# PRIVACY POLICY
## GeoChain Marketplace

**Last Updated: November 3, 2025**
**Effective Date: [Date of Implementation]**

---
**Publisher & Operator:** [GeoChain Labs LLC](https://geochainlabs.com/)



## 1. INTRODUCTION & SCOPE

This Privacy Policy (hereinafter "Policy") describes how GeoChain Labs LLC ("GeoChain"), operator of the decentralized blockchain-based geospatial data marketplace located at https://geo-chain.xyz/ (hereinafter "Platform," "we," "us," "our," or "GeoChain"), collects, uses, discloses, retains, and protects information about users (hereinafter "you," "users," or "data subjects") who access and use our Platform.

This Privacy Policy applies to:
- All visitors to the GeoChain website
- Users who create accounts on the Platform
- Users who buy or sell geospatial data
- Users who interact with GeoChain services in any form

This Policy is designed to comply with:
- **European Union**: General Data Protection Regulation (GDPR/Regulation 2016/679), ePrivacy Directive, and Digital Services Act (DSA)
- **United States**: CAN-SPAM Act, FTC Act Section 5, and state privacy laws including CCPA/CPRA (California)
- **International**: OECD Privacy Principles and applicable data protection laws worldwide

### 1.1 Data Controller
GeoChain Labs LLC ("GeoChain") operates as the **data controller** for personal data collected through the Platform. As data controller, GeoChain determines the purposes and means of data processing.

**Contact Information:**
- Email: contact@geochainlabs.com
- Website: https://geochainlabs.com/
- Platform: https://geo-chain.xyz/
- Data Protection Officer inquiries: contact@geochainlabs.com

### 1.2 Data Processors
GeoChain engages third-party data processors, including:
- **Backblaze B2**: Cloud storage provider for geospatial data and system infrastructure
- **Email Service Provider**: For transactional and operational communications
- Wallet integration providers for blockchain transaction processing

These processors operate under Data Processing Agreements (DPAs) that ensure adequate data protection standards.

---

## 2. CATEGORIES OF PERSONAL DATA COLLECTED

### 2.1 Direct Collection
GeoChain collects personal data directly from users during platform interaction:

**2.1.1 Account Registration Data**
- Full name (optional)
- Email address
- Username/display name
- Profile description (optional)
- Profile picture or avatar (optional)
- Wallet address(es) connected to account
- Authentication credentials (encrypted password hash)
- Age verification (confirmation of 18+ years)
- Account creation date and time

**2.1.2 Transaction Data**
- Buy/sell transaction history
- Data listing titles and descriptions
- Transaction amounts and dates
- Payment cryptocurrency type (XRP, RLUSD, USDC)
- Transaction hashes and smart contract interaction records
- Buyer/seller identities (pseudonymous wallet addresses or names)
- Delivery receipts and decryption key access logs

**2.1.3 Communication Data**
- Support inquiries and correspondence
- Dispute reports and resolution records
- Email communications and notifications
- Chat logs (if support chat is utilized)
- Feedback and platform reviews
- Messages between buyers and sellers (if implemented)

**2.1.4 Profile & Preference Data**
- Seller shop information and description
- Buyer preferences and saved searches
- Wishlist or bookmarked listings (if implemented)
- User settings and notification preferences
- Language and regional preferences
- Device settings and browser preferences

### 2.2 Automatically Collected Data
GeoChain automatically collects certain technical information:

**2.2.1 Device & Connection Data**
- Internet Protocol (IP) address
- Device type and operating system
- Browser type and version
- Mobile device identifiers (IMEI, IDFA)
- MAC address
- Device model and manufacturer
- Screen resolution and display settings
- Mobile network information

**2.2.2 Usage & Activity Data**
- Pages visited and time spent on each page
- Links clicked
- Search queries performed
- Data listings viewed and for how long
- Transactions initiated and completed
- Login frequency and duration
- Upload and download activities
- Error pages encountered
- Features used and interaction patterns

**2.2.3 Location Data**
- Approximate geolocation based on IP address
- GPS coordinates (if location services are enabled on user device)
- City and country of access
- Regional preferences

**2.2.4 Blockchain Data**
- Wallet addresses and associated transaction history
- Smart contract interactions
- Cryptocurrency payment amounts and timestamps
- Cross-chain bridge transaction data
- Public blockchain transaction records (inherently public)

### 2.3 Third-Party Data Sources

---

## 3. SUPPORT CHAT AND DISCORD

### 3.1 Processing of Conversations
- We process in‑app support chat and Discord support conversations, including message content, timestamps, and technical metadata (device, IP, browser)
- Purpose: provide assistance, troubleshoot issues, prevent abuse, improve support quality

### 3.2 Data Minimization
- Do not include Secret Recovery Phrase (SRP), private keys, seed phrases, passwords, 2FA codes, or payment card numbers in support chats
- GeoChain will never ask for SRP or private keys

### 3.3 Retention and Deletion
- Support conversation records are retained according to operational needs and legal obligations
- Users may request deletion of conversation records; GeoChain will process requests consistent with applicable law and technical constraints

### 3.4 International Transfers
- Support systems may be operated across regions; standard safeguards are applied for international data transfers

---
GeoChain may receive personal data from:

