1. Introduction

The Insumer Model™ ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, applications, and services (collectively, the "Platform").

The Platform is operated by The Insumer Model LLC, 18 Locust Ave. #115, New Canaan, CT 06840, United States, which is the controller of the personal information described in this Privacy Policy.

By accessing or using the Platform, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Platform.

2. Information We Collect

Information You Provide

  • Business Information: When a business creates a store through the merchant API, we collect the business name, location, website, domain verification information, and its discount tier settings. Verified businesses may be listed in our public merchant directory.
  • Contact Information: If you contact us, we may collect your name, email address, and message content.
  • Newsletter: Our blog pages offer an optional newsletter signup. The signup form is provided and run by Substack and is loaded from Substack’s site. If you subscribe, you give your email address to Substack, which handles it under Substack’s privacy policy, and we can see the subscriber list as the newsletter’s publisher. You can unsubscribe from any newsletter email.
  • Earlier email signups: Apart from the newsletter, this website no longer collects email addresses for marketing. A small number of addresses gathered through earlier signup forms are still held by our email marketing provider (Mailchimp). You can unsubscribe from any message you receive, or contact us to have your address removed.

Information Collected Automatically

  • Wallet Addresses: When you connect a cryptocurrency wallet, we read your public wallet address to verify token holdings. We do not have access to your private keys or the ability to move your funds.
  • Token Holdings: We query public blockchain data to evaluate the conditions in an API request, a pass or a store’s discount tiers.
  • Usage Data: We may collect information about how you interact with the Platform, including scan logs, timestamps, and discount applications.
  • Device Information: Browser type, operating system, and device identifiers.
  • Website Analytics: Aggregate visit counts from Vercel Web Analytics, which does not use cookies, and, only if you agree, Google Analytics. See Cookies and Similar Technologies below.
  • Chat Conversations: When you use InsumerChat (our website chat widget), we process your messages to generate responses using an AI language model. Conversation content is not stored after the session ends.
  • Partner passes: When a member uses a pass from a partner app built on InsumerAPI, such as Skye Meta’s Bothy Pass, InsumerAPI signs the pass’s time-limited code and checks sticker taps for that partner. To do this we receive a summary of what the pass holds, a shortened wallet address and an anonymous session ID for the browser. The record of a tap keeps the result, not the wallet address; the session ID is removed within 24 hours, and tap records are deleted 12 months after the tap. The partner’s privacy policy covers the member’s account.

Blockchain Data

Our Platform interacts with public blockchain networks. All blockchain transactions are public by nature. We read publicly available blockchain data but do not store your complete transaction history.

What we store and what we don’t: Wallet addresses recorded with in-store scans are truncated before storage (e.g., 0x1234...abcd) and cannot be used to look up a wallet on a block explorer. Wallet addresses submitted via the API are not stored and are not logged in full, and conditions are not stored (see API Developer Information below). Actual token balances and NFT counts are never stored or logged. By default, API responses return only boolean (true/false) results, never raw balances. If the caller explicitly opts in to Merkle proofs (proof=“merkle”), raw on-chain data is included in the response so the caller can independently verify the result: for an ERC-20 balance this is a storage proof of the balance slot, and for a native-asset balance it is an account proof carrying that account’s balance, nonce, and code hash. This opt-in data is not stored by our systems. All blockchain queries are transient and used only to determine eligibility at the moment of verification.

