Privacy Policy

Last updated: February 28, 2026

1. Introduction

HashPrism ("we", "us", "our") is operated by its individual creator and operates the HashPrism platform at hashprism.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

By using HashPrism, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address (for authentication and notifications)
  • Username (public, chosen by you)
  • Solana wallet address (public, provided by you)
  • Profile information you optionally provide: display name, bio, website URL, Twitter handle, country

2.2 Transaction Data

When payments are processed through HashPrism, we record:

  • Transaction signatures (publicly available on the Solana blockchain)
  • Payment amounts, currency type, and USD equivalent
  • Buyer wallet addresses (publicly available on the Solana blockchain)
  • Payment status and timestamps
  • Product associated with each payment

2.3 Product Data

When you create products, we store:

  • Product name, description, and price
  • Currency acceptance preferences (USDC, SOL)
  • Creator wallet address for receiving payments

2.4 Webhook Data

If you configure webhooks, we store:

  • Webhook endpoint URLs you provide
  • HMAC signing secrets (hashed)
  • Delivery logs including HTTP status codes and timestamps

2.5 Automatically Collected Data

We may collect standard web analytics data including:

  • IP addresses and browser user agents (via server logs)
  • Pages visited and timestamps
  • Referring URLs

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the HashPrism platform
  • Process and verify payments on the Solana blockchain
  • Send payment confirmation emails and notifications
  • Deliver webhook events to your configured endpoints
  • Display your public storefront and products
  • Prevent fraud and abuse
  • Comply with legal obligations

4. Third-Party Services

HashPrism relies on the following third-party services that may process your data:

Supabase

Database hosting and authentication. Stores account data, products, and payment records. See Supabase Privacy Policy.

Solana Blockchain

All payment transactions are recorded on the Solana blockchain and are publicly visible. Transaction data on the blockchain cannot be deleted.

Resend

Email delivery service for payment notifications. Processes creator email addresses. See Resend Privacy Policy.

Price Oracles

We query CoinGecko, Coinbase, Binance, Kraken, and CoinCap APIs for SOL/USD price data. These services may log request IP addresses per their respective privacy policies.

Vercel

Hosting and deployment. May collect access logs and performance data. See Vercel Privacy Policy.

Vercel Analytics

We use Vercel Analytics and Speed Insights to collect anonymized page view and performance data. No cookies are used and no personally identifiable information is collected. See Vercel Analytics Privacy.

5. Blockchain Data

Payments processed through HashPrism are recorded on the Solana blockchain. Blockchain data is public, immutable, and cannot be modified or deleted by HashPrism or any other party. This includes:

  • Transaction signatures and amounts
  • Sender and receiver wallet addresses
  • Timestamps and block numbers

If you delete your HashPrism account, on-chain transaction data will remain on the blockchain. We will delete your account data, products, and payment records from our database.

6. Cookies

HashPrism uses essential cookies for authentication session management. These cookies are required for the service to function and cannot be disabled. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

7. Data Retention

We retain your account data for as long as your account is active. Payment records are retained for accounting and dispute resolution purposes. When you delete your account:

  • Your profile, products, payment records, refund records, webhooks, and webhook event logs are permanently deleted
  • Your authentication credentials are deleted
  • On-chain blockchain data remains (cannot be deleted by anyone)

8. Data Security

We implement security measures including:

  • Row Level Security (RLS) on all database tables
  • HTTPS encryption for all data in transit
  • HMAC-SHA256 signed webhook payloads
  • Server-side authentication validation on all protected endpoints
  • On-chain transaction verification with amount and recipient validation

While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

9. Your Rights

You have the right to:

  • Access your personal data through your dashboard and settings
  • Update your profile and account information at any time
  • Delete your account and all associated data via Settings → Danger Zone
  • Export your data by viewing your dashboard and transaction history

To exercise these rights or for any privacy-related requests, contact us.

10. Children's Privacy

HashPrism is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date at the top of this page. Continued use of HashPrism after changes constitutes acceptance of the updated policy.

12. Contact

For questions about this Privacy Policy, contact us.