Privacy Policy

Last updated: January 7, 2025

Effective Date: January 7, 2025

1. Introduction

Welcome to NYKNYC (“we,” “our,” or “us”). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Web3 smart wallet platform and services.

By using NYKNYC, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our services.

2. Information We Collect

2.1 Account Information

When you create a NYKNYC account, we collect:

  • Email address (for email-based registration)
  • OAuth profile information (name, email, profile picture) when you sign in through Google, Twitter, Discord, or Apple
  • Important: We do NOT store passwords. Authentication is handled through OAuth providers or email verification.

2.2 Wallet and Blockchain Information

When you use our smart wallet services, we collect:

  • Wallet addresses (ERC-4337 smart wallet addresses)
  • Signer information (passkey public keys, EOA addresses)
  • Transaction data (transaction hashes, amounts, recipients, gas usage)
  • Blockchain network information (which networks you use)

2.3 Technical and Usage Information

We automatically collect certain information when you use NYKNYC:

  • Device information (browser type, operating system, device identifiers)
  • IP address and general location information
  • Session information (via HTTPonly cookies for authentication)
  • Error and diagnostic information (via Sentry for debugging)
  • Usage patterns (features used, frequency of access)

2.4 Developer Integration Data

If you're a developer using NYKNYC:

  • App registration information (app name, app ID, redirect URLs)
  • API usage data (requests made, gas sponsorship usage)
  • OAuth authorization codes (for PKCE flow)

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Account Management: Create and manage your NYKNYC account and smart wallets
  • Authentication: Verify your identity through OAuth providers or email verification
  • Transaction Processing: Execute blockchain transactions on your behalf
  • Gas Sponsorship: Provide free gas credits and transaction sponsorship
  • Customer Support: Respond to your questions and provide technical assistance
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Service Improvement: Debug issues, analyze usage patterns, and improve our platform
  • Legal Compliance: Comply with applicable laws and regulations

We will NEVER: Sell your data to third parties, use your data for advertising, or share your information for marketing purposes.

4. Blockchain and Public Data

Important: NYKNYC operates on public blockchains. You must understand the following:

  • Permanent and Public: All transactions and wallet addresses are permanently recorded on public blockchains and cannot be deleted, modified, or made private
  • Publicly Accessible: Anyone can view your wallet balance, transaction history, and all on-chain activities using blockchain explorers
  • Immutable: Even if you delete your NYKNYC account, all blockchain data remains public and permanent
  • Pseudonymous: While wallet addresses don't contain your personal information, they can potentially be linked to you through transaction patterns or if you share your address

NYKNYC has no control over blockchain data. We are not responsible for information that is publicly available on blockchains.

5. Information Sharing and Disclosure

We share your information only in the following limited circumstances:

5.1 Smart Contract Infrastructure (ZeroDev)

NYKNYC uses smart contracts and infrastructure provided by ZeroDev (ZeroDev Privacy Policy). When you use our service:

  • Your wallet addresses and transaction data may be processed by ZeroDev's infrastructure
  • ZeroDev provides the ERC-4337 account abstraction smart contracts that power your wallet
  • ZeroDev may collect and process technical data necessary for their services to function
  • We recommend reviewing ZeroDev's privacy policy to understand their data practices

NYKNYC uses ZeroDev's services AS-IS. We are not responsible for ZeroDev's data handling practices or privacy policies.

5.2 OAuth Providers

When you sign in with Google, Twitter, Discord, or Apple, we share minimal information necessary for authentication. These providers may collect information according to their own privacy policies.

5.3 Debugging Services

We use Sentry for error tracking and debugging. Sentry receives error logs and diagnostic information to help us identify and fix technical issues.

5.4 Developer Applications

When you authorize a developer's application through NYKNYC:

  • The developer receives an OAuth authorization code to interact with your wallet
  • The developer can create and sponsor transactions on your behalf
  • The developer may receive transaction data and wallet information necessary for their application
  • Each developer is responsible for their own privacy policy and data practices

5.5 Legal Requirements

We may disclose your information if required by law, legal process, or governmental request, or if we believe it's necessary to:

  • Comply with legal obligations
  • Protect our rights, property, or safety
  • Prevent fraud or abuse
  • Protect the safety of users or the public

We do NOT: Sell your data, share it for advertising, or provide it to third-party marketers.

6. Cookies and Tracking Technologies

We use HTTPonly cookies for:

  • Authentication: Keeping you signed in to your account
  • Security: Protecting against unauthorized access and CSRF attacks
  • Session Management: Maintaining your session state

We do NOT use third-party tracking cookies or advertising cookies. Our cookies are essential for the functioning of our service and cannot be disabled without affecting core functionality.

7. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data in transit is encrypted using TLS/SSL
  • Secure Authentication: OAuth 2.0 with PKCE flow for secure authorization
  • HTTPonly Cookies: Protecting against XSS attacks
  • No Password Storage: We don't store passwords; authentication is handled by OAuth providers
  • Regular Security Audits: Ongoing monitoring and security assessments

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. Specifically:

  • Account Data: Retained while your account exists
  • Transaction History: Retained while your account exists for service functionality
  • Blockchain Data: Permanently public on blockchains (cannot be deleted)
  • Deleted Accounts: Most data is deleted within 90 days of account deletion, except where required for legal compliance or legitimate business purposes

Note: Deleting your NYKNYC account does NOT remove your wallet addresses or transaction history from public blockchains.

9. Your Privacy Rights

Depending on your location, you may have the following rights:

9.1 Access and Portability

You have the right to access your personal data and request a copy in a portable format.

9.2 Correction

You can update your account information through your account settings or by contacting us.

9.3 Deletion

You can request deletion of your personal data by contacting [email protected]. We will delete your data within 90 days, except:

  • Data required for legal compliance
  • Data necessary to resolve disputes
  • Blockchain data (which is permanently public and cannot be deleted)

9.4 Objection and Restriction

You may object to certain data processing or request restriction of processing in certain circumstances.

9.5 Withdraw Consent

Where we process data based on consent, you can withdraw consent at any time by deleting your account or contacting us.

To exercise any of these rights, contact us at [email protected].

10. International Data Transfers

NYKNYC is a global service. Your information may be transferred to and processed in countries other than your country of residence. We ensure that any such transfers comply with applicable data protection laws and implement appropriate safeguards to protect your information.

11. Children's Privacy

NYKNYC is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected], and we will delete such information.

12. Third-Party Services and Links

NYKNYC may contain links to third-party websites or integrate with third-party services (such as OAuth providers and developer applications). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes

Your continued use of NYKNYC after any changes indicates your acceptance of the updated Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: [email protected]

For privacy-related inquiries, data access requests, or account deletion requests.

15. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process your personal data based on:

  • Contractual Necessity: To provide you with our services
  • Legitimate Interests: To improve our services, ensure security, and prevent fraud
  • Consent: Where you have given explicit consent
  • Legal Obligations: To comply with applicable laws

Disclaimer

This Privacy Policy applies only to information collected by NYKNYC. It does not apply to information that is publicly visible on blockchains, which is governed by the inherent properties of blockchain technology. NYKNYC cannot control, modify, or delete blockchain data.

By using NYKNYC, you acknowledge and accept that blockchain transactions and wallet addresses are public and permanent.