Privacy Policy
This Privacy Policy explains what data LPHunt collects when you use lphunt.com, the LPHunt API, the LPHunt Chrome extension and related services (together, the "Service"), why we collect it, who we share it with, and the choices you have. We wrote it to be specific rather than vague: if we collect something, it is listed here.
1. Who we are and scope
LPHunt ("LPHunt", "we", "us") operates the Service. LPHunt is the data controller for the personal data described in this policy. You can reach us at [email protected].
This policy applies to everyone who visits lphunt.com, creates an account, uses the Chrome extension, pays for a subscription, or contacts us. It does not cover the decentralized exchanges, blockchains, wallets, browsers or other third-party services you use alongside LPHunt. Those have their own policies.
2. Data we collect
2.1 Data you give us
| Data | When | Notes |
|---|---|---|
| Email address, name, username | Account creation, email-only signup | Email is required to create an account and to send alerts. |
| Password | Account creation, password reset | Stored only as a bcrypt hash. We cannot read your password. |
| Google or Apple account identifier, email and display name | Sign in with Google or Apple | We receive only what the provider returns for authentication. We never receive your Google or Apple password. |
| Wallet address | Sign in with a wallet, import positions from a wallet | You sign a one-time text message to prove ownership. We never ask you to sign a transaction and never receive your private key or seed phrase. |
| Position URLs, position or NFT identifiers, network and exchange | Adding a position | This is the core of the Service: what we watch for you. |
| Notes, group names, initial amounts you enter | Organizing positions | Free text you choose to add. Do not put secrets in notes. |
| Profile avatar | Settings | Stored in object storage (Vultr). |
| Onboarding answers (goal, pain points, exchanges used, position size band) | Onboarding | Used to personalize the dashboard and the figures shown during onboarding. |
| Messages you send to support | Email or chat | See section 5 for the chat provider. |
2.2 Data we derive about your positions
For every position you add, we read public data from the relevant blockchain (through RPC providers) or, as a fallback, from the exchange's public position page. This includes the token pair, liquidity amounts, token balances, unclaimed fees, claimed fees, price range, in-range or out-of-range status, and whether the position is closed. We store a history of these readings and of fee changes so you can see trends, run reports and export CSVs. All of this data is already public on the blockchain. What LPHunt adds is the link between those public positions and your account.
2.3 Login and security telemetry
Each time a session token is issued (password login, wallet login, Google or Apple login, signup, or password reset) we record:
- the time of the login,
- your IP address, taken from the Cloudflare connecting-IP header or, failing that, the forwarding headers of the request, and
- the two-letter country code that Cloudflare derived from that IP address.
We keep only the most recent value of each; a new login overwrites the previous one. We do not keep a full login history. We also keep an audit trail of changes to the unclaimed-fee figure of each active position, which includes a request identifier but no personal data beyond your account reference.
2.4 Payment data
Premium is paid in USDT on BNB Smart Chain (BEP-20). When you start a checkout we create an invoice with a unique deposit address generated through our payment processor, and we record the plan, the amount due, the amount received, the on-chain transaction identifier, the balance of the deposit address, and timestamps. We never collect or store card numbers, bank details or billing addresses, because the Service does not accept cards. Blockchain transactions are public: anyone can see that a transfer was made to the deposit address, but the blockchain does not contain your name or email.
2.5 Usage analytics
We use Amplitude to understand how the Service is used. Amplitude automatically captures page views, clicks and other interface interactions, together with device, browser, operating system, approximate location (from IP) and a random device identifier. We use this to find broken flows and decide what to build next. We do not send your email, password, wallet address or position identifiers to Amplitude as part of autocapture.
2.6 Technical data
Like every website, our servers and Cloudflare record requests: IP address, timestamp, URL requested, response code, user agent and referrer. These logs are used for security, debugging and abuse prevention.
3. How we use your data
- Providing the Service: tracking your positions, computing fees and PnL, generating reports and CSV exports, running the dashboard and the extension.
- Alerts: sending you an email when a position changes status (for example, goes out of range or is closed). Alerts are the main reason we need your email.
- Account emails: welcome, password setup, password reset, payment confirmation, subscription expiry.
- Payments: matching on-chain transfers to your invoice and activating or extending your subscription.
- Security and fraud prevention: detecting account takeover, unusual login locations, abuse of free-tier limits, and automated attacks. The login IP and country data exist for this purpose.
- Support: answering your questions and investigating problems you report.
- Product improvement: analytics on how features are used, so we can improve them.
- Legal compliance: keeping financial records, responding to lawful requests, enforcing our Terms.
We do not use your data for advertising, we do not build advertising profiles, and we do not sell or rent personal data to anyone.
4. Legal bases
Where data protection law (such as the GDPR or UK GDPR) requires a legal basis, we rely on:
- Performance of a contract for everything needed to run your account, track your positions, send alerts and process payments.
