Skip to main content
Home/Legal/Privacy Policy

Privacy Policy

Last updated: 20 July 2026 (v2.1 — cookie section expanded, GDPR consent banner added) · Effective date: 29 June 2026

Operated by N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121)

NavScope (“we”, “us”, or “our”) is committed to protecting your privacy. This Policy is compliant with the Australian Privacy Act 1988 (Cth) — 13 Australian Privacy Principles (APPs) — and provides GDPR Article 6 / CCPA disclosures for EU, UK, and California residents.

Table of Contents

  1. About This Policy
  2. What Personal Information We Collect
  3. Webhook Delivery — Customer-Controlled URLs
  4. How We Use Personal Information
  5. How We Share Personal Information
  6. Fractional ID and Payment Attribution Data
  7. Data Retention
  8. Security of Personal Information
  9. Your Rights (APPs / GDPR / CCPA)
  10. Cookies and Local Storage
  11. International Data Transfers
  12. Complaints
  13. Policy Amendments

1. About This Policy

This Privacy Policy describes what personal information NavScope (N.S. IT SERVICES PTY LTD, ABN 75 122 740 121) collects about you, why we collect it, how we use and share it, how long we keep it, and your rights regarding it.

This Policy applies to all personal information collected through navscope.io, staff.navscope.io, NavScope’s APIs, webhook delivery services, and any interaction between you and NavScope.

This Policy does not apply to publicly available on-chain data, exchange market data, or public social media posts about cryptocurrency projects.

2. What Personal Information We Collect

Account Information

Email address; display name or username; hashed password; account creation timestamp; subscription tier and history.

Token Issuer Registration Data

Token name/symbol; contract address(es); project team name/entity; website URL; social media handles (X/Twitter, Telegram, Discord); contact email; DNS verification token; representations and warranties submitted.

Payment Data

Ethereum wallet address from which USDT payment was sent (recorded from blockchain); transaction hash; payment amount (USDT) and timestamp; Fractional ID; invoice ID and subscription period. NavScope does not collect credit card numbers, bank account details, or any fiat payment data.

Usage and Technical Data

IP address; browser type/version; operating system; referring URL; pages visited and timestamps; features accessed; API request logs.

Communications Data

Emails and support tickets; right-of-reply submissions (retained 7 years from publication per defamation limitation periods under the Limitation Act 1969 (NSW)).

Voluntary Wallet Tying

You may voluntarily associate an Ethereum wallet address with your NavScope account via the wallet-tying flow (POST /api/v1/public/checkout/wallets/tie and POST /api/v1/public/checkout/wallets/tie/verify). This involves signing a one-time challenge nonce with your Ethereum wallet (MetaMask or hardware wallet via personal-sign) and submitting the signed message to NavScope for verification. On successful verification, your Ethereum wallet address is stored in the customer_tied_wallets table, linked to your account. This collection is voluntary — it enables faster refund processing and simplified subscription renewal. The wallet address is retained for the duration of the account and 7 years after closure, consistent with payment record retention (see Data Retention table). You may untie a wallet at any time by contacting [email protected].

Webhook Configuration Data

Webhook endpoint URL(s); configuration settings (event types, filter criteria, authentication headers if provided); delivery logs (timestamps, HTTP response codes, retry counts, payload summaries) — retained for 30 days rolling, then auto-purged.

3. Webhook Delivery — Customer-Controlled URLs and Data-in-Transit

NavScope’s webhook service delivers NavScope market data events (token prices, gate statuses, narrative publication events) to HTTPS endpoints you configure. Webhook payloads do not contain personal information about NavScope customers or individuals.

Customer-Side Responsibility

You are the data controller for all NavScope market data received via webhooks and for any personal information you associate with that data on your own systems. You are solely responsible for: (a) the security of your webhook endpoint; (b) access controls to your endpoint server; (c) not embedding personal information in your registered endpoint URL.

