Privacy Policy.

Last updated: 5 October 2026

1. Who we are

This policy explains how Capveon (“Capveon”, “we”, “us”) handles personal data on capveon.org. Capveon is the controller of the personal data described here.

General and business enquiries: business@capveon.org. Privacy requests and account questions: support@capveon.org.

2. What we collect

DataWhenWhy
Name, email addressYou create an account or send a requestRun your account, answer your request, send security codes
PasswordYou create an accountSign-in. We never see or store your password in readable form; our authentication provider stores a secure hash
Wallet address (optional)You add it to your profileDeliver NFTs and certificates to you
Messages, requests, ownership recordsYou use your account or buy a workSupport, delivery, proof of ownership
Details of works you offer for sale, and evidence of ownershipYou ask us to place a work from your collectionAssess and verify the work, prepare the sale, keep it confidential
Identity and payment verification detailsBefore or during an acquisition, if requiredLegal checks (anti-money-laundering, sanctions, tax)
Technical data (IP address, browser, timestamps)You visit or sign inSecurity, abuse prevention, reliability

We do not collect special-category data on purpose. Please do not send it to us.

3. Why we use it, and our legal bases

4. Who we share it with

We do not sell personal data. We use service providers (“processors”) who handle data only on our instructions:

ProviderPurpose
SupabaseDatabase and authentication
CloudflareWebsite hosting, DNS, security, email routing
ResendSending account and security emails
Banks, payment and identity-verification providersSettlement and legal checks, where a sale requires them

We may also disclose data when the law requires it, or to protect our rights and the safety of others.

5. Blockchain records

NFTs and their transfers are recorded on a public blockchain. Wallet addresses and token records on a blockchain are public and permanent. We cannot edit or delete them. Do not link a wallet to your account if you do not want the connection between that wallet and your identity to exist in our records.

6. International transfers

Our providers may process data outside your country, including outside the European Economic Area and the United Kingdom. Where required, we rely on safeguards such as Standard Contractual Clauses.

7. How long we keep it

8. Your rights

Depending on where you live, you can ask to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent. Write to support@capveon.org. You can also delete your account yourself in Account → Security. We aim to respond within 30 days. You may complain to your local data-protection authority.

9. Cookies and local storage

We use only what is strictly necessary: your sign-in session is kept in your browser’s local storage so that you stay signed in. We do not use advertising or tracking cookies and we do not run analytics at present. If that changes, we will update this policy and ask for consent where required.

10. Security

Data is encrypted in transit. Passwords are stored only as secure hashes. Access to each account’s records is restricted to that account through database access rules, and studio access is limited to those who need it. No system is perfectly secure; if a breach affects you, we will notify you and the authorities as the law requires.

11. Children

Capveon is for adults only. We do not knowingly collect data from anyone under 18.

12. Changes

We may update this policy. The date above shows the latest version. For material changes we will notify account holders by email.

13. Contact

Capveon · business@capveon.org · support@capveon.org