TokenGIP Privacy Policy
Effective date: 01-10-2026 Last updated: 01-10-2026 Operator / legal entity: Token GIP Registered/business address: Delaware, USA Privacy contact: info@tokengip.com Grievance / DPO contact where applicable: info@tokengip.com
Publication note: This is a comprehensive production draft for
implementation. Replace every bracketed placeholder with verified
information and reconcile the document with the actual production data
flows, vendors, retention schedule, jurisdictions, cookie inventory,
and legal advice before publication.
1. Introduction
This Privacy Policy explains how Token GIP, operating TokenGIP ("TokenGIP," "we," "us," or "our"), collects, uses, stores, discloses, protects, and otherwise processes personal information when you visit TokenGIP websites, request Early Access, communicate with us, create or use an account when account functionality is available, participate in a workspace, use administrative or research features, or otherwise interact with TokenGIP services.
TokenGIP is being developed as a blockchain research and intelligence platform focused on the earliest observable evidence surrounding token creation and subsequent blockchain activity.
This Policy distinguishes between information relating to an identifiable or potentially identifiable person, information associated with TokenGIP accounts, and information obtained from public or otherwise lawfully accessible blockchain networks.
2. Scope
This Policy applies to personal information processed by TokenGIP-controlled websites, applications, APIs, Early Access systems, administrative systems, support channels, and other services that expressly link to this Policy.
It does not govern independent third-party websites, wallet applications, blockchain networks, social platforms, exchanges, launchpads, or services that TokenGIP does not control.
When a third party processes information under its own terms and privacy policy, you should review that third party's documentation.
3. Who Is Responsible for Your Information
The entity responsible for processing personal information under this Policy is:
`Token GIP` Delaware, USA Privacy: info@tokengip.com
Where applicable law requires a Data Protection Officer, grievance officer, representative, or other privacy contact, the applicable contact is:
info@tokengip.com
The final published Policy must accurately identify the actual responsible entity.
4. Categories of Information We May Collect
The information TokenGIP processes depends on the features you use and the stage of the service.
We may process the categories described below.
5. Information You Provide Directly
You may provide information such as:
- first and last name;
- email address;
- telephone number;
- X/Twitter username;
- Telegram username;
- other social or professional profile identifiers;
- professional role or user category;
- stated product interests;
- Early Access application information;
- account profile information;
- workspace information;
- preferences;
- communications with TokenGIP;
- support requests;
- feedback;
- privacy requests;
- security reports.
Fields described as optional should remain optional unless a legitimate product or legal requirement changes.
6. Early Access Information
When you request Early Access, TokenGIP may collect:
- email address;
- optional name;
- optional X/Twitter username;
- optional Telegram username;
- role or user category;
- optional description of your interest in TokenGIP;
- consent to receive relevant communications where required;
- privacy-policy version presented at submission;
- submission timestamp;
- application status;
- internal review status;
- invitation status;
- source or referral information;
- UTM campaign parameters where applicable;
- anti-abuse metadata reasonably required to protect the form.
Early Access information is used to manage pre-launch interest, evaluate access requests, communicate about TokenGIP, issue invitations, prevent abuse, and understand the types of users interested in the platform.
An Early Access submission does not guarantee access.
7. Account and Profile Information
If TokenGIP account functionality is available, we may process:
- internal user identifier;
- account status;
- profile information;
- verified email address;
- verified phone number where used;
- connected authentication identities;
- workspace memberships;
- role assignments;
- preferences;
- notification settings;
- terms/privacy acceptance records;
- account creation and update timestamps.
8. Authentication Information
Depending on the authentication methods offered, TokenGIP may process:
- email or phone verification status;
- password hashes;
- verification-challenge metadata;
- MFA configuration;
- recovery-code status;
- session identifiers;
- session creation and expiration information;
- authentication events;
- failed-login information;
- security-related metadata;
- session revocation information.
TokenGIP should not store plaintext passwords.
Security credentials should be protected using cryptographic techniques appropriate to their purpose.
9. Wallet Authentication Information
Where supported wallet authentication is offered, TokenGIP may process:
- public wallet address;
- authentication challenge;
- nonce;
- challenge issue and expiration timestamps;
- signed authentication message;
- signature-validation result;
- connected-wallet metadata necessary for authentication;
- identity-linking status.
TokenGIP must not request or store a wallet seed phrase or private key for ordinary authentication.
