Pre-release Privacy Notice
Last updated: 26 July 2026 · prelaunch-2026-07-26
Pre-release legal draft
The current website has no player accounts, wallet connection, token purchase, real-money gameplay, marketing sign-up or first-party analytics. Technical network data may still be processed by the hosting provider and external services requested by the browser.
This pre-release draft has not been approved by local counsel. Mandatory local law and local-language rights continue to apply.
1. Controller and contact
The legal data controller, registered address, company number, privacy email, data-protection officer and any required EU or UK representative have not yet been published. These details are mandatory launch blockers and this draft must not be treated as a complete commercial privacy notice.
Until a dedicated privacy email is published, the official XTAP Telegram is the public project contact. Do not send identity documents, payment information, private keys or seed phrases through Telegram.
2. Data currently processed
The current website may involve:
- IP address, request time, URL, referrer, browser/device details and security logs processed by the hosting or delivery provider;
- the selected language code stored in window.name for continuity within the current browser tab;
- network request data sent directly by the browser to Binance APIs to display public BTC/USDT information;
- network requests to Google Fonts to deliver typefaces; and
- messages voluntarily sent to the project through an external social platform.
3. Data not requested by this website
This version does not ask for account registration, email subscriptions, identity documents, payment information, wallet addresses, private keys or seed phrases. Standard infrastructure logs are still personal data in many jurisdictions and are not described as “no data collection”.
4. Purposes and legal bases
Technical data may be used to deliver and secure the website, prevent abuse, remember the selected language, display requested market information and answer messages. The operator must document a lawful basis for each purpose before publication of the final notice; consent must not be used as a universal basis.
5. Recipients and external services
The current deployment uses Netlify for hosting and may involve Google Fonts and Binance. X, Telegram, PinkSale and blockchain explorers receive data after a visitor chooses to open their service. Each third party applies its own terms and privacy notice.
The final notice must confirm the actual legal names, roles, processing countries and contracts of every hosting, security, analytics, support, KYC, payment or infrastructure provider.
6. Cookies and browser storage
The current version does not intentionally set first-party cookies, use localStorage or load first-party analytics. It stores the selected language code in window.name for tab-level continuity.
Analytics, advertising, fingerprinting or non-essential storage must not be activated until the required consent mechanism and updated notice are in place.
7. Retention
Exact retention periods for hosting/security logs and project messages have not yet been confirmed. The controller must publish a period or objective criterion for each data category and must implement deletion and backup-retention procedures before commercial launch.
8. International transfers
External providers may process data outside the visitor’s country. Where required, the controller must identify the destinations, recipients and lawful safeguards, such as an adequacy decision or approved contractual clauses. No transfer mechanism is claimed in this draft before the operator and contracts are confirmed.
9. Privacy rights
Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. California residents may have additional rights if the CCPA applies.
The final notice must identify the request channel, verification method, response deadlines and competent supervisory authority. Request data may be used only to process and document the request.
10. Future processing and automated decisions
Before accounts, wallet connections, identity checks, transactions, marketing or real-money features are enabled, this notice must be updated with the exact data categories, purposes, legal bases, processors, retention, transfers, profiling, fraud controls and regulatory obligations.
The current website does not make automated decisions producing legal or similarly significant effects. Future eligibility, fraud, sanctions or player-protection systems require a separate disclosure and assessment.
11. Children
The website and planned real-money service are not directed to minors. Future participation must require age and identity controls appropriate to each permitted jurisdiction. Identified minor data must be handled and deleted according to applicable law.
12. Security, complaints and updates
Proportionate technical and organisational safeguards are used, but no internet service can guarantee absolute security. Visitors must never send private keys or seed phrases.
The final operator must publish an incident contact, privacy request email and competent supervisory authority. Material changes will be shown with a new effective date.