RSVPPrivacy Policy · v1.0

Privacy Policy · Version 1.0

Your privacy
at RSVP

A walk through every part of RSVP: what we see at each step, why we need it, and who else can see it.

Privacy Policy v1.0·RSVP Token ($RSVP)·Reserve Tech·One global standard

What we do

✓Collect identity details only when you mint or redeem, because the law requires it before dollars change hands.
✓Keep names, documents and contact details off the blockchain, always.
✓Share information only with those RSVP needs in order to work, and with authorities when the law demands it.
✓Put a person in charge of any refusal an automated check suggests.
✓Delete or anonymise information once its job is done.

What we never do

✕Ask for your private keys or recovery phrase.
✕Sell, rent or trade personal information.
✕Use advertising cookies or follow you around the web.
✕Ask about your health, beliefs, ethnicity, sexuality or political views.
✕Charge you, or treat you worse, for using a privacy right.

Public by design

A wallet's history on BNB Smart Chain, including every transfer, mint, burn, stake and on-chain vote, can be read by anyone and can never be wiped. We can erase what we hold; nobody can erase the chain. Section 04 explains how to live with that.

Part One · The Basics

01RSVP Privacy in One Minute

Most privacy policies are organised around types of data. This one follows you instead. Each part of RSVP you might use has its own short section that says what we see, why, who else sees it and how long it stays. The rules that hold everywhere come after that.

02Who Runs RSVP and Where This Policy Stops

In short The RSVP Token Foundation answers for your information across every RSVP service. Wallets, exchanges, Earn partners and the DAOs you join answer for their own.

RSVP Token ($RSVP) is a governance token on BNB Smart Chain, issued one-for-one against USD held in reserve. The RSVP Token Foundation ("the Foundation", "we") operates the services around it and decides how personal information is handled in them. "You" is anyone we hold information about, whether you hold RSVP, vote, contribute, buy our services or simply sent us an email.

2.1 Covered here

This policy applies to rsvp.io, rsvp.finance and rsvp.network; to the gateways where verified participants deposit and redeem USD; to our smart contracts; and to our support desk, community spaces, events and surveys. Together we call these the Services.

2.2 Covered elsewhere

If you are dealing with…
Whose policy applies
Your wallet app, an exchange or a bridge
Theirs
An Earn partner platform
Theirs, under its own terms
A DAO built on our DAO-as-a-Service platform
The DAO's. It decides what to ask its members, and we handle that information only on its instructions
A website or app we link to
Theirs. We don't control it, so read its policy before you share anything

2.3 The same standard everywhere

We don't run a strong policy for some places and a thin one for others. Everyone gets the protections in this document and its Annex. Where a rule that binds you, or us, goes further than we do, the stricter rule wins.

Part Two · Your Journey Through RSVP

03When You Browse Our Sites

In short Your browser tells us a little about your device and what you click. We use it to keep the sites working and to learn what confuses people, never to advertise.
What we see
Browser, device type, operating system, language and time zone; your IP address and the city or country it points to; pages opened, buttons clicked, searches and errors.
Why
Keeping pages fast, secure and in your language (running the service); spotting what needs fixing (running it safely); counting visits, only if you allow measurement cookies (your yes).
Who else sees it
Our hosting and analytics providers, acting for us.
How long
Cookies expire within 24 months at most. Logs are cleared once they stop being useful for security or fault-finding.

3.1 Cookies in three kinds

Kind
Its job
Can you refuse?
Essential
Holds your session, routes traffic, blocks attacks
No, the sites need them
Preferences
Remembers language, display settings and notices you closed
Yes
Measurement
Counts visits, pages and errors, reported only in totals
Yes

3.2 Saying no

  • The cookie settings panel on each site, at any time.
  • Your browser's own cookie controls. Blocking essential cookies will break some features.
  • Google's opt-out add-on for Google Analytics: https://tools.google.com/dlpage/gaoptout
  • A tracker-blocking browser or extension.

