Privacy Policy
Last updated: July 18, 2026
1. What we collect
To run your account we store: your username, a hash of your password (we never store the password itself), an optional recovery email, an optional avatar, your hosted wallet addresses and their private keys (encrypted at rest with AES-256-GCM), campaign content you post (titles, stories, images, links), notification preferences, push-notification subscription tokens if you enable them, and basic technical logs (IP address and browser user-agent on sessions) for security.
2. What we don't collect
No government ID or KYC data, no phone number, no contact lists, no advertising trackers, and no third-party analytics scripts. We don't sell or rent personal data to anyone.
3. The blockchain is public
Wallet addresses, token launches, trades, and fee payouts live on Robinhood Chain — a public ledger that anyone can read and nobody (including us) can edit or erase. Don't put anything on-chain, or in campaign content, that you need to keep private.
4. How we use your data
Solely to operate goPumpMe: signing you in, custodying your hosted wallet, launching and displaying campaigns, sending notifications you asked for (push milestones/digests, password-reset and fundraising-progress emails), preventing abuse, and debugging.
5. Who processes it for us
We run on vetted infrastructure providers that process data on our behalf: Railway (API + database hosting), Vercel (website hosting), Supabase (public campaign registry + image storage), Namecheap Private Email (outbound email), and blockchain RPC providers (Alchemy) for on-chain reads. Campaign pages can embed TikTok videos — loading an embed is subject to TikTok's own privacy policy. If you link a social account in the future, we'll store only the public handle and identifiers needed to display it.
6. Cookies and storage
We use one session credential (an httpOnly cookie and/or a token in your browser's local storage) to keep you signed in. No cross-site tracking cookies.
7. Security
Hosted-wallet private keys are encrypted at rest; passwords are bcrypt-hashed; all traffic runs over HTTPS; access to production systems is restricted. No system is perfectly secure — enable a strong unique password, and export your wallet key to self-custody if you hold significant funds.
8. Retention and deletion
Account data is kept while your account exists. Email info@gopumpme.net to delete your account — we'll remove your off-chain personal data (username, email, avatar, subscriptions) within 30 days. On-chain records and any content already public cannot be erased, and we may retain minimal records where the law requires.
9. Children
goPumpMe is not for anyone under 18. We don't knowingly collect data from minors; if you believe a minor has an account, contact us and we'll remove it.
10. Changes and contact
goPumpMe is operated by Mavrk Inc. We'll update this policy as the platform evolves and change the date above. Questions or requests: info@gopumpme.net
