Privacy Policy
Bounce Board (bouncebox.xyz) Effective date: October 10, 2026
This policy covers the testnet preview. We will review it again before real payments open.
This policy explains what data Bounce Board collects, why, who receives it and how long we keep it. Bounce Board is run by CT Wendt Holdings LLC, an Indiana limited liability company ("we", "us", "our"). Contact: see "Contact" at the end.
The short version
- You do not need an account. We do not ask for your email, phone number or real name.
- Our code sets no cookies and uses no analytics or tracking tools.
- If you buy a takeover, your card is public. Your payment is also public on the Base blockchain, and anyone may be able to link your card to the wallet that paid for it.
- We do not store raw IP addresses. We store hashed versions to limit abuse and to count reports. The hashes are not salted, so they are pseudonymous, not anonymous.
- Right now we keep cards, logos, payment records and reports with no set deletion date.
What we collect and why
1. Your card (only if you buy a takeover)
- What: display name, description, link, X handle, token ticker, chain and contract address, and logo image (with its file type).
- Why: to show your card on the board.
- Public: yes. See "What is public" below.
- Kept: indefinitely, including after your turn ends. If we remove a card, we delete its logo but keep the card text with a removal record.
About logos. The site's form crops your logo and converts it to a new 256 x 256 image (WebP, or PNG if your browser cannot make WebP). The new image does not carry over the original file's metadata. If an image is sent to our API some other way, we store the file exactly as received, including any metadata it contains (such as camera or location data).
2. Payment records
- What: the paying wallet address, the transaction hash, the amount and its US dollar value, the network, chain and asset (USDC on Base), our receiving address, the time we received the payment, the facilitator used, and the takeover it paid for.
- Why: to queue your takeover, prevent duplicates, keep our books and tax records, and answer support questions.
- Public: we do not show these records on the board or in our public data feed. But the same payment is public on the Base blockchain. See "What is public" below.
- Kept: indefinitely.
3. Takeover timing
- What: when you paid, when your turn started and ended, how many times the box hit a corner, and the takeover's status.
- Why: to run the queue and the box.
- Public: yes, in our public data feed.
- Kept: indefinitely.
4. Rate limits
We limit how often anyone can request quotes, submit payments and send reports. To do this, we store short-lived counters keyed by:
- A hash of your IP address. We read your IP address from the connection. For an IPv6 address we use only its network part (the first 64 bits). We compute a SHA-256 hash and keep the first 32 hex characters. We never store the raw IP address. The hash is not salted, so someone who has it could work out an IPv4 address by trying every possible address. We treat it as personal data. We use it to limit quote and purchase requests (20 per 10-minute window, and a purchase normally uses 2), AI moderation runs (10 per day) and reports (10 per hour).
- Your wallet address, in plain text (lowercase). This is the paying wallet as verified by the payment facilitator. We use it to limit paid takeovers (10 per hour per wallet) and AI moderation runs (5 per day per wallet).
- Your listing name, in plain text (lowercase). This is your ticker (for example "$abc") or, if you did not list a token, your display name. We use it when a signed payment is submitted (3 per hour per listing, across all wallets).
Kept: a counter becomes eligible for deletion once its time window started more than 24 hours ago. Cleanup is not scheduled. It runs at random, on about 1 in 100 counter updates. When traffic is low, counters can stay well past 24 hours.
5. Reports
- What: the takeover reported, the category, your note (up to 200 characters), the time, and a reporter fingerprint. The fingerprint is a SHA-256 hash of your IP address (for IPv6, its network part) combined with the takeover ID. It is not salted, so for an IPv4 address it could be reversed by trying every possible address.
- Why: to review reports, and to count only one report per IP address per card. Our admin tools do not display the fingerprint.
- Public: no.
- Kept: indefinitely. Please do not put personal information in report notes.
6. Moderation and check records
- Moderation results. For each card we check (this happens after a wallet signs a payment), whether or not the purchase completes, we store a fingerprint (SHA-256 hash) of the card and logo, the result, the reason and the time. We reuse a result for 24 hours. Old records are not deleted. A record is only replaced if the same card and logo are checked again after 24 hours.
- Token check results. For each token we check, whether or not the purchase completes, we store the chain, contract address and ticker, the result and the time. We reuse a result for 10 minutes. Old records are not deleted.
