Legal
Privacy Policy
Effective 2 July 2026 · Version 1.3
This Privacy Policy describes how 0xFútbol Inc, a BVI Business Company (registration number 2169115, registered office at Trinity Chambers, PO Box 4301, Road Town, Tortola, VG1110, British Virgin Islands), trading as Realmint ("Realmint", "we", "us", or "our"), collects, uses, discloses, and protects personal data when you visit our website at realmint.io, use our web application, subscribe to our newsletter, or call our APIs (together, the "Service").
We are the controller of the personal data described below for the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"), and equivalent laws in other jurisdictions where they apply to us.
1. Scope
This Policy applies to personal data we process in connection with:
- the public website at realmint.io and any subdomain we operate;
- the Realmint web application, including authentication, watchlists, asset comparisons, and any feature we add over time;
- the Realmint newsletter and any other email we send;
- our programmatic APIs;
- communications you have with us by email or otherwise.
This Policy does not apply to third-party websites, smart contracts, blockchains, or services that you may access through links or integrations in the Service. Public blockchain transactions you sign are, by their nature, public — once a transaction is confirmed on a public network, we cannot remove or alter the on-chain record.
2. The personal data we collect
2.1 Authentication and account data
We use Privy Technologies, Inc. ("Privy") as our authentication and embedded-wallet provider. When you create an account, Privy issues you a decentralised identifier ("Privy DID") and, if you choose, an embedded wallet whose keys you control. We mirror the following information from Privy into our users database:
- your Privy DID;
- your email address (when the Privy SDK supplies it);
- your primary wallet address.
We may also store sign-in counts and timestamps for security and fraud-prevention purposes. We do not have access to your wallet's private keys at any time.
2.2 Newsletter signups
When you subscribe to a newsletter, we collect: your email address, the signup-source label, the page path on which you subscribed, the HTTP referrer, your user-agent string, and the timestamp.
2.3 Server logs
When you make a request to our website or APIs, our servers automatically record: your IP address, user-agent string, the request path and method, the HTTP status code, request and response sizes, timestamps, and a limited set of request headers necessary for diagnosing issues.
2.4 Analytics
We use Google Analytics 4 ("GA4"), provided by Google LLC, and OpenPanel for product and traffic analytics. These tools collect pseudonymous identifiers, page views, and custom events such as button clicks, watchlist actions, and conversion events. When you are signed in, we associate your OpenPanel profile identifier with your Privy DID and may attach your wallet address and email address as profile properties so that we can connect product behaviour to a known account.
2.5 Session replay
OpenPanel offers an optional session replay feature. We use it only if you opt in through the cookie consent banner. When enabled, recordings:
- mask all text content and form input values by default;
- are sampled at approximately 10% of sessions; and
- are not used to attempt to identify you beyond what other authenticated data already does.
Session replay is off by default. You can withdraw consent at any time via the cookie preferences control on the website.
2.6 Product activity
When you create a watchlist, run an asset comparison, or use any other authenticated feature, we associate that activity with your Privy DID so that we can render your view, deliver notifications you ask for, and improve the Service. We also store route intents associated with on-chain transactions you ask us to compose, so that we can build, execute, track, and reconcile those transactions.
2.7 Categories of data we do not collect
We do not collect, request, or store: government-issued identification documents, biometric data, special-category personal data within the meaning of Article 9 GDPR / UK GDPR, financial-account credentials, or know-your-customer ("KYC") records. We are not a regulated financial institution and we do not perform identity verification.
3. How we use your data and our lawful bases
| Purpose | Categories of data | Lawful basis (GDPR / UK GDPR Art. 6) |
|---|---|---|
| Provide and maintain the Service, including authentication, watchlists, and comparisons | Account data, product activity | Performance of a contract (Art. 6(1)(b)) |
| Send transactional emails (security, account, billing) | Email address, account data | Performance of a contract (Art. 6(1)(b)) |
| Send the newsletter | Email address, signup metadata | Consent (Art. 6(1)(a)) |
| Operate strictly-necessary cookies and core security | Server logs, session cookies | Legitimate interests — operating the Service securely (Art. 6(1)(f)) |
| Operate analytics (GA4, OpenPanel events) | Pseudonymous identifiers, events | Consent (Art. 6(1)(a)) |
| Operate session replay | Recordings (text/inputs masked) | Consent (Art. 6(1)(a)) |
| Detect, prevent, and respond to fraud, abuse, security incidents, and sanctions-list matches | Account data, server logs, security-event logs | Legitimate interests — protecting the Service and our users (Art. 6(1)(f)); compliance with legal obligation where applicable (Art. 6(1)(c)) |
| Comply with tax, accounting, sanctions-screening, and other legal obligations | The minimum data set necessary | Legal obligation (Art. 6(1)(c)) |
| Establish, exercise, or defend legal claims | The minimum data set necessary | Legitimate interests (Art. 6(1)(f)); legal claims (Art. 9(2)(f) where applicable) |
We do not use your personal data for automated decision-making with legal or similarly significant effects, and we do not use it for behavioural advertising.
