Privacy Policy

Last updated: 2026-04-17

1. Overview

RecordPool is a phygital music marketplace. This Privacy Policy describes how we collect, use, and protect your information when you use the RecordPool platform.

By using RecordPool, you agree to the practices described in this policy.

2. Information We Collect

  • Wallet Address — Your Ethereum wallet address, provided when you connect via WalletConnect. This is your primary identifier on RecordPool
  • SIWE Signature — A signed message used to verify wallet ownership. The signature is validated server-side and a session cookie is issued
  • Shipping Address — Name and mailing address, provided when purchasing physical NFC cards
  • Email Address — Provided during Stripe checkout for fiat purchases, used for order communication and stream access reactivation
  • Transaction Data — On-chain transaction hashes, token IDs, and purchase records associated with your wallet
  • Upload Content — Audio files, cover art, and metadata uploaded by creators
  • Usage Analytics — Anonymous page views and events collected via Plausible Analytics (no cookies, no personal data)

3. How We Use Your Information

  • Authenticate your identity via wallet signature (SIWE)
  • Process purchases and ship physical NFC cards
  • Distribute royalties to creators and contributors via on-chain split contracts
  • Provide stream access to purchased music
  • Create on-chain attestations binding NFC chips to tokens and metadata
  • Send transactional emails (order confirmation, stream access reactivation)
  • Improve the platform based on anonymous usage patterns

4. Blockchain Data

  • Wallet addresses, token ownership, attestations, and transaction history are recorded on public blockchains (Ethereum, Sepolia)
  • Blockchain data is immutable and publicly visible — RecordPool cannot delete or modify it
  • On-chain attestations include release metadata, NFC chip identifiers, and content hashes

5. Data Storage

  • Off-chain data (shipping addresses, session data, order records) is stored in a MongoDB database hosted on Google Cloud Platform
  • Audio files and cover art are stored in Google Cloud Storage
  • Session cookies are used for authentication and expire after the browser session ends
  • We do not use tracking cookies or third-party advertising

6. Third-Party Services

  • WalletConnect — Wallet connection protocol. Subject to WalletConnect's Privacy Policy
  • Stripe — Fiat payment processing. Subject to Stripe's Privacy Policy
  • Google Cloud Platform — Infrastructure and file storage
  • Plausible Analytics — Privacy-friendly, cookie-free web analytics
  • 0xSplits — On-chain royalty distribution contracts
  • Ethereum Attestation Service (EAS) — On-chain attestation protocol

7. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. Information is shared only as necessary to:

  • Process payments (Stripe receives email and payment details)
  • Ship physical cards (shipping carriers receive name and address)
  • Record on-chain data (public blockchain transactions)
  • Comply with legal obligations

8. Data Retention

  • Account data is retained as long as your wallet has activity on RecordPool
  • Order and shipping records are retained for legal and accounting purposes
  • Blockchain data is permanent and cannot be deleted
  • You may request deletion of off-chain data by contacting us

9. Your Rights

  • Disconnect your wallet at any time to end your session
  • Request access to or deletion of your off-chain personal data
  • On-chain data (tokens, attestations, transactions) cannot be modified or deleted by RecordPool

10. Security

We use encryption (HTTPS/TLS), secure session management, and access controls to protect your data. Private keys are never stored or transmitted by RecordPool — all wallet interactions are signed client-side.

11. Changes to This Policy

RecordPool may update this privacy policy at any time. Continued use of the platform after changes constitutes acceptance. Material changes will be communicated via the platform.

12. Contact

For privacy inquiries, contact support@recordpool.io or RecordPool Discord