01Who we are
This policy explains how ShareStocks handles personal information when you browse Stock Tokens, sign in, use a wallet, send or claim a gift, or manage your portfolio. ShareStocks is the name of this project, based in the United Arab Emirates; it is not presented here as an incorporated or licensed financial institution.
ShareStocks is responsible for information it processes to operate its interface and gifting service. Wallet, login, blockchain, and market-data providers also process information under their own policies. This policy should be read alongside our Terms of Service.
02Information we handle
- Account and sign-in information. Privy account identifiers, verified email addresses or linked Google/X identities, public profile details made available through sign-in, and linked wallet addresses. We use signed identity information to verify accounts; we do not receive your Google or X password.
- Gift instructions. The recipient email or X handle you enter, the selected token, gift identifier, sender account and wallet, token amount, expiry, deposit transaction, and assigned claim wallet.
- Wallet activity. Public balances, token contracts, transaction hashes, recipient addresses, and the information needed to quote a swap, check a deposit, or authorize a claim.
- Technical information. Requests sent by your browser include network and device information, such as an IP address and browser headers. Hosting, RPC, authentication, and security providers may process this information when delivering their services.
If you send someone a gift, we receive their recipient identifier from you before they necessarily have an account. Enter only information you are entitled to use for that purpose, and give the recipient the claim link and access to this notice.
03Recipient matching
We process an email address to match a gift to the account that later verifies that address. Our gift database stores a keyed hash for matching and a masked display label, rather than the full recipient email. The full address is still processed when you submit it and may be held separately by your sign-in provider.
For X gifts, we send the entered handle to X to resolve its stable account identifier. The gift database stores a keyed hash of that identifier and the display handle. This helps prevent a later username change from redirecting a gift to a different X account.
These hashes are pseudonymous, not anonymous: we can match them to a verified account. A sender can see the masked email or X handle they selected. Only a matching verified recipient receives a claim authorization.
04Why we use information
We use information to sign you in, associate your embedded wallet with your account, prepare gifts and swap quotes, verify deposits and recipient identities, prevent duplicate claims and abuse, show holdings and gift status, and investigate service problems.
Where applicable law requires a legal basis, processing necessary to provide a feature you request is based on that request and the relevant contractual or other permitted basis. We obtain consent where it is required, and process information to meet applicable legal obligations when necessary. Recipient matching and security processing must also have a valid basis under the laws that apply; sending a gift is not consent on someone else’s behalf.
Providing verified account and wallet information is necessary for account-specific features. You can browse the public market without signing in, but cannot claim a gift without the required identity verification. We do not use recipient details to send promotional messages.
05Providers and sharing
Information is shared as needed to deliver the feature you choose:
- Privy and login providers handle authentication and embedded-wallet services. Google or X may provide the identity information you authorize. See Privy’s Privacy Policy, Google’s Privacy Policy, and X’s Privacy Policy.
- KyberSwap receives swap parameters, including token addresses, amount, and the wallet that will send and receive the swap. See KyberSwap’s Privacy Policy.
- GeckoTerminal supplies market and chart data through requests for token and pool addresses. We do not need to send gift-recipient information with those market-data requests. See GeckoTerminal’s Privacy Policy.
- Card funding providers and Relay process optional wallet funding. Privy’s on-ramp providers handle card purchases and any identity checks they require. The purchase delivers USDC on Base to a Relay deposit address, which converts it to ETH on Robinhood Chain for your wallet. We send your public wallet address and route details to Relay and store the deposit address for later reference. If conversion fails, the configured refund address is your wallet on Base. ShareStocks does not receive your card number.
- Google Translate provides optional automatic page translation when you choose a language other than English. The widget loads from Google and sends page text for translation; Google also receives the network information needed to serve it. Account, gift-claim, and transaction panels are excluded from translation. Google’s handling of this information is described in its Privacy Policy. Choose English to stop loading the translation widget.
- Infrastructure providers process the requests and records needed for hosting, database storage, and blockchain RPC access. Wallet addresses are sent to RPC providers to read balances and transaction status.
We may also disclose information when required by law or necessary to establish or defend legal rights. The current service does not include selling personal information or sharing recipient lists for targeted advertising.
06Public blockchain records
Robinhood Chain is a public blockchain. Deposits, transfers, claims, refunds, wallet addresses, token amounts, expiry times, and gift commitments can be visible to anyone and retained by explorers and other third parties.
ShareStocks does not put a recipient’s raw email or X handle into the gift contract. That does not make a transaction anonymous: public records can still be linked to a person through other information. We cannot edit or erase confirmed blockchain records, including when an account or an off-chain record is deleted.
07Cookies and local storage
ShareStocks uses browser storage for your watchlist, a saved theme preference when available, your language choice, and transaction references that help recover pending gift deposits. Privy and connected wallet services may use their own cookies or browser storage for authentication, wallet sessions, and security.
Your language choice is saved in local storage and a first-party cookie. Google Translate may also set a cookie to remember the translation language.
We have not added a separate advertising or marketing-analytics SDK to the current app. Third-party providers’ practices are described in their policies. You can clear site data or manage cookies in your browser; this can sign you out, remove preferences, and remove local recovery references. It does not reverse a transaction or delete an on-chain gift.
08Retention and security
Gift records are needed while deposits, claims, and refunds remain relevant. Settled records may also be needed to investigate disputes, protect the service, or satisfy applicable legal obligations. The present implementation does not automatically delete gift records when a gift expires or settles; expiry is not a data-deletion deadline. A detailed off-chain retention schedule must be established before public launch.
We use signed identity verification, account-level access checks, recipient hashes, and on-chain deposit checks to restrict access and authorize claims. These measures reduce risk but cannot guarantee security. Keep your sign-in accounts, recovery methods, and device secure. ShareStocks’ gift records do not store your wallet private key or recovery phrase.
09International processing
ShareStocks is based in the United Arab Emirates, but login, hosting, database, market-data, and blockchain providers may process information in other countries. Public blockchain information is globally accessible.
Any transfer of personal information by ShareStocks must meet applicable requirements. Where a transfer requires a safeguard, consent, or another permitted basis, that must be in place before the transfer. This draft does not represent that a particular provider location or contractual transfer safeguard has already been verified.
10Your choices and rights
Depending on the laws that apply, you may request access to your personal information, correction, deletion, a copy or transfer of your data, or restriction or cessation of processing. You may withdraw consent for processing that relies on consent, without affecting earlier lawful processing, and complain to the competent data-protection authority. These rights can have legal exceptions. See the UAE government’s information on data-protection rights.
We may need to verify your identity before acting on a request. Account deletion cannot remove public blockchain history or bypass an escrow’s claim or refund rules. Requests about information held independently by Privy, Google, X, or another provider may also need to be addressed to that provider.
The service is intended for adults aged 18 or older, and is not directed to children. If you believe a child’s information has been submitted, contact us once the dedicated contact channel below is available.
11Contact and updates
ShareStocks
United Arab Emirates
A dedicated contact address for privacy requests and legal enquiries will be published here before public launch. No contact mailbox is represented as available in this draft.
We will update this page when our practices change and revise the date above. Where required, we will provide additional notice or obtain consent before a material change takes effect. Publishing this policy does not itself create consent to optional processing.
