1.Who we are and what this covers
iCOA is operated by Conglomerate Media Group, LLC, a Wyoming company ("we", "us"). This policy explains what personal information we collect when you use the iCOA website at www.icoa.io, the iCOA mobile app, our certificate pages and WeMintArt, our art vertical (together, the "Service"), and what we do with it.
It goes with our Terms of Service. We have tried to write it so that it says exactly what the software does, no more and no less.
2.What we collect
We collect only what the Service needs to work.
- Your email address, to sign you in with a one-time code and to email you about your account and certificates.
- Your profile: a handle, and optionally a display name, a short bio, a website, an Instagram handle and a wallet address you control.
- Your certificates: the item's photo, up to six story photos with captions, and the details you enter (title, story, category, year, edition, and category fields such as medium, materials, maker or serial number), plus the time you attested to it.
- Transfer recipients: the email address you send a claim link to. We keep it with the transfer record and mask it on the claim page.
- Usage: how many certificates you have issued each month, your credit balance, and your plan.
- Payment: handled by Stripe on the web and, where the iOS app offers subscriptions, by Apple in-app purchase. We store a Stripe customer id and subscription status, or an Apple transaction id, so we know what you have paid for. We never see or store your card number.
- Technical data: our hosting provider keeps ordinary request logs (IP address, browser, time, page) for security and to keep the Service running. If crash reporting is enabled, error reports go to Sentry with your identity, cookies, headers, form contents and claim links stripped out first.
We do not buy data about you, and we do not run advertising trackers.
3.How we use it
We use your information to:
- sign you in and keep your account secure;
- issue, publish, fingerprint, record and transfer certificates, which is the point of the Service;
- email you sign-in codes, claim links and notices about your account;
- enforce plan limits and bill you for what you have chosen to buy;
- answer your questions and investigate reports of misuse;
- find and fix errors;
- comply with the law.
Where the GDPR or UK GDPR applies, we rely on our contract with you for the first five, on our legitimate interest in running a reliable Service for the sixth, and on legal obligation for the last. We do not use your information to profile you or to make automated decisions about you.
4.Where it lives and who processes it
We do not sell your personal information, and we do not share it with anyone for their own marketing. The companies below process it on our behalf to run the Service:
- Supabase hosts our database, sign-in and file storage, in the United States.
- Vercel hosts the website and serves certificate pages.
- Resend delivers our email.
- Stripe takes payment on the web and holds your card details; Apple handles any purchase made through in-app purchase, where the iOS app offers one.
- Sentry receives crash reports, if reporting is enabled, with personal details stripped out.
We may also disclose information when the law requires it, to protect someone's safety or our rights, or, if the business is sold or merged, to the new owner under this policy.
5.What is public
A certificate exists to be shown. Once you issue one, its page is public to anyone with the link, and so is the metadata that describes its blockchain token. The public page shows:
- the item's photo, story photos and every detail you entered;
- your name and handle as the issuer, and whether your account is verified;
- the name of the current owner, once a buyer has claimed it;
- the provenance timeline: when it was issued, recorded on chain and transferred (never to whom by email);
- the content fingerprint, and the token, contract and transaction on the blockchain.
Your profile (handle, name, bio, links and wallet address, if you gave one) is public as well, because certificate pages name their issuer and owner. Your email address is never shown on any page. Drafts are private until you issue them.
6.What is on the blockchain, forever
When a certificate is recorded on chain, we write a token to a public blockchain (Base, or the Base Sepolia test network while the Service is in preview). The token carries the certificate's content fingerprint (a hash), a token id, and the address of its metadata page on our servers. That is all. It is public. The fingerprint, the token id and the minting transaction cannot be changed or deleted, by us or by anyone. We can update only the metadata address the token points at (for example if our domain changes).
Your email address is never written to the chain. Your name and the item's details are not written to it either: the chain only points at our metadata page, which we control and can take down. The fingerprint is a hash of the certificate's details and cannot be reversed into them.
Free-plan certificates are recorded at their first transfer; paid plans and credits record them at issue. Wherever you have a choice, think of recording as publishing.
8.How long we keep it
- Your account and profile: for as long as your account exists.
- Issued certificates, their images and provenance: for as long as the certificate exists, because holders rely on them. This outlasts your account (see the next section).
- Drafts and their files: until you delete them or your account.
- Transfer records, including the recipient email address: kept with the certificate, as part of its ownership history. Expired and cancelled links cannot be used.
- Billing records: for as long as tax and accounting law requires.
- Crash reports and request logs: for the short retention periods our providers set, then discarded.
9.Deleting your account
You can delete your account yourself from Settings on the web or in the app. We delete your profile, your email address, your drafts and their files, and cancel any transfer you had open. Your email address may remain in another person's transfer record if they sent a certificate to you.
We cancel any Stripe subscription. A subscription bought through Apple is managed by Apple and is not cancelled when you delete your account: cancel it yourself in your Apple ID settings (Settings > Apple ID > Subscriptions), before or after you delete.
Certificates you have already issued survive, because the people who hold them are entitled to their record. They keep their images and details and show your name as it was when you left, marked "account closed". Records on the blockchain cannot be removed. Stripe and Apple keep their own transaction records under their own policies.
If you would rather we delete for you, or want an issued certificate's image and details taken down from our servers, write to support@icoa.io.
10.Children
The Service is not for children. We do not knowingly collect personal information from anyone under 13, or under 16 where that is the age of consent for online services, and our terms require account holders to be adults. If you believe a child has given us information, tell us at support@icoa.io and we will delete it.
11.Your rights
Wherever you live, you can see and correct what we hold about you from your account settings, and delete your account yourself. For anything else, email support@icoa.io; we answer within 30 days and never charge for it.
If you are in the EU, the EEA or the UK, you also have the rights to restrict or object to processing, to data portability, and to complain to your data protection authority. We transfer your data to the United States under standard contractual clauses or an equivalent lawful basis.
If you are in California, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to not be discriminated against for exercising these rights. We do not sell or share your personal information as those terms are defined in the CCPA, and we have not done so in the preceding twelve months. You may make a request through an authorized agent, and we will verify it against your account email.
12.Security
Data is encrypted in transit and at rest by our providers. Sign-in uses one-time codes rather than passwords, so we hold none. Access to certificate records is enforced in the database itself, claim links are stored only as hashes, and issued certificates are frozen and fingerprinted so tampering shows. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.
13.Changes to this policy
When we change this policy we will post the new version here with a new effective date, and for changes that matter we will email account holders before they take effect. Continued use after that date means you accept the change.
14.Contact
Privacy questions and requests go to support@icoa.io. Conglomerate Media Group, LLC, Wyoming, United States.