- Removal records. If we remove a card, we store that it was removed and our reason (up to 200 characters).
- Public: no.
- Kept: indefinitely.
Apart from these records and the rate-limit counters above, we do not store card content from purchases that do not complete.
7. Error logs
Our code writes a log line only when something goes wrong, plus a daily count from our phishing-list update. Our code does not log each request. Error logs can include error messages from the payment facilitator, which can contain a wallet address or a transaction hash. When a payment settles but the card is not queued, or we cannot confirm whether a payment settled, the log includes the paying wallet address and any transaction hash, so we can reconcile it. These log lines are kept in Cloudflare Workers Logs for a few days. Cloudflare's per-request logs are turned off, so request headers (including payment signatures) are not stored in them.
What we do not collect
- No accounts, logins, passwords, emails, phone numbers, real names or ID documents.
- No cookies set by our code.
- No analytics, ad trackers, tracking pixels or error-tracking tools.
- No raw IP addresses stored in our database. (Cloudflare, our host, does process them. See "Third parties".)
- No location, network provider, browser type, language or referring page. Our code does not read or store these.
- No wallet balances. The site makes no blockchain calls of its own, does not read your balances and does not ask for token approvals.
- The paying wallet address is not shown on the board, is not in our public data feed, and is not sent to our moderation or token-check providers.
- The site's live connection sends a timing ping. We answer it with our server's time and do not store it.
What is public
- Your card. Every field on your card is public: display name, description, link, X handle, token ticker, chain and contract address, and logo. It is shown on the board and in our public data feed, with its takeover ID. It can appear in the list of recent holders, and your ticker or display name can appear on the leaderboards.
- Timing. When your turn started and ended, and how many corners the box hit. While your card is queued or showing, the feed also shows when you paid.
- Your logo file. Each logo is served at a public address based on its takeover ID. Logos are sent with caching headers that let browsers and shared caches keep a copy for up to 5 minutes.
- Your payment, on the blockchain. USDC payments on Base are public and permanent. Anyone can see the paying wallet, our receiving address, the amount, the time and the transaction hash. This is also true on the Base Sepolia test network. Our receiving address is shown in every payment quote, and the time you paid is in our public data feed while your card is queued or showing. So anyone may be able to match your card to the wallet that paid for it. If you do not want your card linked to a wallet you use for other things, pay from a different wallet.
- Restored cards. If we remove the card that is showing and nobody is queued, the most recent previous card that we did not remove can be shown again for free. While it shows, it is public like any other card.
Removed cards. When we remove a card that is showing or queued, it comes off the board and out of our public data feed, and it is not restored later. If it was a restored card, the original is removed too. Its logo file is deleted. Copies cached by browsers or our host can last up to 5 minutes. Our current tools cannot remove a card whose turn has already ended. See "Removing your listing and other requests". Nobody can remove blockchain records.
Third parties
We do not sell your personal information or share it for advertising. These services receive data so the site can work:
- Cloudflare (hosting, storage, live updates and scheduled jobs). Every request to the site passes through Cloudflare. This includes your IP address, request headers, card content, logo and payment signature. All of the data in this policy is stored with Cloudflare. Cloudflare's privacy policy applies to the data it processes.
- Cloudflare Workers AI (content moderation). Your display name, description, link, X handle, ticker and chain (not the contract address), and your logo image. This is sent for every check that is not already cached, after a wallet signs a payment, whether or not the purchase completes. No IP address or wallet address is sent.
- DexScreener (token checks). Our server sends the chain, contract address and ticker. No IP address, wallet address or other card details. If you click a card's "chart" link, your browser goes to dexscreener.com directly.
- x402 payment facilitator (currently x402.org; verifies and settles payments). Our server sends your signed payment authorization: your wallet address, our receiving address, the amount, the time window, a random nonce and your signature. It also sends the payment terms, a short description of the purchase and the address of our purchase endpoint. No card content and no IP address. We may switch facilitators (for example, to Coinbase's) when we move to mainnet. We will update this policy if we do.
- Base blockchain (settlement). The USDC transfer: your wallet address, our receiving address, the amount, the time and the transaction hash. Public and permanent.