A wallet used to authenticate to TokenGIP may be treated separately from wallets or blockchain addresses you choose to research.
10. Workspace and Collaboration Information
Where workspace functionality exists, TokenGIP may process:
- workspace identifier and name;
- membership;
- invitation records;
- assigned roles;
- permissions;
- invitation status;
- workspace preferences;
- activity relevant to collaboration and administration.
Workspace administrators may be able to view or manage information associated with members according to their permissions.
11. Preferences
TokenGIP may store preferences such as:
- appearance/theme;
- display density;
- reduced-motion preference;
- timezone;
- research defaults;
- chart defaults;
- notification preferences;
- cookie/consent preferences;
- interface settings.
Some preferences may be stored locally in the browser, while account-level preferences may be stored on TokenGIP servers.
12. Information Collected Automatically
When you use TokenGIP, systems may automatically receive technical information such as:
- IP address;
- approximate region inferred from IP where used;
- browser type and version;
- operating system;
- device characteristics;
- language;
- referring URL;
- requested URL;
- timestamps;
- request/correlation identifiers;
- HTTP status;
- performance information;
- application errors;
- security events;
- consent state;
- session metadata;
- anti-abuse signals.
The exact information collected must correspond to the actual production implementation.
13. Cookies and Similar Technologies
TokenGIP may use cookies, local storage, session storage, or similar technologies.
The production consent system should classify technologies into:
Strictly Necessary
Technologies required for essential operation, such as authentication, security, consent-state management, load balancing, or essential session functionality.
Preferences
Technologies that remember non-essential choices such as interface preferences.
Analytics
Technologies used to understand website usage, performance, and aggregate interaction patterns.
Marketing
Technologies used for advertising, cross-site marketing, campaign attribution beyond strictly necessary operation, or comparable purposes.
TokenGIP must not describe optional trackers as active unless they are actually configured.
Where consent is required, non-essential technologies should remain disabled until valid consent is obtained.
14. Cookie Preference Center
Where the production site uses optional cookies, users should be able to:
- accept all optional categories;
- reject non-essential technologies;
- customize categories;
- save preferences;
- reopen Cookie Settings;
- change or withdraw consent.
Strictly necessary technologies may remain enabled where they are required for essential service operation and permitted without consent.
15. Consent Records
Where TokenGIP records consent, we may store:
- consent identifier;
- applicable policy version;
- cookie-policy version;
- categories accepted;
- categories rejected;
- timestamp;
- subsequent change/withdrawal timestamp;
- account association where applicable;
- a limited pseudonymous identifier where appropriate.
We seek to avoid collecting unnecessary device fingerprinting information merely to prove consent.
16. Global Privacy Control and Similar Signals
Where applicable law requires recognition of Global Privacy Control or comparable legally effective preference signals, TokenGIP intends to configure its production systems accordingly.
Actual behavior depends on the jurisdictions and technologies applicable to the production service.
17. Public Blockchain Information
TokenGIP analyzes public or otherwise lawfully accessible blockchain information.
This may include:
- blockchain addresses;
- token mint/contract addresses;
- token creation events;
- transfers;
- swaps;
- transaction histories;
- liquidity events;
- holder information;
- creator/deployer addresses;
- transaction timing;
- wallet interactions;
- public smart-contract events;
- graph relationships derived from on-chain activity.
Blockchain addresses are generally pseudonymous rather than inherently anonymous.
Depending on context, a blockchain address or associated activity may constitute or become associated with personal information.
18. Derived Blockchain Intelligence
TokenGIP may generate research outputs based on blockchain information and other permitted data sources.
Outputs may include:
- Token DNA;
- Creator DNA;
- Wallet DNA;
- Buyer Quality;
- Transaction DNA;
- Liquidity DNA;
- Distribution DNA;
- Graph DNA;
- manipulation indicators;
- velocity indicators;
- timing indicators;
- risk indicators;
- Genesis Fingerprints;
- historical similarity;
- Winner DNA comparisons;
- Genesis Score;
- Risk Score;
- Confidence;
- Why Now explanations;
- classifications.
These are analytical outputs and may involve uncertainty.
A wallet relationship or cluster should not automatically be interpreted as proof that multiple addresses belong to the same identified natural person.
19. Social and Narrative Information
If TokenGIP later analyzes publicly available social or narrative information, the final Privacy Policy must be updated to accurately describe:
- sources;
- categories of information;
- purposes;
- retention;
- provider relationships;
- applicable legal bases;
- user rights.
