EFFECTIVE: 29 APRIL 2026 · VERSION 1.0
1. INTRODUCTION
This Privacy Policy ("Policy") explains how Moongenz ("we", "us", "our") collects, uses, discloses, retains, and protects personal information when you visit moongenz.io (the "Site") or use our services (collectively, the "Services").
This Policy is designed to comply with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom GDPR ("UK GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and other applicable data protection laws.
If you do not agree with this Policy, please do not use the Services.
2. DATA CONTROLLER
The Moongenz team currently acts as the data controller for the personal information collected through the Services. [TODO: A registered legal entity will be designated as data controller upon formation. The entity name, registered address, and a Data Protection Officer (where required) will be added to this Policy.]
For all data protection matters, please contact: privacy@moongenz.io.
3. CATEGORIES OF PERSONAL INFORMATION COLLECTED
3.1 Information You Provide Directly
- Identity and contact information: email address, optional name, optional Telegram handle.
- Wallet identifiers: Ethereum, Solana, or other blockchain wallet addresses you provide or connect.
- Communications: support tickets, emails, messages, and survey responses.
- Marketing preferences: opt-in choices for newsletters and updates.
3.2 Information Collected Automatically
- Device and connection data: IP address, approximate geolocation derived from IP, browser type and version, operating system, device type, screen resolution, language preference.
- Usage data: pages visited, time spent, click events, referring URL, navigation paths, session duration.
- Cookies and similar technologies: see our Cookie Policy for full details.
- Performance data: error logs, crash reports, page load times.
3.3 Information from the Blockchain
The Ethereum, Solana, and other blockchains we interact with are public ledgers. When you transact with our Smart Contracts, the following information is permanently recorded on-chain and is publicly visible:
- Your wallet address;
- The amount and type of cryptocurrency transferred;
- The timestamp of the transaction;
- The destination contract or address;
- Any data field included in the transaction.
We can read and analyze this data but cannot modify, delete, or restrict access to it. This is an inherent property of public blockchain technology.
3.4 Information from Third Parties
- Payment processors (NOWPayments) may share transaction confirmation, blockchain payment metadata, and network status data.
- Audit and KYC partners for team verification purposes.
- Analytics providers for aggregated usage data.
4. PURPOSES OF PROCESSING
We process your personal information for the following purposes:
4.1 Service Delivery
- Operating the Site, the Presale, staking, and the referral program;
- Enabling wallet connection and transaction processing;
- Sending transactional emails (purchase confirmations, account notifications);
- Processing card payments through third-party providers;
- Calculating and distributing referral bonuses.
4.2 Compliance
- Verifying your eligibility under Section 4 of our Terms;
- Enforcing geographic restrictions;
- Complying with anti-money-laundering (AML) and counter-terrorist-financing (CTF) obligations;
- Sanctions screening;
- Responding to lawful requests from authorities;
- Preserving records required by tax law.
4.3 Security and Fraud Prevention
- Detecting and preventing fraud, abuse, and unauthorized access;
- Investigating potential breaches of these Terms;
- Protecting the integrity of the Services and its users;
- Maintaining audit trails.
4.4 Communications and Marketing
- Sending presale updates, newsletters, and announcements (with consent);
- Responding to your inquiries;
- Notifying you of changes to our terms or policies;
- Conducting surveys.
4.5 Improvement and Analytics
- Understanding how the Site is used;
- Diagnosing technical issues;
- Improving user experience;
- Conducting product research.
5. LEGAL BASIS FOR PROCESSING (GDPR / UK GDPR)
For users in the European Economic Area, the United Kingdom, or other GDPR-equivalent jurisdictions, we rely on the following legal bases under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)): for delivering the Services you have requested.
- Compliance with legal obligations (Art. 6(1)(c)): for AML, CTF, sanctions, and tax compliance.
- Legitimate interests (Art. 6(1)(f)): for security, fraud prevention, internal analytics, and limited direct marketing of similar services to existing users. We balance our interests against your rights and freedoms in each case.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing emails to new contacts, and any processing of special categories of data. You may withdraw consent at any time.
6. DISCLOSURE OF PERSONAL INFORMATION
We may disclose your personal information to:
6.1 Service Providers (Processors)
We engage third-party processors who handle data on our instructions. Categories include:
- Hosting and infrastructure: Vercel, Cloudflare;
- Email delivery: e.g. SendGrid, Mailchimp, Resend;
- Analytics: e.g. Google Analytics, Plausible, Fathom;
- Customer support tools;
- Payment processing: NOWPayments (crypto only, no card processing);
- Database storage: e.g. Supabase, PostgreSQL hosts;
- Error monitoring: e.g. Sentry.