04When You Connect a Wallet

In short Connecting a wallet shows us a public address. Everything that address does on-chain is visible to the world and permanent, so we keep anything that identifies you off the chain.
What we see
The address you connect and whatever the chain already shows about it: balance, transfers, mints, burns, stakes and votes.
Why
Showing your balance and letting you sign actions (running the service); flagging addresses tied to theft, fraud or sanctions (running it safely).
Who else sees it
Everyone. Public chain data can be read by anyone with a block explorer. Blockchain analytics providers also score addresses for us.
How long
On the chain: forever. In our systems: while you keep using the Services.

4.1 A notice board nobody can wipe

BNB Smart Chain is copied across independent computers worldwide. Once something is written there, no one, the Foundation included, can edit or remove it. That covers the mint recorded when you deposit, the burn recorded when you redeem, and every transfer in between.

An address carries no name, but it stops being anonymous the moment someone can tie it to you. When you ask us to erase your information we clear everything we control; the chain is the one place we cannot reach.

4.2 What stays off the board

  • Names, identity documents and contact details never go on-chain.
  • When an on-chain entry needs to point to a file, it carries a pseudonymous reference or salted hash, and the file itself sits in access-controlled storage.
  • Gateway permissions are attached to addresses, not recorded as facts about people.

05When You Get Verified

In short Before USD changes hands, the law requires us to know who you are. Checks are partly automated, but a person decides any refusal.
What we see
Name, date of birth, nationality, identity document, tax number, proof of address, source-of-funds evidence and a selfie or liveness capture; the results of sanctions, politically exposed person and adverse media screening.
Why
Anti-money-laundering, sanctions and counter-terrorist-financing laws require these checks before we mint or redeem (legal duty).
Who else sees it
Identity verification and screening partners, bound by contract to use it only for us.
How long
At least five years after your last transaction or the end of our relationship, and longer if an authority or a legal case requires it.

5.1 Machines check, people decide

Our partners compare your document with your selfie, test that the selfie is live, and run your details against screening lists. If any of that points towards refusing or limiting you, a member of our compliance team looks at it before the decision stands. You can ask why, send us anything we missed, and ask for a second look.

Your selfie serves one purpose: confirming that the person matches the document. The verification result stays in our systems and is linked to your address only as a yes-or-no permission.

06When You Mint or Redeem

In short Each deposit and redemption leaves a record tying dollars to tokens. Your bank and our custodians see what they need; the public sees the token movement, not your name.
What we see
Amounts and dates, the bank account you pay from or are paid into, the reserve reference, the wallet that receives or burns tokens, and the status of each request.
Why
Issuing exactly one RSVP per USD received and returning USD when you redeem (running the service); keeping the records the law requires (legal duty).
Who else sees it
Reserve custodians and banks that move the money; the accounting firm that attests the reserve each month; authorities where the law compels disclosure.
How long
At least five years, the same as verification records.

07When You Vote, Stake or Run a DAO

In short Governance is public by nature. We hold the account details behind it, and DAOs using our platform decide what they ask of their members.
What we see
Your forum profile and posts, proposals you file, votes you sign and staking positions; for organisations buying DAO-as-a-Service, business contact and billing details; for contributors paid through our payroll tools, their wallet and payment schedule.
Why
Operating the governance, staking, payroll and escrow tools you or your DAO use (running the service); billing and accounting (legal duty).
Who else sees it
The public, for votes, proposals and forum posts; the DAO you belong to, for its own member and payroll records.
How long
Public records: permanently. Account records: while you use the Services. Billing records: as long as accounting rules require.

When a DAO runs on our platform, it chooses what to collect from its members and why. We keep the tools running and follow its instructions; its own policy tells you the rest.

08When You Use Earn or an Exchange

In short Earn partners and exchanges are independent businesses. We exchange only what is needed to confirm eligibility or complete your instruction.
What we see
A partner's confirmation that you are eligible for Earn, the wallet involved, and the details needed to settle an instruction you gave the partner.
Why
Routing rewards and settling transactions you asked for (running the service).
Who else sees it
The partner, under its own privacy policy and terms.
How long
While you take part, then as long as our records of the program require.

Earn rewards come from partner platforms, not from the RSVP token contract, so each partner decides what it collects to run them. Read its policy before you join.

