Privacy Policy

Effective date: June 21, 2026

This Privacy Policy explains how Teqll ("Teqll", "we", "us", or "our") collects, uses, stores, and protects information about you when you use our platform. By creating an account or using Teqll you agree to the practices described here.

1. Information We Collect

Account information. When you sign up we collect your email address and, once you choose one, your username and display name. We also store a hashed password (managed by Supabase Auth — we never see your plaintext password) or, if you sign in with Google, the OAuth identity token issued by Google.

Profile information. You may optionally provide a profile photo, bio, location, and links to external profiles. Only information you choose to add is stored.

Wallet address. If you connect and verify a cryptocurrency wallet, we store the public wallet address. We never request, store, or have access to your private key or seed phrase.

Transaction and deal data. We store records of deals created on the platform including deal terms, status, messages exchanged between parties, and any evidence submitted in a dispute. On-chain transactions are also publicly visible on BNB Smart Chain; we do not control the public blockchain record.

Usage and technical data. We collect standard server-side logs (IP address, browser type, pages visited, timestamps) to operate and secure the platform. We do not use third-party analytics trackers or advertising SDKs.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate you on sign-in.
  • Facilitate deals between buyers and sellers, including displaying counterparty wallet addresses and usernames to each other for verified transactions.
  • Send transactional emails: email verification, password reset, deal notifications, and dispute updates. We do not send marketing emails without your explicit consent.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Respond to support requests and resolve disputes.
  • Comply with legal obligations, including responding to valid legal process.

We do not sell, rent, or trade your personal information to any third party for their own marketing purposes.

3. Data Storage — Supabase

Your account and profile data, deal records, and messages are stored in a PostgreSQL database hosted by Supabase. Supabase stores data in the AWS region selected at project creation. Supabase's privacy and security practices are described in their Privacy Policy.

Row-Level Security (RLS). Our database enforces row-level security policies so that each user can only read and write their own data. Deal data is visible only to the buyer, the seller, and Teqll administrators. Public profile information (username, display name, avatar, bio) is readable by any authenticated user to support the marketplace.

Server-side access only. The Supabase service-role key — which bypasses RLS — is stored only as a server-side secret and is never exposed to the browser or to any client-side code.

4. Wallet Address Handling

Your blockchain wallet address is a pseudonymous identifier; it does not by itself reveal your name or contact details, but it is permanently visible on the public blockchain. We store your verified wallet address in our database to link it to your account for deal creation.

Your wallet address is shared with a deal counterparty (buyer or seller) once a deal is created, so that both parties can verify the on-chain transaction. We do not display wallet addresses on public profile pages visible to unauthenticated visitors.

Wallet connection and transaction signing happen entirely in your browser through your own wallet software (e.g. MetaMask, WalletConnect-compatible wallets). Teqll never intermediates the private key or signs transactions on your behalf.

5. Authentication and Session Security

Authentication is managed by Supabase Auth. Sessions are stored as HTTP-only, secure cookies. We support optional multi-factor authentication (MFA) via time-based one-time passwords (TOTP); we strongly recommend enabling MFA on your account.

If you sign in with Google (OAuth), we receive your Google email address and a unique identifier from Google's OAuth service. We do not receive your Google password. Google's data practices are governed by Google's Privacy Policy.

"Keep me signed in" sessions persist for up to 30 days of inactivity. Standard sessions expire after the browser is closed.

6. File and Media Uploads

Profile photos and listing images you upload are stored in Supabase Storage, a cloud object store. Uploaded files in public storage buckets are accessible to anyone with the URL; private bucket files are accessible only to authenticated users with the appropriate permissions. We do not analyse the content of uploaded files beyond basic virus scanning at the infrastructure layer.

7. Data Retention

We retain your account information for as long as your account is active. Deal records are retained for a minimum of 7 years after deal closure to meet financial record-keeping obligations and to support dispute resolution. Inactive accounts (no login for 3 years) may be flagged for deletion; you will be notified by email before any deletion occurs.

On-chain data (transactions, wallet addresses, deal IDs) recorded on BNB Smart Chain cannot be deleted — the blockchain is a permanent public record outside our control.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate personal data.
  • Erasure — request deletion of your account and associated off-chain personal data, subject to our legal retention obligations.
  • Restriction — request that we limit processing of your data in certain circumstances.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.

To exercise any of these rights, contact us through the support channel in your account settings. We will respond within 30 days. Some rights may be limited where we have a legal obligation to retain data or where the data relates to an open or disputed deal.

9. Cookies and Tracking

We use essential cookies to maintain your login session. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics services that track you across the web. If we introduce non-essential cookies in future, we will update this policy and provide an opt-out mechanism.

10. Third-Party Services

We use the following sub-processors to operate the platform:

  • Supabase — database, authentication, and file storage.
  • WalletConnect — wallet connection relay (no personal data beyond public wallet address is transmitted).
  • BNB Smart Chain (public blockchain) — immutable record of on-chain transactions.

We do not share personal data with any other third parties except as required by law or to protect the rights and safety of our users.

11. Security

We implement industry-standard technical and organisational measures to protect your data, including encrypted connections (TLS), row-level security in the database, server-side secret management, and optional MFA. No system is perfectly secure; if you discover a security vulnerability please disclose it responsibly through our security contact.

12. Children's Privacy

Teqll is not directed at children under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page and notify registered users by email or in-platform notification. Material changes will be notified at least 14 days in advance. Your continued use of the platform after the effective date of any change constitutes your acceptance of the revised policy.

14. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us through the support channel in your account settings or via the contact details published on the Teqll website.