Do not publish a claim that TokenGIP processes a particular social source until that integration actually exists.
20. Sources of Information
We may receive information:
- directly from you;
- from your browser or device;
- from public blockchains;
- from infrastructure and security providers;
- from communications providers;
- from analytics providers if enabled;
- from public or licensed data sources;
- from workspace administrators or invitations;
- from third-party services you choose to connect.
The production Policy must be reconciled with the actual provider inventory.
21. Purposes for Which We Process Information
We may process information to:
- operate TokenGIP;
- provide requested features;
- process Early Access applications;
- communicate about Early Access;
- create and maintain accounts;
- authenticate users;
- secure accounts and sessions;
- provide workspace functionality;
- enforce roles and permissions;
- remember preferences;
- provide research and intelligence features;
- generate analytical outputs;
- detect abuse;
- prevent fraud and unauthorized access;
- investigate security events;
- maintain audit records;
- provide support;
- respond to privacy requests;
- measure reliability and performance;
- improve the service;
- comply with applicable legal obligations;
- establish, exercise, or defend legal claims;
- enforce applicable agreements.
22. Communications
TokenGIP may send service-related communications such as:
- verification messages;
- security notifications;
- Early Access confirmations;
- invitation messages;
- account notices;
- privacy-request acknowledgements;
- essential operational communications.
Where required, promotional or optional communications should be based on an appropriate permission or legal basis and should provide an unsubscribe mechanism.
Unsubscribing from optional marketing communications may not stop essential security or transactional messages.
23. Legal Bases Where GDPR Applies
Where the GDPR applies, TokenGIP may rely on one or more legal bases depending on the processing activity, including:
- performance of a contract;
- steps taken at your request before entering into a contract;
- legitimate interests, such as operating, securing, and improving the
service;
- consent, where required;
- compliance with legal obligations;
- establishment, exercise, or defense of legal claims where
applicable.
The actual legal basis must be mapped to the actual processing activity. TokenGIP should maintain an internal processing inventory rather than treating this section as a substitute for that analysis.
24. Legitimate Interests
Where TokenGIP relies on legitimate interests, those interests may include:
- operating a secure service;
- preventing abuse;
- maintaining system integrity;
- understanding service performance;
- improving user experience;
- protecting legal rights;
- maintaining appropriate audit records.
Where required, these interests should be balanced against the rights and interests of affected individuals.
25. Consent
Where processing relies on consent, consent should be specific enough for the relevant purpose, capable of being withdrawn, and recorded where appropriate.
Withdrawal does not necessarily affect the lawfulness of processing carried out before withdrawal.
Some information may still need to be retained where another legal basis or legal obligation applies.
26. India Data Protection
Where applicable, TokenGIP intends to process digital personal data in accordance with applicable Indian data-protection requirements as they come into force and apply to the service.
The final production implementation should maintain appropriate notices, consent or other lawful processing mechanisms, user-rights workflows, security safeguards, grievance mechanisms, and data-governance processes required by applicable law.
The final published Policy must be reviewed against the legal provisions actually in force on its effective date.
27. European Economic Area, United Kingdom, and Similar Jurisdictions
Where applicable data-protection law provides individual rights, those rights may include:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection;
- withdrawal of consent;
- complaint to a competent supervisory authority.
Rights are subject to applicable conditions, exceptions, identity verification, and lawful retention obligations.
28. California and Other U.S. State Privacy Rights
If a U.S. state privacy law applies to TokenGIP and a particular user, rights may include, depending on the law:
- confirmation/knowledge of processing;
- access;
- correction;
- deletion;
- portability;
- opt-out of certain sale, sharing, targeted advertising, or
profiling;
- limitation of certain sensitive-data uses;
- appeal of certain request decisions;
- protection from unlawful discrimination for exercising privacy
rights.
TokenGIP must not claim that it "does not sell or share" personal information until the actual production vendor, analytics, advertising, and data-disclosure architecture has been verified under applicable statutory definitions.
29. Sale, Sharing, and Targeted Advertising
The production version of this section must accurately state whether TokenGIP sells personal information, shares it for cross-context behavioral advertising, or processes it for targeted advertising as those concepts are defined under applicable law.
If TokenGIP does not engage in such activities, state that only after confirming the actual production data flows.