**2.3.1 Wallet Providers**
- MetaMask, OKX, Trust Wallet, Xaman, and other integrated wallets provide:
  - Wallet address verification
  - Transaction confirmation data
  - Wallet balance information
  - Connected application data

**2.3.2 Blockchain Networks**
- XRPL EVM Sidechain provides:
  - Transaction records
  - Smart contract execution logs
  - Gas fee information
  - Block timestamp and sequence data

**2.3.3 Third-Party Services & Analytics**
- Web analytics platforms
- Customer service platforms
- Payment processors and bridges (Axelar, etc.)
- Email service providers

**2.3.4 Other Users**
- Information provided about you by other users (e.g., buyer name provided by seller in transaction context)
- Transaction-related information shared by counterparty
- Dispute information shared by other parties

### 2.4 Special Categories of Personal Data
GeoChain does NOT intentionally collect "sensitive" or "special categories" of personal data as defined by GDPR (including racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification, health data, or sexual orientation).

However, if sensitive data is inadvertently included in geospatial data listings, users acknowledge:
- Sellers are responsible for anonymizing or removing sensitive data before upload
- Buyers must comply with applicable laws regarding sensitive data use
- GeoChain cannot verify or audit data content for sensitive information

---

## 3. LEGAL BASIS FOR DATA PROCESSING

### 3.1 GDPR Legal Basis
For users subject to GDPR, GeoChain processes personal data on the following legal bases:

**3.1.1 Contractual Necessity (Article 6(1)(b))**
- Account creation and management
- Transaction processing and payment confirmation
- Service delivery and technical support
- Data listing management and delivery
- Contract performance (Terms & Conditions agreement)

**3.1.2 Legal Obligation (Article 6(1)(c))**
- Tax reporting and compliance
- Anti-money laundering (AML) and Know Your Customer (KYC) requirements (current and future)
- Law enforcement and court order compliance
- Regulatory reporting

**3.1.3 Legitimate Interests (Article 6(1)(f))**
- Platform security and fraud prevention
- System administration and maintenance
- Service improvement and analytics
- Marketing and promotional communications (with opt-out available)
- Legal claims and dispute resolution
- Blockchain transaction immutability

**3.1.4 Consent (Article 6(1)(a))**
- Marketing emails and promotional newsletters
- Cookies and tracking technologies (except strictly necessary)
- Certain analytics and behavioral tracking
- Optional profile features and communication preferences

### 3.2 CCPA Legal Basis
For California residents, GeoChain processes personal information for the following purposes:
- Providing and maintaining the Platform
- Processing transactions and payments
- Communicating with users and providing support
- Preventing fraud and ensuring security
- Complying with legal obligations
- Improving platform functionality
- Marketing and promotional purposes (complying with opt-out rights)

---

## 4. PURPOSE OF DATA PROCESSING

GeoChain collects and processes personal data for the following purposes:

### 4.1 Service Provision
- Creating and maintaining user accounts
- Processing buy/sell transactions
- Delivering geospatial data to buyers
- Generating and providing decryption keys
- Managing user profiles and preferences
- Enabling peer-to-peer communication between buyers and sellers

### 4.2 Transaction Processing
- Verifying payment and transaction details
- Executing smart contracts on XRPL EVM Sidechain
- Confirming cryptocurrency payments
- Recording transaction history
- Generating transaction receipts and invoices
- Facilitating refunds or dispute resolution (if applicable)

### 4.3 Account Security & Fraud Prevention
- Verifying user identity during account creation
- Detecting and preventing fraudulent transactions
- Identifying suspicious account activity
- Protecting against unauthorized access
- Enforcing account suspension or termination policies
- Investigating potential violations of Terms & Conditions

### 4.4 Technical Operations & Maintenance
- Ensuring platform availability and functionality
- Diagnosing and fixing technical issues
- Conducting system maintenance and updates
- Monitoring system performance and uptime
- Backing up data for disaster recovery
- Managing encryption keys and data security

### 4.5 Communication & Support
- Responding to user inquiries and support requests
- Sending transactional emails (payment confirmations, delivery notifications)
- Providing customer service and technical assistance
- Notifying users of important platform changes
- Sending security alerts and password reset links
- Resolving disputes between buyers and sellers

### 4.6 Analytics & Service Improvement
- Analyzing user behavior and platform usage patterns
- Generating anonymized/aggregated statistics
- Testing new features and improvements
- Optimizing platform performance and user experience
- Conducting A/B testing and usability studies
- Identifying and addressing platform issues

### 4.7 Marketing & Promotional Communications
- Sending promotional emails about new features
- Notifying users of special offers or promotions
- Providing industry news and marketplace updates
- Conducting user surveys and feedback collection
- Personalizing user experience based on interests
- Users may opt-out of promotional communications at any time

### 4.8 Legal Compliance & Regulatory Requirements
- Complying with tax reporting requirements
- Fulfilling law enforcement and legal process requests
- Maintaining records for regulatory audits
- Implementing AML/KYC verification (current and future)
- Enforcing intellectual property rights
- Protecting against legal liability