Each processor is bound by a contract requiring confidentiality, security, and processing only on our instructions.
6.2 Audit and Compliance Partners
SolidProof, Coinsult, and similar audit firms may receive limited information necessary to verify the team and the Smart Contract.
6.3 Legal and Regulatory Authorities
We may disclose information to courts, regulators, and law enforcement agencies where legally compelled or where we believe in good faith that disclosure is necessary to comply with Applicable Law, enforce our terms, or protect rights and safety.
6.4 Successors
If Moongenz is acquired, merged, or restructured, personal information may be transferred to the successor entity, subject to this Policy.
6.5 No Sale of Personal Information
We do not sell personal information for monetary consideration. We do not engage in cross-context behavioral advertising as defined under CPRA.
7. INTERNATIONAL DATA TRANSFERS
Your personal information may be transferred to and processed in countries outside your country of residence, including jurisdictions whose data protection laws differ from those in your country.
For transfers from the EEA, UK, or Switzerland to third countries that have not received an adequacy decision, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- UK International Data Transfer Agreements where applicable;
- Supplementary measures including encryption in transit and at rest.
You may request a copy of the relevant safeguards by contacting privacy@moongenz.io.
8. DATA RETENTION
We retain personal information only for as long as necessary for the purposes described in this Policy, subject to legal retention requirements:
- Email addresses: until you unsubscribe, plus 12 months for legitimate-interest analysis, or up to 3 years from last interaction.
- Wallet addresses tied to purchases: a minimum of 5 years from the year of the transaction, in line with AML record-keeping requirements.
- KYC data from card processors: 5 years from the date of the underlying transaction.
- Support communications: 24 months following case closure.
- Analytics data: aggregated and anonymized after 14 months.
- Server logs and security data: 90 days, or longer where investigation requires.
- Blockchain data: retained on-chain indefinitely; we cannot delete.
9. SECURITY
We implement appropriate technical and organizational measures to protect personal information, including:
- Encryption in transit (TLS 1.2+) and at rest where supported;
- Access controls and least-privilege principles;
- Regular security reviews and dependency monitoring;
- Incident response procedures;
- Staff training and confidentiality agreements.
No system can guarantee absolute security. In the event of a personal data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours where required by Applicable Law.
10. YOUR RIGHTS
10.1 Rights Under GDPR / UK GDPR
Subject to certain conditions and exemptions, you have the right to:
- Access: obtain confirmation of and a copy of your personal information;
- Rectification: correct inaccurate or incomplete data;
- Erasure: request deletion (subject to legal retention obligations and the limits of blockchain technology);
- Restriction: limit how we process your data in certain circumstances;
- Portability: receive a structured, machine-readable copy of data you provided;
- Object: oppose processing based on legitimate interests, including direct marketing;
- Withdraw consent: for any processing that relies on consent;
- Lodge a complaint with your local data protection authority.
10.2 Rights Under CCPA/CPRA
Although we restrict access from California residents under our Terms, where CCPA/CPRA applies you have the right to:
- Know what personal information is collected, used, shared, or sold;
- Delete personal information held about you;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information (we do not sell or share);
- Limit the use of sensitive personal information;
- Non-discrimination for exercising your rights.
10.3 Exercising Your Rights
To exercise any of these rights, please email privacy@moongenz.io. We will respond within 30 days (one month under GDPR), with a possible extension of up to two further months for complex requests, in which case we will notify you.
We may need to verify your identity before fulfilling your request. We will not charge a fee for reasonable requests; we may charge or refuse manifestly unfounded or excessive requests.
11. AUTOMATED DECISION-MAKING
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, except in connection with sanctions screening and fraud prevention. You have the right to request human review of any such decision.
12. CHILDREN
The Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a minor has provided personal information, we will delete it without delay.
13. THIRD-PARTY SITES
The Site may contain links to third-party sites. We are not responsible for the privacy practices of those sites. Please review their policies before providing any personal information.
14. CHANGES TO THIS POLICY
We may update this Policy to reflect changes in our practices or in Applicable Law. Material changes will be posted on the Site and, where you have provided an email address, sent to you by email. The "Effective" date at the top of this Policy will be updated accordingly.
15. CONTACT
Privacy questions and rights requests: privacy@moongenz.io.
For users in the EEA, you may also contact your local supervisory authority. A list is available at edpb.europa.eu.