The 60-second version
- We collect the bare minimum to operate your Membership and prove what you agreed to.
- We never publish your name, email, or mobile on a public chain — only cryptographic hashes.
- We never sell your data. Ever.
- You can request access or deletion of your off-chain data at any time.
1. What we collect, in plain English
| Bucket | What's in it | Why we need it |
|---|---|---|
| Enrollment data | Full name, email, optional mobile, sponsor, package, ISK wallet, payment tx hash | To open and operate your Membership |
| Consent records | Which version of which document you agreed to, and exactly when | To prove informed consent if anyone asks |
| Session metadata | IP address and user agent at enrollment time | Fraud prevention. Hashed where we can. |
That's it. We do not run third-party analytics that ship your behavior off to ad networks.
2. What we do with it
- Operate your Membership — provision your backoffice, route your distributions, contact you when something matters.
- Produce your on-chain attestation — the canonical record that you joined the Cooperative, what you agreed to, and on what terms.
- Meet our legal obligations — keeping enough records that we can answer a subpoena or a tax authority without losing sleep.
3. What goes on the public chain — and what doesn't
The on-chain attestation we publish to your ISK wallet contains:
- Your Member ID and ISK wallet address (these are public by design).
- SHA-256 hashes of your username and email — not the raw values.
- The package you purchased and the transaction hash that paid for it.
- The slug, version, and IPFS CID of every legal document you agreed to.
- A timestamp.
It does not contain your name, email address, phone number, IP, or any document you uploaded. If someone scrapes the chain, they cannot dox you from it.
4. Who else sees your data
Almost nobody.
- Service providers strictly necessary to run the Cooperative — payment scanners, wallet infrastructure, IPFS pinning. Each is bound by contract to use your data only for the work we ask them to do.
- Authorities when we're legally required to respond, and only for the specific records they're entitled to see.
- The public chain, but only in the hashed form described above.
We do not sell your personal data, and we never will.
5. Your rights
- Access — ask us what we hold on you.
- Correction — fix it if it's wrong.
- Deletion — we'll delete your off-chain personal data on request, subject to records we're legally required to keep.
- On-chain records — these cannot be deleted. They can only be superseded by issuing a new attestation that supersedes the old one.
Reach us at privacy@iskandercoin.com for any of the above.
6. Cookies and the like
We use a tiny amount of localStorage and sessionStorage to keep you signed in and to remember your sponsor if you arrived via a referral link. No tracking cookies. No ad pixels.
7. Changes to this policy
If we materially change this policy, we bump the version, re-pin it to IPFS, and surface the change to you on your next sign-in. The version + CID that you agreed to is preserved in your on-chain attestation forever.
