Privacy Policy

1. What we collect

  • Account data: username, email address, hashed password, signup timestamp, accepted Terms version.
  • Profile data (optional): bio, website, avatar, cryptocurrency wallet addresses you enter.
  • Transactional data: orders you place or receive, the assets you upload, blockchain transaction hashes, payment amounts and timestamps.
  • Technical data: server access logs (IP address, user agent, request URL) retained for up to 14 days for security and debugging.

2. What we do not collect

  • We do not collect government IDs, real-world addresses, phone numbers, or social-security numbers.
  • We do not collect cryptocurrency private keys — we never see them, hold them, or store them.
  • We do not use third-party advertising trackers or analytics that profile you across sites.

3. Why we collect it

  • To deliver the service you signed up for (login, purchases, downloads).
  • To send transactional emails (order confirmations, underpayment warnings, password reset).
  • To detect fraud and abuse, and to comply with applicable law.
  • To calculate and collect the 7% platform fee from sellers.

4. Who we share it with

We do not sell your data. We share data with third parties only when strictly necessary:

  • Email provider (currently Brevo) — to deliver outgoing emails.
  • Hosting provider — your data is stored on servers operated by our cloud host.
  • Public blockchain APIs (Blockstream, Etherscan, Tronscan) — to verify payments. These services see only the wallet address and transaction hash, not your account identity.
  • Law enforcement — only when compelled by a valid legal request from the jurisdiction where we operate.

5. Cryptocurrency wallet addresses

Wallet addresses you enter on your profile are stored in plain text in our database and are visible to buyers who purchase your assets (so they know where to send payment). Do not enter wallet addresses you wish to keep secret. Public addresses are not sensitive on their own — but the link between an address and your username is publicly visible to anyone who buys from you.

6. Cookies

We set only the cookies required to operate the site:

  • sessionid — keeps you logged in (Django default, HTTP-only).
  • csrftoken — prevents cross-site request forgery (Django default).

We do not set advertising or third-party tracking cookies.

7. Data retention

  • Account data: kept as long as your account is active.
  • Order data: kept indefinitely for tax and audit purposes (we may be legally required to retain it).
  • Server logs: 14 days, then rotated and deleted.
  • Soft-deleted assets: hidden from users but retained until permanently purged by an administrator.

8. Your rights

You can:

  • Edit or remove your profile data at any time from your profile page.
  • Request a copy of all data we hold about you by emailing support.
  • Request deletion of your account by emailing support — note that order records may be retained for tax / legal reasons even after account deletion.

9. Security and Breach Notification

Passwords are hashed with PBKDF2 (Django default). The site is served over HTTPS. We use parameterised database queries and CSRF protection on all state-changing requests.

In the event of a data breach that affects your personal data, we will notify affected users by email within 72 hours of becoming aware of the incident, describing what data was involved and what steps we are taking. If you discover a security vulnerability, please report it to support immediately and we will respond within 24 hours.

10. Contact

Questions or requests: support@digitalsummit.com


See also Terms of Service & Risk Disclosure.