4. Cookies and similar technologies
We use three categories of cookies and similar technologies:
- Strictly necessary — required for the Service to function (session, security, load balancing, cookie consent state). Cannot be disabled.
- Analytics — GA4 and OpenPanel events.
- Session replay — OpenPanel session recording. Off by default everywhere; loaded only after you explicitly opt in.
How analytics are loaded depends on the law of the country from which you are visiting:
- If you are visiting from the European Economic Area, the United Kingdom, Switzerland, Brazil, or any other jurisdiction whose law requires prior opt-in consent for non-essential cookies, we present a cookie consent banner before loading any analytics or session replay technology. Analytics and session replay are off by default and are loaded only after you opt in. We detect your jurisdiction on a best-effort basis from your browser-reported timezone.
- In jurisdictions where prior opt-in consent is not legally required for non-essential analytics (for example, the United States, Canada, Australia, and most of Asia), we may load Google Analytics 4 and OpenPanel by default and we do not present the banner. You can opt out at any time using the "Cookie preferences" control linked from the site footer.
- Regardless of your jurisdiction, if your browser sends the Global Privacy Control signal (
navigator.globalPrivacyControl), we treat it as a refusal of analytics and session replay and we do not load those technologies.
We use Google Consent Mode v2 with ad_storage, ad_user_data, ad_personalization, and analytics_storage defaulting to denied on every page load; tags are updated to "granted" only when the applicable consent state above allows it. You can change your preferences at any time using the "Cookie preferences" control linked from the site footer.
5. Sharing your data
We do not sell your personal data. We share it only with the following categories of recipient and only to the extent necessary:
- Subprocessors that operate parts of the Service on our behalf (see Section 6).
- Professional advisers (lawyers, accountants, auditors), where covered by professional confidentiality.
- Authorities, regulators, and courts, where required by law, regulation, or a valid legal process binding on us, or to protect our rights, the rights of users, or the integrity of the Service.
- Acquirers in the context of a merger, acquisition, or transfer of all or part of our business, subject to confidentiality undertakings and to your rights under data-protection law.
We do not share personal data with advertisers and we do not participate in real-time bidding or any cross-context behavioural advertising network.
6. Subprocessors
The current list of subprocessors that process personal data on our behalf is:
| Subprocessor | Purpose | Region of processing |
|---|---|---|
| Privy Technologies, Inc. | Authentication, embedded wallets | United States |
| OpenPanel | Product analytics and optional session replay | European Union |
| Google LLC | Google Analytics 4 | United States and other regions |
| Our hosting and database provider | Web, application, and database hosting | United States and other regions |
| Our email-delivery provider | Transactional and newsletter email | United States |
| Our error-monitoring provider | Application error tracking | United States or European Union |
We have a written data-processing agreement in place with each subprocessor that includes the obligations required by Article 28 GDPR and Article 28 UK GDPR. The current list above will be updated when subprocessors change. A current list with the legal name and address of each subprocessor is available on request to [email protected].
7. International data transfers
Because some of our subprocessors process data outside the European Economic Area or the United Kingdom (in particular in the United States), we transfer personal data internationally. Where we do, we rely on appropriate safeguards required by Chapter V GDPR / UK GDPR, in particular:
- the EU Standard Contractual Clauses (2021/914) and, for transfers from the UK, the UK International Data Transfer Addendum issued by the Information Commissioner's Office;
- supplementary technical and organisational measures where required by the transfer-impact assessment; and
- certifications under the EU–US Data Privacy Framework and the UK Extension to the EU–US Data Privacy Framework where the recipient is certified.
Copies of the relevant transfer mechanism are available on request to [email protected].
