified to subscribers by email at least 14 days before taking effect.

10. Contact

contact@stakecito.com for any privacy question, rights request, or complaint.

See also: Terms of Service · Cookies · Methodology

Privacy Policy · web3radar by Stakecito