Legal

Privacy Policy

Effective date: July 28, 2026

1. What We Collect

  • TON wallet address and network from TonConnect sign-in, plus proof-related fields used to verify the session (for example public key and wallet state init).
  • Telegram username submitted in a DAO membership application.
  • Discord username when you have linked Discord or include it in a DAO membership application.
  • DAO membership application fields: application message, holder-mode wallet and signature when you apply as a holder, and the connected application wallet address.
  • Connect form submissions at /connect: topic intent, name, contact (email or Telegram handle), and message.
  • Optional profile fields you choose to add after membership (for example display name, bio, avatar, or location).
  • Referral attribution data: referral code or session identifiers, plus hashed IP and hashed user-agent values for abuse prevention.
  • Technical logs for security, abuse prevention, and troubleshooting.
  • Internal product events stored in our systems (for example: home view, auth connect click/success/error, DAO application open/submit). When you are signed in, these events may be associated with your wallet address.

2. Why We Collect It

  • Authenticate users and maintain secure sessions.
  • Process DAO membership applications and governance access.
  • Route Connect inquiries to the team and respond to outreach.
  • Operate referral attribution and membership funnels.
  • Protect the platform against spam, fraud, and abuse.
  • Measure product flow and improve UX using internal analytics.

3. Cookies and Session Data

We use cookies and similar browser storage for authentication (access and refresh tokens), session continuity, and referral or session attribution features.

Public forms that use hCaptcha (Connect and DAO membership application) may load third-party verification services that set their own cookies or similar identifiers. We use hCaptcha for bot protection, not for advertising.

We do not use third-party advertising trackers for core product analytics.

4. Sharing

We do not sell personal data. Data may be processed by infrastructure providers required to operate the service (hosting, security, delivery). Access is restricted to authorized operators.

Bot verification on public forms is handled by hCaptcha (Intuition Machines). When configured, team alerts for new DAO applications or Connect inquiries may be delivered through Telegram to authorized operators.

On-chain activity read through XDAO or TON infrastructure is public blockchain data, not private account data we control.

5. Retention and Security

We retain data only as long as needed for operations, security, compliance, and dispute resolution. Referral sessions expire after a limited period. We apply technical and organizational safeguards to reduce unauthorized access risk.

6. Your Choices

You can disconnect your wallet session through TonConnect and end your signed-in session in the app. To request a review of stored account data or deletion where applicable, contact the Quavence DAO team through official community channels. Some records (for example governance, treasury, or security logs) may need to be retained even after a deletion request.

There is no self-service account deletion button in the product today; requests are handled manually by operators.

7. Contact

For privacy questions, contact the Quavence DAO team via official community channels.

2025-2026 Quavence DAO/Privacy/Terms