Privacy Policy
The short version
DollarParking has no accounts, no sign-up, no KYC, and no custody of your funds. We never ask for your name, email, phone number, or ID, and we never see your private keys or recovery phrase. The only thing that identifies you to us is your public wallet address. Your transaction history and profit/loss are computed and kept on your own device, not on our servers. This policy explains exactly what we do store, and why.
What we never collect
We do not collect your name, date of birth, email address, phone number, postal address, government ID, ID documents, selfies, bank account details, or card details. There is no identity-verification (KYC) step anywhere in the service. We do not collect, store, or transmit your private keys or recovery phrase — they never leave your wallet, and we could not access your funds even if we wanted to. We do not use advertising cookies of our own, we do not sell your data, and we do not share it with data brokers or ad networks.
Your wallet address is the identifier
When you connect a wallet, we receive its public address. That address is the only user identifier we use. It is pseudonymous rather than anonymous: it does not contain your name, but it is persistent, it is publicly visible on the blockchain, and anyone who learns that the address belongs to you can link it to everything it has ever done on-chain — including activity that has nothing to do with DollarParking. If you want your DollarParking activity kept separate from other activity, use a separate address.
What we store on our servers
Our database holds only the following, each keyed by your public wallet address: (1) Watchlist — the address plus the ticker symbols you saved, so your watchlist follows you across devices. (2) Wallet activity — the address plus timestamps for when it was first seen and when it last connected, disconnected, or acted, so we can count how many wallets use the service. (3) Referral attribution — if you arrived through a partner link, the address plus that partner's name and the date, recorded once on a first-touch basis and never overwritten. (4) Order audit trail — one append-only record per order event, holding the order hash, your address, whether it was a buy or a sell, the ticker, and what we asked your wallet to sign at what price, so that a reimbursement claim can be reconstructed if an order goes wrong. Each record is chained to the previous one by a hash. We also cache non-personal operational data (token prices, exchange rates) that is not linked to any user.
What stays on your device
Your transaction history, holdings, and profit/loss are built on your device from public blockchain data and stored there — in your browser's IndexedDB on the web, and in local app storage on mobile. This is a deliberate design decision: we chose not to run a server-side index of per-wallet financial history, so we never become the holder of that record. Your language preference, your record of accepting the Terms of Service, and your trade-limit settings are also stored locally. Clearing your browser data or uninstalling the app erases all of it; nothing is lost that cannot be rebuilt from the blockchain.
Cookies
We set two of our own cookies, neither used for advertising: dp_locale, which remembers your language for one year, and dp_ref, which remembers a referral partner for 90 days if you arrived through a partner link. Google Analytics sets its own cookies on the website (see below). The mobile app does not use cookies.
Analytics
The website uses Google Analytics 4 to measure how people move through the service — wallet connections, token approvals, orders submitted, and whether they succeeded or failed. We enforce a hard rule in code: analytics never receives your wallet address or any other raw identifier. Order events carry only the ticker symbol, whether it was a buy or a sell, a success or failure flag, the chain ID, and the size as a coarse bucket (under $100, $100–1k, $1k–10k, over $10k) rather than the exact amount. Google independently processes standard web data such as your IP address, device, and browser under its own privacy policy. The mobile app contains no analytics — we do not measure usage inside the app at all. It does send crash reports, which the next section describes. If you would rather not be measured, a browser setting or ad blocker that blocks Google Analytics is enough; the service works normally without it. Google privacy policy
Crash reporting
The mobile app uses Sentry to report crashes and errors so we can fix them. A report carries the error and its stack trace, the app version, and device and operating-system information. We keep it deliberately narrow: session replay is disabled, so the app never records your screen; Sentry's default personal-data collection is turned off, so the software development kit attaches no IP address or other personal context; app logs are not shipped; and we never attach your wallet address to a report. The website does not use Sentry. Sentry privacy policy
Sanctions screening
To comply with sanctions law, we check your wallet address against the Chainalysis sanctions oracle when you connect and before an order is quoted. The check is a read of public on-chain data; we do not send your address to a third-party screening company, and we cache the result for up to one hour. If your address is flagged, access is restricted. This is required — see the Terms of Service for the sanctions and prohibited-jurisdiction terms. Terms of Service
Blockchain data is public and permanent
Every transaction and order you sign is recorded on the Ethereum blockchain, which is public and permanent. That record is created by the network, not by us. We cannot edit it, hide it, or delete it, and no privacy policy — ours or anyone else's — can. Anyone can look up your address and see its full history. Please treat this as the baseline reality of using any on-chain service.
Who else receives data
Using the service necessarily involves third parties we do not control: your wallet (for example MetaMask) handles the connection and signing; the UniswapX order service receives your signed order, which includes your address, because that is how the order reaches the market; Ondo Global Markets supplies token and price data, which we fetch server-side without sending any user data; an Ethereum RPC provider serves blockchain reads, which we route through our own server by default so your IP address is not exposed to it; Google Analytics receives website usage data as described above; Sentry receives mobile-app crash reports as described above; and our hosting providers (Vercel for the website, Amazon Web Services for the API and database) process data on our behalf. These parties handle data under their own policies, and the third-party terms in our Terms of Service apply to them.
Server logs
Our API and our hosting providers keep standard technical logs — IP address, browser user agent, requested path, and timestamps — for security, abuse prevention, and debugging. When you place an order, the server briefly handles your wallet address in order to build and relay that order, but does not store it in our database beyond the order record described above.
Where data is processed
Our API and database run on Amazon Web Services in the Seoul region (ap-northeast-2). The website is served by Vercel's global network, and the third parties listed above operate internationally. If you use the service from another country, your data will be processed outside it.
How long we keep it
Watchlist entries are kept until you remove the symbol. Wallet-activity and referral records are kept while we operate the service. Order-audit records are kept for 5 years from the order and deleted after that; they are excluded from deletion requests because they are the evidence we would use to adjudicate a reimbursement claim, and because each record is hash-chained to the previous one, so removing a row would destroy the integrity of the trail. Price and exchange-rate caches are overwritten continuously and hold no user data. Data on your own device stays until you clear it.
Your choices and requests
You can clear everything held on your device at any time by clearing your browser storage or uninstalling the app. You can remove watchlist symbols yourself. You can block analytics with a browser setting or ad blocker. You can disconnect your wallet, or use a different address, at any time. If you want us to delete the database rows tied to your address, message @dollarparking on Telegram — the data-deletion page sets out the exact steps, what is removed, and what is kept. Two limits we cannot get around: the order-audit trail is retained for 5 years, and nothing on the blockchain can be deleted by anyone. Delete your data @dollarparking on Telegram
Security
Traffic is encrypted in transit. Because our servers hold no private keys, no custody of funds, and no identity documents, the worst case for our database is limited: it would expose already-public on-chain addresses along with the watchlist symbols and activity timestamps tied to them. That is a deliberate consequence of the design, not an accident. No system is perfectly secure, and we make no guarantee that a breach cannot happen.
Children
The service is not directed to anyone under 18, and we do not knowingly collect data from children.
Changes
We may update this policy. The date at the top of this page shows when it last changed, and continued use after an update means you accept the revised policy.
Contact
Questions about this policy. Deletion requests go to @dollarparking instead — see Your choices and requests above. Telegram