Legal
Privacy
What Virtuallock stores, why, and who else sees it. We keep this short because we collect very little.
Draft — not legal advice, to be reviewed by counsel.
Public blockchain data
Virtuallock keeps a copy of public TokenLock events from the blockchain: lock ids, token and wallet addresses, amounts, burn settings, unlock times and transaction hashes. This data is already public on the chain. We copy it so pages load quickly. Wallet addresses are pseudonymous, but they can sometimes be linked to a person, so we treat them with care.
Blockchain records cannot be edited or deleted by anyone, including us. Removing our copy would not remove them from the chain or from block explorers.
What we store about you
Beyond the public chain data, we store only:
- Feature requests: when you ask to feature a lock, we store your wallet address, the token address and the lock transaction hash.
- Dashboard layout: if you save a dashboard layout, we store it against your wallet address.
- Developer API keys: if you create a key, you sign in by signing a message with your wallet (no password). We store your wallet address, the key's label, a hash of the key (never the key itself), when it was created and last used, and a count of requests per day per endpoint. A session cookie keeps you signed in to the developer console and is used for nothing else.
- Rate limiting: to stop abuse we count requests per IP address, using a one-way hash of the address rather than the address itself, for a short time.
What we don't collect
We don't ask for your name, email or phone number. We don't currently use advertising or analytics trackers, and we don't set cookies for tracking or advertising. We never see your private keys or seed phrase.
Your wallet connection library keeps your recently used wallet in your browser's local storage so it can reconnect you. That stays on your device. The wallet connection code also contacts WalletConnect (Reown) servers to load its configuration and record connection usage events, and if you connect with WalletConnect, its relay service carries messages between the site and your wallet. Those services operate under their own terms.
Error reporting
We use Sentry to find and fix errors. When something breaks, an error report is sent containing technical details such as the error message, the page address, and your browser and operating system, and it may include your IP address. We don't use session replay and we don't intentionally send wallet addresses or other personal details to Sentry.
Service providers
The site is hosted on Vercel and our database runs on Supabase. Like any web host, they process technical request data such as IP addresses in server logs. We read public data from blockchain RPC providers and the network's block explorer; those requests are made by our servers, not on your behalf.
Your choices and rights
You can ask us to delete your saved dashboard layout, feature requests or developer API keys. Depending on where you live (for example under the EU or UK GDPR), you may also have rights to access, correct, delete or restrict the use of personal data we hold, to object to its use, and to complain to your data protection authority. Write to [CONTACT EMAIL]. We cannot erase public blockchain data. Our basis for this processing is our legitimate interest in running and protecting the service, plus your request where you ask for a feature. The data controller is [LEGAL ENTITY NAME — counsel to confirm].
Our providers (Vercel, Supabase, Sentry and WalletConnect) may process data outside your country, including in the United States. [INTERNATIONAL TRANSFER MECHANISM — counsel to confirm.] We keep stored data only as long as we need it for the purposes above. [RETENTION PERIODS — counsel to confirm.]
Changes
If we start collecting more, for example an email address for unlock alerts, we will update this page before that feature goes live and ask for your consent where required.