### 4.9 Blockchain & Immutability
- Recording transactions on XRPL EVM Sidechain (publicly visible)
- Creating immutable transaction records
- Enabling smart contract execution
- Verifying data integrity and tamper-proof delivery
- Supporting cross-chain bridge operations

---

## 5. DATA RETENTION & DELETION

### 5.1 Data Retention Periods

**5.1.1 Active Account Data**
- Account information (name, email, wallet address): Retained indefinitely while account is active
- Transaction history: Retained indefinitely on blockchain (immutable)
- User profile data: Retained indefinitely unless deleted by user
- Support communications: Retained for 7 years for regulatory compliance

**5.1.2 Inactive or Deleted Account Data**
- Email address: Retained indefinitely unless deletion requested
- Transaction history: Retained indefinitely (blockchain immutability)
- Personal profile data: Deleted or anonymized within 30 days of account deletion request
- Authentication credentials: Deleted within 7 days of account deletion
- IP addresses and device data: Retained for 12 months then deleted

**5.1.3 Blockchain Data**
- On-chain transaction records: Retained indefinitely (immutable blockchain property)
- Smart contract execution logs: Retained indefinitely
- Wallet addresses and transaction hashes: Retained indefinitely on blockchain

**5.1.4 Operational & Technical Data**
- Server logs and IP addresses: Retained for 90 days then deleted
- Error logs and debugging data: Retained for 30 days then deleted
- Backup data: Retained for 12 months for disaster recovery purposes
- Analytics and aggregated data: Retained indefinitely (anonymized)

**5.1.5 Payment & Financial Data**
- Cryptocurrency transaction records: Retained for 7 years (tax/regulatory compliance)
- Payment processor records: Retained as required by payment providers (typically 7 years)
- Invoice and receipt data: Retained for 7 years

**5.1.6 Legal & Compliance Data**
- Data subject access requests (DSAR) records: Retained for 3 years
- Dispute records: Retained for 3 years after resolution
- Law enforcement requests: Retained as required by law
- Regulatory compliance records: Retained for 7 years

### 5.2 User Rights to Deletion

**5.2.1 Right to Delete Personal Data**
Users have the right to request deletion of their personal data. Upon receiving a valid deletion request:
- GeoChain will initiate deletion procedures within 30 calendar days
- Personal data will be deleted or anonymized (where retention is not legally required)
- Blockchain records cannot be deleted due to immutability, but off-chain personal data will be removed

**5.2.2 Exceptions to Deletion**
Personal data may be retained if:
- Retention is required by law (tax laws, anti-money laundering, securities regulations)
- A legal dispute is pending or anticipated
- Data relates to an immutable blockchain record
- Data is necessary for Platform security or fraud prevention
- Data is subject to a legal hold or injunction

**5.2.3 Deletion Request Process**
Users may request data deletion by:
- Emailing: contact@geochainlabs.com
- Subject line: "DSAR - Request for Data Deletion"
- Providing account identification (email, wallet address)
- GeoChain will respond within 30 days with confirmation or explanation if deletion cannot be completed

**5.2.4 Data Retained After Account Deletion**
The following data may be retained indefinitely even after account deletion:
- Blockchain transaction records (due to immutability)
- Anonymized analytics data
- Aggregated usage statistics
- Tax and regulatory compliance records

---

## 6. DATA SHARING & DISCLOSURE

### 6.1 Limited Disclosure Policy
GeoChain restricts sharing of personal data. However, data may be disclosed in the following circumstances:

### 6.2 Required Disclosures

**6.2.1 To Other Users (Transactional Necessity)**
- Sellers receive partial buyer information: wallet address, email (if provided)
- Buyers receive partial seller information: profile name, wallet address, transaction history
- Neither party receives complete personal information beyond transaction necessity
- GeoChain does not share full legal names, physical addresses, or phone numbers between users

**6.2.2 To Service Providers & Data Processors**
- **Backblaze B2**: Encrypted geospatial data storage and backup
- **Email Service Providers**: For sending transactional and promotional emails
- **Wallet Integration Providers**: MetaMask, OKX, Trust Wallet, Xaman for transaction processing
- **Blockchain Nodes**: Transaction data is publicly recorded on XRPL EVM Sidechain
- **Bridge Protocol Providers**: Axelar and other bridges for cryptocurrency conversion
- **Customer Support Platforms**: For managing support inquiries (if implemented)

All service providers operate under Data Processing Agreements ensuring adequate data protection.

**6.2.3 To Legal & Government Authorities**
GeoChain may disclose personal data when:
- Required by law, subpoena, court order, or legal process
- Necessary to comply with tax reporting requirements
- Required to enforce the Terms & Conditions or other agreements
- Necessary to prevent fraud, security breaches, or legal liability
- Required by law enforcement, regulatory agencies, or government entities
- Necessary to protect the safety, rights, or property of GeoChain, users, or the public

GeoChain will:
- Provide notice to affected users when legally permitted
- Limit disclosure to only the information required by the legal request
- Assert available legal privileges and objections

**6.2.4 For Business Transactions**
If GeoChain is involved in a merger, acquisition, bankruptcy, or sale of assets:
- Personal data may be transferred as part of the business transaction
- Users will be notified of any change in data practices
- Users may opt-out if new practices differ materially from this Policy