API Developer Information

  • API Key Registration: When you register for an InsumerAPI key, we collect your email address, application name, and a hashed version of your IP address for rate limiting.
  • API Usage Data: We record which endpoints you call, timestamps, and credit usage. Wallet addresses submitted in API verification requests are not stored and are not logged in full. Conditions are not stored. When a blockchain read fails, the public contract address involved may appear in error logs and operator alerts so the failure can be diagnosed, and we keep a technical cache of which storage slot a token contract uses for Merkle proofs; neither is linked to a wallet or an API key. We keep a record that a verification took place, its result, and when, tied to the API key that made it — or, for per-call payments made without a key, to the payer identity described under Payment Information below — but not the wallet, the conditions, or any balance. Wallet addresses are passed to upstream blockchain data sources to perform the read. Standard platform request logs, which do not include request contents, are retained for up to 30 days. By default, API responses return only boolean results. A balance reaches the caller in two cases only: when the caller opts in to Merkle proofs, as described above, and on ratio-to-supply conditions for older (v1) API keys, where the response states the wallet’s share of the token’s supply. Raw balances are never logged or stored. If you authenticate with a wallet signature instead of an API key (wallet auth), the signing wallet is your account identity rather than a wallet being verified: we store it with your API identity and with the single-use sign-in record that prevents a signature from being replayed, and it may appear in operational logs.
  • Payment Information: Paid API subscriptions are processed by Stripe. We store your Stripe customer ID and subscription ID but never your card number or payment details. For crypto credit purchases (USDC, USDT, or BTC), we store the transaction hash, sender wallet address, chain, amount, and — for BTC — the exchange rate at time of verification, for payment verification and fraud prevention. The sender wallet address from your first crypto purchase is registered to your API key; subsequent purchases must originate from the same wallet unless explicitly updated. The same applies to x402 pay-per-call payments: we store the payer wallet address, transaction reference, and amount for payment verification and fraud prevention, together with a one-way fingerprint of the request, which prevents a payment being reused for a different request and does not contain the wallet or the conditions themselves (settlement records are deleted after 90 days), and the payer wallet is registered to an API identity on first payment.

Telegram Bot

Our Telegram bot (@insumermodelbot) responds to direct messages and @mentions in group chats. We process message content to generate responses but do not store conversation history. Telegram usernames and chat IDs are not persisted.

3. Cookies and Similar Technologies

This section lists what the website stores in your browser or reads from it, and why.

Change your cookie settings

  • Google Analytics (only with your consent): Google Analytics helps us see how the site is used. It sets cookies and is loaded only after you choose Accept on the cookie banner. If you choose Decline, or make no choice, it is not loaded. If your browser sends a Global Privacy Control signal and you have not made a choice, we treat that as Decline and do not show the banner. You can change your choice at any time with the “Cookie settings” link in the footer of most pages or in this section; if you withdraw consent, we stop Google Analytics on this site and remove its cookies from our domain. Google handles this data under Google’s privacy policy.
  • Your cookie choice: We remember your Accept or Decline choice in your browser’s local storage, so we do not ask on every page. It stays on your device.
  • Vercel Web Analytics: Our hosting provider counts page visits in aggregate. It does not use cookies and does not follow you across other websites.
  • Session storage for API keys: When you create or enter an API key on some of our developer pages, the key is kept in your browser tab’s session storage so the code samples can fill it in for you (and, on the XRPL demo, so the live request can use it). It is not sent to anyone other than our own API, and it is cleared when you close the tab.
  • Newsletter form: The newsletter signup on blog pages is loaded from Substack, which may set its own cookies under Substack’s privacy policy.
  • Fonts: Our web fonts are served from our own domain. No font requests go to a third party.

4. How We Use Your Information

We use the information we collect to:

  • Evaluate wallet conditions and return signed results to API callers
  • Verify token ownership for discount eligibility
  • Process and display appropriate discounts at checkout
  • Maintain and improve the Platform
  • Provide customer support
  • Generate analytics and usage statistics
  • Prevent fraud and ensure platform security
  • Comply with legal obligations
  • Issue and manage API keys for developers
  • Enforce API rate limits and prevent abuse
  • Process API subscription payments through Stripe

5. Information Sharing

We do not sell your personal information. We may share information in the following circumstances:

  • Service Providers: We may share information with third-party vendors who assist in operating the Platform (e.g., hosting, analytics).
  • Legal Requirements: We may disclose information if required by law or in response to valid legal processes.
  • Business Transfers: In connection with any merger, acquisition, or sale of assets.
  • Payment Processors: Stripe processes payments for paid API subscriptions. See Stripe's Privacy Policy.

Skye Meta: The merchant dashboard, Skye Meta’s in-person scanner, Bothy membership passes and the browser extension are provided by Skye Meta Corp, a separate company. When you use them, Skye Meta’s privacy policy covers the personal information Skye Meta collects through them.

6. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption of data in transit (HTTPS)
  • Time-limited cryptographic signatures for QR codes
  • Read-only blockchain access (we cannot move your tokens)
  • Regular security assessments
  • API keys hashed with SHA-256 before storage. The plaintext key is shown once at creation; for card checkouts it is held server-side for up to 30 minutes solely so it can be displayed once after the payment redirect, then deleted.
  • ECDSA P-256 cryptographic signatures on API verification responses, each accompanied by a post-quantum companion signature (ML-DSA-65, FIPS 204) so that responses remain verifiable if the classical signature scheme is broken in future
  • By default, API and discount responses return tier-level or boolean results (e.g., "Gold tier, 10% discount" or true/false), not raw balance amounts. A balance reaches the caller only in the two cases described under API Usage Data above: Merkle proofs, which include raw on-chain data for independent verification and which the caller opts in to per request, and ratio-to-supply conditions on older (v1) API keys. Where a response names a wallet (the subject of a JWT-format result, and agent and delegation conditions), it is the wallet the caller submitted.

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

7. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request a copy of the information we hold about you.
  • Correction: Request correction of inaccurate information.
  • Deletion: Request deletion of your information, subject to legal retention requirements.
  • Disconnect: You can disconnect your wallet at any time, which stops us from reading your token holdings.

To exercise these rights, contact us at the information provided below.

EEA and UK Residents (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the right to access, correct and delete your personal information, to restrict or object to our use of it, to receive it in a portable format, and to withdraw consent at any time without affecting earlier processing. You also have the right to complain to your local data protection authority (in the UK, the Information Commissioner’s Office).

We rely on these legal bases:

  • Contract: to provide the API service you sign up for, including API keys, credits, subscriptions and support.
  • Legitimate interests: to keep the Platform secure, prevent fraud and abuse, and enforce rate limits.
  • Consent: for Google Analytics cookies. You can withdraw it with the “Cookie settings” link in the footer of most pages, or in the Cookies section above.
  • Legal obligation: where the law requires us to keep or disclose information.

California Residents (CCPA/CPRA)

We do not sell personal information, and we do not share it for cross-context behavioral advertising. Google Analytics runs only if you agree to it, and we honor Global Privacy Control signals as described in Cookies and Similar Technologies. You have the right to know what personal information we collect and how we use it, to ask us to delete or correct it, and not to be treated differently for using these rights.

How to Exercise Your Rights

Email support@insumermodel.com with your request. We may ask you to confirm the request from the email address linked to your account or API key, so that we only act on requests from the right person.

8. Data Retention

We retain information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law. Scan logs and analytics data may be retained for statistical purposes.

For API developers: keys remain active until revoked, the associated subscription ends, or — for crypto-purchased keys — their 30-day validity period lapses. Standard platform request logs, which do not include request contents, are retained for 30 days and then deleted. Rate limit records are purged after 24 hours.

9. Third-Party Services

The Platform integrates with third-party services including:

  • Blockchain Networks: 37 chains — 31 EVM networks including Ethereum, Base, Polygon, Arbitrum and Optimism, plus Solana, XRP Ledger, Bitcoin, Tron, Stellar and Sui
  • Wallet Providers: MetaMask, Phantom, Coinbase Wallet
  • Google Analytics: For website traffic analysis, only if you agree to analytics cookies
  • Vercel: Website hosting and cookieless, aggregate visit counts
  • Substack: Runs the optional newsletter signup on blog pages
  • Mailchimp: Holds email addresses gathered through earlier signup forms; no longer used to collect addresses through this website
  • Anthropic: For AI-powered chat responses (InsumerChat and Telegram bot)
  • Data Providers: CoinGecko for token metadata
  • Firebase: For real-time data synchronization
  • Stripe: For paid API subscription payments
  • Blockchain Data Providers: Independent upstream data providers for blockchain data queries
  • Cloudflare: For DNS, CDN, and security services

These services have their own privacy policies, and we encourage you to review them.

10. Children's Privacy

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of the Platform after changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Last Updated: October 7, 2026