← Back to MoonPrint

Privacy Policy

Effective Date: September 2, 2026  |  Last Updated: September 2, 2026  |  Version 2026-09-02

1. Introduction

1.1. This Privacy Policy ("Policy") describes how Moonsters DAO LLC, doing business as MoonPrint, acts as the operator and data controller ("Company," "Platform," "we," "us," or "our"), collects, uses, discloses, retains, and protects information when you access or use the MoonPrint platform, website, applications, tools, and related services (collectively, the "Service"), and the choices available to you.

1.2. This Policy is a notice, not a request for blanket consent. We rely on the legal bases described below. Where consent is required—for example, for optional analytics—we request it separately and you may withdraw it prospectively through cookie preferences.

1.3. This Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined herein have the meanings ascribed to them in the Terms of Service.

2. Information We Collect

We collect the following categories of information:

2.1. Information You Provide Directly

  • Blockchain Wallet Address: Your Solana public key, used for authentication, NFT verification, and account identification.
  • Account Identifier: Your generated MoonPrint UID and blockchain wallet address.
  • Exchange API Keys: Third-party exchange API credentials submitted by you for automated trade execution. See Section 3 below for detailed information on API key handling.
  • Trading Configurations: Strategy selections, risk management parameters, asset preferences, and other settings you configure within the Service.
  • Communications: Any messages, feedback, or correspondence you send to us.

2.2. Information Collected Automatically

  • Network and Request Information: IP address, user-agent string, request timestamps, origin information, and security/session metadata used for authentication, rate limiting, fraud prevention, and audit logging.
  • Usage and Preference Data: Features and settings you use, consent preferences, and actions recorded by the Service.
  • Optional Performance Data: Error, trace, and diagnostic information sent to Sentry only when the current analytics consent is present.
  • Cookies and Similar Technologies: See Section 8 for detailed information.

2.3. Trading and Financial Data

  • Trading Activity: Orders submitted, positions opened and closed, trade execution details, and portfolio performance metrics generated through the Service.
  • Signal Data: Trading signals generated for your account, signal history, and signal performance metrics.
  • Subscription and Payment Data: Subscription tier, billing history, and payment status. MoonPrint subscription payments are planned to be processed through MoonTap. Legacy Stripe and Coinbase Commerce scaffolding is disabled by default and is not the intended production subscription processor.
  • NFT Holdings: Information about Moonsters NFTs held in your connected wallet, verified via the Solana blockchain.
  • Referral and Payout Records: Referral attribution, commission amounts and status, destination wallet addresses, and transaction references. When settlement verification is enabled, it will also process destination-ownership evidence and relevant compliance decisions. Do not include private wallet keys in these records.

2.4. Information from Third Parties

  • Blockchain Data: Publicly available on-chain data from the Solana blockchain, including wallet balances and NFT ownership.
  • Exchange Data: Account balances, positions, and order information retrieved from third-party exchanges via your API keys.
  • Infrastructure and Error Monitoring: Operational metadata processed by hosting, database, cache, and—only with applicable consent—Sentry error-monitoring services.

3. API Key Handling — Critical Disclosures

🔒 API Key Security

3.1. Encryption. All exchange API keys submitted to the Service are encrypted at rest using AES-256-GCM encryption, an industry-standard authenticated encryption algorithm. Encryption keys are managed separately from encrypted data.

3.2. No Withdrawal Capability.The Company strongly recommends that all API keys provided to the Service be configured with "trade only" permissions and without withdrawal permissions. The Company does not request, require, or use API keys with withdrawal capabilities. The Service does not initiate, process, or facilitate any withdrawal of funds from your exchange accounts.

3.3. Trading Permissions. Trading balances remain with your exchange or wallet, but delegated execution permissions can allow the Service to place orders that affect those balances. This is not read-only access. Subscription receipts and commission payments are separate from exchange trading balances.

3.4. Limited Use. Your API keys are used solely for the purpose of (a) querying account and position information for display within the Service, and (b) submitting trading orders to the exchange on your behalf when automated trading features are enabled by you.

3.5. No Guarantee of Security. While we employ commercially reasonable encryption and security measures, no system is impenetrable. We cannot and do not guarantee that your API keys will not be subject to unauthorized access, interception, breach, or compromise. You acknowledge this inherent risk and use the Service at your own risk.