### 6.3 Prohibited Disclosures
GeoChain does NOT:
- Sell personal data to third parties for commercial purposes
- Share personal data with marketing companies or data brokers
- Use personal data for targeted advertising without consent
- Disclose personal data to competitors or unrelated third parties
- Disclose financial data to unaffiliated entities
- Use personal data for profiling or automated decision-making

---

## 7. DATA PROTECTION & SECURITY

### 7.1 Security Measures
GeoChain implements technical, organizational, and administrative safeguards to protect personal data:

**7.1.1 Encryption**
- **In Transit**: All data transmitted between user devices and Platform servers uses TLS/SSL encryption (HTTPS)
- **At Rest**: Personal data stored on servers is encrypted using AES-256 or equivalent
- **End-to-End Encryption**: Geospatial data is encrypted from upload through delivery; GeoChain cannot access unencrypted content
- **Wallet Integration**: Cryptocurrency keys and wallet information are encrypted and secured

**7.1.2 Access Controls**
- Only authorized GeoChain personnel have access to personal data
- Role-based access control (RBAC) restricts data access by job function
- Multi-factor authentication (MFA) required for administrative access
- Regular access reviews and audits to prevent unauthorized access

**7.1.3 Data Minimization**
- GeoChain collects only personal data necessary for specified purposes
- Off-chain storage of personal data is minimized
- On-blockchain personal data is limited to transaction-necessary identifiers
- Regular audits assess whether retained data remains necessary

**7.1.4 Network Security**
- Firewalls and intrusion detection systems
- Regular penetration testing and vulnerability assessments
- DDoS protection and attack mitigation
- Secure API design and implementation
- Web Application Firewall (WAF) protection

**7.1.5 Database Security**
- Database encryption and access control
- SQL injection prevention
- Regular database security audits
- Automated backup encryption
- Secure backup storage with access restrictions

### 7.2 Blockchain Security
- Smart contracts deployed on XRPL EVM Sidechain benefit from blockchain's inherent security
- Transaction immutability prevents unauthorized modification of transaction records
- Cryptographic verification ensures data integrity (tamper-proof property)
- Distributed nature of blockchain provides redundancy against single points of failure

### 7.3 Limitations of Security
While GeoChain implements comprehensive security measures, users acknowledge that:
- No security system is completely immune to attacks
- Sophisticated attackers may bypass security measures
- Cryptocurrency transactions are inherently irreversible
- Wallet security depends partially on user behavior and device security
- Blockchain data is pseudonymous but potentially traceable with sufficient resources

### 7.4 Data Breach Notification
If GeoChain discovers a data breach involving personal data:

**7.4.1 EU/GDPR Users**
- GeoChain will notify affected data subjects within 72 hours of discovery
- Notification will include: nature of breach, affected data categories, consequences, measures taken
- GeoChain will notify relevant data protection authorities within 72 hours

**7.4.2 US/CCPA Users (California)**
- GeoChain will notify affected users without unreasonable delay
- Notification will include information about the breach and steps to protect personal information
- Notification may be provided by email, postal mail, or other means

**7.4.3 Other Jurisdictions**
- GeoChain will comply with breach notification requirements of applicable laws
- Notification will occur within timeframes required by local law

---

## 8. INTERNATIONAL DATA TRANSFERS

### 8.1 Cross-Border Data Transfers
GeoChain is based in the United States and processes personal data in the United States and potentially other countries where service providers operate. By using the Platform, users consent to:
- Transfer of personal data from their country of residence to the United States
- Processing of personal data in the United States and other countries
- Application of United States law and regulatory frameworks

### 8.2 GDPR International Transfer Mechanisms
For users subject to GDPR (EU/EEA residents), GeoChain relies on:

**8.2.1 Standard Contractual Clauses (SCCs)**
- GeoChain has implemented Standard Contractual Clauses (Module 2: Controller-to-Processor) for transfers to Backblaze B2 and other processors
- SCCs are pre-approved by the European Commission as providing adequate protection for international data transfers
- SCCs ensure that data processors outside the EEA provide equivalent protection to GDPR standards

**8.2.2 Transfer Impact Assessments (TIA)**
- GeoChain conducts Transfer Impact Assessments to evaluate data protection laws in destination countries
- TIA assesses whether national security/surveillance laws in destination countries may undermine SCC protections
- If TIA identifies risks, GeoChain implements supplementary safeguards (enhanced encryption, further restrictions)

**8.2.3 Supplementary Safeguards**
- Enhanced encryption of personal data
- Restricted access to personal data by service providers
- Contractual commitments limiting data use to specified purposes
- Regular audit and compliance monitoring
- Data minimization strategies

### 8.3 Adequacy Decisions
- European Commission has not issued an adequacy decision for the United States (post-Schrems II)
- GeoChain relies on SCCs supplemented by additional safeguards per EDPB guidelines
- Users acknowledge the different legal protections in the United States versus EU

### 8.4 Right to Object
EU users have the right to:
- Request information about data transfer mechanisms and safeguards
- Object to transfers to countries without adequacy decisions
- Request enhanced safeguards or restriction of data transfers
- Contact: contact@geochainlabs.com

