Privacy
Minimal data for API operation.
Effective: July 29, 2026 · Version: 2026-07-29-beta-v2
This notice explains how the SolTrench beta operator processes personal information when you visit the website, apply for beta access, link a wallet, use the API, or contact SolTrench. SolTrench minimises the data it requests and does not ask for wallet private keys or seed phrases.
Information We Process
- Account and eligibility: wallet public key, invite information, self-certified country of residence, location and ordinary-residence confirmations, accepted policy versions and hashes, acceptance time, and account status.
- API operation: API-key prefix and hash, scopes, request route, timing, refusal reason, quotas, usage counters, transaction-intent metadata, and audit events.
- Network and security: source IP address and Cloudflare country signal at the edge, request identifiers, user-agent and protocol information where logged, and short-lived abuse-prevention counters.
- Communications: your email address and the content and metadata of support, privacy, security, or abuse reports you choose to send.
- Public-chain information: public wallet addresses, transaction signatures, token addresses, and transaction or event data obtained from Solana or public data providers when needed to provide requested features.
Where Information Comes From
Information comes from you, your browser or API client, the wallet-ownership process, Cloudflare's trusted edge signal, service activity, the person who issued an invitation, and public blockchain or market-data sources. Public blockchain records may identify or be linked to a person even though they are publicly available.
Purposes And Lawful Bases
- To review access, create and administer accounts, authenticate wallets, issue API keys, deliver requested data and transaction-building features, and provide support. The basis is taking steps at your request and performing the beta agreement.
- To meter use, maintain reliability, debug faults, protect accounts, prevent abuse, enforce eligibility and these Terms, investigate security events, and improve the service. The basis is SolTrench's legitimate interests in operating a secure, reliable, and appropriately restricted developer service.
- To retain required records, respond to lawful requests, establish or defend legal claims, and comply with tax, regulatory, sanctions, or other legal duties. The basis is legal obligation or, where applicable, legitimate interests in protecting legal rights.
SolTrench does not currently use personal information for behavioural advertising, sell personal information, or send general marketing emails. If optional marketing is introduced, it will use a separate lawful process and opt-out.
Eligibility And Automated Refusals
The closed-beta onboarding flow uses your country declaration and the trusted edge country signal to enforce geographic restrictions. Requests from excluded, missing, malformed, or unknown country signals can be refused automatically. This is an access-control decision, not profiling for advertising or an assessment of creditworthiness. If you believe a refusal is incorrect, contact support@soltrench.io; an invitation cannot override an incompatible United Kingdom location or residence declaration.
Guernsey, Jersey, and the Isle of Man are excluded as a conservative beta business policy, not because this notice claims that they are legally part of the United Kingdom. The current onboarding flow does not request identity documents or claim to perform full know-your-customer verification. Do not send passports, other identity documents, a residential address, or unnecessary personal information to support.
Network And Abuse-Prevention Data
The Cloudflare edge necessarily processes connection data, including source IP address and country signal, and replaces client-supplied forwarding headers before the request reaches SolTrench. For public wallet-auth rate limiting, the API derives a keyed digest from the client address and stores only that digest in a short-lived counter with a maximum 180-second lifetime; the raw address is not placed in the counter key. Country and IP controls can reduce incompatible access but cannot perfectly identify VPN, proxy, travel, or residence facts.
Website Storage
The public website does not currently load third-party advertising or analytics code and does not set browser
cookies. Trade Lab keeps an active API key and wallet session in tab-scoped browser
sessionStorage after you use the account tools. This storage is necessary to provide the
requested Trade Lab session, is not used for cross-site tracking, and is cleared when that browser tab's
session ends. You can clear it earlier by closing the tab or clearing site data.
Who Receives Information
Information is available only where needed to the operator and service providers supporting the beta. Current
provider categories include Cloudflare for edge security and country signals, infrastructure providers for
hosting, network, storage, and backups, and the provider used for
@soltrench.io email. Public Solana, RPC, wallet, venue, and market-data systems process
information under their own terms when you or SolTrench interact with them. SolTrench may also disclose
information where legally required, to protect users or the service, or in connection with a business
transfer subject to appropriate confidentiality and notice.
International Transfers
Infrastructure providers may process information in the United Kingdom, United States, or other countries. Where UK data-protection law requires a transfer mechanism, SolTrench relies on applicable adequacy regulations or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum. You may request information about applicable safeguards through the privacy contact.
Retention And Security
Short-lived controls expire automatically: the public wallet-auth rate-limit digest lasts no more than 180 seconds; wallet-auth nonces normally expire after five minutes; developer sessions normally expire after 24 hours; websocket access tokens normally expire after 60 seconds; and transaction-tracking intents normally expire after ten minutes.
Durable account, acceptance, API-key, usage, and audit records are kept while the account is active and afterwards only for as long as reasonably needed for security, abuse prevention, legal compliance, dispute handling, and the establishment or defence of legal claims. Support and incident records are kept until the matter is resolved and then according to the same criteria. Retention is reviewed periodically; information is deleted or anonymised when no continuing purpose applies. Backups may retain deleted information until their ordinary secure replacement cycle completes.
Access is restricted to operational need. API-key secrets are displayed once and stored only as hashes. SolTrench uses access controls, encrypted transport, request limits, secret separation, audit trails, and infrastructure monitoring. No internet service can guarantee absolute security.
Public Blockchains
Solana transactions and wallet activity are public and may be permanent. SolTrench cannot erase or alter data recorded by an independent blockchain, RPC provider, venue, or explorer. Closing an account does not remove public-chain records.
Your Rights
Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction, or portability of your personal information. You may also complain about how it is used. Some rights are limited where information must be retained for security, legal obligations, or legal claims. SolTrench may ask for proportionate information to verify a request but will not ask for a seed phrase or private key.
Your right to object: where processing is based on legitimate interests, you may object by emailing support@soltrench.io. SolTrench will stop unless there are compelling legitimate grounds or the information is needed for legal claims.
Required Information
Wallet ownership, eligibility declarations, current Terms acceptance, and necessary request metadata are required to provide a beta account. If you do not provide them, SolTrench cannot activate or operate that account. Optional support information should be limited to what is necessary for the issue.
Children
The service is not directed to anyone under 18, and SolTrench does not knowingly create accounts for children. Contact the privacy route if you believe a child has supplied information.
Complaints And Requests
Send privacy or account requests to support@soltrench.io. Security reports should go to security@soltrench.io. Please contact SolTrench first so the issue can be investigated. You may also complain to the UK Information Commissioner's Office or another competent supervisory authority.
Changes To This Notice
Material changes will update the effective date and version on this page. If a change materially affects account processing, SolTrench will provide notice through the service or require updated acceptance where appropriate.