
Privacy
We are a family lure project, not an advertising business. We collect the least we can get away with, we do not sell any of it, and there are no third-party trackers on this site. Here is the whole of it.
1. What we collect
Your wallet address, and a signature. If you claim a slip, we store the wallet address and the message you signed to prove the wallet is yours. A wallet address is public by nature; the signature proves control, and contains no private key.
An email address, if you give us one. Either because you signed in with email instead of a wallet, or because you joined the waitlist. Email sign-in and the wallet it creates for you are handled by Privy (see §3).
Delivery details, only if you order something physical. Name, email, street address, city, state, postal code, country, and any note you add to the order. We need these to post you a lure; there is no other reason we hold them.
A payment record, for shop orders. The chain, transaction hash, amount and token. The shop takes USDC and ETH only. We never see or store a card number, because we do not accept cards.
Catch submissions, if you send one. The handle you submit under, the photographs, and whatever you tell us about the fish — species, rough location, date, notes — plus a record that you consented to us using the photograph.
Ordinary request logs. Your IP address, browser user-agent, the page requested, the referring page, and the coarse country/region/city our host derives from the IP. We keep these to rate-limit abuse and to see whether the dock is being hammered. They are not joined to your identity for any other purpose.
Counts of which home page works better. To test which version of the home page works better, we count, on our own server, how many times each version is shown and which of a few buttons get tapped. For these counts we store only daily totals — no IP address or device details are attached to them, and nothing in them identifies you (the ordinary request logs described above are separate). A small cookie (qb_ab) remembers which version you saw so it doesn’t switch on you; it holds only “A” or “B” and expires after 90 days. We don’t use third-party analytics, ad pixels or tracking cookies.
Angler profiles. If you set up an angler profile — a display name, tribe name, tribe story, and names for the feesh you hold — we store those details along with your wallet address, the date you set them, the message you signed to save them, and a hash of your IP address for abuse prevention. These profiles are public by design: they appear on the On the Line leaderboard, on your angler profile page (/line/<your-wallet>), on the tribal gallery (/line/tribes), and in promotional materials about the community.
2. What we do not collect
No third-party analytics package. No advertising or social pixels. No third-party tracking cookies. No cross-site profiling. No card numbers. No biometric identifiers — we do not run face recognition or any other biometric scan on submitted photographs, and we do not derive biometric data from them (Illinois BIPA, 740 ILCS 14). And we do not sell, rent or trade personal information to anyone, for any price.
3. Who else sees it
Only the services it takes to run this: Vercel, which hosts the site and therefore handles every request; Turso, which stores the database; Privy, which runs email sign-in and embedded wallets if you use that lane; and ShipStation plus the postal carrier, which receive a delivery address only when there is a parcel to send. Each gets the minimum its job requires.
And the blockchain gets the permanent part. Anything minted on 22 September is public, worldwide, and permanent. We cannot edit it, hide it or delete it, and neither can anyone else. Please decide what you are comfortable with before you mint, because that decision is not reversible by us.
4. Cookies
Four, all HttpOnly, Secure and SameSite=Lax. Three are strictly functional: qb_gate remembers that you passed the gate, qb_beta that you are admitted crew, and qb_pending that a sign-in is in progress. The fourth, qb_ab, remembers which version of the home page you were shown — its value is only “A” or “B” — so it doesn’t switch on you between visits; it expires after 90 days. None of them track you anywhere else, and there is nothing to opt into because there is no advertising layer to opt out of.
5. How we protect it
Traffic is encrypted in transit. Session cookies cannot be read by JavaScript. The relayer's private key lives only in server-side environment variables and is never logged or sent to a browser. Access to the database is limited to the people running the project. We rate-limit and we log abuse.
We are a small operation and we will not pretend to enterprise security theatre. What we will do is hold as little as possible, so that there is not much to lose.
6. If there is ever a breach
Illinois law (the Personal Information Protection Act, 815 ILCS 530) requires notice to affected Illinois residents in the most expedient time possible and without unreasonable delay. We will do that, and we will not restrict it to Illinois — if your data is caught up in a breach we will tell you, say plainly what was taken, and say what we are doing about it.
7. How long we keep it
Order and delivery details: as long as we need them for the order and for our records. Claim records and signatures: for the life of the collection, because they are the proof of who claimed what. Waitlist emails: until you ask us to remove you.
Request logs are the honest exception. We keep them for abuse prevention, and we do not currently run an automatic expiry on them — so assume they persist until we prune them. We would rather write that down than claim a retention schedule we do not actually run. When we put one in place, this line changes to say what it is.
8. Your say over it
Ask us and we will tell you what we hold on you, correct it, or delete it. There is no form and no ticket queue — ask and a human does it. Two honest limits: we cannot delete anything that has been written to the blockchain, and if you delete a claim record before minting you give up the claim.
Angler profiles: to clear your profile, save all fields blank. To request deletion, contact us at partnerships@quaig.ai. We keep profile data for as long as your profile is visible on the site; if you delete your profile, the names you gave your feesh remain visible to future holders until they choose to change them.
9. Children
This site is not directed to children under 13 and we do not knowingly collect their information. If you believe a child has sent us something, tell us and we will remove it.
10. Changes, and how to reach us
If this policy changes, the revision and date above change with it. For privacy questions, deletion requests and anything else in this document, write to partnerships@quaig.ai, or reach us at @web3feesh on X. What this page says we do is what the code does; if you ever find the two disagreeing, that is a bug and we want to hear about it.
