1. Scope and controller
This policy covers CashLink and its short URLs, images, files, reminders, price alerts, advertising and support tools. Operator details will be added before commercial launch.
2. Data we collect
We may process account and contact data, user content, evidence metadata, blockchain transactions, earnings, technical security signals and reports. Consented analytics processes named pages, feature events, source hostnames, allowed UTM fields, country, device, and versioned HMAC visitor/session identifiers. It does not retain full Referer URLs, raw IP addresses, analytics tokens, or User-Agent strings.
2A. Google sign-in data
When you choose Google sign-in, Google provides a stable account identifier, verified email address, and profile name. CashLink stores only a SHA-256 hash of the Google account identifier, the provider name, linkage timestamps, and the CashLink account relationship. The name is used only to initialize a new account. We do not store Google access tokens, refresh tokens, raw ID tokens, provider payloads, or Google profile photos, and those credentials are excluded from data exports. Google may process authentication data across borders under its own privacy terms.
3. Purpose and legal basis
Data supports service delivery, verification, analytics, rewards, fraud prevention, support, legal requests, security and compliance. Bases may include contract, consent, legal duty and legitimate platform safety interests.
4. Use, location and recipients
Data is processed by automated or manual means in operating and backup locations and may be shared with cloud, mail, payment, security or legal providers when necessary. Advertising destination URLs may be checked by Google Web Risk; do not put passwords or tokens in them.
5. Retention
Traffic detail and the analytics cookie follow the general analytics retention setting (90 days by default); non-financial fraud rejections last 180 days. De-identified aggregates may be retained longer with small-group protection. Withdrawing analytics consent removes linkable visitor detail while aggregates remain. Financial, reward, governance, legal-hold and public blockchain records may be permanent. Exports and backups default to 30 days; account deletion has a 365-day withdrawal period. Legal holds prevail.
6. Your rights
Members can create an encrypted export or request account deletion from the privacy center after re-verification. Exports exclude other people’s data, internal risk notes and security credentials. You may also request access, correction, copies or restriction.
7. If data is not provided
Missing required account or service data may prevent account creation, rewards, responses or specific features. Optional data remains optional.
8. Browser data, security, keys and transfers
Anonymous image history and visitor tools may remain only in browser storage. We use versioned HMACs, hashes, password hashing, access control, CSRF, anti-fraud and key rotation without retaining raw identifiers. Providers may process data abroad with reasonable safeguards.
9. Children and updates
Rewards and advertising are not offered to people under 18. Material updates are announced on the site. Contact: [email protected].
10. Administrator security data
Admin email 2FA and trusted devices process device class, a country code from verified Cloudflare data or the local IP-country database fallback, masked IP, token hashes and activity time. Visitor-supplied country headers are ignored; raw tokens and full IPs are not stored. Challenges last 7 days and revoked devices are removed after 180 days.
11. External image tools
Evidence pages only link to third-party AI and Content Credentials Verify tools. CashLink does not automatically upload photos or metadata; third parties apply their own policies.
12. Advertising events and private reports
Advertising records selected, served, viewable, qualified, billable and click states and uses HMACs for attribution and anti-fraud. Report capabilities are stored only as SHA-256 hashes and can be revoked or rotated by the owner.
13. Guest faucet abuse-prevention identity
Guest claims use a versioned HMAC of the source IP and a SHA-256 hash of a dedicated random first-party browser cookie for cooldown, queue access, and authorized reclaims. CashLink does not store the raw IP, cookie, or token. Anonymous identifiers are retained for up to 365 days and then redacted, while necessary on-chain transaction and claim audit records remain. An active legal hold overrides cleanup.
14. Named donations and honor roll
When you expressly consent to a named donation, your display name, message, actual BCH received, and receipt date are published in the honor roll. CashLink allocates a dedicated HD receive address and stores only a hash of the status token; BCH transactions are public on-chain data. You may ask us to hide the public entry, while necessary payment, financial, fraud-prevention, and audit records may be retained for legal or accounting integrity.
