Privacy Policy
This Privacy Policy explains how D-Sports Alliance LLC collects, uses, shares, and retains personal information when you use our websites, D-Sports Engage applications, wallets, and related services (the “Services”). It also describes your rights under laws such as the GDPR and CCPA/CPRA, and how blockchain immutability limits certain deletion requests.
Last updated: September 9, 2026
1. Who is responsible for your data
The controller (or “business” under California law) is D-Sports Alliance LLC, organized in Florida, USA. Registered address: 5419 Ternberry Road, Ave Maria, FL 34142, US. EIN: 93-3728585.
Canonical contact for privacy requests and general correspondence: support@d-sports.org. Security vulnerability reports: admin@d-sports.org (see /security).
2. Scope
This Policy covers the marketing site, support form, authenticated product app, mobile applications, custodial and linked wallets as they interact with our backend, and related communications. It does not cover third-party websites linked from the Services, app-store privacy practices (Apple/Google), or blockchains themselves as public networks.
3. Information we collect
3.1 Information you provide
- Account details such as name, display handle, email address, password or auth credentials managed via our authentication provider, and profile information you choose to add.
- Support requests and attachments you send through /support or email.
- PIN-related data for custodial wallets: we store a hash suitable for verifying your six-digit PIN, not the plaintext PIN.
- Identity or compliance information if we request KYC/AML verification (which may include government ID images, date of birth, address, and screening results).
- Payment-related details you submit to processors or stores; we typically receive transaction metadata (amount, time, status, last-four or wallet address), not full card PANs from ordinary checkout.
3.2 Information generated by use of the Services
- Device and log data: IP address, operating system, browser or app version, device identifiers, crash diagnostics, and approximate location derived from IP.
- Product telemetry: feature usage, quest progress, leaderboard-related events, and performance metrics needed to operate and secure the Services.
- Wallet and chain-related data we create or store for custodial wallets: blockchain addresses, encrypted private keys, encrypted mnemonics, salts, authentication tags, transaction history we index, and linked external wallet addresses you connect.
- On-chain data that is publicly visible on Ethereum, Polygon, Arbitrum, or other supported networks once a transaction is broadcast (see Section 12).
3.3 Cookies and similar technologies
We and our processors may use cookies, local storage, and similar technologies to maintain sessions, remember preferences, measure traffic, and secure the Services. You can control cookies through browser settings; disabling some cookies may break login or form flows.
4. Custody model and key material (how wallet data is processed)
The default D-Sports wallet is custodial. Our systems generate the recovery phrase and private key, encrypt them with AES-256-GCM using a key derived through PBKDF2 (100,000 iterations, unique salt per wallet), and store the ciphertext. Signing and seed reveal require server-side PIN verification. This is personal data / security data we process to provide the wallet feature. Linked external wallets are different: we do not receive those private keys.
Treating custodial key ciphertext as ordinary “deletable profile text” would be misleading. Deletion and export rules for wallet material are described in Sections 11–12 and may be limited by security, fraud, and legal holds.
5. Purposes and legal bases (GDPR)
If the EU/UK GDPR (or similar) applies, we rely on the following bases:
- Contract (Art. 6(1)(b)) — creating accounts, providing Engage features, processing purchases you request, operating custodial wallets you enable, and providing support.
- Legitimate interests (Art. 6(1)(f)) — securing the Services, preventing fraud and abuse, improving reliability and UX, and understanding aggregate feature usage, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, AML/CTF, sanctions, and responding to lawful requests.
- Consent (Art. 6(1)(a)) — where we use non-essential cookies or optional marketing communications, you may withdraw consent without affecting prior lawful processing.
Where we process special-category data (we do not seek to), we would only do so with a valid Art. 9 condition. Please do not submit sensitive health or biometric data through support forms.
6. How we use information
We use personal information to:
- Provide, maintain, personalize, and improve the Services;
- Authenticate users, verify PINs, and authorize wallet operations;
- Process payments, fulfill digital goods, and reconcile refunds;
- Communicate service notices, security alerts, and (with consent where required) product updates;
- Detect, investigate, and mitigate fraud, abuse, and security incidents;
- Enforce Terms, moderate content, and protect rights and safety;
- Comply with law and respond to lawful process;
- Produce aggregated, de-identified analytics that do not reasonably identify you.
7. Sharing, payment processors, and subprocessors
We do not sell personal information for money. We share data with processors and partners who help run the Services, under contracts that require appropriate safeguards.
Payment processors (current): Stripe, Apple, Google, RevenueCat.
Subprocessors (current as of September 9, 2026). This list is drafted from the known D-Sports stack and may be updated as vendors change. It is not a warranty that every vendor processes data for every user on every day:
- Vercel — Hosting and edge delivery for d-sports.org and related web apps
- Clerk — Authentication and session management for the product app (d-sports-api)
- Resend — Transactional email for the marketing-site support form
- Stripe — Payment processing where card/web checkout is enabled
- Apple — App Store distribution and in-app purchase billing on iOS
- Google — Google Play distribution and in-app purchase billing on Android
- RevenueCat — Mobile subscription / IAP entitlement orchestration
- Supabase — Object storage used by product tooling (e.g. pack/animation assets)
- Thirdweb — Web3 wallet connectivity for linked external wallets
- OneSignal — Push and related messaging for Engage (per ecosystem integrations docs)
- Sentry — Application error monitoring and diagnostics
- Cloudflare — CDN/proxy in front of docs.d-sports.org (marketing apex is DNS-only / Vercel primary)
We may also share information with professional advisors and authorities when required or appropriate, and in a merger, acquisition, financing, or sale of assets, subject to continued confidentiality and notice where required.