Data-in-Transit Security

NavScope transmits webhook payloads using HTTPS with TLS encryption and optionally signs payloads with an HMAC-SHA256 signature (available to API subscribers) so you can verify authenticity. NavScope is not liable for security breaches at your endpoint or for misuse of NavScope data that you associate with personal information on your systems.

Delivery Log Retention

Delivery attempt logs (endpoint URL, HTTP status, retry count, payload summary) are retained for 30 days, then auto-purged. Customers may request a delivery log extract via [email protected] within the 30-day window.

4. How We Use Personal Information

  • Account creation and maintenance
  • USDT payment processing and attribution via Fractional ID
  • Provisioning subscribed services and delivering webhook events
  • Subscription invoicing, renewal reminders, and payment confirmations
  • Token Issuer verification (DNS TXT verification) and critical-question outreach workflows
  • Sanctions screening (OFAC / Australian DFAT) on incoming USDT transactions
  • Fraud detection, abuse prevention, and security monitoring
  • ATO tax compliance and potential AUSTRAC obligations
  • Aggregated, de-identified usage analytics for product improvement
  • Legal proceedings and regulatory compliance

5. How We Share Personal Information

No sale of personal information. NavScope does not sell, rent, or trade personal information to third parties for their marketing or commercial purposes.

Sub-ProcessorPurposeLocation
Hetzner Online GmbHCloud infrastructure hosting — servers, DB, object storage. DPA to be executed before first paying customer.Germany / Finland (EU)
Cloudflare, Inc.CDN, DNS, DDoS protection, TLS termination. Cloudflare processes request metadata only, not application-layer data.USA (EU SCCs / DPA)
Mailu (self-hosted)Transactional email delivery — hosted on NavScope's Hetzner servers. No third-party email SaaS.EU (Hetzner servers)
Blockchain analytics (OFAC screening)Wallet address and TX hash screening against OFAC SDN and AU DFAT sanctions lists.Varies by provider

NavScope may also share data with legal authorities (valid court order/subpoena) and business successors (merger/acquisition), subject to the same privacy commitments.

5b. Legal Basis for Processing (EU/UK GDPR — Article 6)

Processing ActivityLegal Basis
Account registration and authenticationContract (Art. 6(1)(b)) — necessary to provide the Service
Transactional emails (OTP, invoices, renewal notices)Contract (Art. 6(1)(b)) — essential service communications
USDT payment processing and attributionContract (Art. 6(1)(b)) — fulfilling the payment agreement
Webhook delivery to Customer-configured endpointsContract (Art. 6(1)(b)) — fulfilling the API subscription agreement
API access logging for rate-limiting and fair useLegitimate interests (Art. 6(1)(f)) — protecting service integrity
Sanctions screening (OFAC / AU DFAT)Legal obligation (Art. 6(1)(c)) — AML/CTF compliance
Anonymised usage analyticsLegitimate interests (Art. 6(1)(f)) — product improvement; opt-out available
Newsletter subscriptionConsent (Art. 6(1)(a)) — withdrawable at any time by unsubscribe

6. Fractional ID and Payment Attribution Data

When you make your first payment to NavScope, our system assigns you a permanent 6-decimal Fractional ID (e.g., .000123) embedded in every USDT invoice amount for the lifetime of your account.

The Fractional ID alone is not personally identifiable. However, when linked to your account in the customer_fractional_assignments table, it forms part of a personal information dataset. NavScope treats all associated records as personal information subject to APP protections.

Your Fractional ID is retained permanently for your account lifetime and for at least 7 years after account closure per ATO and potential AUSTRAC record-keeping obligations. For deletion requests, NavScope may retain the Fractional ID in pseudonymised form to comply with AML record-keeping obligations.

