This Privacy Policy (“Policy”) describes how 3Box Labs, our related products, including but not limited to Ceramic, IDX, and self.ID ( “we”, “our”, or “us”) collects, uses, shares, and stores Personal Information when app developers and other users (“you”) use 3Box Labs, Ceramic, IDX, self.ID, and all related tools, applications, websites, data, software, infrastructure, and other services we provide (the “Products, Services, and Network”).
By accessing or using the Products, Services, and Network you accept this Policy and our Terms and Conditions, and you consent to our collection, use, disclosure, and retention of your Personal Information as described in this Policy. If you do not agree with any part of this Policy or our Terms and Conditions, you must stop accessing the Products, Services, and Network. To exercise any rights you may have over your Personal Information, please see the section on Your Choices below.
Our Products, Services, and Network are blockchain-agnostic and leverage distributed-data-storage systems, so nearly all data is kept directly with you and other users and not on our servers, computers, or other systems and devices. To help you manage your data and content, our Products and Services allow you to create and link an Account or Decentralized ID (“DID”). These features are intended to give you more control over your data and privacy-preserving options to choose how your Personal Information is shared and used by other applications or services. For example, to the extent any data is stored privately on the Products and Services, it is unreadable by other apps and users unless you expressly grant others permission to access your data.
If you shared your data with other users or a third-party app hosted on or linked to the Products, Services, and Network, you should look to the privacy policy and any terms those third parties or dApps. We do not control third-party apps and are not responsible for how they may treat your Personal Information.
When you visit our Sites or use our Products, Services, and Network, we may collect information that could identify you directly or indirectly (“Personal Information”). Personal Information does not include publicly available information or any data that has been deidentified, aggregated, or otherwise anonymized.
We only collect the minimum information needed to provide the Products, Services, and Network including:
We will never ask you to share your private keys, wallet seed, or other sensitive Personal Information. Trust no one that asks you to enter your private keys or wallet seed.
Cookies, tags, and similar technologies are small pieces of code placed on your browser, device, or hard drive when you visit a website or use an application (“Cookies”).
We are not responsible for the completeness, effectiveness, or accuracy of any of these or other third party opt-out options or programs.
We use the Personal Information we collect for:
We may use Personal Information for other limited purposes consistent with the purposes for which we collected that information. We will not use Personal Information for materially different or incompatible purposes without first taking reasonable steps to notifying you and, if necessary, obtain your consent.
We only disclose or share Personal Information with others with your consent or when permitted by applicable law, including under these circumstances:
We retain Personal Information only for as long as it is necessary and relevant to fulfill the purposes for which it was collected. We may retain Personal Information longer if we must do so to comply with applicable law. Once we no longer need to retain Personal Information, we permanently delete it or we may anonymize it so the Information can no longer be associated with a specific individual.
We use industry-standard security measures to protect the security and confidentiality of Personal Information. However, the security of information transmitted through or stored on the internet can never be guaranteed. To the fullest extent permitted by law, we are not responsible for any interception, interruption, or loss of data through the internet. You are responsible for maintaining the security of any password, user ID or other form of authentication involved in obtaining access to password-protected or secure areas of any of our Products, Services, and Network. We may suspend use of any aspect of the Products, Services, and Network without notice if we suspect any breach of security or similar issues.
Our Products, Services, and Network allow you to share information through other third-party applications, including dApps, or websites. These links are provided solely as a convenience to you if you share content. When you visit third-party websites or applications, those third parties may collect your Personal Information along with all content you share. We do not control those websites and applications, and we are not responsible for how they may treat your information. We encourage you to check the privacy policies and terms of those websites and applications to learn more about their practices.
You may review, opt-out of sharing, correct, or delete your Personal Information through your Account at any time or by contacting us at support@3box.io.
California residents may have additional rights over their Personal Information.
You may have the right to request more information about how we treated your Personal Information in the past 12 months, including:
You also may have the right to request access to your Personal Information.
Under certain conditions, you may have the right to request that we delete your Personal Information. Simply logging out does not delete your account or the Personal Information we may have collected.
We do not provide your information to third parties for their direct marketing purposes. Neither do we intend to sell your personal information to third parties without providing you notice and an opportunity to opt out.
To submit a request to exercise these rights you may contact us at support@3box.io. For all requests, please clearly state that the request is related to “Your California Privacy Rights” and provide your name, Account or DID name, Ethereum public key and an e-mail address or mailing address where you may be reached.
If you make a request, we will acknowledge we have received it within ten days. If you do not receive a response, please ensure your request was submitted and send a follow up email to support@3box.io.
Before we can respond to your request, we must verify your identity using Personal Information. If we cannot verify your request, we will contact you for more information. If we cannot verify your identity after a good faith attempt, we may deny the request and, if so, will explain the basis for the denial.
You may designate someone to submit requests and act on your behalf (an “Authorized Agent”). To do so, you must provide us with written permission to allow your Authorized Agent to act on your behalf.
If you are located in the European Economic Area, you may have additional rights over your Personal Information.
Some of the information you provide us may constitute sensitive data as defined in the GDPR (also referred to as special categories of personal data), including identification of your race or ethnicity on government-issued identification documents.
We only use your Personal Information as permitted by applicable law, including:
We operate from the United States. This means your Personal Information may be transferred to or from the United States where privacy laws may not be as protective as those in your jurisdiction.
We transfer Personal Information between the European Economic Area (“EEA”) and the U.S. or other countries based on a data transfer mechanism recognized by the European Commission as adequately protecting personal information.
We will maintain your Personal Information for as long as reasonably necessary to accomplish the purposes for which it was collected, or as otherwise required or permitted by law.
If you are an individual in the EEA, you have the following additional rights over your Personal Information:
To submit a request to exercise these rights please contact us:
Email: support@3box.io.
For all requests, please clearly state that the request is related to “Your EU Privacy Rights” and provide your name, Account or DID name, Ethereum public key and an e-mail address or mailing address where you may be reached.
If you make a request, we have one month to respond to you. We may require you to verify your identity before we may respond to you.
Although we urge you to contact us to find a solution for every concern, you have the right to lodge a complaint with your competent data protection authority.
The Products, Services, and Network are not intended for children under age 13, and we do not knowingly collect Personal Information from children under 13. If we discover we have Personal Information related to a child under 13 we will delete that information.
If you are under the age of majority in your jurisdiction of residence, you may use the Products, Services, and Network only with the consent of or under the supervision of your parent or legal guardian.
If you are the parent or legal guardian of a child under 13 or minor and you believe we have collected your child has used our Site or Products and Services without your permission, please contact us at support@3box.io.
We may change this Policy. We encourage you to periodically review this page for the latest information on our privacy practices. If we make any material changes, we will take reasonable steps to notify you and, if necessary, obtain your consent. We will take your continued use of the Products, Services, and Network after any new Policy is posted as an indication you accept the modified Privacy Policy.
If you have questions or concerns about this Policy, please contact us at support@3box.io.