privacy.txt — Notepad
OFFICIAL COMPANY DOCUMENT — READ IN FULL. HR WILL NOT SUMMARIZE IT (THERE IS NO HR).REV 1.0
WAGIE CORP.
est. 1999 — Corporate documents. Filed on the board; if it’s not on the board, it’s not real.

Privacy Policy — Personnel Files (There Is No Personnel Department)

Effective: [EFFECTIVE DATE] · Operator: [ENTITY NAME] · Contact: [CONTACT E-MAIL] · X: @WagieCorp
Plain-English summary (a courtesy, not a substitute for the full document): The only personal data we collect is what you type into apply.exe (your X handle, wallet address, department choice and the pledge boxes) plus a salted hash of your IP address, your browser’s user-agent string and timestamps, used to process the allowlist and stop abuse. It lives in a Supabase database, is never sold, is shared only with our hosting and database processors, and is deleted or anonymised 12 months after launch. Public pages set no cookies and run no analytics; only the staff admin area uses login cookies. You can ask for a copy or deletion by X DM or e-mail.
Items shown as [BRACKETED PLACEHOLDERS][ENTITY NAME], [JURISDICTION], [CONTACT E-MAIL], [SUPABASE REGION], [EFFECTIVE DATE] — must be completed by the operator before this document is relied on. Until then this text is a draft.
← back to desktop

1. WHO IS RESPONSIBLE AND WHAT THIS COVERS

This Privacy Policy explains how [ENTITY NAME] (“Wagie Corp.”, “we”, “us”) handles personal data in connection with the WagieNet™ website (the “Site”), the apply.exe allowlist form, the Site’s API endpoints and the staff-only administration area. We are the controller of that data. It should be read together with the Terms of Service and the Risk Disclaimer.

This policy does not cover data you publish on a public blockchain (Section 4) or data collected by third-party sites we link to (Section 13).

2. WHAT WE COLLECT (THE WHOLE FILE)

CategoryDataSource / when
WL applicationX handle (stored without the leading “@”); wallet address; department preference; your answer to “Did you buy the top in 2021?”; the three pledge flags; the queue reference we assign; review status; any notes our staff add; time of submission and of review.You, when you submit apply.exe.
Abuse preventionA keyed hash (HMAC-SHA256 with a secret salt) of your IP address — the raw IP address is not written to the database; your browser’s user-agent string; request timestamps.Automatically, when you submit apply.exe.
Wallet connectionYour public wallet address, read from your wallet software when you press CONNECT WALLET. It is held in the page’s memory, shown on screen and pre-filled into the application form. It is not sent to us unless you submit the form.Your wallet, only on your request.
Local device storagediamond.exe stores your best hold time under the key wagie_hebest in your browser’s localStorage. It never leaves your device.Your browser.
Staff (admin area only)Staff e-mail address, authentication session and sign-in timestamps for the people we authorise to review applications.Supabase Auth, only for staff.
Hosting logsStandard, short-lived server and edge logs (IP address, requested URL, user-agent, status, timing) kept by our hosting provider for security and operations.Automatically, on every request.
CorrespondenceWhatever you send us by e-mail or X direct message, including your handle and the content of the message.You, if you contact us.
What we do not collect: no analytics or advertising trackers, no cookies on public pages, no e-mail address (unless you e-mail us), no name, no identity documents, no KYC, no private keys or seed phrases — ever. We do not read your other browser data.

3. WHY WE USE IT AND ON WHAT LEGAL BASIS

  • Processing your WL application — deciding who gets one of the 2,000 allowlist places, generating a queue number, and, if accepted, including your wallet address in the on-chain allowlist. Basis: steps taken at your request before entering into an arrangement with you, and your consent given by submitting the form.
  • Verifying the follow and the engagement — the application requires that you follow the company’s X account and have engaged with its public X posts. We check both against your public X activity using the handle you supply. Basis: our legitimate interest in running the allowlist as announced.
  • Preventing abuse — rate-limiting submissions per hashed IP, rejecting duplicate wallets, and detecting bots. Basis: our legitimate interest in the integrity and security of the Site.
  • Security and operations — keeping the Site running, diagnosing failures, protecting against attacks. Basis: legitimate interest.
  • Announcements — accepted queue numbers may be announced publicly on the board (queue numbers only; never wallet addresses linked to handles unless you have published that link yourself). Basis: legitimate interest and the expectation set in apply.exe.
  • Legal compliance — responding to lawful requests and enforcing our Terms. Basis: legal obligation and legitimate interest.

Where the law of [JURISDICTION] or of your country requires a specific basis, the bases above apply as that law provides. We do not use automated decision-making that produces legal effects on you; a human reviews applications.

4. PUBLIC BLOCKCHAIN DATA

Transactions you sign — buying, selling, burning, swapping badges, escrow, pawns, envelopes — are recorded on Robinhood Chain, a public ledger that we do not control and cannot edit or delete. Your wallet address and the full history of its activity are public and permanent by design. If you post your queue number together with your handle on X, you are linking your handle to that application yourself. Please consider this before you connect a wallet you regard as private.

