Summary: OxeChain collects only the data needed to operate the platform — your account info, activity data, and transaction records. We do not sell your personal data. You can request deletion of your account at any time by contacting support@oxechain.com.

1. Who We Are

OxeChain ("we", "us", "our") operates the earn-and-spend platform available at oxechain.com and through our mobile applications. We are responsible for your personal data under this Privacy Policy.

For privacy-related questions, contact us at privacy@oxechain.com.

2. Information We Collect

Account Information: When you register, we collect your username, email address, full name, and a securely hashed password (scrypt, 64-byte output). We never store passwords in plain text.

Activity Data: We record taps, task completions, trivia results, daily claims, referrals, and video submissions in order to calculate and credit your earnings correctly.

Transaction Records: All USDT balance changes, withdrawals, membership upgrades, and referral bonuses are logged for accuracy and dispute resolution.

Device & Session Data: We collect standard session data (IP address, browser type, device type) for security, fraud prevention, and analytics. We do not use third-party tracking cookies.

Profile Uploads: If you upload an avatar or (for Diamond members) a video, the files are stored securely on our servers.

3. How We Use Your Data

  • To operate and maintain your OxeChain account
  • To calculate, record, and credit your token and USDT earnings
  • To process membership upgrades and referral payments
  • To send transactional notifications (balance changes, task completions, membership status)
  • To prevent fraud, abuse, and unauthorized access
  • To comply with legal obligations
  • To improve the platform based on aggregate usage analytics

We do not use your data for advertising profiling or sell it to third parties.

4. Data Sharing

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

  • Service providers: Hosting, database, and infrastructure providers who process data on our behalf under data processing agreements.
  • Partner verification: When you present your QR code at a partner location, the partner can verify your membership tier only — no other personal data is shared.
  • Legal requirements: If required by law, court order, or government authority, we may disclose information as legally required.
  • Business transfers: In the event of a merger or acquisition, your data may transfer to the acquiring entity under equivalent privacy protections.

5. Data Security

We take security seriously at every layer:

  • Passwords are hashed with scrypt (64-byte key, 32-byte random salt) — never stored in recoverable form
  • All financial operations use MySQL transactions with SELECT FOR UPDATE to prevent double-spend
  • Admin authentication uses timing-safe comparison to prevent timing attacks
  • All API communications use HTTPS/TLS encryption
  • Session tokens are rotated on login and invalidated on logout

Despite these measures, no system is perfectly secure. If you discover a security vulnerability, please report it responsibly to security@oxechain.com.

6. Data Retention

We retain your account data for as long as your account is active. Financial transaction records are retained for a minimum of 5 years for legal and auditing purposes, even after account deletion.

Activity data (taps, tasks, trivia) is retained for 12 months rolling and then aggregated anonymously.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and personal data (subject to legal retention requirements)
  • Export your data in a portable format
  • Object to certain processing activities

To exercise any of these rights, contact privacy@oxechain.com. We will respond within 30 days.

8. Cookies

OxeChain uses only essential cookies required to maintain your login session and protect against CSRF attacks. We do not use advertising, tracking, or analytics cookies from third parties.

9. Children's Privacy

OxeChain is not intended for users under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us at support@oxechain.com and we will remove it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification and by updating the "Last updated" date above. Continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact

For privacy inquiries: privacy@oxechain.com
For general support: support@oxechain.com
Or use our contact form.