Privacy policy
Last updated: July 2026
This policy explains what ryfto.io processes for a global public audience on our Polygon raffle platform: wallet data, on-chain activity, technical browser/server data, and—only if you accept—aggregated analytics. It is operational transparency, not legal advice, and is not a GDPR/LGPD “certificate” or official compliance seal. The operator’s internal inventory lives under docs/privacy in the repository.
1. Information we process
Wallet address and Web3 session
When you connect a wallet (e.g. via Reown AppKit / Wagmi), we use your public address for raffles, tickets, notifications, and signing flows. Private keys never pass through our servers.
Transactions and blockchain data
Ticket purchases, draws, and claims are recorded on Polygon (or a test network). That data is public and immutable by design; we cannot delete it from the chain.
Technical data and IP
Hosting providers (e.g. Vercel) may process IP, user-agent, path, and request metadata for security, performance, and operations. On Vercel deployments, an approximate country code may be used only to suggest UI language when no saved preference or useful Accept-Language is available.
Preferences and app usage
UI language, cookie preferences, and—for the admin panel—signed session cookies. Optionally, aggregated visit metrics if you enable analytics in the cookie banner.
2. How we use information
We use information to:
- Operate raffles, purchases, draws, and prize delivery
- Show the right language and experience
- Security, abuse prevention, and service reliability
- Meet legal obligations when they apply
- Improve the product (analytics only with consent)
4. Third parties and blockchain
We may rely on third parties that process data under their own policies, for example:
- Hosting and edge (Vercel) and related infrastructure
- Wallet connection (Reown AppKit / the user’s wallet providers)
- Polygon RPCs, indexing, and transaction relayers when applicable
- Media storage (e.g. IPFS/Pinata) for raffle images
- Social APIs only to show public organizer avatars/profiles when requested
5. What we control (and what we don’t) · practical rights
Ryfto is not a profile-account app (name, email, KYC). Your main identity is your wallet and what is public on Polygon. Off-chain we do not keep a personal dossier you can request like “download my data.” In practice:
- In your browser: language, cookie preference, and wallet session — you clear them (Cookie preferences, disconnect wallet, or clear site data)
- On-chain: purchases, tickets, and results are public and immutable; we cannot export or delete them as a private database
- On our servers/Redis: mostly technical caches derived from already-public chain data (e.g. purchase history keyed by wallet address), public delivery-proof links, rate limits, and ops flags — not a CRM with your name or email
- We do not offer a contact form or support email: the platform is self-service (wallet, on-chain, and browser preferences)
- If a law grants you further rights, the real limit is technical: without an off-chain profile or support channel there is no personal file to inspect or port
6. Security and limits
We apply reasonable technical and organizational measures (HTTPS, signed admin session cookies, access controls). No system is 100% secure. You are responsible for protecting your keys and devices. The blockchain is public by design.
7. Changes to this policy
We may update this policy. The “Last updated” date reflects the current version. Material changes will be communicated on the platform when reasonable. Continued use after publication means you have read the current version.
By using ryfto.io, you accept this privacy policy and our Terms of Service.