Privacy Policy
Last Updated: February 25, 2025
1. Information We Collect
1.1. Information You Provide
| Data | When | Purpose |
|---|---|---|
| Email address | Account registration | Authentication, communication, password recovery |
| Name (optional) | Account profile | Personalization |
| Company name (optional) | Account profile | Invoicing, personalization |
| Job title (optional) | Account profile | Service customization |
| Payment information | Subscription purchase | Payment processing (handled by Stripe) |
1.2. Information Generated by the Service
| Data | When | Purpose |
|---|---|---|
| SHA-256 hashes | When you stamp a file | Core service: blockchain timestamping |
| Transaction IDs (txID) | After blockchain confirmation | Verification and proof retrieval |
| Timestamps | After blockchain confirmation | Proof of existence at a point in time |
| File metadata (filename, size) | When you stamp a file (optional) | Display on verification page and badge |
1.3. Information Collected Automatically
| Data | When | Purpose |
|---|---|---|
| IP address | Page visits and API calls | Security, rate limiting, abuse prevention |
| Browser type and version | Page visits | Compatibility and debugging |
| Device information | Page visits | Responsive design optimization |
| Pages visited and actions taken | While using the Service | Analytics and service improvement |
| API usage data | API calls | Usage metering and billing |
| Cookies and similar technologies | Page visits | Session management, preferences |
2. What We Do NOT Collect
This is critical to understand about IOStamp:
- We do NOT receive, store, view, or access your original files. Hashing is performed client-side in your browser using the Web Crypto API. Only the resulting hash (a 64-character string) is transmitted to our servers.
- We do NOT have the ability to reconstruct your files from hashes. SHA-256 is a one-way function. It is mathematically impossible to reverse a hash into the original file.
- We do NOT store Badge images. Badges are generated client-side in your browser and downloaded directly to your device.
- We do NOT track what type of content you timestamp. We receive a hash string — we cannot determine whether it represents a photo, document, song, or any other file type.
3. How We Use Your Information
We use your information for the following purposes:
- Providing the Service: Processing hashes, anchoring to the blockchain, generating verification pages, and managing your account.
- Billing and payments: Processing subscriptions and managing usage-based billing through Stripe.
- Communication: Sending account-related emails (welcome, password reset, billing receipts), and, with your consent, marketing communications.
- Security: Preventing fraud, abuse, and unauthorized access to the Service.
- Analytics: Understanding how the Service is used to improve performance and features.
- Legal compliance: Meeting our obligations under applicable laws and regulations.
4. How We Share Your Information
We do NOT sell your personal information. We share information only in the following circumstances:
4.1. Service Providers
We use trusted third-party providers to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Payment information, email, billing address |
| Vercel, Inc. | Website and API hosting | IP address, usage data |
| Bitcoin SV Network | Blockchain anchoring | SHA-256 hashes only (no personal data) |
| Analytics provider | Usage analytics | Anonymized usage data |
4.2. Blockchain (Public)
When a hash is anchored to the Bitcoin SV blockchain, the following becomes publicly and permanently available:
- The SHA-256 hash
- The blockchain transaction ID
- The timestamp of the transaction
This data is public by design and cannot be removed. However, hashes alone cannot be linked to your identity or your original content without additional information.
4.3. Verification Pages (Public)
When a stamp is created, a verification page may be accessible at iostamp.com/verify/. This page displays:
- The hash
- The timestamp
- The blockchain transaction link
- File metadata (if provided by you)
This page is publicly accessible to allow anyone to verify a timestamp.
4.4. Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.5. Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account, or 90 days after account termination |
| Hash data and metadata | Indefinitely (required for verification service) |
| Blockchain records | Permanent (cannot be deleted from public blockchain) |
| Payment records | As required by tax and financial regulations (typically 7 years) |
| Server logs (IP, access) | 90 days |
| Analytics data | 24 months (anonymized) |
After the retention period, data is deleted or anonymized, except for blockchain records which are permanent by design.
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
- All data in transit is encrypted using TLS 1.2 or higher.
- API keys are hashed before storage.
- Access to production systems is restricted and logged.
- We conduct regular security reviews.
- Payment data is processed by Stripe (PCI DSS Level 1 certified) and never touches our servers.
While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights
7.1. All Users
Regardless of your location, you have the right to:
- Access your personal data by contacting us.
- Correct inaccurate personal data in your Account settings or by contacting us.
- Delete your Account and associated personal data by contacting us at hello@iostamp.com.
- Export your data (hashes, timestamps, transaction IDs) through the API or by request.
- Opt out of marketing communications at any time via unsubscribe links or by contacting us.
7.2. European Economic Area (EEA) Residents — GDPR Rights
If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to access (Article 15): Request a copy of all personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate data.
- Right to erasure (Article 17): Request deletion of your personal data ("right to be forgotten"). Note: hashes anchored to the blockchain cannot be deleted as they are on a decentralized public ledger outside our control.
- Right to restrict processing (Article 18): Request that we limit how we use your data.
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Article 7): Withdraw consent at any time where processing is based on consent.
Legal bases for processing (Article 6 GDPR):
- Contract performance: Processing hashes, managing accounts, providing the Service.
- Legitimate interests: Security, analytics, service improvement.
- Consent: Marketing communications.
- Legal obligation: Tax and financial record keeping.
Data controller: IOStamp LLC, hello@iostamp.com
International transfers: Your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where applicable.
To exercise your GDPR rights, contact us at hello@iostamp.com. We will respond within 30 days.
7.3. California Residents — CCPA Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
- Right to know what personal information we collect, use, and disclose.
- Right to delete your personal information, subject to certain exceptions.
- Right to opt out of the sale of personal information. We do not sell personal information.
- Right to non-discrimination for exercising your CCPA rights.
To exercise your CCPA rights, contact us at hello@iostamp.com.
8. Cookies
8.1. What Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Session management, authentication, security | Session |
| Functional | User preferences, language settings | 1 year |
| Analytics | Understanding usage patterns (anonymized) | 24 months |
8.2. Managing Cookies
You can control cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.
We do NOT use advertising cookies or tracking pixels from third-party ad networks.
9. Children's Privacy
The Service is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at hello@iostamp.com.
10. Third-Party Links
The Service may contain links to third-party websites, including blockchain explorers and payment processors. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website.
- Updating the "Last Updated" date at the top of this document.
- Sending an email notification for significant changes.
Continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
12. The Blockchain and Your Privacy
This section addresses a unique aspect of our Service:
Blockchain records are permanent and public. When you use IOStamp, a SHA-256 hash is recorded on the Bitcoin SV blockchain. This record:
- Cannot be modified or deleted by IOStamp or any other party.
- Is publicly visible to anyone with access to a blockchain explorer.
- Contains ONLY the hash — not your name, email, files, or any personal information.
- Cannot be linked to your identity without additional information that only you possess.
If you request account deletion, we will delete your personal data from our systems. However, hashes on the blockchain will remain, as we have no technical ability to remove them. These hashes, standing alone, are not personal data as they cannot identify you or reveal the content of your files.
13. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy, contact us at:
IOStamp LLC Email: hello@iostamp.com Website: iostamp.com
For GDPR inquiries, please include "GDPR Request" in your email subject line. For CCPA inquiries, please include "CCPA Request" in your email subject line.
By using IOStamp, you acknowledge that you have read and understood this Privacy Policy.