8. International transfers
We may process data in the United States and other countries where our processors operate. Where GDPR requires a transfer mechanism, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, plus supplementary measures our processors document. Contact support@d-sports.org for more information about transfer safeguards applicable to your request.
9. Retention schedule
We retain personal information only as long as needed for the purposes above:
- Account profile and auth records — for the life of the account, then deletion or anonymization within 90 days after closure, unless a legal hold applies.
- Support tickets and email — typically up to 24 months after closure of the ticket, longer if needed for disputes.
- Payment and transaction metadata — generally 7 years where required for tax/accounting, or shorter if law allows and the record is not needed for fraud prevention.
- Security logs — typically 12–24 months, unless investigating an incident.
- Custodial wallet ciphertext and salts — for the life of the wallet feature on the account; after account closure we delete or cryptographically destroy server-held key material when legally permitted and operationally safe, noting Section 12 limits for on-chain residues.
- KYC records — for the period required by AML law after the relationship ends (often five years or more, depending on jurisdiction).
Aggregated analytics may be kept indefinitely because they no longer identify you.
10. Security measures
We use administrative, technical, and organizational measures appropriate to the risk, including TLS in transit, encryption at rest for custodial key material as described above, access controls and least privilege, monitoring, and incident response procedures. No method of transmission or storage is perfectly secure. More detail for researchers is on /security.
11. Your rights (access, correction, deletion, portability)
Depending on your location, you may have rights to access, correct, delete, or export personal data; to restrict or object to certain processing; and to withdraw consent. California residents have additional rights described in Section 13. To exercise rights, email support@d-sports.org from your account email (or verify identity by another reasonable method). We will respond within the time required by law (generally 30 days under GDPR, 45 days under CCPA/CPRA, subject to permitted extensions).
We may deny requests that are unfounded, excessive, or that would compromise the security of others, reveal trade secrets improperly, or conflict with legal obligations. Deletion rights for on-chain data are limited as explained next.
12. On-chain data and the limits of deletion
Public blockchains are append-only ledgers. When you authorize a transaction, wallet addresses, token transfers, contract interactions, and related metadata may be permanently recorded by network participants worldwide. D-Sports cannot erase data that has been confirmed on Ethereum, Polygon, Arbitrum, or similar networks.
If you request deletion of your account, we will delete or anonymize personal data we control in our databases and systems (profile fields, off-chain support content, and—when permitted—server-held custodial key ciphertext), subject to legal retention. We will not claim that on-chain history disappears. Where possible we will stop associating off-chain identifiers we control with public addresses, but the addresses and transactions remain publicly inspectable on-chain and via third-party explorers.
This reconciliation is intentional: a “right to erasure” under GDPR applies to personal data under our control; it does not create a technical ability to rewrite decentralized ledgers. If you need a wallet mode where we never hold key material, use a linked external wallet and avoid broadcasting transactions you do not wish to be public.
13. CCPA / CPRA notice (California)
If you are a California resident, the CCPA/CPRA provides rights to know, delete, correct, and opt out of certain sharing. In the prior 12 months we may have collected the categories in Section 3 (identifiers, commercial information, internet/electronic activity, approximate geolocation from IP, and inferences limited to product personalization). We collect this information for the business purposes in Section 6.
Do Not Sell or Share. We do not sell personal information as “sell” is commonly understood (exchanging data for money). We also do not “share” personal information for cross-context behavioral advertising as defined by the CPRA. If that practice changes, we will provide a “Do Not Sell or Share My Personal Information” control and update this Policy. You may still email support@d-sports.org with the subject line “CCPA Request” to exercise know/delete/correct rights or to ask us to confirm our non-sale/non-share posture.
We will not discriminate against you for exercising CCPA/CPRA rights. Authorized agents may submit requests with proof of authority. We do not knowingly “sell” or “share” personal information of consumers under 16.
14. Children's privacy
D-Sports is intended only for users who are at least 18 years old, or the age of majority in their jurisdiction if higher. We do not knowingly collect personal data from anyone under that age. If you believe a minor has provided personal data, contact support@d-sports.org and we will take appropriate steps to delete it.
15. Breach notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and competent authorities as required by applicable law (including GDPR timelines where they apply, and any US state breach-notification statutes that apply to us). Notifications will describe the nature of the breach, likely consequences, measures taken or proposed, and contact points—without disclosing information that would increase risk to remaining users.
16. Automated decision-making
We may use automated fraud scoring or abuse detection to flag risky sign-ins, payments, or transfers. These systems help protect accounts and are subject to human review when they produce legal or similarly significant effects that you contest. Contact support@d-sports.org to request review of an automated decision that blocked access.
17. Changes to this Policy
We may update this Policy. Material changes will update the effective date and may be accompanied by in-app or email notice. Continued use after the effective date means you acknowledge the updated Policy, except where affirmative consent is required.
18. Contact
Privacy and data-rights requests: support@d-sports.org. Security disclosures: admin@d-sports.org. See also /security.