---

## 9. GDPR RIGHTS & DATA SUBJECT RIGHTS

For users subject to the General Data Protection Regulation (EU residents), GeoChain acknowledges and facilitates the following rights:

### 9.1 Right of Access (Article 15)
Users have the right to:
- Request confirmation of whether GeoChain processes their personal data
- Obtain a copy of their personal data in a structured, commonly used, machine-readable format
- Receive information about data processing purposes, recipients, retention periods
- Obtain information about data sources and automated decision-making

**How to Exercise**: Send email to contact@geochainlabs.com with subject "GDPR Article 15 - Right of Access"

**Response Timeline**: GeoChain will respond within 30 calendar days (extendable to 90 days for complex requests)

### 9.2 Right of Rectification (Article 16)
Users have the right to:
- Request correction of inaccurate or incomplete personal data
- Complete incomplete information
- Have outdated data updated

**Examples**: Correcting email address, updating profile information, modifying wallet addresses

**How to Exercise**: Users may update profile information directly in account settings, or contact contact@geochainlabs.com

**Response Timeline**: Changes will be implemented without unreasonable delay

### 9.3 Right to Erasure/Right to be Forgotten (Article 17)
Users have the right to request deletion of personal data when:
- Data is no longer necessary for original purposes
- Consent is withdrawn and no other legal basis exists
- Data is processed unlawfully
- Data must be erased to comply with legal obligations
- Data was collected based on consent and user withdraws that consent

**Limitations**: Erasure may not be possible if:
- Data retention is required by law (tax, AML, KYC)
- Data constitutes an immutable blockchain record
- Data is necessary for legal claims or defense
- Data relates to Platform security or fraud prevention

**How to Exercise**: Email contact@geochainlabs.com with subject "GDPR Article 17 - Right to Erasure"

**Response Timeline**: GeoChain will respond within 30 days (60 days for complex requests)

### 9.4 Right to Restrict Processing (Article 18)
Users have the right to request restriction of data processing when:
- Accuracy of personal data is contested
- Processing is unlawful but user prefers restriction rather than erasure
- Data is no longer needed but user requires it for legal claims
- User has objected to processing and determination is pending

When processing is restricted:
- Data will be stored but not actively processed
- Processing will resume only with user consent or legal basis
- GeoChain will notify user before lifting restrictions

**How to Exercise**: Email contact@geochainlabs.com with subject "GDPR Article 18 - Right to Restrict Processing"

### 9.5 Right to Data Portability (Article 20)
Users have the right to:
- Receive their personal data in a structured, commonly used, machine-readable format (CSV, JSON, etc.)
- Transmit data to another data controller without hindrance
- Request direct transfer to another controller (where technically feasible)

**Limitations**: Right does not apply to data necessary for service provision or data derived from user information

**How to Exercise**: Email contact@geochainlabs.com with subject "GDPR Article 20 - Right to Data Portability"

**Response Timeline**: GeoChain will provide data export within 30 days

### 9.6 Right to Object (Article 21)
Users have the right to object to processing of personal data on grounds of legitimate interests when:
- Processing is based on legitimate interests
- User objects to marketing communications
- User objects to profiling or automated decision-making
- Processing serves statistical or research purposes

**For Marketing Communications**: Users may opt-out by:
- Clicking the "Unsubscribe" link in promotional emails
- Updating preferences in account settings
- Emailing contact@geochainlabs.com with "Unsubscribe" request

GeoChain will honor opt-out requests within 10 business days

### 9.7 Right to Not Be Subject to Automated Decision-Making (Article 22)
Users have the right to:
- Not be subject to automated decision-making (including profiling) that produces legal/significant effects
- Receive human review of automated decisions
- Express views and obtain explanation of automated decisions

**Current Status**: GeoChain does not conduct automated decision-making with legal/significant effects

### 9.8 Right to Lodge a Complaint
Users have the right to lodge a complaint with relevant data protection authorities:

**EU Users**: Contact your national data protection authority:
- Austria: Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
- France: Commission Nationale de l'Informatique et des Libertés (CNIL)
- Germany: Federal Data Protection Commissioner (BfDI)
- [Other EU member states have equivalents]

Users may also lodge complaints via the European Data Protection Board's complaint registration system

### 9.9 Exercising Rights - General Process
To exercise any GDPR rights:

**Step 1**: Email contact@geochainlabs.com with:
- Specific right being exercised (Article number and right name)
- Account identifier (email, wallet address)
- Detailed description of the request
- Preferred response format (if applicable)

**Step 2**: GeoChain will:
- Verify user identity to prevent unauthorized access to data
- Process request within applicable legal timeframes (typically 30 days)
- Provide response in clear, intelligible language
- Deny request only if lawful grounds exist

**Step 3**: If user disputes GeoChain's response, user may:
- Request reconsideration within 15 days
- Lodge complaint with relevant data protection authority
- Pursue legal action

---

## 10. CCPA & US STATE PRIVACY RIGHTS

For users who are residents of California and other US states with privacy laws, GeoChain acknowledges the following rights:

### 10.1 CCPA (California Consumer Privacy Act) - California Residents

**10.1.1 Right to Know (CCPA Section 1798.100)**
California residents have the right to request:
- What personal information GeoChain collects
- Purposes for collection and use
- Categories of third parties with whom information is shared
- Specific pieces of personal information collected