5. WHERE THE DATA LIVES AND WHO PROCESSES IT

  • Supabase (database and authentication) — the application table, its indexes and staff accounts are stored in a Supabase Postgres project located in [SUPABASE REGION]. Supabase acts as our processor under its data processing terms.
  • Hosting provider — the Site and its API run on Vercel (or another hosting provider the operator chooses; the board will say which). The provider processes request data and short-lived logs as our processor.
  • X Corp. — if you press “Post My Queue # on X”, your browser opens X with a pre-filled draft. We do not send anything to X; X’s own privacy policy applies from that moment.
  • Wallet software — your wallet (for example MetaMask) is a separate product with its own policy.

International transfers. Our processors may store or process data outside your country, including in [SUPABASE REGION] and in the United States. Where required, transfers rely on safeguards recognised under the law of [JURISDICTION] (such as standard contractual clauses or an adequacy decision).

6. SHARING (THERE IS NO DEPARTMENT TO SHARE IT WITH)

  • We do not sell personal data and do not share it for advertising.
  • We share it only with the processors in Section 5, acting on our instructions.
  • We may disclose it if required by law, court order or a lawful request from a public authority, or to establish, exercise or defend legal claims.
  • If the project or [ENTITY NAME] is reorganised, merged or transferred, the data may pass to the successor under this policy.
  • We may publish aggregated, anonymised statistics (for example the number of applications or their distribution by department) that cannot identify you.

7. HOW LONG WE KEEP IT

  • Application data (including hashed IP and user-agent): kept until launch plus twelve (12) months, then deleted or irreversibly anonymised (counts only). If the launch never happens, we delete it twelve months after the allowlist closes.
  • In-memory rate-limit counters: at most one hour, in server memory only.
  • Staff accounts: for as long as the person is authorised, then deleted.
  • Hosting logs: per the provider’s standard retention (typically days, not months).
  • CSV exports made by staff for review: deleted when the review purpose ends.
  • Backups: database backups roll off under the provider’s schedule after the live data is deleted.
  • Correspondence: as long as needed to handle your request and any follow-up, then deleted.

8. HOW WE PROTECT IT

  • The application table is protected by row-level security and is not readable by the public or by signed-in visitors; only our server, using a secret key that never reaches the browser, can read or write it.
  • IP addresses are stored only as keyed hashes with a secret salt; the salt is kept outside the database.
  • All traffic to the Site and to our processors is encrypted in transit (TLS).
  • The administration area requires authentication and is limited to a fixed list of staff e-mail addresses.
  • No system is perfectly secure. If a breach affecting your data occurs, we will notify you and the relevant authority as required by the law of [JURISDICTION], normally via the board.

9. YOUR RIGHTS (YES, YOU HAVE SOME)

Depending on where you live you may have the right to:

  • ask what personal data we hold about you and receive a copy (access / portability);
  • have inaccurate data corrected (rectification);
  • have your data deleted (erasure) — this removes your application from the queue;
  • restrict or object to processing based on legitimate interest;
  • withdraw consent at any time, without affecting processing before withdrawal;
  • complain to the data-protection authority of [JURISDICTION] or of your country of residence.

How to exercise them: send a direct message to @WagieCorp on X from the handle used in the application, or e-mail [CONTACT E-MAIL] from any address, stating the wallet address or queue number. Because applications are identified by wallet, we may ask you to sign a short message with that wallet to prove it is yours before we release or delete data. We answer within thirty (30) days, or sooner if the law requires. We do not charge for reasonable requests and we do not discriminate against you for making one.

10. COOKIES AND LOCAL STORAGE

  • Public pages (the desktop, the legal pages): no cookies, no analytics, no third-party scripts, no fingerprinting.
  • Administration area (/admin): after a staff member signs in, Supabase sets strictly necessary authentication cookies (named sb-…-auth-token) to keep the session. Visitors never receive them.
  • localStorage: the key wagie_hebest holds your diamond.exe best time on your own device. Clear your browser storage to remove it.
  • Because only strictly necessary storage is used, no consent banner is shown. Third-party sites you open from the Site (X, MetaMask, ponsfamily.com) set their own cookies under their own policies.

11. CHILDREN

The Site and the Protocol are not directed at, and may not be used by, anyone under 18 years of age (or the age of majority where they live, if higher). We do not knowingly collect personal data from children. If you believe a child has submitted an application, contact us and we will delete it.

12. DO NOT TRACK AND GLOBAL PRIVACY CONTROL

We do not track visitors across sites or sell data, so there is nothing to opt out of; browser “Do Not Track” and Global Privacy Control signals are honoured by default.

13. THIRD-PARTY LINKS

The Site links to ponsfamily.com, X, metamask.io and other third-party sites. We are not responsible for their content or privacy practices. Read their policies before using them.

14. CHANGES TO THIS POLICY

We may update this policy by posting a revised version with a new effective date on this page; material changes are also announced on the board. Continued use of the Site after a change means you accept the updated policy.

15. CONTACT

Controller: [ENTITY NAME], [JURISDICTION]. E-mail: [CONTACT E-MAIL]. X: @WagieCorp. Data-protection requests are handled by e-mail or X direct message as described in Section 9. There is no HR, but there is an inbox.

← back to desktop
Best viewed at 800×600 in Internet Explorer 5.0. © 1999–2026 Wagie Corp. — All rights belong to the staff. · Terms · Privacy · Disclaimer