Skip to main content
ChainStream is committed to protecting user data privacy. This document explains how we collect, process, and protect your data, as well as your privacy rights.
Last Updated: February 2025 | Version: v2.0

Data Collection Scope

Data We Collect

ChainStream only collects data necessary to provide our services: Account Data
Data TypeCollection PurposeNecessity
Email addressAccount identification, notificationsRequired
Password hashAccount securityRequired
Company nameEnterprise customer identificationOptional
Payment infoBilling processingRequired for paid users
Usage Data
Data TypeCollection PurposeRetention Period
API call recordsBilling, performance optimization90 days
Error logsTroubleshooting30 days
Feature usage statsProduct improvementLong-term after anonymization
Technical Data
Data TypeCollection Purpose
IP addressSecurity protection, geographic routing
Device infoCompatibility optimization
Browser typeInterface adaptation

Data We Don’t Collect

ChainStream commits to never collecting the following sensitive information:
  • Private keys or seed phrases — Our service architecture is designed without access to user private keys
  • On-chain asset details — We only provide query capabilities, we don’t store asset information
  • Real identity information — No KYC required, no real identity association
  • Associated identity of queried addresses — Query requests are decoupled from identity

Cookies and Tracking Technologies

Cookie TypePurposeCan Be Disabled
Essential CookiesSession management, securityNo
Functional CookiesUser preference settingsYes
Analytics CookiesService improvementYes
Users can manage cookies through browser settings.
Disabling essential cookies may prevent the service from functioning properly.

Data Processing Principles

Minimization Principle

We only collect and process the minimum data necessary for business operations.

Purpose Limitation

Data is only used for the following purposes:
  • Providing and improving services
  • Billing
  • Security protection
  • Customer support

Transparency Principle

  • Clear disclosure of data usage
  • Advance notification of significant changes
  • Provision of data access channels

Data Storage and Protection

Storage Locations

Data TypeStorage LocationBackup Location
Primary dataAWS SingaporeAWS Tokyo
Log dataAWS Singapore-
Backup dataAWS Tokyo-

Encryption Measures

Transmission Encryption
  • All API communications use TLS 1.3
  • WebSocket connections use WSS protocol
  • Insecure cipher suites are disabled
Storage Encryption
Data TypeEncryption Method
DatabaseAES-256
File storageAES-256
BackupsAES-256
Key managementAWS KMS

Access Control

  • Role-Based Access Control (RBAC)
  • Least privilege principle
  • Access log auditing
  • Multi-factor authentication required

Security Audits

  • Regular security assessments
  • Third-party penetration testing
  • Vulnerability response mechanism
  • Security incident notification

Data Retention Periods

Data TypeRetention PeriodDeletion Method
Account dataAccount lifetime + 30 daysAutomatic deletion
API call logs90 daysAutomatic deletion
Error logs30 daysAutomatic deletion
Billing records7 years (legal requirement)Deletion upon expiry
Security logs1 yearAutomatic deletion
After account deletion, we will clear all identifiable personal data within 30 days, except for data required to be retained by law.

Third-Party Data Sharing

Data Sharing Principles

  • No data selling: We never sell user data to third parties
  • Minimal sharing: Only share the minimum data required for services
  • Contractual constraints: All sub-processors sign data processing agreements

Sub-processors

Enterprise customers can contact [email protected] for the complete sub-processor list.

User Rights

Rights Overview

RightDescriptionHow to Exercise
Right of AccessObtain a copy of your dataEmail request
Right of RectificationCorrect inaccurate dataEmail request
Right of ErasureRequest deletion of your dataEmail request
Right of PortabilityExport in machine-readable formatEmail request
Right to ObjectObject to certain data processingEmail request

Right of Access

You have the right to request access to your personal data held by us. How to request: Send email to [email protected]

Right of Rectification

You have the right to request correction of inaccurate personal data. How to exercise: Send email to [email protected]

Right of Erasure

You have the right to request deletion of your personal data. How to exercise:
  • Account deletion: Send email to [email protected]
  • Complete deletion: Data will be cleared within 30 days
  • Retention exceptions: Data required by law to be retained

Right of Portability

You have the right to obtain a copy of your data.
  • Supported formats: JSON, CSV
  • Export scope: Account information, usage records
  • How to request: Send email to [email protected]
  • Processing time: Within 30 days

Right to Object

You have the right to object to certain data processing activities:
  • Marketing communications: Can unsubscribe at any time
  • Data analytics: Can opt out

Compliance Statement

GDPR Compliance

ChainStream complies with the EU General Data Protection Regulation (GDPR):
  • Lawful basis for data processing
  • Data subject rights protection
  • Data protection impact assessment
  • Data breach notification mechanism

CCPA Compliance

For California users, we comply with the California Consumer Privacy Act:
  • Right to know
  • Right to delete
  • Right to opt-out
  • Right to non-discrimination

Data Processing Agreement

Enterprise customers can sign a Data Processing Agreement (DPA):
  • Standard Contractual Clauses (SCCs)
  • Data processing scope definition
  • Security measure commitments
  • Sub-processor list
How to apply: Contact [email protected]

Privacy Policy Updates

  • 30 days advance notice for significant changes
  • Update date clearly marked
  • Historical versions available for review

FAQ

No. ChainStream’s architecture is designed to ensure we cannot access users’ private keys or seed phrases. We only provide on-chain data reading services and do not involve any private key operations.
API query records are only used for: billing statistics, service performance optimization, and anomaly detection. We do not analyze the specific address content of your queries, nor do we sell query data to third parties.
After account deletion, we will clear all identifiable personal data within 30 days. However, billing-related records need to be retained for the legally required period.
Primary data is stored in AWS Singapore region, backups are stored in AWS Tokyo region.
You can exercise your rights to access, correct, delete, and export data by sending an email to [email protected]. We will respond to your request within 30 days.

Contact Information

Privacy Inquiries

MatterContactResponse Time
Privacy issues[email protected]5 business days
Data requests[email protected]Within 30 days
Security issues[email protected]Within 24 hours
Enterprise DPA[email protected]3 business days

Complaints and Suggestions

If you have any concerns about our data processing, you can:
  • Contact our privacy team
  • File a complaint with your local data protection authority