**How to Exercise**: 
- Email: contact@geochainlabs.com
- Subject: "CCPA Right to Know Request"
- Include: Full name, email, wallet address

**Response Timeline**: GeoChain will respond within 45 days (extendable 45 additional days)

**Verification**: GeoChain will verify identity before disclosing personal information

**10.1.2 Right to Delete (CCPA Section 1798.105)**
California residents have the right to request deletion of personal information collected, except when:
- Information is necessary to complete transaction requested by consumer
- Information is necessary for security or fraud prevention
- Retention is required by law
- Information is necessary for dispute resolution or legal claims

**How to Exercise**: Email contact@geochainlabs.com with subject "CCPA Right to Delete Request"

**Response Timeline**: GeoChain will respond within 45 days and delete information within 60 days

**10.1.3 Right to Opt-Out (CCPA Section 1798.120)**
California residents have the right to direct GeoChain to not:
- Sell personal information
- Share personal information for cross-context behavioral advertising
- Use personal information for automated decision-making with significant effects

**Current Status**: GeoChain does not sell personal information and does not share for behavioral advertising

**How to Exercise**: Email contact@geochainlabs.com with "Opt-Out Request"

**10.1.4 Right to Correct (CPRA Amendment - Section 1798.010)**
California residents have the right to request correction of inaccurate personal information

**How to Exercise**: Update profile directly in account settings or email contact@geochainlabs.com

**10.1.5 Right to Limit (CPRA Amendment - Section 1798.120)**
California residents can limit use of sensitive personal information to:
- Necessary business operations
- Services requested by consumer
- Legal/regulatory compliance

GeoChain will respect limitations upon request

**10.1.6 Right to Non-Retaliation (CCPA Section 1798.125)**
GeoChain will not:
- Discriminate against users for exercising CCPA rights
- Deny goods or services
- Charge different prices
- Degrade service quality
- Threaten, intimidate, or coerce users

---

## 11. CHILDREN'S PRIVACY & COPPA

### 11.1 Age Minimum
The Platform is intended only for users 18 years of age or older. GeoChain does not knowingly collect personal information from children under 13 years of age.

### 11.2 Children Under 13
If GeoChain becomes aware that it has collected personal information from a child under 13:
- GeoChain will delete such information promptly
- GeoChain will notify the child's parent/guardian
- GeoChain will not condition service participation on collection of unnecessary data

**Report**: Parents who believe their child's information was collected should contact contact@geochainlabs.com

### 11.3 Children 13-18 Years
While the Platform requires 18+ years of age:
- GeoChain acknowledges that some users may be under 18
- Parental consent is required for users under 18 (in applicable jurisdictions)
- GeoChain provides additional privacy protections for young users

---

## 12. MARKETING & PROMOTIONAL COMMUNICATIONS

### 12.1 Email Communications
GeoChain sends emails for:
- **Transactional**: Account confirmations, payment receipts, delivery notifications, password resets
- **Operational**: Platform updates, security alerts, maintenance notices
- **Marketing**: Promotional offers, new features, marketplace updates (opt-in required)

### 12.2 CAN-SPAM Compliance
GeoChain complies with the CAN-SPAM Act regarding commercial email messages:

**All Emails Include:**
- Accurate identifying information about GeoChain
- Clear subject line accurately describing content
- Valid physical postal address (included in email footer)
- Clear opt-out mechanism for promotional communications
- Response to opt-out within 10 business days

**Marketing Email Format:**
- "From" field contains sender identity
- Subject line is not deceptive
- Email body includes GeoChain's physical address
- Unsubscribe link is functional and removes address within 10 days

### 12.3 Opt-Out & Unsubscribe
Users can opt-out of promotional emails by:
- Clicking the "Unsubscribe" link in the footer of any promotional email
- Updating preferences in account settings
- Emailing contact@geochainlabs.com with "Unsubscribe" request

**Opt-Out Timeline**: GeoChain will remove email within 10 business days

**Transactional Emails**: Users cannot opt-out of transactional or operational emails as these are essential to account and transaction management

### 12.4 Marketing Consent
- Promotional emails require prior opt-in consent (for non-transactional communications)
- GeoChain will not send promotional emails to users who have not consented
- Users may withdraw consent at any time

---

## 13. COOKIES & TRACKING TECHNOLOGIES

### 13.1 Cookie Usage
GeoChain uses cookies and similar tracking technologies to:

**Strictly Necessary (No Consent Required)**
- Maintain user sessions and authentication
- Remember login credentials (encrypted)
- Store user preferences and settings
- Enable basic Platform functionality
- Prevent fraud and enhance security

**Functional/Performance (Consent Required)**
- Remember user choices and preferences
- Analyze Platform usage and performance
- Identify technical issues and errors
- Measure page load times and optimization

**Analytics/Tracking (Consent Required)**
- Track user behavior and usage patterns
- Generate anonymized usage statistics
- Understand which features are popular
- Improve Platform design and functionality

**Marketing/Advertising (Explicit Opt-In Required)**
- Track cross-site behavior for targeted advertising
- Retarget users with promotional content
- Conduct audience analysis for campaigns

### 13.2 Cookie Consent
Upon first visit, GeoChain displays a cookie consent banner allowing users to:
- Accept all cookies
- Accept only necessary cookies
- Customize cookie preferences
- Opt-out of non-essential tracking

Users can modify cookie preferences in account settings at any time

### 13.3 Third-Party Cookies
Third-party services (analytics, wallets, payment processors) may set their own cookies. Users should review their privacy policies for details.

