Privacy Policy
At SOQUPOOL we value your privacy and protect your personal data. We collect and use data only in accordance with this Privacy Policy ("Policy"). By accessing and using our services, you accept the terms of this Policy.
We may update this Policy to reflect changes in our technology, business practices, or legal requirements. When we make material changes, we will provide notice as required by applicable law, including the California Privacy Rights Act ("CPRA") and the General Data Protection Regulation ("GDPR"), and where required we will obtain your consent or give you the opportunity to exercise applicable rights before the changes take effect. Notice may be given by updating the "Last Updated" date above, posting a notice on our website, or other appropriate means. Changes become effective on posting. We encourage you to review this Policy periodically.
1. What data we collect
- Account information: username, email address, password (stored as a bcrypt hash), optional two-factor secrets, notification preferences, and your miner name.
- Institutional information (for institutional and genesis-tier applicants): entity identification number, proof of legal formation, proof of business address, and personal identification for material beneficial owners.
- Identity verification: identity documents are collected and held by our independent identity-verification processor (iDenfy), not by us. When the processor reports a verification result, document attributes are processed transiently to compute a salted one-way identifier used solely to enforce one identity, one account. What we retain is: that one-way identifier, the verification outcome, the processor's reference number, and any compliance screening flags the processor reports. We do not store your identity document, document images, document number, name as it appears on the document, or date of birth; those remain with the verification processor under its own privacy policy.
- Financial information: your payout (receiving) blockchain addresses and, for institutional applicants, source-of-funds and compliance records.
- Mining data: declared and actual hashrate, worker and rig identifiers, and share and reward records, including the IP address and user agent of each connecting rig. We may use IP-derived location to confirm that our service is used in permitted locations and to meet legal, regulatory, and contractual requirements.
- Technical and usage data: IP address, connecting stratum endpoint, browser type, operating system, session identifiers, and dates and times of sign-ins.
2. How we collect, use, and share your data
We collect data: when you provide it (for example when you apply for or use an account, or contact support); automatically when you use the service (our website keeps your session token in your browser's local storage rather than tracking cookies, and we do not run third-party analytics; our infrastructure providers may set strictly necessary operational cookies for security purposes such as bot mitigation); when you communicate with us; and from third parties, principally our identity-verification processor (verification outcomes and compliance screening results, as described above).
We process personal data only where necessary for lawful business activity, relying on: performance of contract (providing the mining service, crediting shares, and paying you); consent where we ask for it; legal obligation (KYC/AML, sanctions, and other legal duties); and legitimate interests (securing the service, detecting and preventing fraud, operating a compliant pool, and protecting the network from abuse such as Sybil or launch-emission attacks).
We may use your personal data to: verify your identity; perform sanctions and watchlist screening; detect and prevent fraudulent or unauthorized use; manage our business and your relationship with us; improve our products and services; respond to inquiries and resolve disputes; and, where you have opted in, send you notifications.
We may share your personal data with:
- Identity-verification services (our processor, iDenfy) to verify identity and prevent fraud, under a data-processing agreement.
- Service providers under contract (for example hosting, content delivery, email delivery, and professional advisers) who may use your data only to perform services for us and are prohibited from selling it.
- Blockchain networks: by the nature of public blockchains, your payout transactions and receiving addresses are recorded publicly on-chain.
- A successor entity in a merger, acquisition, or consolidation, which we will require to honor this Policy for your personal data.
- Affiliates that need the data to provide services you request.
- Regulators, law enforcement, or other government authorities where required by law, regulation, or valid legal process, including routine regulatory examinations.
3. Data storage and international transfers
SOQUPOOL and its processors may store and process your personal data outside the jurisdiction in which you reside, including in the United States, where laws may differ from those in your country. When we transfer data across borders we apply appropriate safeguards in accordance with applicable law. By accepting this Policy and submitting your personal data, you consent to such transfer, storage, and processing.
4. Sale of personal information
We do not sell, rent, or purchase personal information, and we do not disclose it to third parties for monetary or other valuable consideration.
5. Children's privacy
Our services are not directed to children and we do not knowingly collect personal information from them. In the United States we do not knowingly collect personal information from children under 13 (COPPA); in the EEA, the UK, and other applicable jurisdictions, not from individuals under 16 (or the applicable age of digital consent). Our vetted-access onboarding additionally requires government identity verification, which is limited to adults. If we learn we have collected such data, we will delete it promptly. If you believe a child has provided us data, please contact us.
6. Your rights
Subject to your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent. Some data cannot be deleted while legal retention obligations apply, and deleting verification data may require closing your account. Account deletion is available directly in the member console (Settings). To exercise any other right, contact us using the address in section 10.
7. How we protect your data
We protect your data with encryption in transit, password hashing (bcrypt), optional two-factor authentication (TOTP), a per-account stratum credential, a 48-hour freeze on payout-address changes, step-up verification on sensitive actions, dual-administrator control for privileged operations, and audit logging of privileged actions. No system is perfectly secure; in the event of a breach we will notify you and, where applicable, the relevant supervisory authority in accordance with law. You are responsible for safeguarding your login credentials.
If you choose to use a product or service offered by another company, any personal data you share with that company is subject to its privacy policy, not ours.
8. Retention
We retain personal data for the duration of your relationship with us and afterwards for as long as necessary for legitimate business purposes (including compliance with legal obligations, fraud prevention, dispute resolution, and enforcing agreements) and as required by applicable law. We retain the salted one-way identity identifier rather than any raw document identifier. We may retain anonymized and aggregated information, which does not identify you, for analytics and product improvement beyond these periods, and we maintain measures designed to prevent re-identification.
9. California and EU/EEA/UK rights
California residents may request that we disclose the categories and specific pieces of personal information we collect, the purposes for collection, and the categories of third parties with whom we share it, and, subject to exceptions, may request deletion. Under no circumstances do we sell your personal data.
If you are in the EEA, the UK, or Switzerland, you have rights under the GDPR and equivalent laws: access and a copy of your data; rectification; erasure in certain circumstances; restriction of processing; data portability; objection to processing (including for direct marketing); and withdrawal of consent (without affecting prior lawful processing). We may need to verify your identity before responding. You also have the right to lodge a complaint with a supervisory authority in your country.
10. Contact us
For questions, or to exercise your privacy rights, contact us at mining@soqu.org or at the address above. We respond in accordance with applicable privacy law, including the GDPR and the CPRA.