15. Image tips
General image tips reveal the creator's selected BCH, CashToken, ETH, BTC, or DOGE receive address only after the visitor selects that asset. BCH and LinkCash may use temporary payment-monitoring state; ETH, BTC, and DOGE are manual transfers that CashLink does not monitor, attribute, or record as donations. Named image tips remain limited to BCH, LinkCash, and LinkCredit and process the submitted name, optional message, visibility choice, requested and received amount, image and recipient relationship, payment state, and necessary on-chain evidence. An entry appears in that image's public honor roll only when publication is selected; otherwise it is visible only to the image creator and necessary administrators. Funds go directly to the creator's wallet and are not CashLink revenue, while exact-amount attribution, reversal, and duplicate-claim evidence for named tips is retained.
14. BCH payment and guest recovery data
To issue paid credits, deliver live updates, recover orders, refund funds, and preserve audits, we store orders, hashed guest and recovery identifiers, HD address allocations, UTXO links, state events, refund addresses, and transaction identifiers. A raw recovery code is displayed only on creation or successful recovery and is not stored in the database, Redis, URLs, or logs. Required payment, refund, and public blockchain audit data may be retained permanently, and CashLink cannot erase public blockchain data.
15. Guest space and recovery
A guest space may link short URLs, uploads, pastes, reminders, alerts, and transaction records. The server stores only versioned HMACs of each device cookie and the recovery code, never their originals. After 365 inactive days private reminders and alerts are deleted, public content is detached, and financial or legal audit is retained without the guest link.
16. Public Image Space API
Only hashes of account, recovery, and order tokens are stored. Trusted source IPs, request times, file hashes, and payment events are processed for rate limits, abuse prevention, webhook delivery, and security audit; IP data follows the existing retention policy.
17. BCH on-chain proof credit data
To administer proof credits, we store per account or guest space the balance, immutable ledger, purchase batches, Taipei calendar week, free-credit source, actual BCH intent, and payment/reversal events. Guest recovery or verified adoption transfers these records to the new owner while a guest intent keeps a null creator. Public on-chain content, TXIDs, and timestamps cannot be removed from the blockchain when an account is deleted.
18. Authenticator and recovery-code data
TOTP secrets and pending setup secrets are stored with application encryption. Recovery codes are stored only as purpose-separated hashes and their plaintext is shown or downloaded once after creation. QR provisioning URIs, one-time passwords, and plaintext recovery codes are excluded from logs, audit context, queued mail, and data exports. TOTP is a security confirmation method; it does not verify email ownership or replace membership identity requirements. This data is cleared when account deletion is scheduled.
19. Paid image unlock
Image payment retains the image, order, amounts, receipt events, versioned HMAC hashes of the anonymous browser token and trusted source IP, the permanent browser entitlement, and the IP’s fixed seven-day expiry. For immediate returns it also retains the source txid, encrypted payment raw transaction, the refund CashAddr derived from the first input prevout, gross amount, platform-sponsored fee, and refund state for signing, broadcast, recovery, reversal, and audit. It stores neither the raw browser token nor raw IP.
20. Short URL paid analytics
Paid analytics retains the account-linked expiry, quote snapshots, total, consumed, remaining, and revoked seconds, and payment state for FIFO settlement, reversals, refunds, audit, and recovery. An active entitlement temporarily blocks account deletion; afterward the account link may be anonymized while immutable purchase and payment history remains under financial retention duties.
21. File sales
File sales retain orders, allocations, txids, provider consensus, states, and immutable fee entries. Guest buyers use a buyer-cookie hash and GuestOwner association; cross-device recovery reuses the versioned Guest Center credential and creates no file-specific recovery code. Legacy per-order recovery hashes remain only for compatibility and are no longer issued. Linking to a member revokes the buyer cookie, GuestOwner association, and legacy codes. A member export includes that member’s orders and entitlements but excludes secrets and raw provider data; account deletion never restores anonymous access.
22. CashCell data and retention
CashCell does not retain raw IP addresses, one-use connection tickets, raw WebSocket payloads, or raw per-input data. It processes purpose-separated IP/browser HMACs, account and country eligibility, participations, fragment authority, and safe gameplay summaries for connectivity, anti-collusion, replay, and recovery; gameplay summaries are kept for 30 days. LinkCredit admission, absorption, extraction, bounty, and refund events are immutable financial evidence that may be retained permanently and included in your export; unsettled escrow temporarily blocks account deletion.