Privacy Policy

Effective date: August 1, 2026

Section 1: Automated Verification and Data Collection

1. When participants buy chat coins or register a card for auction authorization, payment runs through Stripe’s security review. Card authentication also completes practical identity and credit checks in the system.

2. To run those reviews and operate the Service, the Platform collects and manages email, user ID, profile photo (including single-initial avatars), country of residence (GeoIP from IP address), coin purchase history, and bid history.

Section 2: Complete Credit Card Data Protection

As a hard security rule, the Platform does not store raw credit card numbers, expiry dates, CVV codes, or identity-document images on its own servers. All payment data is sent directly to Stripe’s encrypted PCI-DSS compliant systems.

Section 3: Purposes of Information Use

Personal data is used only for the automated systems and service delivery below. It is not sold or reused for unrelated purposes.

1. Fully automatic display of language (selected locales) and currency based on the user’s location (IP).

2. Instant settlement of Uniform Price and Second-Chance Raffle outcomes on secure backend servers (Firebase) when an auction ends.

3. Fast delivery of win/draw notification emails via Resend within seconds after auction end or raffle completion.

Section 4: Safe Third-Party Integration

Minimum necessary data is shared with carefully selected providers to keep the Service secure and automated. Credentials are kept in backend environment variables.

  • Stripe / Stripe Connect: Card payments, identity checks, and automatic split of settled amounts (after platform fee) to charities and hosts without the Platform holding funds beyond its fee.
  • Resend: Automatic delivery of win/draw emails worldwide (including QQ Mail, Gmail, etc.) from a test address (onboarding@resend.dev) and, later, a custom domain.

Section 5: Global Standards (GDPR/CCPA compliant)

Data is stored on Firebase (Google Cloud) distributed infrastructure and operated in the spirit of the EU GDPR and California CCPA. Users may request access, correction, or full account deletion (permanent erasure) of registered email and account data (including chat history) at any time.