Privacy Policy
Version 1.1.0 · revised 2026-09-02 · keccak256 0x7e3cfb27a588377b78c03fa8a4a9731655c7960e9bb41f1df243f1e6552cf950
SuperStrat Privacy Policy
Version 1.1.0 Date of last revision: 2026-09-02 Effective from: publication on the Interface
This Privacy Policy explains how SuperStrat, a company in formation, to be incorporated under the laws of the British Virgin Islands (the "Operator", "we", "us"), processes personal data in connection with the SuperStrat interface at superstrat.io and its subdomains (the "Interface"). It forms an integral part of the SuperStrat Terms of Use (the "Terms"). Capitalized terms have the meanings given in the Terms.
This Policy is drafted to comply with the Data Protection Act, 2021 of the British Virgin Islands and, where it applies to you, the General Data Protection Regulation of the European Union. Until the Operator's incorporation is complete, the persons acting on behalf of the company in formation are responsible for the processing described here; the Operator's legal name, registered address and company number will be published on the Interface upon incorporation and added to this Policy by amendment under Section 8.
The short version: we collect little. No account is created for depositors, no identity document is requested from depositors, and no third-party advertising or behavioural analytics trackers are installed. What we process: your wallet address and your signed acceptance of the Terms; the country derived from your IP address, which we use to apply the access restrictions required by the Restricted Jurisdictions Policy and which we record as evidence that those restrictions were applied; an email address if you voluntarily join our mailing list; profile information Curators choose to publish; identity documents that Curators provide for verification before their first Vault is deployed; and standard technical server logs. Blockchain data is public by nature and outside anyone's control.
1. Data We Process
1.1. Wallet address and terms acceptance. When you connect a wallet, we process your public wallet address. When you accept the Terms, we store your wallet address, the version and cryptographic hash of the accepted document, your cryptographic signature, the timestamp you signed and the time we received it. This record is kept as proof of contract formation.
1.2. On-chain data. Your deposits, redemptions, claims, Vault Shares and related transactions are recorded on the Polygon PoS public blockchain. This data is public, permanent, replicated worldwide and outside the Operator's control; we read and index it (for example to display balances, performance, points and leaderboards) but we do not create it and cannot erase it.
1.3. Email address (optional). If you voluntarily submit an email address (whitelist or newsletter signup), we store it and use it to send you the communications you requested. You can unsubscribe at any time.
1.4. Curator profile data (optional). Curators may publish a display name or pseudonym, biography, photograph and links. Publishing this information is the Curator's choice; it is displayed publicly on the Interface.
1.5. Technical data and geolocation. Our servers and hosting providers automatically record standard request logs (IP address, browser type and language, date and time, pages requested) for security, debugging and abuse prevention. The Interface uses only cookies and similar storage necessary for it to function (such as wallet connection state and preferences).
Because access to the Interface is restricted by jurisdiction under the Restricted Jurisdictions Policy, we also derive an approximate country from your IP address, using the geolocation provided by our hosting provider at the network edge. We record the result of that determination, together with your wallet address if a wallet is connected, the date and time, the action you attempted (for example wallet connection, acceptance of the Terms, a deposit, redemption or claim request, or Vault creation) and whether access was refused. We keep that record as evidence that access controls were applied. We do not store your precise location and we do not use location data for any other purpose.
1.6. Wallet connection services. Wallet connection is provided through Reown AppKit and the WalletConnect protocol. To establish and maintain the connection between the Interface and your wallet, Reown's servers process your IP address and wallet metadata (such as wallet type and connection identifiers). The analytics features of this service are disabled. No third-party advertising or behavioural analytics trackers are installed on the Interface; this statement was verified against the deployed Interface on 2026-09-02 and will be re-verified at each revision of this Policy.
1.7. Compliance screening. At the date of this version, we do not screen wallet addresses or transactions against sanctions or financial-crime risk indicators through any third-party blockchain intelligence provider. The Operator may introduce such screening, limited to wallet addresses and transaction identifiers, and may restrict access based on its results. If screening is introduced, this Policy will be updated to name the provider and the processing, and re-versioned, before or at activation.
1.8. Curator identity verification. Before a Curator's first Vault is deployed, we verify the Curator's identity, whether the Curator is an individual or an entity. At the date of this version, this verification is performed by the Operator itself: the Curator provides a government-issued identity document and a proof of address (and, for an entity, its constitutional documents and the identity of its directors and beneficial owners) through an encrypted channel, and we review them. No automated verification provider is used at this version; if one is engaged, this Policy will be updated to name it. Identity records are stored separately from the public Curator profile. A Curator may operate under a pseudonym on the Interface; the verified identity is nonetheless known to the Operator and may be disclosed under the conditions stated in Section 1.4 of the Curator Terms, that is, to a competent authority where Applicable Law requires it, or to an arbitral tribunal or court in connection with a claim brought by a depositor in that Curator's Vault.
