BFlow/Privacy Policy

Privacy Policy

April 2026

1. Data controller

2. Data collected

  • Account data: email address, username, hashed password
  • Wallet data: public Solana wallet address (read-only, no private keys)
  • Activity data: picks submitted, performance statistics, active subscriptions
  • Technical data: IP address (for security and rate limiting), connection logs

BFlow does not collect banking data or identity documents.

3. Purposes

  • Service delivery (account creation and management)
  • Calculation and display of pick statistics
  • Processing of $BFLOW payments and withdrawals
  • Security (fraud detection, rate limiting)
  • Transactional communication (signup confirmation, notifications)

4. Legal basis

  • Contract performance (Terms of Service) for data required to operate the service
  • Legitimate interest for security and fraud prevention
  • Consent for marketing communications (opt-in)

5. Data retention

  • Account data: duration of account activity + 2 years after closure
  • Technical logs: 90 days
  • Transaction history: 5 years (legal obligations)

6. Data sharing

BFlow does not sell your data. Your data may be shared with:

  • Hetzner Online GmbH (hosting) — processing on servers in Europe
  • Third-party monitoring services (Sentry) — anonymized data for error detection

No data transfers outside the European Union without appropriate safeguards.

7. Your rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Access: obtain a copy of your personal data
  • Rectification: correct inaccurate data
  • Erasure: request deletion of your account and data
  • Portability: receive your data in a structured format
  • Objection: object to certain processing activities
  • Restriction: request restriction of processing

To exercise these rights: [email protected]. Response within 30 days.

8. Cookies

BFlow uses only technically necessary cookies required for service operation (authentication session). No advertising or tracking cookies are used.

9. Security

Data is hosted on secure servers in Europe (Hetzner, Germany). Passwords are encrypted (bcrypt). All communications are encrypted via HTTPS/TLS.