### 13.4 Local Storage & Similar Technology
GeoChain may use browser local storage, IndexedDB, and similar technologies for:
- Caching Platform data locally
- Storing user preferences
- Improving Platform performance
- Enabling offline functionality

---

## 14. ADVERTISING & ANALYTICS

### 14.1 Analytics Services
GeoChain may use analytics services to understand Platform usage:
- These services collect anonymized usage data
- Personally identifiable information is not shared with analytics providers
- Users can opt-out of analytics tracking

### 14.2 Targeted Advertising
GeoChain does NOT use personal information for behavioral advertising or targeting without consent

### 14.3 User Analytics & Profiling
- GeoChain does not conduct automated profiling with legal consequences
- Usage data is analyzed on aggregate/anonymized level
- Individual users are not subject to automated decision-making

---

## 15. THIRD-PARTY LINKS & SERVICES

### 15.1 External Links
The Platform may contain links to external websites and services not operated by GeoChain:
- GeoChain is not responsible for external sites' privacy practices
- Users should review third-party privacy policies before providing information
- GeoChain does not endorse external sites or their practices

### 15.2 Wallet Providers
Users connecting wallets (MetaMask, OKX, Trust Wallet, Xaman) should:
- Review each wallet provider's privacy policy
- Understand that wallet data is controlled by the wallet provider
- Recognize that wallet interactions are pseudonymous but may be traceable

### 15.3 Blockchain Explorer
Transaction data visible on blockchain explorers:
- GeoChain does not control blockchain explorer privacy policies
- Users should be aware that blockchain transactions are publicly visible
- Transaction details cannot be made private once recorded on-chain

---

## 16. DATA RETENTION & ACCOUNT DELETION

### 16.1 Active Account Data Retention
While your account is active, GeoChain retains personal data indefinitely to:
- Maintain account and transaction history
- Provide ongoing services
- Comply with legal requirements

### 16.2 Account Deletion Process
Users may request account deletion by:
- Emailing contact@geochainlabs.com with subject "Account Deletion Request"
- Providing account identifier (email, wallet address)

Upon account deletion:
- Personal profile data will be anonymized or deleted within 30 days
- Transaction history will be retained indefinitely (required by law and blockchain immutability)
- Data may continue to exist on public blockchains (irreversible)

### 16.3 Data Deletion Exceptions
Certain data is retained indefinitely including:
- Blockchain transaction records (immutable)
- Tax and regulatory compliance data (7-year retention)
- Legal hold data (during litigation)
- Aggregated/anonymized analytics data

---

## 17. DATA PROTECTION OFFICER & COMPLIANCE

### 17.1 Data Protection Officer
GeoChain has designated responsibility for data protection matters. 

**For Data Protection Inquiries:**
Email: contact@geochainlabs.com
Subject: "Data Protection Inquiry"

### 17.2 Regulatory Compliance
GeoChain commits to compliance with:
- **GDPR** (General Data Protection Regulation - EU)
- **CCPA/CPRA** (California Privacy Laws - USA)
- **ePrivacy Directive** (EU electronic communications)
- **Digital Services Act** (DSA - EU platform regulation)
- **CAN-SPAM Act** (USA email marketing)
- **COPPA** (Children's Online Privacy Protection Act - USA)
- **State Privacy Laws** (California, Virginia, Colorado, Connecticut, Utah, Montana, Delaware, Maine, Mississippi, Florida)

### 17.3 Regular Compliance Assessments
GeoChain conducts:
- Annual data protection impact assessments
- Privacy policy reviews and updates
- Security audits and penetration testing
- Staff training on data protection compliance
- Third-party processor compliance verification

---

## 18. CHANGES TO THIS PRIVACY POLICY

### 18.1 Policy Updates
GeoChain may update this Privacy Policy to:
- Reflect changes in data practices
- Comply with new legal requirements
- Clarify existing provisions
- Address user feedback

### 18.2 Notification of Changes
For material changes to privacy practices:
- GeoChain will notify users via email
- GeoChain will post notice on the Platform
- GeoChain will provide 30 days before changes take effect
- Users may opt-out if changes are material and unacceptable

### 18.3 Acceptance of Changes
Continued use of the Platform after notification of changes constitutes acceptance of the revised Privacy Policy.

### 18.4 Version History
Users can request previous versions of this Privacy Policy by emailing contact@geochainlabs.com

---

## 19. INTERNATIONAL PRIVACY CONSIDERATIONS

### 19.1 Global Users
GeoChain users may reside in any jurisdiction worldwide. This Privacy Policy attempts to comply with major privacy frameworks but cannot address all jurisdictional variations.

