Privacy Policy (Draft)
Draft Privacy Policy for FOOM Trade — collect little, never sell, blockchain is public by design.
Last updated: [DATE — set at launch]
⚠️ DRAFT — pending counsel review. Entity details are placeholders (
[FOOM ENTITY]). Do not publish until the operating entity and data-processing inventory are finalized.
This Privacy Policy explains how [FOOM ENTITY], Inc. ("FOOM," "we," "us," or "our") collects, uses, shares, and protects information when you use the FOOM Trade application, the foom.trade website, and associated services (the "Services"). By using the Services, you agree to this Policy.
Our approach in one line: we collect as little as possible, we never sell your personal data, and everything you do on a blockchain is public by design — not by our choice.
1. Information We Collect
1.1. Information you provide
- Account information: email address; optionally a username, display name, profile photo, and social handles you choose to add.
- Wallet information: public wallet addresses associated with your account. We never collect, store, or have access to your private keys, seed phrases, or wallet passwords. Embedded wallet keys are generated and managed by our third-party wallet infrastructure provider (e.g., Privy) such that FOOM cannot access them.
- Identity verification (only if required): if a feature or applicable law requires it, our verification partners may collect government ID and related KYC information. We receive verification results and screening flags, not full document archives, wherever feasible.
- User content: posts, comments, chat messages, and other content you submit to social features.
- Communications: messages you send to support or legal contacts.
1.2. Information collected automatically
- Device and usage data: device type, operating system, app version, language, IP-derived coarse region (used for security, fraud prevention, and geographic compliance), session events, crash logs, and feature-usage analytics.
- We do not collect precise GPS location. Geographic compliance uses coarse, IP-based signals only.
- Cookies and similar technologies on the website, limited to what is needed for authentication, security, and analytics. We honor applicable consent requirements.
1.3. Blockchain data (public by design)
When you transact through the Services, your wallet addresses, transactions, balances, and token holdings are recorded on public blockchains. This data:
- is public, permanent, and immutable;
- is not controlled by FOOM and cannot be modified, deleted, or anonymized by FOOM or anyone else;
- can be viewed by anyone and may be associated with you by third parties.
Deleting your FOOM account does not and cannot remove on-chain data.
1.4. Information from third parties
We may receive information from wallet-infrastructure, analytics, fraud-prevention, sanctions/wallet-screening, and identity-verification providers, and from social platforms if you connect them, in each case limited to operating the Services and meeting legal obligations.
2. How We Use Information
We use information to:
- provide, maintain, and improve the Services;
- create and secure your account and embedded wallet;
- display social features you opt into (profiles, leaderboards, feeds);
- detect and prevent fraud, abuse, market manipulation, and security incidents;
- comply with legal obligations, including sanctions, AML/CFT, and jurisdiction restrictions;
- communicate with you about the Services (service messages; marketing only with consent, opt-out anytime);
- produce aggregated or de-identified analytics that do not identify you.
Legal bases where GDPR or similar laws apply: performance of contract, legitimate interests (security, fraud prevention, service improvement), legal obligation, and consent (where required).
3. How We Share Information
We never sell your personal data, and we do not share it for cross-context behavioral advertising.
We share information only with:
- Service providers that operate parts of the Services under contract (hosting, wallet infrastructure such as Privy, analytics, customer support, identity verification and screening, on/off-ramp partners) — bound to use it only for the services they provide to us;
- Legal and safety recipients: courts, regulators, and law enforcement when required by law, and parties as needed to protect the rights, safety, and security of users, the public, or FOOM;
- Corporate transaction parties in connection with a merger, acquisition, financing, or sale of assets (with notice where required);
- Other users, only for information you choose to make public (profile, posts, leaderboard entries — noting that your on-chain activity is inherently public).
4. Data Retention
We keep personal data only as long as needed for the purposes above: account data for the life of your account; legal-compliance records (e.g., KYC where collected) for the period required by law; security logs for a limited rolling window. When you delete your account, we delete or de-identify your personal data within a reasonable period, except what we must retain by law. On-chain data is permanent and outside anyone's control (Section 1.3).
5. Your Rights and Choices
Depending on your jurisdiction (including GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have the right to:
- access the personal data we hold about you and receive a portable copy;
- correct inaccurate data;
- delete your data (subject to legal retention duties and the immutability of blockchain data);
- object to or restrict certain processing;
- withdraw consent at any time where processing is based on consent;
- opt out of marketing at any time;
- not be discriminated against for exercising these rights;
- appeal a rights decision and complain to your data-protection authority.
In-app account deletion is available in Settings, and you can also request any of the above by emailing privacy@foom.trade. We respond within the time required by applicable law (e.g., 45 days under CCPA/Virginia rules, extendable as permitted). We may need to verify your identity before acting on a request.
California: we do not sell or share personal information as defined by the CCPA/CPRA, and we have no actual knowledge of selling or sharing personal information of consumers under 16.
6. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit, access controls, and least-privilege practices. No system is perfectly secure; you are responsible for securing your devices, credentials, and wallet. If a breach affecting your personal data occurs, we will notify you and regulators as required by law.
7. International Transfers
We may process data in countries other than yours, including the United States. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
8. Children
The Services are for adults. We do not permit use by anyone under 18 and do not knowingly collect personal data from anyone under 18. If we learn we have collected such data, we will delete it and terminate the account. If you believe a minor is using the Services, contact privacy@foom.trade.
9. Third-Party Services
The Services link to and integrate third-party services (blockchain networks, wallet infrastructure, on/off-ramps, social platforms). Their privacy practices are governed by their own policies, which we encourage you to read. This Policy does not apply to them.
10. Do Not Track
Some browsers send "Do Not Track" signals. Where applicable law requires us to honor opt-out preference signals (such as Global Privacy Control), we do.
11. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and notify you of material changes in-app or by other reasonable means. Continued use after changes take effect constitutes acceptance.
12. Contact
[FOOM ENTITY], Inc. — [REGISTERED ADDRESS — TBD] privacy@foom.trade · legal@foom.trade