We do not collect identity documents from depositors, do not run identity verification on depositors, and do not knowingly collect data of minors, who are not permitted to use the Interface.
2. Purposes and Legal Bases
We process personal data:
(i) to provide and secure the Interface and record your acceptance of the Terms (performance of a contract);
(ii) to apply and evidence the access restrictions required by the Restricted Jurisdictions Policy, including deriving your country from your IP address and recording the result (compliance with legal obligations, including sanctions and gambling laws, and our legitimate interest in operating lawfully and in being able to demonstrate that we did);
(iii) to verify the identity of Curators before their first Vault is deployed (performance of the Curator Terms, and our legitimate interest in knowing who operates Vaults on the Protocol and in being able to enforce the Curator Terms);
(iv) to comply with legal obligations, including sanctions laws and lawful requests from competent authorities (legal obligation);
(v) to prevent fraud, abuse and attacks, to establish, exercise or defend legal claims, and to enforce the Terms (legitimate interests); and
(vi) to send you communications you have requested (consent, withdrawable at any time).
3. Sharing
We share personal data only with:
(i) service providers acting on our instructions, bound by appropriate data protection commitments, currently: hosting and edge infrastructure, including the geolocation of IP addresses (Vercel); database (Supabase); transactional email (Resend); and wallet connection services (Reown, operator of AppKit and the WalletConnect network). If a blockchain intelligence provider or an identity verification provider is engaged under Sections 1.7 or 1.8, it will be added here;
(ii) professional advisers (legal, accounting) under confidentiality;
(iii) competent authorities, including financial, sanctions and gambling regulators and law enforcement, where required by Applicable Law or necessary to protect rights, safety or the integrity of the Interface;
(iv) an arbitral tribunal or court, to the extent necessary to establish, exercise or defend legal claims, including the disclosure of a Curator's verified identity under Section 1.8; and
(v) a successor entity in the event of a corporate transaction, including the incorporated Operator upon incorporation, under this Policy.
We do not sell personal data and we do not share it for advertising.
4. International Transfers
Our service providers may process data in jurisdictions other than yours, including the United States and the European Union. Where required, transfers rely on appropriate safeguards such as standard contractual clauses implemented by the relevant providers, or on another lawful transfer mechanism available under the law that applies to you.
5. Retention
- Terms acceptance records (wallet address, hash, signature, timestamps): retained for as long as necessary to prove contract formation and to establish, exercise or defend legal claims, and thereafter as required by Applicable Law.
- Access-control records (derived country, wallet address, timestamp, action, refusal result): 24 months from the date of the record, unless a longer period is necessary to establish, exercise or defend a legal claim or is required by Applicable Law.
- Curator identity verification records: 5 years from the closure of the Curator's last Vault, or longer where Applicable Law requires.
- Email addresses: until you unsubscribe or ask for deletion.
- Curator profile data: until the Curator removes or updates it, subject to legal retention needs.
- Technical logs: short rotation periods set by our infrastructure providers.
- On-chain data: cannot be deleted by anyone; this is a property of public blockchains, not a retention choice.
6. Your Rights
Subject to Applicable Law, you may request access to, correction or deletion of your personal data, object to or ask for restriction of processing, withdraw consent, and receive a copy of data you provided. We honour these rights except where retention is legally required or necessary for the establishment, exercise or defence of legal claims (which is the case for terms acceptance records, access-control records and Curator identity records during the periods stated in Section 5), and except for on-chain data, which no one can modify or erase.
To exercise your rights, contact privacy@superstrat.io. You may also lodge a complaint with the Information Commissioner of the British Virgin Islands or, if you are in a jurisdiction with its own data protection authority, with that authority.
7. Security
We apply industry-standard technical and organisational measures, including encryption in transit, access controls, server-side verification of signatures, append-only storage of acceptance records, and separate, access-restricted storage of Curator identity records. No system is perfectly secure; you remain responsible for the security of your own wallet, keys and devices.
8. Changes
We may update this Policy, including to reflect changes in our providers, the activation of compliance screening, the engagement of an identity verification provider, or the completion of the Operator's incorporation. Amendments are governed by Section 18 of the Terms; the current version, its version number and its cryptographic hash are published on the Interface.
9. Contact
Privacy requests: privacy@superstrat.io. General legal notices: legal@superstrat.io. Security reports: security@superstrat.io.
SuperStrat Privacy Policy, Version 1.1.0. The authoritative version of this document and its cryptographic hash are published at superstrat.io/privacy.