4. How We Use Your Information

4.1. We use the information we collect for the following purposes:

  • Service Provision: To provide, operate, maintain, and improve the Service, including signal generation, automated trading, and portfolio monitoring.
  • Authentication and Access Control: To verify your identity via wallet signature, confirm NFT ownership, and enforce access permissions.
  • Trade Execution: To submit orders to third-party exchanges on your behalf using your API keys when automated trading features are enabled.
  • Billing and Payments: To process subscription payments, manage billing, and communicate regarding account status.
  • Communication: To send you service-related notifications, security alerts, technical notices, and support communications.
  • Security and Fraud Prevention: To detect, investigate, and prevent unauthorized access, fraud, abuse, and security threats.
  • Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.
  • Analytics and Improvement: To analyze usage patterns, diagnose technical issues, and improve the Service's features, functionality, and performance.
  • Enforcement: To enforce our Terms of Service and protect the rights, property, and safety of the Company and its users.

4.2. We use your configured strategies and trading parameters to generate software outputs. Those outputs are not a personalized suitability assessment. This description does not determine whether an activity is regulated or remove duties imposed by applicable law.

5. Disclosure of Information

5.1. We do not sell, rent, lease, or trade your personal information to third parties for their marketing purposes.

5.2. We may disclose your information to the following categories of recipients:

Service Providers and Processors

  • MoonTap: Planned subscription payment processing once the MoonTap payment processor is available.
  • Legacy payment scaffolding: Stripe and Coinbase Commerce code paths may exist for development history, but they are disabled by default and are not the intended production subscription processor.
  • Third-Party Exchanges (e.g., Hyperliquid): Depending on the exchange protocol, requests contain account identifiers, signed instructions, or authentication data needed for account retrieval and authorized execution. We do not intentionally disclose private signing keys to the exchange.
  • Solana RPC Providers: Helius supports NFT ownership checks. Alchemy is the selected provider for planned Solana USDC settlement verification. RPC requests can disclose queried public addresses, transaction references, and connection metadata to the provider. Selection does not mean the settlement feature is active.
  • Cloud and Hosting Providers: Vercel provides application hosting and deployment infrastructure. Supabase provides the production PostgreSQL database through its official Vercel integration. These providers process operational and account data needed to run the Service under their applicable security, retention, location, and subprocessor terms.
  • Error Monitoring: Sentry may process error, trace, and diagnostic information only when optional analytics consent is active.

Legal and Regulatory Disclosures

5.3. We may disclose your information if we believe in good faith that such disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or governmental request;
  • Respond to a valid subpoena, court order, search warrant, or other legally binding request;
  • Enforce our Terms of Service or other agreements;
  • Protect the rights, property, safety, or security of the Company, its users, or the public;
  • Prevent or investigate suspected fraud, illegal activity, or security threats;
  • Comply with tax reporting, anti-money laundering, or know-your-customer obligations.

Business Transactions

5.4. In the event of a merger, acquisition, reorganization, asset sale, bankruptcy, dissolution, or similar corporate transaction, your information may be transferred to the acquiring or surviving entity. We will use reasonable efforts to ensure that such entity is bound by substantially similar privacy protections.

6. Third-Party Platforms and Services

⚠️ Important Limitation of Responsibility

6.1. The Service interacts with and transmits data to third-party platforms, including but not limited to cryptocurrency exchanges, blockchain networks, payment processors, and analytics services. The Company does not own, operate, control, or manage any third-party platform.

6.2. Each third-party platform has its own privacy policy, terms of service, security practices, and data handling procedures. The Company is not responsible for the privacy or security practices of any third-party platform, and this Policy does not apply to any third-party platform.

6.3. Third-party platforms have their own responsibilities. Using a service provider does not remove the Company's applicable duties concerning selection, contracts, security, disclosures, international transfers, or assistance with your privacy rights.

6.4. You are encouraged to review the privacy policies and security practices of all third-party platforms with which you interact through the Service.

