Privacy Policy
Draft pending qualified legal review. This policy has not yet been reviewed by qualified counsel and may change before launch.
Effective 1 September 2026
We collect as little as the Service needs to run: a public key, an optional email, payment records and traffic metadata. We never store request bodies and never log URLs, paths or query strings. 127ohoh1.com is the controller of the personal data described here. Contact: privacy@127ohoh1.com.
2.1 What we collect and why
| Data | Source | Purpose | Legal basis (where GDPR applies) |
|---|---|---|---|
| Public key and its fingerprint | Your client | Authenticate you and route your Endpoint | Contract |
| Email address (stored encrypted) | You, if you create an account | Sign-in codes, account recovery, service and billing notices | Contract |
| Session records and a coarse device label | Sign-in | Keep you signed in; show your active sessions | Contract; legitimate interest in security |
| Endpoint names and plan details | Your use of the Service | Provide the plan you chose | Contract |
| Byte counts per Endpoint per period | Our edge | Enforce transfer limits, billing, capacity planning | Contract |
| Request metadata: method, status code, duration, bytes, time | Our edge | Operate, debug and protect the Service | Legitimate interest |
| Wallet address, transaction hash, amount | The blockchain and your payment transaction | Settle payments, prevent fraud, keep accounting records | Contract; legal obligation |
| Keyed hashes of attempt identifiers | Sign-in and forms | Rate limiting and abuse prevention | Legitimate interest |
| Abuse reports and support messages (contact details encrypted) | You or third parties | Investigate reports, answer requests | Legitimate interest; legal obligation |
| Audit records of account and admin actions | Our systems | Security, accountability, dispute resolution | Legitimate interest; legal obligation |
What we do not collect. We do not store request or response bodies, and we do not log URLs, paths or query strings. We do not keep IP addresses in our databases. We use no advertising or third-party analytics, and no tracking cookies. The website sets only a strictly necessary session cookie when you sign in.
How traffic flows. Visitors to your Endpoint connect to our edge over TLS 1.3. Our edge decrypts the request to route it, then sends it to your client over an encrypted tunnel. Content passes through memory in transit only. We add the visitor's IP address in an X-Forwarded-For header so your application can see it. Once it reaches your application, you are responsible for that data.
2.2 Your application's visitors
For personal data inside the traffic to your Endpoint, you are the controller and we act only as a conduit. You must give your own visitors any notice the law requires.
2.3 Sharing
We do not sell or rent personal data, and we do not share it for cross-context advertising. We share it only with:
- Service providers under written contracts: hosting and infrastructure and email delivery. We use no payment facilitator: payments are direct blockchain transactions from your wallet to ours.
- The public blockchain. Payments are recorded permanently on the public blockchain. Wallet addresses and amounts are public by nature, and we cannot erase them.
- Authorities, when required by law valid in New Zealand or a treaty binding on it, or to protect people from serious harm. Where allowed, we notify you first.
- A successor in a merger or acquisition, bound by this policy.
2.4 International transfers
We are based in New Zealand, and our providers may process data in other countries. Where GDPR or UK GDPR applies, we rely on an adequacy decision or on Standard Contractual Clauses (with the UK Addendum) for transfers. You can request a copy from privacy@127ohoh1.com.
2.5 Security
We encrypt personal fields such as email addresses at the field level. Sign-in codes and rate-limit identifiers are stored only as hashes. The audit log is append-only and hash-chained. Backups are encrypted. Staff access is limited to the people who need it and is itself logged.
2.6 Retention
We keep each type of data only as long as our Data Retention Policy states, then delete or anonymise it.
2.7 Your rights
Depending on where you live, you can ask to access, export, correct or delete your data; to restrict or object to processing; and to withdraw consent. You can export your data and delete your account from your account settings, or email privacy@127ohoh1.com. We answer within 30 days and may need to verify control of your key or email first.
Some records are kept despite a deletion request: on-chain transactions, payment records we must keep by law, and the audit log. Deleting your account leaves only an identifier with no personal data.
If you are in the EU or UK, you may complain to your local data protection authority.
California residents. We do not sell or share personal information as the CCPA defines those terms. We do not use sensitive personal information to infer characteristics. You have the right to know, delete and correct your data, and we will not discriminate against you for using these rights.
2.8 Children
The Service is not directed at anyone under 18, and we do not knowingly collect their data.
2.9 Changes
We will post changes here and give 30 days' notice of material changes by email where we have one.