Privacy Policy
Last updated: April 1, 2026
1. Information We Collect
We collect information you provide directly: account registration data (name, email, phone number), KYC verification documents (government ID, proof of address), wallet addresses, asset information submitted for digitization (photos, serial numbers, descriptions), and communication preferences.
We automatically collect: device information, browser type, IP address, usage patterns, pages visited, and interaction data. On-chain transaction data (wallet addresses, token transfers, smart contract interactions) is publicly visible on the Polygon blockchain.
2. How We Use Your Information
We use your information to: operate and improve the Platform, verify your identity for KYC/AML compliance, process asset verifications via Boss Vision AI, facilitate marketplace transactions, manage DeFi lending positions, distribute ERS revenue, send transactional notifications (verification results, loan alerts, distribution confirmations), provide customer support, and comply with legal obligations.
3. AI Processing
Boss Vision AI processes photographs and asset data you submit to provide verification and valuation analysis. This processing uses the Anthropic Claude API. Submitted images and descriptions are sent to the AI service for analysis and are not stored by the AI provider beyond the duration of the request. Verification results are stored in our database and, for verified assets, recorded on the Polygon blockchain.
4. Data Sharing
We do not sell your personal information. We share data with: KYC/AML verification providers (identity documents only, processed through regulated third parties), payment processors (Stripe for subscription billing), cloud infrastructure (Supabase for database, Vercel for hosting), and the Polygon blockchain (wallet addresses and transaction data are publicly recorded on-chain).
We may disclose information when required by law, to protect our rights, or to comply with legal process, court orders, or government requests.
5. Data Security
We implement industry-standard security measures: TLS 1.3 encryption for data in transit, AES-256 encryption for data at rest, Supabase Row-Level Security policies, environment variable management for API keys, and regular security reviews. KYC documents are processed through regulated third-party providers and are not stored directly in our database.
6. Blockchain Data
Blockchain transactions are permanent and publicly visible. When you mint a token, list on the marketplace, take a loan, or participate in an ERS pool, the associated wallet addresses and transaction details are recorded on the Polygon blockchain and cannot be deleted. This is inherent to blockchain technology and is not within our control.
7. Your Rights
Depending on your jurisdiction, you may have the right to: access, correct, or delete your personal data, object to or restrict processing, data portability, and withdraw consent. To exercise these rights, contact us at privacy@bosstag.co. Note that on-chain data cannot be modified or deleted due to the immutable nature of blockchain.
8. Cookies
We use essential cookies for authentication and session management. We use analytics cookies to understand Platform usage and improve the service. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent certain Platform features from functioning.
9. Data Retention
Account data is retained for the duration of your account plus 5 years for legal compliance. KYC documents are retained per regulatory requirements (typically 5-7 years after account closure). Transaction records are retained permanently as they exist on the blockchain. You may request deletion of off-chain data by contacting us.
10. Children's Privacy
The Platform is not intended for users under 18 years of age. We do not knowingly collect information from children. If we become aware that a child has provided personal data, we will take steps to delete it.
11. Changes
We may update this Privacy Policy periodically. Material changes will be communicated via email or Platform notification. The “Last updated” date at the top reflects the most recent revision.
Contact
Privacy questions? Contact us at privacy@bosstag.co