1Data controller
ICONIQ SAS determines the purposes and means of the processing described in this policy and is therefore the data controller within the meaning of Regulation (EU) 2016/679 ("GDPR").
- Data controller
- ICONIQ SAS, Société par actions simplifiée
- Registered office
- À COMPLÉTER
- SIREN
- À COMPLÉTER
- Privacy contact
- privacy@iconiq.io
- Data Protection Officer
- À COMPLÉTER
This policy applies to the ICONIQ platform and its related services. It supplements our Terms of Service, of which it forms an integral part.
2Data we process
We limit collection to what the service needs. We do not ask for your full date of birth or for identity documents, except where the law or an anti-fraud check requires it.
Account data
- email address, passed on by our authentication provider;
- account identifier and display name;
- the public address of your digital asset wallet;
- level, experience points, login streaks, missions and bonuses attached to your account.
Transaction data
- packs purchased, amounts in USDC;
- the signatures of the corresponding blockchain transactions;
- opening sessions, draw commitments and seeds, prizes allocated;
- buyback requests, refunds and failed payments;
- promotional codes used, referrals and related commissions;
- marketplace listings, offers and sales.
Shipping data
- recipient name, postal address, city and country, when you request shipment of a prize.
Technical data
- connection and API logs, including IP address, timestamp and user agent;
- diagnostic data when an application error occurs;
- audience and usage measurement, as set out in the section "Cookies and trackers".
3Purposes and legal bases
Each processing operation rests on a distinct legal basis under article 6 GDPR.
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage your account | Account | Performance of the contract (art. 6.1.b) |
| Sell and deliver packs, allocate prizes | Account, transaction | Performance of the contract (art. 6.1.b) |
| Ship physical prizes | Shipping | Performance of the contract (art. 6.1.b) |
| Ensure draws are traceable and verifiable | Transaction | Contract and legitimate interest in proving fairness (art. 6.1.b and 6.1.f) |
| Prevent fraud, duplicate accounts and abuse | Account, transaction, technical | Legitimate interest in protecting the service (art. 6.1.f) |
| Handle your requests and complaints | Account, transaction | Contract and legitimate interest (art. 6.1.b and 6.1.f) |
| Meet our accounting and tax obligations | Transaction | Legal obligation (art. 6.1.c) |
| Measure audience and improve the service | Technical | Consent (art. 6.1.a) |
| Send you marketing communications | Account | Consent (art. 6.1.a), withdrawable at any time |
| Maintain security and diagnose incidents | Technical | Legitimate interest in security (art. 6.1.f) |
Where we rely on legitimate interest, we have balanced that interest against your rights. You may object to such processing as set out in the section "Your rights".
4Recipients and processors
We do not sell or rent your data. We share it only with the providers needed to run the service, each bound by a contract compliant with article 28 GDPR and acting solely on our instructions.
| Provider | Role | Data involved |
|---|---|---|
| Privy | Authentication and embedded wallets | Email, identifier, wallet address |
| Supabase | Application database | Account, transaction, shipping |
| Vercel | Platform hosting | Technical logs |
| Sentry | Error detection and diagnostics | Technical logs, account identifier |
| PostHog | Audience and usage measurement | Identifier, email, usage events |
| Resend | Transactional email delivery | Email, message content |
| Helius | Access to Solana blockchain nodes | Wallet address, transactions |
We may also disclose data to our advisers, our insurers, our carriers for the shipment of prizes, and to administrative or judicial authorities where the law requires it.
5Transfers outside the European Union
Some of our providers are established in the United States or host part of their infrastructure there. Depending on the provider, these transfers are covered by the European Commission's standard contractual clauses, by certification under the EU–US Data Privacy Framework, or by both.
You can obtain a copy of the safeguards in place by writing to privacy@iconiq.io.
6Retention periods
| Data | Period | Starting point |
|---|---|---|
| Account and profile | Life of the account, then 12 months | Account closure |
| Accounting records and transactions | 10 years | End of financial year |
| Shipping data | 3 years | Delivery of the prize |
| Opening sessions and verifiability records | 5 years | Pack opening |
| Connection logs | 12 months | Recording |
| Error diagnostic data | 90 days | Recording |
| Audience measurement | 13 months maximum | Tracker set |
| Proof of consent | 3 years | Consent collected |
| Rights requests | 3 years | Response given |
At the end of these periods, data is deleted or irreversibly anonymised. Some may be kept longer in restricted archive where a legal obligation, ongoing litigation or the applicable limitation period requires it.
7Blockchain: a limit on the right to erasure
A wallet address is pseudonymous data: it does not carry your name, but it can be linked back to you by correlation. We treat it as personal data accordingly.
In practice, when you request erasure, we delete what we hold in our own systems and sever the link between your identity and your wallet address in our records. Entries already on the blockchain remain: they are outside our control.
Use a wallet address dedicated to this service if you want to limit correlation with your other activity.
9Automated decisions and profiling
The outcome of a pack opening is determined by a verifiable random draw, described in our Terms of Service. The draw takes into account counters attached to your account, whose purpose is to keep published odds accurate over time. It uses no behavioural profile and does not vary with your identity, your purchase history or your balance.
We run automated checks to detect fraud, duplicate accounts and abuse. Where a check leads to an account being suspended or a transaction blocked, you are informed and may obtain human intervention, express your point of view and contest the decision by writing to the address in the section "Contact".
We take no decision producing legal effects concerning you based solely on automated processing, within the meaning of article 22 GDPR, without that possibility of human intervention.
10Security
We implement technical and organisational measures appropriate to the risk: encryption in transit, compartmentalised database access, systematic server-side authorisation checks, logging of administrative actions and regular dependency review.
No system is infallible. In the event of a data breach likely to result in a high risk to your rights and freedoms, we will inform you promptly and notify the CNIL in accordance with articles 33 and 34 GDPR.
You contribute to this security by protecting your credentials and your wallet keys, which we do not hold and cannot restore.
11Your rights
Under the GDPR you have the following rights:
- access: confirm whether your data is processed and obtain a copy;
- rectification: have inaccurate or incomplete data corrected;
- erasure: request deletion of your data, subject to the section "Blockchain" and to our legal retention obligations;
- restriction: request that processing be frozen while a challenge is examined;
- objection: object to processing based on our legitimate interest, on grounds relating to your particular situation;
- portability: receive, in a structured format, the data you provided that we process on the basis of the contract or your consent;
- withdrawal of consent: at any time, without affecting the lawfulness of processing carried out beforehand;
- post-mortem instructions: set out what should happen to your data after your death.
To exercise these rights, write to privacy@iconiq.io from the address linked to your account. We respond within one (1) month, extendable by two (2) months for complex requests, in which case we will tell you. We may ask for proof of identity where there is reasonable doubt as to who is making the request, and only in that case.
12Minors
The service is prohibited to persons under 18. We do not knowingly collect data relating to minors.
If you hold parental authority and find that a minor has created an account, write to privacy@iconiq.io: we will close the account and delete the associated data, subject to our legal retention obligations.
13Changes to this policy
We may amend this policy, in particular where the service, our providers or the regulations change. The date of the latest update appears at the top of this page.
Any material change, in particular adding a purpose or a recipient, is notified to you before it takes effect. Where processing rests on your consent, it is requested again.
14Contact
- Privacy and rights requests
- privacy@iconiq.io
- Data Protection Officer
- À COMPLÉTER
- Support
- support@iconiq.io
- Postal address
- À COMPLÉTER
© 2026 ICONIQ. This document is provided for information and does not constitute legal advice.