- Your wallet app (for example, Coinbase Wallet or MetaMask). The site's address and requests to connect your account, switch to the right network and sign the payment. No card content. This happens only after you submit the purchase form and we return a price quote. Your wallet's own privacy policy applies.
- Google Fonts (web fonts). When you load a page, your browser requests fonts from Google. Google receives your IP address, browser details and our site's address. Google's privacy policy applies.
- GitHub (phishing list). Once a day, our server downloads MetaMask's public phishing-domain list from GitHub. No user data is sent. Link checks run against our own stored copy.
- GitHub Pages (demo preview). If you visit our demo preview on GitHub Pages, GitHub receives your IP address and request details. The preview shows demo data only and cannot take payments.
- Links you click. If you click a card's link, an X handle, a "chart" link, a block explorer link, or our links to x402.org or GitHub, that site receives your visit. Our links tell your browser not to send our page's address.
We may also disclose data if the law requires it, to protect people or the service from fraud or harm, or as part of a sale or reorganization of our business.
Browser storage
- The main site does not use cookies, local storage, session storage or IndexedDB.
- While a page is open, it keeps some data in memory only, such as the current board and logo images. It is gone when you close the tab.
- Your browser may cache logo images for up to 5 minutes.
- Your wallet app may remember that you connected to the site. You can manage that in your wallet.
- Our admin page, which only we use, keeps its access token in session storage. It is cleared when the tab closes.
- Our code sets no cookies. If Cloudflare security features are turned on for our domain, Cloudflare may set its own security cookies.
How long we keep data
| Data | How long |
|---|---|
| Cards | Indefinitely, including after removal |
| Logos | Indefinitely, deleted if we remove the card |
| Payment records | Indefinitely |
| Takeover timing and removal records | Indefinitely |
| Reports and reporter fingerprints | Indefinitely |
| Moderation and token-check results | Indefinitely (only replaced when the same item is checked again after its reuse period) |
| Rate-limit counters (IP hash, wallet, listing name) | Eligible for deletion after 24 hours, removed by random cleanup, so they may last longer |
| Error logs | A few days (Cloudflare Workers Logs) |
| Logos cached in browsers | Up to 5 minutes |
| Blockchain records | Permanent. Nobody can delete them |
Removing your listing and other requests
To ask us to remove your card, contact us (see "Contact") with:
- the transaction hash of your payment, or the card's display name and about when it showed;
- what you want removed.
We may ask for more information to confirm the card is yours, such as proof that you control the wallet that paid.
What we can do:
- If your card is showing or waiting in the queue, we can take it off the board and out of our public data feed. If it is showing, your turn ends. There is no refund.
- Our current tools cannot remove a card whose turn has already ended. It stays in the list of recent holders until 10 newer cards replace it, and your ticker or display name can stay on the leaderboards. Our tools also cannot delete a stored card or report, or the logo of a card whose turn has ended. Each of these takes a one-off change to our database or code. If you ask, we will review the request and make that change where we reasonably can. We may keep payment records where we need them for tax, accounting or legal reasons.
- We cannot change or delete anything on the blockchain.
- We cannot control copies others have made, such as screenshots or cached images.
You can also ask what data we hold about you, or ask us to correct or delete it. Contact us (see "Contact"). We do not store names or emails, so we can usually only find data linked to a wallet address, a transaction hash or a card. Some lookups need a manual database query, which can take longer. We cannot match a hashed IP address to you unless you give us your IP address. We will respond within a reasonable time, and as required by the law that applies to you.
Anyone can report a card that is showing or queued with the report button on the site.
Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has submitted a card, contact us (see "Contact"). We will remove it as described in "Removing your listing and other requests".
Where data is processed
We are based in the United States. Cloudflare runs a global network, so your data may be processed and stored in data centers outside your country. Blockchain data is copied to computers around the world.
Security
The site uses HTTPS. Admin functions require a secret token. We hash IP addresses before we store them. No system is fully secure, and we cannot guarantee the security of your data.
Changes to this policy
We may update this policy. We will post the new version on the site and change the effective date.
Contact
CT Wendt Holdings LLC
For now, open an issue at github.com/cwendt6/bounce-board/issues (do not post private details there; a private email address is coming before real payments open).