1. Purpose and Scope
This Privacy Policy ("Policy") describes how Purch ("Purch," "we," "us," or "our") collects, processes, uses, stores, and discloses personal data in connection with your access to, or use of, Purch's AI-powered shopping assistant, website, software, and related services (collectively, the "Services"). By accessing or using the Services, you confirm that you have read, understood, and agreed to the data-processing practices set forth herein.
2. Key Definitions
"Personal Data" means any information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person.
"Processing" refers to any operation performed upon Personal Data, whether or not by automated means, including collection, recording, storage, retrieval, disclosure, or erasure.
"Service Provider" means a third party that processes Personal Data on Purch's behalf pursuant to a written agreement imposing data-protection obligations.
3. Categories of Personal Data Collected
Purch collects the following categories of Personal Data:
- Account and Authentication Data: Wallet addresses, cryptographic signatures, and authentication tokens when you connect your wallet or create an account through Privy.
- Commerce and Shipping Data: Name, email address, and physical shipping address when you make purchases.
- Technical and Transactional Data: Transaction hashes, blockchain network identifiers, device identifiers, IP addresses, browser information, and session logs.
- Conversation Data: Chat messages, prompts, AI assistant responses, product searches, and interaction history to provide and improve our shopping assistant services.
- Preference Data: Size preferences, style preferences, and shopping history to personalize recommendations.
4. Sources of Personal Data
Purch obtains Personal Data directly from you when you connect a wallet, create an account, submit shipping information, chat with our AI assistant, or otherwise interact with the Services. We also gather information automatically through technical mechanisms such as cookies and log files, as well as through blockchain explorers that record publicly broadcast transactions. Additionally, Personal Data may be received from third-party integrations you elect to use, such as Crossmint for smart wallet functionality or Privy for authentication.
5. How We Use Your Data
Purch uses Personal Data to:
- Verify identity and authenticate your wallet connection
- Process and fulfill your product purchases
- Coordinate shipping with third-party vendors
- Provide personalized product recommendations
- Improve our AI shopping assistant's accuracy and relevance
- Monitor for fraud, security threats, or violations
- Perform analytics and product improvements
- Comply with legal and regulatory requirements
- Communicate with you about orders, updates, and support
6. Legal Basis for Processing
Purch processes Personal Data only where permitted by law:
- Contractual Necessity: Processing required to authenticate sessions, process orders, and fulfill purchases you initiate.
- Legitimate Interests: Processing for platform security, fraud detection, and service improvement, provided such interests do not override your rights.
- Legal Obligations: Processing to comply with applicable laws, including financial crime prevention and consumer protection statutes.
- Consent: Where required, we obtain your consent for optional processing activities such as marketing communications.
7. Data Sharing and Disclosure
Purch discloses Personal Data to carefully vetted service providers that deliver infrastructure, cloud hosting, analytics, payment processing, or logistics support under confidentiality and data-processing agreements. These include:
- Crossmint: For smart wallet creation and management
- Privy: For authentication services
- Shipping Partners: To fulfill and deliver orders
- Product Vendors: To process and ship purchased items
Personal Data may also be disclosed to competent authorities when compelled by legal process or when necessary to investigate fraud, security incidents, or violations. Purch does not sell or rent Personal Data for monetary or other valuable consideration.
8. Data Retention
Purch retains Personal Data only for as long as reasonably necessary to achieve the processing purposes outlined in this Policy or to satisfy legal and regulatory requirements. Shipping addresses and order information are retained for the duration necessary to complete orders and handle any disputes or returns. After the retention period, Personal Data is securely deleted or irreversibly anonymized.
9. Data Security
Purch employs administrative, technical, and physical measures designed to safeguard Personal Data against unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of sensitive data in transit and at rest
- Shipping addresses and sensitive personal information are stored encrypted
- Secure authentication through Privy
- Role-based access controls for internal personnel
- Regular security monitoring and assessments
However, no Internet-based system can guarantee absolute security, and you remain responsible for protecting your wallet credentials and account access.
10. Your Rights
Subject to applicable law, you may have the right to:
- Request access to your Personal Data
- Seek rectification of inaccuracies
- Request erasure or restriction of processing
- Receive your Personal Data in a portable format
- Object to certain processing activities
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at info@purch.xyz. We will verify your identity and respond within the timeframe required by law.
11. Children's Privacy
The Services are not directed to, and Purch does not knowingly collect Personal Data from, individuals under the age of 18. If we discover that we have inadvertently processed such data, we will delete it without undue delay.
12. Cookies and Tracking
Purch uses cookies and similar technologies for authentication, session management, and security purposes. These are essential for the proper functioning of the Services. We do not use non-essential tracking cookies without your consent where required by law.
13. International Data Transfers
Because Purch's infrastructure and service providers may be located outside your jurisdiction, Personal Data may be processed in countries with different privacy laws than where you reside. Where required, we rely on appropriate safeguards to ensure cross-border transfers maintain adequate protection.
14. Changes to This Policy
Purch reserves the right to amend this Policy at any time. Revisions will be posted with an updated effective date. Continued use of the Services after the posting of an amended Policy constitutes acceptance of the changes. Material changes will be communicated via reasonable means, such as in-app notices or email.
15. Contact Information
Questions, requests, or complaints regarding this Policy or Purch's data-processing practices may be directed to:
Email: info@purch.xyz
© 2025 Purch. All rights reserved.