If such activities are introduced, the appropriate notices and opt-out mechanisms must be implemented before the Policy is updated to describe them.
30. Service Providers and Processors
TokenGIP may disclose information to service providers that perform functions such as:
- hosting;
- databases;
- object storage;
- email delivery;
- SMS delivery;
- authentication;
- security;
- monitoring;
- analytics;
- support;
- infrastructure;
- backups;
- content delivery;
- communications.
Providers should receive only information reasonably required for their functions and should be subject to appropriate safeguards where required.
The final internal vendor inventory should identify the actual providers and their roles.
31. Other Disclosures
We may disclose information when reasonably necessary to:
- comply with applicable law;
- respond to valid legal process;
- protect TokenGIP, users, or others;
- investigate fraud or abuse;
- enforce agreements;
- protect security and integrity;
- establish or defend legal claims;
- respond to emergencies where legally permitted.
Requests from authorities should be assessed for validity and scope as appropriate.
32. Corporate Transactions
If TokenGIP or the relevant business is involved in a merger, acquisition, financing, restructuring, sale of assets, insolvency process, or similar transaction, information may be transferred as part of that transaction subject to applicable law and appropriate safeguards.
33. International Data Transfers
TokenGIP and its service providers may process information in different countries.
Where applicable law requires safeguards for international transfers, TokenGIP should use an appropriate transfer mechanism and supplementary measures where required.
The actual hosting regions and providers must be reflected in TokenGIP's production compliance analysis.
34. Data Retention
TokenGIP seeks to retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including operational, security, legal, compliance, dispute-resolution, and audit needs.
Different categories may require different retention periods.
The production platform should maintain a documented retention schedule for categories such as:
- Early Access applications;
- declined or archived applications;
- consent records;
- account records;
- sessions;
- audit records;
- security logs;
- email-delivery metadata;
- privacy requests;
- support communications.
Do not publish arbitrary retention periods until they are approved and implemented.
35. Early Access Retention
Early Access information may be retained while TokenGIP evaluates applications, manages invitations, communicates about launch, prevents duplicate submissions, and maintains appropriate consent or audit records.
The exact production retention period should be documented and reflected in administrative retention controls.
36. Security and Audit Retention
Security and audit records may be retained for periods necessary to investigate incidents, maintain platform integrity, comply with applicable obligations, resolve disputes, and demonstrate privileged activity.
Deletion requests may not require deletion of records that TokenGIP must lawfully retain for security, fraud prevention, legal claims, or compliance purposes.
37. Blockchain Data Retention
TokenGIP does not control the retention of records maintained by public blockchain networks.
A request to delete information from TokenGIP cannot cause an independent blockchain transaction or public ledger entry to disappear.
TokenGIP may be able to delete, restrict, or dissociate off-chain information under its control, subject to applicable law and technical feasibility.
38. Security of Personal Information
TokenGIP uses or intends to use administrative, technical, and organizational measures appropriate to the nature of the information and service.
These may include:
- access controls;
- authentication;
- MFA for privileged accounts;
- encryption in transit;
- appropriate protection at rest;
- secrets management;
- server-side authorization;
- logging;
- audit controls;
- rate limiting;
- secure software-development practices;
- dependency management;
- incident-response processes.
No security measure can guarantee absolute security.
39. Your Privacy Choices
Depending on the service and applicable law, you may be able to:
- update account/profile information;
- change preferences;
- modify cookie choices;
- withdraw optional consent;
- unsubscribe from optional communications;
- revoke sessions;
- disconnect certain identities;
- submit a privacy request;
- request account deletion where available.
Some essential operational or security communications cannot be disabled while an account remains active.
40. Privacy Rights Requests
To exercise an applicable privacy right, contact:
`info@tokengip.com`
or email [info@tokengip.com](mailto:info@tokengip.com).
A request should identify the right being exercised and provide enough information for TokenGIP to locate relevant records without requesting unnecessary sensitive information.
41. Verification of Requests
Before disclosing, correcting, exporting, or deleting personal information, TokenGIP may need to verify that the requester is authorized to make the request.
Verification should be proportionate to the sensitivity of the request.
TokenGIP should not request unrelated identity documents merely as a default verification mechanism.
Authorized-agent requests may require additional verification where applicable law permits.
42. Responding to Requests
TokenGIP intends to respond within timelines required by applicable law.
Complexity, identity verification, legal exceptions, or the nature of the request may affect timing.