### 19.2 Jurisdiction-Specific Rights
- **EU/EEA Residents**: GDPR rights apply (Sections 9)
- **California Residents**: CCPA/CPRA rights apply (Section 10)
- **Other US State Residents**: Check your state's privacy law
- **Canada**: PIPEDA principles apply where applicable
- **Australia**: Australian Privacy Principles apply where applicable
- **Other Jurisdictions**: Applicable local privacy laws supersede this Policy where more protective

### 19.3 Right to Legal Recourse
If GeoChain violates privacy rights:
- Users may file complaints with relevant data protection authorities
- Users may pursue legal action in competent courts
- Users retain all rights provided by applicable law

---

## 20. BLOCKCHAIN & IMMUTABILITY DISCLOSURE

### 20.1 Understanding Blockchain Privacy Limitations
Users should understand:
- **Immutability**: Data recorded on blockchain cannot be deleted or modified
- **Transparency**: Public blockchains show all transaction details (though parties are pseudonymous)
- **Traceability**: Wallet addresses can be linked to real identities through analysis or KYC processes
- **Irreversibility**: Transactions cannot be undone or reversed

### 20.2 Pseudonymity vs. Anonymity
- Blockchain transactions are pseudonymous (linked to wallet address rather than name)
- Pseudonymous data is NOT anonymous and remains personal data under GDPR/CCPA
- Wallet addresses can be linked to real identities through:
  - KYC processes at exchanges
  - Transaction analysis and pattern matching
  - Blockchain forensics
  - Law enforcement investigation

### 20.3 Public Data & Privacy Expectations
Users should NOT expect privacy for:
- Wallet addresses and balances
- Transaction amounts and dates
- Smart contract interactions
- Data shared on public blockchains
- Information linkable via transaction analysis

### 20.4 Off-Chain Privacy
GeoChain maintains privacy protections for:
- Personal account data (not on blockchain)
- Email addresses and contact information
- IP addresses and device data
- Communications and support records

---

## 21. CONTACT & REQUESTS

### 21.1 Privacy Inquiries & Requests
For questions, complaints, or to exercise privacy rights:

**Email**: contact@geochainlabs.com
**Platform**: https://geo-chain.xyz/
**Chat Support**: Available through Platform dashboard

**Include in Your Request:**
- Full name or account identifier
- Nature of inquiry or specific right being exercised
- Detailed description of request
- Preferred response method

**Response Timeline**:
- Acknowledgment: Within 5 business days
- Full response: Within 30-60 days depending on request complexity and legal requirements

### 21.2 Complaints & Disputes
If users believe GeoChain has violated privacy rights:
- First, attempt resolution through direct communication (contact@geochainlabs.com)
- For unresolved complaints, users may lodge complaint with:
  - Relevant national data protection authority (GDPR)
  - California Attorney General or California Privacy Protection Agency (CCPA)
  - Other relevant regulatory authorities in your jurisdiction

### 21.3 Legal Representative
Users or their legal representatives may submit privacy requests on their behalf by providing:
- Written authorization from the data subject
- Proof of legal representation
- Contact information for both parties

---

## 22. FINAL PROVISIONS

### 22.1 Entire Agreement
This Privacy Policy, together with the Terms & Conditions and any other policies referenced, constitutes the entire agreement regarding privacy practices.

### 22.2 Governing Law
This Privacy Policy is governed by the laws of the United States, specifically the State of [Applicable State] where GeoChain operates, without regard to conflict of laws principles.

### 22.3 Dispute Resolution
Disputes regarding privacy practices shall be resolved:
1. Through good faith negotiation
2. Through informal mediation if available
3. Through applicable legal procedures in accordance with Terms & Conditions

### 22.4 Severability
If any provision of this Privacy Policy is found invalid or unenforceable, remaining provisions remain in effect.

---

**END OF PRIVACY POLICY**

---

## APPENDIX: KEY DEFINITIONS

**Personal Data**: Information relating to an identified or identifiable natural person who can be identified directly or indirectly

**Processing**: Any operation performed on personal data including collection, storage, use, transfer, or deletion

**Data Controller**: Entity determining purposes and means of personal data processing (GeoChain Labs LLC)

**Data Processor**: Entity processing personal data on behalf of controller (Backblaze B2, etc.)

**Data Subject**: Individual to whom personal data relates

**Pseudonymous Data**: Data not directly identifying individual but linked to person through additional information

**Sensitive/Special Categories**: Data relating to racial/ethnic origin, political opinions, religious beliefs, union membership, genetic/biometric data, health data, or sexual orientation

**Legitimate Interests**: Organization's interest in processing data for reasonable purposes not outweighed by data subject's rights

**Consent**: Clear, specific, informed, voluntary permission to process personal data

**DSAR**: Data Subject Access Request (right to know what data controller holds)

**Data Breach**: Unauthorized access or disclosure of personal data

**Blockchain**: Decentralized, immutable digital ledger recording transactions

**Smart Contract**: Self-executing code on blockchain executing transaction terms

**Wallet Address**: Unique cryptocurrency identifier for sending/receiving assets

**GDPR**: General Data Protection Regulation (EU data protection law)

**CCPA**: California Consumer Privacy Act (California privacy law)

**CAN-SPAM**: USA law regulating commercial email

---

**Document Version**: 1.0
**Language**: English
**Last Updated**: November 3, 2025
**Effective Date**: [Date to be determined by GeoChain]