Privacy Policy
This policy describes what Your Ripple Coin Effect collects, why, and what we do with it. It is written against the actual database behind the service rather than from a template: where it says something is not collected, there is no field for it.
The short version. A coin's journey is public — that is the point of it. Your precise location is not. An email address is held only if you chose an email-and-password account, and it never appears on a coin. We do not sell data or run advertising.
1. Who we are
Your Ripple Coin Effect operates this website, the mobile app, and the service behind the code engraved on each coin. For questions about this policy or about your data, write to privacy@yourripplecoineffect.com.
2. What we collect
| What | Why we hold it |
|---|---|
| Sign-in identifier | If you used Apple or Google: an opaque identifier from them, plus which of the two you used. That is not your email address, and in that case we never receive one. If you made an account here: the email address you chose. Either way it is what lets us recognise you on your next visit. |
| Email address | Held only for accounts created with an email and a password. Used to tell one account from another and to let you recover yours. Never published, never attached to a coin, never sold. |
| Password | Held only for those accounts, and only as a scrypt hash. We cannot read your password and cannot tell you what it was. |
| Display name | A first name and a last initial, shown publicly on the coins you have carried. |
| Language and time zone | To write dates correctly and to avoid sending you a notification in the middle of the night. |
| Your kindness entries | A category, a note of up to 140 characters, and a city label. These are public. |
| Precise location | Recorded when you log or claim a handoff, to confirm two people were actually together. Never shown publicly. |
| Approximate location | A deliberately coarsened version of the above. This is the only location anyone else sees. |
| Session records | Your IP address, your browser or app identifier, and an irreversible hash of your session token. Used to keep you signed in and to detect stolen sessions. |
| Device records | Platform, notification token, and a device identifier used to stop a person passing a coin to themselves. |
| Order records | If you buy a coin: the amount, a payment reference, and the shipping address you gave Stripe. Card details go directly to Stripe and never reach us. |
| Automatic checks on what you write | Before a note appears on a coin, it is checked automatically — for language, and for things that should not be on a public page, like a phone number or an email address. Most notes pass and appear straight away. When one does not, the coin still moves and the note waits for a person to read it; you are told, and nothing on the coin's page says anything happened. Your display name is checked the same way when you choose it. Where an outside provider is used for this check, the text of the note is sent to them and nothing else about you — see who else sees it below. |
| Feedback you send | If you use the feedback button: what you wrote, and — so that a report is actionable — the app version, your device model, the operating system version, the screen you were on, your language and time zone, and a short log of the last requests your app made. No note text and no location goes into that log. If you attach a screenshot we hold the image; you are shown it before it is sent and can leave it out. Reports are read by us, and one may be turned into a work item in our own issue tracker, which is not published. |
| Beta requests | If you ask to join the beta: the email address, a name if you give one, which phone you have, anything you wrote in the box, and the date. Confirming the address is what puts you on the list, and every message we send carries a link that takes you off it. If we approve the request, the address is passed to Apple so TestFlight can send you the invitation. |
3. What is public
Anyone who holds a coin — or knows its code — can see its whole journey: every kindness written on it, the display name of each person who carried it, the approximate area of each handoff, when it happened, and how far the coin has travelled.
Please write notes on that basis. A note is limited to 140 characters, it is public the moment it is committed, and it becomes part of a record other people share.
4. How location is handled
This is the part worth reading twice, because we treat two things differently.
- Precise coordinates are used once, at the moment of a handoff, to check that the two people were plausibly in the same place. They are never published and never shown on a map.
- A coarsened location is derived from them and is what appears publicly. It identifies a general area, not a building.
If you decline location access, you can still claim a coin inside the handoff window. The hop is simply marked for human review instead of being verified automatically.
5. What we do with it
- Run the service: showing journeys, transferring coins, and keeping you signed in.
- Confirm that handoffs are real, and detect abuse such as passing a coin to yourself.
- Send notifications you have asked for, at reasonable hours in your own time zone.
- Fulfil and support orders, where you have placed one.
We do not sell personal data, we do not share it with advertisers, and we do not use it to build advertising profiles.
6. Who else sees it
- Apple and Google — they verify who you are when you sign in. We check the proof they issue and then discard it; it is never stored.
- Stripe — our payment processor. If you buy a coin, the card and the delivery address are given to Stripe rather than to us: they take the payment, they email the receipt, and what comes back to us is the amount, a payment reference and the address to post to. We never hold a card number. Their own privacy policy covers what they do with it.
- Apple and Google push services — deliver notifications to your device.
- Our hosting and network providers — carry the traffic that serves these pages.
- Apple TestFlight — only if you asked to join the beta and we approved it. Apple receives the email address so it can send you the invitation, and nothing else about you.
- A content-screening provider — only if one is switched on for this service. It receives the text of a note, on its own, to answer one question: should a person read this before it is published. It is not told who wrote it, which coin it is on, or where. It is not used to train anything. If no provider is switched on, notes are checked by this service alone and no text leaves it.
We may also disclose information where the law genuinely requires it.
7. How long we keep it
Account and session data is kept while your account is active. Session records expire on their own. Order records are kept as long as tax and accounting rules require.
A coin's journey is kept indefinitely, because it is a shared record. The entries on a coin belong to everyone who has carried it, and deleting one person's line would break the chain for all of them.
A note that was held for a person to read is kept exactly as long as the note itself, whether it ends up published or not. What the check found is kept with it, so a decision about somebody's words can be explained later.
Feedback is kept while the problem it describes is still worth fixing. If you erase your account, everything personal in your reports goes with it — what you wrote, the screenshot, the logs, the device details — and what is left is the record that somebody once reported the bug.
A beta request is kept until you take the address off the list, which the link in every message does. A request we have already acted on keeps only the fact that it was made and what was decided.
8. Deleting your account
You can ask us to erase your account. When you do, we anonymise rather than delete: your identifiers, display name and device records are removed, and the entries you wrote remain on their coins with no name attached to them.
We are being direct about this because it is a real trade-off rather than a technicality. Full deletion would tear holes in journeys that other people are part of. If that is not acceptable to you, please do not write a note you would later want removed.
9. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, ask for erasure as described above, object to certain processing, or complain to a data protection authority. Write to privacy@yourripplecoineffect.com and we will respond.
10. Children
This service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
11. Security
Traffic is encrypted in transit. Session and handoff tokens are stored only as irreversible hashes, so a copy of our database does not yield a working token. Reusing an already-rotated session token revokes the whole family of tokens it belongs to, which limits the damage a stolen one can do.
12. Changes
If this policy changes materially we will update the effective date above and, where the change affects how your data is used, tell you in the app.