7. Data Retention

Data CategoryRetention PeriodBasis
Account information (email, name, tier)Account duration + 7 yearsATO + AU civil limitation
Payment records (TX hash, wallet, amount, Fractional ID)7 years from transactionATO + potential AUSTRAC
Fractional ID assignmentPermanent (pseudonymised after 7 years if closed)AML/CTF record integrity
OFAC/sanctions screening records7 yearsCompliance best practice
Token Issuer registration dataRegistration duration + 7 yearsAU civil limitation
Right-of-reply submissions7 years from article publicationDefamation limitation (NSW)
IP address and usage logs12 months rollingSecurity; abuse detection
Email and support records3 years from last communicationContract records
Webhook configuration (endpoint URLs, settings)Webhook subscription duration + 2 yearsService audit
Webhook delivery logs30 days rolling → auto-purgeTroubleshooting
Newsletter subscriber emailUntil unsubscription + 30 daysConsent-based

8. Security of Personal Information

  • All data in transit: HTTPS / TLS 1.3 encryption on all public-facing services.
  • Data at rest: AES-256 encryption for sensitive fields (including customer_fractional_assignments).
  • Passwords: one-way bcrypt hash — NavScope cannot read your plain-text password.
  • Hardware wallet custody: NavScope USDT treasury held in a Ledger hardware wallet under physical PM custody.
  • Webhook payload authentication: optional HMAC-SHA256 signature (API subscribers) for payload origin verification.
  • Access controls: personal data accessible only to NavScope staff requiring it for their role.
  • Data Breach Response (NDB scheme / GDPR Article 33): NavScope will notify the OAIC and affected individuals of eligible breaches as soon as practicable, and within 72 hours consistent with GDPR Article 33 obligations where applicable.

9. Your Rights (APPs / GDPR / CCPA)

Access (APP 12 / GDPR Art. 15)Request a copy of the personal data we hold about you.
Correction (APP 13 / GDPR Art. 16)Request correction of inaccurate or incomplete data.
Erasure / Deletion (GDPR Art. 17)Request deletion where data is no longer necessary, consent is withdrawn, or processing is unlawful. Erasure requests that conflict with legal retention obligations will be handled by de-identification.
Portability (GDPR Art. 20)Receive your personal data in a structured, machine-readable JSON format where processing is based on consent or contract and is automated.
Restriction (GDPR Art. 18)Request that NavScope restrict processing of your data while a correction is disputed or an objection is pending.
Objection (GDPR Art. 21)Object to processing based on legitimate interests. NavScope will cease processing unless it has compelling legitimate grounds.
Opt-out of marketingOpt out of non-essential communications (product updates, editorial announcements) at any time via the unsubscribe link or by emailing [email protected].
CCPA Rights (California residents)Right to know what personal information is collected; right to request deletion; right to opt out of sale (NavScope does not sell personal information); right to non-discrimination for exercising privacy rights.
ComplaintLodge a complaint with your national data protection authority (OAIC for AU; ICO for UK; local supervisory authority for EU).

How to exercise your rights

Email [email protected] with your request. NavScope will verify your identity and respond within 30 calendar days. Complex or numerous requests may be extended by a further 60 days with notification within the first 30 days.

10. Cookies, Local Storage & Your Consent

Cookie consent banner

On your first visit, NavScope displays a consent banner at the bottom of the page. You may accept all cookies, reject non-essential cookies, or manage preferences individually. Your choice is saved to navscope.cookie-consent in your browser’s localStorage and respected immediately. You can change your choice at any time by clearing that key or revisiting the banner (refresh after clearing localStorage).

