Privacy Policy

This document concerns legal rights and is governed by the law of the United Arab Emirates. Contact hello@cryptoforumhub.com with questions.

Privacy Policy

Effective date: August 07, 2026

This Policy explains how Cryptoforumhub LLC, United Arab Emirates, processes personal data in connection with CryptoForumHub.

Data we collect

  • application information: name, email, role, applicant type, and the reasons and intended use you describe;
  • organization or project information where you apply on behalf of one: organization or project name, organization type, official website, official LinkedIn or X account, and the forum category you consider relevant;
  • asset evidence where applicable: network or chain name, whether the asset is a token or a native coin, ticker, and the block-explorer link for the token contract or the chain;
  • technical, governance, or repository references supplied by protocols, foundations, and ecosystems;
  • the plan you say you have in mind, your expected publishing frequency, and any preferred forum username;
  • which policy documents you accepted, when, and which version of each;
  • how you reached the site: the page you landed on, the referring site, and campaign parameters where present;
  • email verification, public social-proof URL, verification result, and timestamps;
  • portal and forum account identifiers, username, verified email, login/session/security records, and Discourse user ID;
  • forum content, moderation history, reports, and public profile information;
  • billing plan, public payment address, invoice, token contract, transaction hash, amount, and subscription dates;
  • API credential metadata, grants, usage, request identifiers, result codes, and security/audit metadata;
  • technical data such as IP address or truncated/hashed IP, user agent, timestamps, cookies, and security logs;
  • correspondence sent to official email addresses.

CryptoForumHub never requests or stores wallet private keys.

Why we use data

We use data to evaluate applications, verify identity, send invitations, operate accounts, prevent abuse, deliver forum/API services, check payments, provide support, moderate content, secure the service, maintain records, and comply with legal obligations.

Public data

Forum Topics, Posts, usernames, public profiles, and public social-proof Posts may be visible worldwide and indexed by search engines. After social proof is verified, applicants may delete the external LinkedIn/X post as described in the access process.

Service providers

Data may be processed by hosting, Discourse, email, CAPTCHA, payment-checking, database, backup, and infrastructure providers needed to operate the service. External websites and blockchain transactions are independently public or controlled by their providers.

The services currently in use are:

  • SendGrid, which delivers automated email such as confirmation links, verification instructions, and decisions;
  • Cloudflare Turnstile, which checks that a form submission comes from a person rather than an automated script;
  • Google Analytics 4, which measures site usage as described in the Cookie Policy and never receives your personal data;
  • Discourse, which operates the public forum and your forum account;
  • the configured payment-verification provider, which is used only to confirm that a transfer matching an invoice exists on the public blockchain.

CryptoForumHub does not open the website, social, or explorer links you submit from its servers. The team opens them manually during review.

Links you submit

Links you provide as evidence are stored so that a reviewer can open them and so that the record of your application is complete. They are shown only to the CryptoForumHub team in the administration area, and are never sent to analytics.

Retention

  • rejected-applicant PII: automatically deleted 30 days after rejection;
  • waitlisted applicant data: up to 180 days unless consent is renewed;
  • social-proof URL: deleted 30 days after successful verification; verification status/timestamp may remain;
  • magic/confirmation tokens: deleted or invalidated after use/expiry;
  • API audit metadata: 180 days by default, configurable by admin;
  • forum content and moderation records: retained while needed to operate the public forum and preserve discussion integrity;
  • payment/invoice records: retained for applicable accounting, tax, fraud-prevention, and legal requirements; implementation default may be up to seven years pending professional review;
  • backups: follow the documented short local retention cycle.

Security

We use access controls, HTTPS, hashed tokens, TOTP for the sole portal admin, protected secrets, restricted ports, logging controls, and local backups. No internet service is perfectly secure.

Your choices and requests

Subject to applicable law and operational/legal needs, you may request access, correction, deletion, restriction, or a copy of personal data by contacting hello@cryptoforumhub.com. Public forum deletion requests may be balanced against discussion integrity, legal claims, moderation records, and the rights of others.

International processing

The forum is global. Data may be processed or accessed outside your country where service providers operate. We use providers and contractual/technical safeguards appropriate to the service.

Children

CryptoForumHub is not intended for persons under 18.

Changes and contact

We may update this Policy and publish the new effective date.

Controller contact: hello@cryptoforumhub.com
Cryptoforumhub LLC, United Arab Emirates

Analytics

We use Google Analytics 4 to understand how people find and evaluate CryptoForumHub. It runs only if you accept it. Until then no analytics script is loaded, no analytics cookies are set, and no analytics events are sent.

Analytics is browser-side only. We do not send our own records to Google. What happens to your application after you submit it — the review, the verification decision, approval or waitlist, your invitation, your forum account, your plan, your Publishing API use and any Managed Presence work — stays in our own systems and is never sent to Google Analytics.

What we send is limited by a fixed allowlist enforced in our code, which rejects anything not on it. It contains controlled codes only. We never send your name, email address (or a hash of it), organisation or project name, the links or text you submitted, your application reference, your forum username or ID, wallet or transaction identifiers, API credentials, or reviewer notes.

Analytics consent is separate from everything else. Refusing it does not affect your application, your account, your invitation, your plan, or any part of the service.