8. How long we keep your data
| Data | Retention |
|---|---|
| Account record (Privy DID, email, wallet address, sign-in counts) | For as long as your account is active, plus twenty-four (24) months after the later of (a) your last sign-in, (b) your account-deletion request, or (c) your last interaction with the Service. After that period we delete or irreversibly anonymise the record. We may retain specific elements longer where required by tax, accounting, AML/CTF, sanctions-screening, or legal-hold obligations, in which case we retain only the minimum dataset necessary for that purpose and for no longer than the applicable statutory period. |
| Newsletter subscription record | For as long as you remain subscribed. After unsubscribe we retain a minimal proof-of-consent record (email address and consent timestamp only) for thirty-six (36) months under Article 7 GDPR / UK GDPR and the PECR, after which it is deleted. |
| Server logs | General request logs (IP, user-agent, path, method, status, size, timestamp, limited request headers): ninety (90) days, after which they are deleted or aggregated. Security-event logs (rate-limit triggers, suspected abuse, authentication anomalies, sanctions-screen hits): up to twelve (12) months, after which they are deleted unless retained under a specific legal hold. |
| Analytics events (GA4, OpenPanel) | Up to fourteen (14) months at the event level, after which the event row is deleted. Aggregated, non-identifying reports may be retained beyond that period. |
| Session replay recordings | Thirty (30) days from the date of recording, after which the recording is permanently deleted. |
| Support and other correspondence | Up to twenty-four (24) months from the last message, unless retained longer for legal-hold reasons. |
9. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you and obtain a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") in the circumstances set out in Article 17 GDPR / UK GDPR;
- restrict processing of your data in the circumstances set out in Article 18;
- object to processing based on legitimate interests, and to direct marketing at any time;
- portability — receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller, where technically feasible;
- withdraw consent at any time where we rely on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal;
- lodge a complaint with a supervisory authority — in particular your local data-protection authority if you are in the EEA, or the UK Information Commissioner's Office (ICO) if you are in the United Kingdom.
To exercise any of these rights, please email [email protected]. We will respond within one (1) month, extendable by up to two further months for complex requests, in accordance with Article 12(3) GDPR / UK GDPR.
10. Marketing
We send marketing emails (the newsletter) only to people who have opted in. Every marketing email contains an unsubscribe link, and you can also unsubscribe at any time by emailing [email protected]. Transactional and security emails are sent on the basis of our contract with you and you cannot unsubscribe from those while you have an active account.
11. Children
The Service is not directed to children under the age of 18 (or the age of majority in your jurisdiction, if higher). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact [email protected] and we will take steps to delete it.
12. Security
We use industry-standard technical and organisational measures to protect your personal data, including encryption in transit (TLS 1.2 or higher), encryption at rest for sensitive fields, role-based access controls, audit logging, and regular review of subprocessors. No system is perfectly secure, however, and we cannot guarantee the absolute security of data transmitted to or stored on the Service.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will update the "Effective date" and version number above. For material changes we will notify you by email (where we have your address) or by a prominent notice on the Service before the change takes effect. Your continued use of the Service after an update constitutes acceptance of the updated Policy, to the extent permitted by applicable law.
14. Contact
For all data-protection enquiries, including subject-access requests, please contact:
Email: [email protected]
Postal address:
Realmint — Data Protection
c/o 0xFútbol Inc
Trinity Chambers, PO Box 4301
Road Town, Tortola, VG1110
British Virgin Islands
EU and UK Representative under Article 27 GDPR / UK GDPR
We have not appointed a representative within the meaning of Article 27 GDPR or Article 27 UK GDPR. We have assessed our processing activities against the exemption in Article 27(2)(a) and concluded that it applies because:
(a) our processing of the personal data of data subjects in the European Economic Area and the United Kingdom is occasional in the regular conduct of our business as an editorial publisher of signals on third-party tokenized real-world assets, and is incidental to that core editorial activity;
(b) we do not process special categories of personal data within the meaning of Article 9, nor data relating to criminal convictions and offences within the meaning of Article 10, on any scale; and
(c) the processing is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account that we do not perform automated decision-making with legal or similarly significant effects, do not engage in behavioural advertising or cross-context tracking, do not profile individuals beyond pseudonymous analytics deployed only with prior opt-in consent, and apply masking and a 10% sample rate to optional session replay.
We keep this assessment under review and will appoint a representative if and when our processing exceeds the threshold of the exemption. In the meantime, all data-protection enquiries from data subjects in the EEA and the UK can be directed to [email protected] and will be handled with the same response times set out above.
Data Protection Officer
We have not appointed a Data Protection Officer because our processing activities do not meet the thresholds in Article 37(1) GDPR or Article 37(1) UK GDPR. Our core activities do not consist of (a) large-scale, regular and systematic monitoring of data subjects, or (b) large-scale processing of special categories of personal data or data relating to criminal convictions. For all data-protection matters please contact us at [email protected].