Cookies and localStorage we set

Name / KeyTypePurposeCategoryRetention
navscope-auth-token (HTTP-only cookie)Session cookieAuthenticates your logged-in session to NavScope APIs. Set on login, cleared on logout or browser close.EssentialSession (browser close or logout)
navscope.cookie-consent (localStorage)localStorageRecords your cookie consent choice: version, selections (analytics, marketing), and timestamp. Used to avoid re-prompting and to gate optional trackers.Essential12 months, then re-prompt
ns-theme (localStorage)localStorageStores your dark/light theme preference so the site renders correctly on return visits. Never transmitted to our servers.EssentialIndefinite — user-controlled
ns-currency (localStorage)localStorageYour selected display currency (USD, EUR, etc.). Never transmitted to servers.EssentialIndefinite — user-controlled
ns-watchlist-* (localStorage)localStorageYour locally-saved watchlist tokens. Synced to server only when logged in.EssentialIndefinite — user-controlled
_ga, _ga_<id> (cookies)Persistent cookieGoogle Analytics 4 — distinguishes unique visitors and sessions for aggregate site analytics. Set ONLY when you consent to analytics cookies.Analytics (optional)2 years (_ga) / 1 year (_ga_<id>)

Third-party cookies

Google Analytics 4 (analytics — consent required)

When you consent to analytics cookies, NavScope loads Google Analytics 4 (gtag.js) from Google’s CDN. Google’s own privacy policy governs their processing of this data. IP anonymisation is enabled (anonymize_ip: true). Google acts as a data processor under a Google Ads Data Processing Terms agreement. Data may be processed in the USA under Standard Contractual Clauses.

If you do not consent to analytics, GA4 is blocked by setting window[‘ga-disable-<id>’] = true before the script loads. No GA4 data is collected in that case.

NavScope does not use advertising, retargeting, or cross-site tracking cookies. No Facebook Pixel, no Google Ads tags, no third-party remarketing scripts.

Your rights regarding cookies

  • Withdraw consentClear localStorage key navscope.cookie-consent and reload the page. The banner will re-appear and GA4 will be blocked until you consent again.
  • Access your dataRequest a copy of any personal data collected via analytics. Email [email protected].
  • Deletion / erasureRequest deletion of any analytics data associated with your browser. Google Analytics provides a Data Deletion Request mechanism; contact [email protected] to initiate.
  • PortabilityRequest your personal data in structured, machine-readable format. Email [email protected].
  • Browser-level opt-outYou may also use browser settings or extensions (e.g. uBlock Origin) to block all analytics scripts regardless of consent choice.
  • Google Analytics opt-outInstall the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout) to block GA4 at the browser level across all sites.

Cookie & privacy enquiries — Data Protection contact

For cookie consent questions, data access requests, or to exercise any GDPR right, contact our Data Protection Officer at [email protected]. We respond within 30 calendar days.

11. International Data Transfers

NavScope is an Australian company. Primary infrastructure is hosted with Hetzner Online GmbH in Germany (EU). By using the Platform, you acknowledge that your personal information may be transferred to and processed in Germany.

NavScope will execute a DPA with Hetzner Online GmbH prior to processing first paying customer’s personal data, governing Hetzner’s handling in accordance with APP 8 (Cross-Border Disclosure of Personal Information).

Where NavScope transfers personal data outside the EU/EEA (for example, to Cloudflare in the USA), NavScope relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms recognised under GDPR.

Supervisory Authority Contact Points

12. Complaints

Privacy Officer. NavScope has designated a Privacy Officer as the first point of contact for all privacy inquiries, access requests, and complaints.

Contact: [email protected]

NavScope will acknowledge your complaint within 5 Working Days and provide a substantive response within 30 days.

If you are not satisfied, you may lodge a complaint with the OAIC (www.oaic.gov.au) for Australian residents, or the relevant supervisory authority in your jurisdiction for EU/UK residents.

13. Policy Amendments

NavScope may amend this Privacy Policy at any time. Material amendments will be notified to registered Customers via email at least 14 days before they take effect. The current version of this Policy is always available at navscope.io/legal/privacy.

Privacy Contact

For all privacy enquiries, data requests, or to report a concern, contact our Privacy Officer at [email protected].

N.S. IT SERVICES PTY LTD · ABN 75 122 740 121 · ACN 122 740 121 · Australia