7. Data Security

7.1. We implement commercially reasonable administrative, technical, and physical security measures designed to protect the confidentiality, integrity, and availability of your information, including:

  • Encryption at Rest: Sensitive data, including API keys, is encrypted using AES-256-GCM. Database contents are encrypted at rest.
  • Encryption in Transit: All data transmitted between your device and our servers is protected by TLS 1.2 or higher.
  • Authentication: JWT-based session authentication with configurable expiration.
  • Access Controls: Role-based access control (RBAC), principle of least privilege, and segregated access to encryption keys.
  • Rate Limiting: API rate limiting and request throttling to prevent abuse.
  • Monitoring: Operational error reporting and configured security-event logs. These are not a guarantee of continuous human review or detection of every threat.
  • Audit Logging: Records of supported authentication, administrative, and security events; coverage varies by feature.

7.2. No electronic transmission or storage system is completely secure. We cannot guarantee that every incident will be prevented. This limitation does not excuse our security obligations or restrict remedies that applicable law makes non-waivable.

8. Cookies and Tracking Technologies

8.1. The Service uses cookies and similar tracking technologies for the following purposes:

  • Strictly Necessary Cookies: Authentication tokens (JWT), session management, and CSRF protection. These are essential for the Service to function and cannot be disabled.
  • Functional Cookies: User preferences, interface settings, and personalization.
  • Analytics Cookies: Usage analytics, performance monitoring, and service improvement. Data may be aggregated and de-identified.
  • Security Cookies: Fraud detection, bot prevention, and abuse mitigation.

8.2. Strictly necessary cookies are always active because they are required for authentication, security, and core Service functionality. Functional and analytics cookies are not enabled unless you actively opt in through the cookie preference banner. You may configure your browser to reject or delete cookies, but doing so may impair or prevent the functionality of the Service.

9. Data Retention

9.1. We retain your information for the following periods:

  • Active Account and Trading Data: Retained while the account is active. A completed self-service erasure deletes the identified live account, strategy, signal, trade, position, credential, subscription, payout, and related records, subject to a documented legal hold or mandatory retention obligation.
  • Audit and Security Logs: The application retention worker targets ninety (90) days for supported database security-log tables. Hosting and monitoring records follow their separately configured provider lifecycles. Records subject to mandatory preservation must be handled separately before enabling a feature that generates them.
  • Backups: Deleted data may remain temporarily in encrypted provider backups until overwritten under the applicable backup lifecycle and is not restored except for disaster recovery.
  • Payment and Tax Records: Retained only when payment processing is active and only for the period required by applicable accounting, tax, fraud-prevention, or dispute obligations.
  • Support Communications: Retained only as reasonably necessary to resolve the request, maintain security and dispute records, and meet applicable legal obligations.

9.2. Following the applicable retention period, data is securely deleted or irreversibly anonymized. Certain data may be retained beyond stated periods if required by applicable law, regulation, or legal proceeding.

9.3. Public blockchain records, including completed USDC transfers, are maintained by independent network participants. Deleting your MoonPrint account cannot erase those records or copies held independently by explorers and other third parties. Wallet addresses can remain linkable to transaction history.

10. Your Rights and Choices

10.1. General Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. Where applicable and subject to legal limitations, these may include:

  • Right of Access: Request a copy of the personal information we hold about you.
  • Right of Rectification: Request correction of inaccurate or incomplete personal information.
  • Right of Erasure: Request deletion of your personal information, subject to applicable legal retention requirements.
  • Right to Data Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to Restrict Processing: Request limitation of the processing of your personal information in certain circumstances.
  • Right to Object: Object to certain types of processing, including processing for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

10.2. European Economic Area (EEA) and United Kingdom (UK) — GDPR

If you are located in the EEA or UK, the General Data Protection Regulation (GDPR) or UK GDPR may apply to our processing of your personal data. Our lawful bases for processing include: performance of a contract (Terms of Service), legitimate interests (security, fraud prevention, service improvement), compliance with legal obligations, and your consent where applicable. You have the additional right to lodge a complaint with your local supervisory authority.

