Privacy Policy
WAI Quest
Version: 2026-07-18
Effective: 18 July 2026
Site: https://www.waiquest.xyz
Companion document: Terms & Risk (same version)
1. Controller and contact
Data controller: The WAI Quest product operators (community hub for $WAI).
Privacy / PDPA contact:
| Channel | Detail |
|---|---|
| Web | https://www.waiquest.xyz |
| Official X | @WEALWAYIN |
| Telegram group | t.me/waitrust |
| Telegram channel | t.me/WAIcommunity |
Mark the message Privacy or PDPA, and include the relevant wallet address if you want us to locate records.
If a separate legal entity is formed later, this policy will be updated with registered name, address, and official email.
2. Data we may store
| Category | Examples | Why |
|---|---|---|
| Wallet data | Solana address used for SIWS, chain | Account, quests, leaderboard |
| In-app profile | Optional handle, role, cached points | Community identity and ranking |
| Session | httpOnly cookie, session row, expiry | Stay signed in; revocable |
| Submissions | URLs, text, tx signatures, evidence | Verify quests, anti-fraud, receipts |
| Linked social | Provider (e.g. X), handle, account id, verified time | social_link quests, anti-sybil |
| Technical logs | Hashed IP, user-agent (if stored), API timing | Security, rate limits, abuse control |
| Terms acceptance | Terms version and acceptance time | Record of agreement |
| On-chain reads | $WAI balances, txs, hold snapshots | Quest verification |
We do not ask for ID/passport by default.
A wallet address alone can still be linkable to a person with other data — we treat it carefully.
We never ask for or store your private key or seed phrase.
3. Purposes and legal bases (PDPA-oriented)
| Purpose | Typical basis |
|---|---|
| Run community features: quests, points, leaderboard, transparency | Contract / necessary to provide the service you request |
| Authenticate via SIWS and (if used) OAuth | Contract / necessary to provide the service |
| Prevent fraud, sybil farming, and abuse | Legitimate interests and/or necessary for a safe service |
| Security and technical logging | Legitimate interests |
| Comply with law when required | Legal obligation |
If we later use non-essential analytics that need consent, we will ask separately and allow withdrawal.
4. Processors / third parties
We may use processors such as:
| Provider | Role |
|---|---|
| Vercel | App hosting, network, Vercel Analytics (aggregate usage) |
| Neon | Postgres database |
| Solana RPC (e.g. Helius) | On-chain balance/tx reads — wallet address as needed for queries |
| X (Twitter) | OAuth 2.0 when you choose Link with X — id/username per granted scopes |
We do not sell user lists for third-party marketing.
We may disclose data when required by law or to protect rights, security, or investigate fraud lawfully.
5. International transfers
Servers and vendors may be outside Thailand.
We use industry-standard providers and process only what is needed for the purposes in this policy.
6. Retention
We keep data as long as needed for:
- Active accounts and limited-lifetime sessions
- Points ledger and submission history for transparency and review
- Anti-fraud and banned-wallet records for a reasonable period
- Legal retention requirements
After a ban or account closure we may keep minimal data to prevent re-abuse.
Append-only ledgers may not silently delete history — revocations are recorded instead.
7. Your rights (PDPA and similar)
Where applicable you may have rights to access, correct, object, restrict, withdraw consent (where consent is the basis), and complain to a regulator.
Limits: Full erasure may not be possible where data is needed for anti-fraud, legal duties, or immutable ledger/receipt design.
Requests go through section 1. We may require proof of wallet control (e.g. SIWS) before releasing data.
8. Cookies and similar tech
| Type | Use |
|---|---|
| Session cookie (necessary) | Signed-in state (httpOnly) |
| Local storage (technical) | Remember Terms checkbox for the current version on this device |
| Analytics (Vercel Analytics) | Aggregate traffic to improve the product |
If we add non-essential marketing cookies later, we will seek consent as required.
9. Social accounts (X OAuth)
When you choose Link with X:
- You authorize on X’s site
- We store only what is needed to bind the account (e.g. X user id, username, verified time) to your wallet user
- One X account maps to one wallet under system rules (anti-sybil)
- We do not use OAuth to post or DM as you by default
You can avoid social quests if you do not want to link. Unlinking may be restricted after use for fraud control.
10. Users in and outside Thailand
- Residing in Thailand (any nationality): this policy and PDPA protections may apply.
- Outside Thailand: we still process technical and wallet data needed to run the service; local rights may also apply — contact section 1.
We do not grant nationality-based exemptions for features that are unlawful in Thailand (e.g. gambling).
11. Security
We use measures appropriate to the service (httpOnly cookies, revocable sessions, hashed IPs for rate limits, admin gated by wallet list).
No system is 100% secure. Significant breaches will be handled as law and good practice require.
12. Changes
We may update this policy with a new version and date.
Material changes will be posted on the site and/or tied to Terms re-acceptance at next sign-in.
13. Disclaimer
This policy describes product data practices. It is not personal legal advice. Update sections 1 and 4 when entity structure or main processors change.
Changelog
| Version | Date | Notes |
|---|---|---|
| draft-2026-07-15 | 2026-07-15 | First M5 draft (Thai source) |
| 2026-07-18 | 2026-07-18 | Complete published EN edition |