If a request cannot be fulfilled, TokenGIP should provide an explanation where required.
Where applicable law provides an appeal mechanism, the production process should support it.
43. Account Deletion
Where account deletion is available, deleting an account may result in deletion, anonymization, or restriction of associated off-chain information, subject to legal, security, fraud-prevention, audit, and dispute-resolution requirements.
Account deletion cannot remove public blockchain records maintained independently of TokenGIP.
44. Children and Minimum Age
TokenGIP is not intended for children.
The production service must define an actual minimum age and eligibility policy based on the jurisdictions and functionality offered.
Minimum age: 18 years
Do not publish this placeholder. The final age threshold should be reviewed in light of digital-asset functionality and applicable law.
45. Sensitive Personal Information
TokenGIP does not intend to request unnecessary sensitive personal information for ordinary Early Access or research use.
Users should not submit:
- wallet seed phrases;
- private keys;
- passwords for third-party services;
- unnecessary government identification;
- financial-account credentials;
- unrelated health or biometric information.
If future functionality requires sensitive information, this Policy and applicable controls must be updated before collection begins.
46. Third-Party Wallets
TokenGIP may interact with third-party wallet applications.
Wallet providers operate independently and may process information under their own privacy policies.
TokenGIP is not responsible for the privacy practices of independent wallet providers.
47. Third-Party Links
TokenGIP may link to third-party websites, social networks, documentation, or services.
A link does not mean TokenGIP controls the third party.
Review the third party's privacy practices before providing information to it.
48. Social Media
TokenGIP may maintain official social-media profiles.
When you interact with TokenGIP through a social platform, the platform may independently process information under its own terms.
TokenGIP's website should display only verified official social links configured through authorized administration.
49. Analytics
TokenGIP uses Google Analytics 4 to understand aggregate public-website usage and interaction patterns. Google Analytics is classified as Analytics and loads only after the visitor enables Analytics consent. TokenGIP configures this integration without Google advertising signals or ad-personalization signals and does not intentionally send Early Access form contents or other directly identifying form data to Google Analytics.
Where consent is required, optional analytics must not load before valid consent.
TokenGIP should prefer data minimization and avoid collecting analytics merely because a tool makes collection possible.
50. Marketing Technologies
If TokenGIP later uses advertising, retargeting, pixels, or cross-site marketing technologies, those technologies must be disclosed and integrated with the consent/opt-out architecture before activation.
This draft does not authorize undisclosed marketing tracking.
51. Automated Analysis and Profiling
TokenGIP performs automated analysis of blockchain activity as part of its research functionality.
These analytical systems may score or classify tokens, wallets, creators, transaction structures, risk indicators, and other blockchain phenomena.
Such blockchain research outputs are not necessarily decisions about an identified natural person.
If TokenGIP later uses automated processing to make decisions producing legal or similarly significant effects on individuals, the Privacy Policy and applicable safeguards must be reviewed and updated before that processing begins.
52. Accuracy of Derived Information
Blockchain intelligence can be probabilistic and incomplete.
A cluster, relationship, classification, or risk indicator may be incorrect or may change as new evidence becomes available.
TokenGIP should distinguish observed facts from derived analytical conclusions where appropriate.
53. Data Quality and Correction
Where personal information is inaccurate, applicable users may have correction rights.
Public blockchain records themselves generally cannot be corrected by TokenGIP.
If an off-chain association or account record maintained by TokenGIP is incorrect, users may contact us through the applicable privacy channel.
54. Do Not Track
Browser "Do Not Track" signals do not have a universally standardized legal meaning.
Where TokenGIP is legally required to recognize a specific browser-based opt-out mechanism such as Global Privacy Control, TokenGIP should do so as described in the applicable production implementation.
55. Changes to This Privacy Policy
TokenGIP may update this Policy as the service, providers, laws, or data practices change.
The current Policy should display its effective date and last-updated date.
Where required, TokenGIP should provide additional notice or obtain consent before material changes take effect.
Historical legal-document versions should be retained where operationally appropriate.
56. Contact Us
Questions, requests, or concerns about this Policy may be directed to:
`Token GIP` Delaware, USA
Privacy: info@tokengip.com Grievance / DPO: info@tokengip.com Privacy requests: [info@tokengip.com](mailto:info@tokengip.com)
If you are entitled to complain to a privacy or data-protection authority, you may also have that right under applicable law.