10.3. United States Residents — CCPA/CPRA Contingency

The Service is not intended for, and access is expressly prohibited for, residents of the United States, including the State of California (see Terms of Service, Section 10 — Restricted Jurisdictions). In the event that a California resident accesses the Service in contravention of these restrictions, the Company acknowledges that the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may provide such individuals with certain rights under applicable law, including:

  • The right to know what personal information we collect, use, disclose, and sell;
  • The right to request deletion of your personal information;
  • The right to correct inaccurate personal information;
  • The right to opt-out of the "sale" or "sharing" of personal information — we do not sell or share personal information as defined by CCPA/CPRA;
  • The right to non-discrimination for exercising your privacy rights.

Important: The inclusion of this Section does not constitute an invitation, authorization, or permission for United States residents to access or use the Service. All restrictions set forth in the Terms of Service remain in full force and effect.

10.4. Exercise of Rights

To exercise any of the above rights, submit a verifiable request to moonstersweb3@gmail.com. We will respond within the period required by applicable law and ordinarily within thirty (30) days. We may request information reasonably necessary to verify identity and protect the account.

11. International Data Transfers

11.1. Your information may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have data protection laws that differ from, and may be less protective than, the laws of your jurisdiction.

11.2. Where required by applicable law, we implement appropriate safeguards for international data transfers, which may include Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms.

11.3. We do not rely on general acceptance of this Policy as a transfer mechanism where applicable law requires another safeguard. You may contact us for information about the safeguard relevant to your data.

12. Children's Privacy

12.1. The Service is not intended for individuals under eighteen (18) years of age, or the age of legal majority in their jurisdiction, whichever is greater. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a minor without appropriate parental consent, we will take commercially reasonable steps to delete such information promptly.

13. Data Breach Notification

13.1. In the event of a data breach that is reasonably likely to result in a risk to your rights and freedoms, we will:

  • Notify affected users without undue delay when required because a breach is likely to result in a high risk or meets another applicable notification threshold;
  • Describe the nature and scope of the breach and the categories of data affected;
  • Provide recommended steps to mitigate potential adverse effects;
  • Report to relevant regulatory authorities as required by applicable law.

13.2. Notwithstanding the foregoing, the Company's obligation to notify shall not be construed as an acknowledgment of fault, liability, or responsibility for the breach, and shall not create any additional legal obligation beyond what is required by applicable law.

14. "Do Not Track" Signals

14.1. Some web browsers transmit "Do Not Track" ("DNT") signals. The Service does not currently respond to DNT signals because there is no industry-standard approach or universally accepted technology for responding to such signals at this time.

15. Limitation of Liability for Data and Privacy

15.1. Any limitation of liability concerning privacy or security is governed by the Terms and applies only to the extent permitted by law. Nothing in this Policy limits regulatory authority, data-subject rights, or liability that applicable privacy, consumer, or cybersecurity law makes non-waivable.

15.2. You may stop using the Service, request deletion, exercise applicable privacy rights, complain to a competent supervisory authority, or pursue any other remedy available under applicable law.

16. Changes to This Privacy Policy

16.1. We reserve the right to modify this Policy at any time and in our sole discretion. Material changes will be communicated through one or more of the following means:

  • Email notification to the address associated with your account;
  • A prominent notice on the Service upon your next login;
  • Posting of the revised Policy with an updated effective date.

16.2. We will not treat silence or continued use as consent where law requires affirmative consent. Material changes affecting consent or contractual processing will be presented for renewed action where required.

17. Contact Information

For questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact:

Controller and Operator: Moonsters DAO LLC, doing business as MoonPrint

Business and service address: 30 N Gould St, Ste R, Sheridan, WY 82801, United States

Privacy, Security, and Rights Requests: moonstersweb3@gmail.com

We will respond to verified requests within thirty (30) days, or within the time period required by applicable law.

ACKNOWLEDGMENT

BY ACCESSING OR USING MOONPRINT, YOU ACKNOWLEDGE RECEIPT OF THIS PRIVACY NOTICE. OPTIONAL PROCESSING THAT REQUIRES CONSENT IS CONTROLLED SEPARATELY. THE COMPANY DOES NOT CONTROL THIRD-PARTY EXCHANGES OR BLOCKCHAINS AND CANNOT GUARANTEE ABSOLUTE SECURITY, BUT THIS NOTICE DOES NOT LIMIT RIGHTS OR REMEDIES THAT APPLICABLE LAW MAKES NON-WAIVABLE.

© 2026 MoonPrint. All rights reserved.

Terms of ServiceHome