Privacy Policy.
Last updated: 5 October 2026
1. Who we are
This policy explains how Capveon (“Capveon”, “we”, “us”) handles personal data on capveon.org. Capveon is the controller of the personal data described here.
General and business enquiries: business@capveon.org. Privacy requests and account questions: support@capveon.org.
2. What we collect
| Data | When | Why |
|---|---|---|
| Name, email address | You create an account or send a request | Run your account, answer your request, send security codes |
| Password | You create an account | Sign-in. We never see or store your password in readable form; our authentication provider stores a secure hash |
| Wallet address (optional) | You add it to your profile | Deliver NFTs and certificates to you |
| Messages, requests, ownership records | You use your account or buy a work | Support, delivery, proof of ownership |
| Details of works you offer for sale, and evidence of ownership | You ask us to place a work from your collection | Assess and verify the work, prepare the sale, keep it confidential |
| Identity and payment verification details | Before or during an acquisition, if required | Legal checks (anti-money-laundering, sanctions, tax) |
| Technical data (IP address, browser, timestamps) | You visit or sign in | Security, abuse prevention, reliability |
We do not collect special-category data on purpose. Please do not send it to us.
3. Why we use it, and our legal bases
- To provide what you ask for (account, requests, delivery): performance of a contract or steps before a contract.
- To keep the service secure and prevent fraud: our legitimate interests.
- To keep private sales confidential: we share the identity of a buyer or seller with the other party only when both agree, or when the law requires it.
- To meet legal duties (record keeping, anti-money-laundering, tax): legal obligation.
- To send you optional notices about your requests and deliveries: your consent, which you can withdraw in your profile at any time. We do not send marketing newsletters at present.
4. Who we share it with
We do not sell personal data. We use service providers (“processors”) who handle data only on our instructions:
| Provider | Purpose |
|---|---|
| Supabase | Database and authentication |
| Cloudflare | Website hosting, DNS, security, email routing |
| Resend | Sending account and security emails |
| Banks, payment and identity-verification providers | Settlement and legal checks, where a sale requires them |
We may also disclose data when the law requires it, or to protect our rights and the safety of others.
5. Blockchain records
NFTs and their transfers are recorded on a public blockchain. Wallet addresses and token records on a blockchain are public and permanent. We cannot edit or delete them. Do not link a wallet to your account if you do not want the connection between that wallet and your identity to exist in our records.
6. International transfers
Our providers may process data outside your country, including outside the European Economic Area and the United Kingdom. Where required, we rely on safeguards such as Standard Contractual Clauses.
7. How long we keep it
- Account data: until you delete your account.
- Messages and requests: while your account exists, then deleted with it unless we must keep them.
- Enquiries from the website form: up to 24 months.
- Sale, ownership, tax and compliance records: as long as the law requires.
8. Your rights
Depending on where you live, you can ask to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent. Write to support@capveon.org. You can also delete your account yourself in Account → Security. We aim to respond within 30 days. You may complain to your local data-protection authority.
9. Cookies and local storage
We use only what is strictly necessary: your sign-in session is kept in your browser’s local storage so that you stay signed in. We do not use advertising or tracking cookies and we do not run analytics at present. If that changes, we will update this policy and ask for consent where required.
10. Security
Data is encrypted in transit. Passwords are stored only as secure hashes. Access to each account’s records is restricted to that account through database access rules, and studio access is limited to those who need it. No system is perfectly secure; if a breach affects you, we will notify you and the authorities as the law requires.
11. Children
Capveon is for adults only. We do not knowingly collect data from anyone under 18.
12. Changes
We may update this policy. The date above shows the latest version. For material changes we will notify account holders by email.
13. Contact
Capveon · business@capveon.org · support@capveon.org