- Legitimate interests for security telemetry (login time, IP, country), fraud prevention, server logs, product analytics and support. We have balanced these interests against your rights and keep the data minimal.
- Legal obligation for keeping payment and tax records.
- Consent where you choose to enable something optional, such as the support chat or sign-in with a third-party provider. You can withdraw consent at any time without affecting processing that already took place.
6. Blockchain data is public and permanent
LPHunt reads from public blockchains. Anything on a public blockchain (positions, balances, fee claims, and transfers to our payment deposit addresses) is visible to anyone, forever, and cannot be edited or deleted by LPHunt or anyone else. When you delete your account we remove the link between you and those positions in our systems, but the on-chain records themselves remain. Please consider this before adding a position or paying from a wallet you consider private.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data, positions, groups, notes, position history | For as long as your account exists. Deleted positions are soft-deleted first and purged from backups within 30 days of account deletion. |
| Last login time, IP and country | Only the most recent value is kept; overwritten on each login; deleted with the account. |
| Invoices, payment and subscription records | Up to 7 years after the transaction, to meet accounting and tax obligations, even if the account is deleted. |
| Server and Cloudflare request logs | Up to 90 days. |
| Email delivery logs at SendGrid | Per SendGrid's retention, typically 30 days for event data. |
| Analytics events at Amplitude | Per our Amplitude plan's retention. You can ask us to delete your Amplitude data; see section 11. |
| Support chat transcripts at Tawk.to | Until deleted by us or by Tawk.to's retention; you can request deletion. |
| Database backups | Rolling, up to 30 days. |
9. Security
We take measures appropriate to the sensitivity of the data we hold:
- All traffic is encrypted in transit with TLS; the Service is served only over HTTPS.
- Passwords are hashed with bcrypt and never stored or logged in plain text.
- Session tokens are signed JSON Web Tokens that expire after 7 days.
- Wallet sign-in uses a one-time challenge that is deleted before verification, so a captured signature cannot be replayed.
- Production systems are behind Cloudflare, and internal services (such as the position reader) are not reachable from the public internet.
- Access to production data is limited to the people who operate the Service.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities without undue delay and, where the law requires, within 72 hours of becoming aware of it. Please use a unique password for LPHunt and keep your email account secure, since email is how passwords are reset.
10. International transfers
Our servers are located in the United States, and the providers in section 5 may process data in the United States and other countries. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred under appropriate safeguards such as the European Commission's Standard Contractual Clauses or the provider's participation in the EU-U.S. Data Privacy Framework. You can ask us for details of the safeguards that apply.
11. Your rights and choices
Depending on where you live you may have the right to:
- Access the personal data we hold about you and receive a copy in a portable format.
- Correct inaccurate data. You can change your name, username and avatar in Settings.
- Delete your data (see section 12).
- Object to or restrict processing based on legitimate interests, including analytics.
- Withdraw consent where processing is based on consent.
- Opt out of marketing. We currently send only transactional and alert emails. If we ever send marketing, every message will include an unsubscribe link.
- Lodge a complaint with your local data protection authority.
If you are a California resident, you have the rights described above under the CCPA/CPRA, including the right to know, delete and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months.
To exercise any right, email [email protected] from the address on your account. We may ask you to confirm your identity (for example, by replying from the account email or by signing a message with the wallet linked to the account). We respond within 30 days, or sooner where the law requires. Exercising your rights is free unless requests are manifestly unfounded or excessive.
12. Deleting your account
Email [email protected] from your account email and ask us to delete your account. Within 30 days we will delete your profile, positions, groups, notes, avatar, onboarding answers, login telemetry and position history, and we will ask Amplitude and Tawk.to to delete the data they hold about you. We keep invoice and payment records for the period in section 8 because the law requires us to, and we may keep a minimal record of your email address if needed to enforce our Terms or to honor an opt-out. On-chain data cannot be deleted by anyone (section 6).
Deleting your account ends any active Premium subscription without refund, except where section 7 of the Terms of Service provides otherwise.
13. Chrome extension
The LPHunt Chrome extension is a popup that loads lphunt.com inside a frame. It does not read your browsing history, the content of other tabs, or any data outside its own popup. It requests no permissions beyond what is needed to show that popup. Data it handles is the same data described in this policy, and it is governed by the same rules. Uninstalling the extension does not delete your LPHunt account; see section 12 for that.
14. Age requirement
The Service is for adults. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
15. Changes to this policy
We will update this policy when the Service changes or the law requires. The effective date at the top tells you when it last changed. For material changes (for example, collecting a new category of data or sharing data with a new kind of recipient) we will notify you by email or with a notice in the Service at least 14 days before the change takes effect. Continued use after that date means you accept the updated policy.
16. Contact
For anything about privacy, including requests to access or delete your data, email [email protected]. We read every message.
