Privacy Policy
Last updated: February 28, 2026
1. Introduction
HashPrism ("we", "us", "our") is operated by its individual creator and operates the HashPrism platform at hashprism.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
By using HashPrism, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (for authentication and notifications)
- Username (public, chosen by you)
- Solana wallet address (public, provided by you)
- Profile information you optionally provide: display name, bio, website URL, Twitter handle, country
2.2 Transaction Data
When payments are processed through HashPrism, we record:
- Transaction signatures (publicly available on the Solana blockchain)
- Payment amounts, currency type, and USD equivalent
- Buyer wallet addresses (publicly available on the Solana blockchain)
- Payment status and timestamps
- Product associated with each payment
2.3 Product Data
When you create products, we store:
- Product name, description, and price
- Currency acceptance preferences (USDC, SOL)
- Creator wallet address for receiving payments
2.4 Webhook Data
If you configure webhooks, we store:
- Webhook endpoint URLs you provide
- HMAC signing secrets (hashed)
- Delivery logs including HTTP status codes and timestamps
2.5 Automatically Collected Data
We may collect standard web analytics data including:
- IP addresses and browser user agents (via server logs)
- Pages visited and timestamps
- Referring URLs
3. How We Use Your Information
We use collected information to:
- Provide and maintain the HashPrism platform
- Process and verify payments on the Solana blockchain
- Send payment confirmation emails and notifications
- Deliver webhook events to your configured endpoints
- Display your public storefront and products
- Prevent fraud and abuse
- Comply with legal obligations
4. Third-Party Services
HashPrism relies on the following third-party services that may process your data:
Supabase
Database hosting and authentication. Stores account data, products, and payment records. See Supabase Privacy Policy.
Solana Blockchain
All payment transactions are recorded on the Solana blockchain and are publicly visible. Transaction data on the blockchain cannot be deleted.
Resend
Email delivery service for payment notifications. Processes creator email addresses. See Resend Privacy Policy.
Price Oracles
We query CoinGecko, Coinbase, Binance, Kraken, and CoinCap APIs for SOL/USD price data. These services may log request IP addresses per their respective privacy policies.
Vercel
Hosting and deployment. May collect access logs and performance data. See Vercel Privacy Policy.
Vercel Analytics
We use Vercel Analytics and Speed Insights to collect anonymized page view and performance data. No cookies are used and no personally identifiable information is collected. See Vercel Analytics Privacy.
5. Blockchain Data
Payments processed through HashPrism are recorded on the Solana blockchain. Blockchain data is public, immutable, and cannot be modified or deleted by HashPrism or any other party. This includes:
- Transaction signatures and amounts
- Sender and receiver wallet addresses
- Timestamps and block numbers
If you delete your HashPrism account, on-chain transaction data will remain on the blockchain. We will delete your account data, products, and payment records from our database.
6. Cookies
HashPrism uses essential cookies for authentication session management. These cookies are required for the service to function and cannot be disabled. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
7. Data Retention
We retain your account data for as long as your account is active. Payment records are retained for accounting and dispute resolution purposes. When you delete your account:
- Your profile, products, payment records, refund records, webhooks, and webhook event logs are permanently deleted
- Your authentication credentials are deleted
- On-chain blockchain data remains (cannot be deleted by anyone)
8. Data Security
We implement security measures including:
- Row Level Security (RLS) on all database tables
- HTTPS encryption for all data in transit
- HMAC-SHA256 signed webhook payloads
- Server-side authentication validation on all protected endpoints
- On-chain transaction verification with amount and recipient validation
While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
9. Your Rights
You have the right to:
- Access your personal data through your dashboard and settings
- Update your profile and account information at any time
- Delete your account and all associated data via Settings → Danger Zone
- Export your data by viewing your dashboard and transaction history
To exercise these rights or for any privacy-related requests, contact us.
10. Children's Privacy
HashPrism is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date at the top of this page. Continued use of HashPrism after changes constitutes acceptance of the updated policy.
12. Contact
For questions about this Privacy Policy, contact us.