09When You Talk to Us or Join In

In short Messages get answered, news goes only to people who asked for it, and campaign details are kept only as long as the campaign needs them.
What we see
Messages and attachments, survey answers, call recordings (only when we say beforehand that a call is recorded), newsletter choices, and entries to hackathons, bounties, ambassador programs and giveaways.
Why
Answering and fixing things, and running campaigns (running the service); newsletters and event invitations (your yes).
Who else sees it
Our support, email and AI service providers, acting for us.
How long
Support: until resolved, plus a follow-up period. Newsletter: until you unsubscribe. Campaigns: until prizes are delivered and eligibility questions are closed.

9.1 Where AI helps

Some support work is assisted by AI services, including large language models, for example to sort tickets, suggest replies or summarise community feedback. We use providers whose terms bar them from training their own models on your information, and we never feed identity documents or bank details into these tools.

Part Three · Rules for Everything

10Lines We Don't Cross

In short Some things are off the table whatever you use. A few things become fair game once information can no longer identify anyone.
We never…
Because
Ask for private keys or recovery phrases
Nobody at RSVP ever needs them. A request for them is a scam.
Sell, rent or trade personal information
Your data is not our product, and we don't hand it to others for their marketing.
Put identity details on-chain
What goes on-chain can't be corrected or removed.
Ask about sensitive traits
Health, beliefs, ethnic origin, sexual life, union membership and political views have no place in RSVP.
Track precise location or open your device's contents
The approximate area from your IP address is all we see. Contacts, photos and files stay yours.
Reuse your verification selfie
It exists only to match you to your document.
Start a new use without checking
A new purpose must fit why we collected the information. If it doesn't, we tell you and, where needed, ask first.

10.1 Totals we can use freely

When information is combined and stripped until it can't be traced to anyone, such as the number of active DAOs or average voter turnout, it is no longer personal. We may publish and share figures like these.

11Keeping It Safe

In short Protection in layers, a clear drill when something fails, and one job only you can do.
Layer
What we do
In our systems
Encryption in transit and at rest; access only for people whose role needs it; separate environments for sensitive data; logging and monitoring
With our providers
Security and privacy checks before we sign; written terms that carry our standard to them and to anyone they use
In our code
Independent review of smart contracts before deployment
In our team
Confidentiality undertakings and regular training

11.1 When something fails

We contain the problem, work out what happened and write it down. If it puts you at real risk, you hear from us, as does anyone else we are required to inform, within the time allowed.

11.2 Your job

Your keys and recovery phrase are yours alone to guard. Keep them offline, never share them, and check that the address bar shows an official RSVP domain before you connect a wallet.

12Information Across Borders

In short Our people and providers work in several countries. Wherever your information goes, the same standard goes with it.

Your information may be stored or viewed outside the country you live in, including in places where privacy rules differ from yours. No provider receives it until we have checked how it treats data and signed terms that bind it to our standard. Where a destination offers less protection than we promise, we add technical and contractual measures to close the gap.

13Your Controls

In short Tell us what you want to happen to your information. It costs nothing, and asking never counts against you.
If you want to…
Ask us to…
Good to know
Know what we hold
Send you a copy
We confirm it's you first
Correct a mistake
Fix it everywhere we store it
On-chain records can't be changed
Leave
Delete your information
We tell you what the law makes us keep
Freeze things during a dispute
Limit how we use it
Normal use resumes once it's settled
Move to another service
Export what you gave us
In a common, machine-readable file
Stop a particular use
Stop it
Marketing always stops; other uses we weigh against safety needs
Change your mind
Withdraw your agreement
Earlier use stays valid
Challenge an automated result
Have a person review it
See Section 05

13.1 Making a request

Email privacy@rsvp.io with what you'd like. We confirm your identity first, and for a wallet we may ask you to sign a short message with it.

13.2 When we can't agree

We may have to refuse if a request would expose someone else's information, stop a service you have asked us to provide, conflict with a record the law requires, or undermine a legal claim. If so, we explain why.

13.3 Unsubscribing

Every newsletter carries an unsubscribe link. Service messages, such as security alerts and changes to our terms, keep coming while you use the Services.

14Young People

In short RSVP is built for adults.

We don't design the Services for anyone too young to agree to how their information is used, and we don't knowingly collect their information. Tell us at privacy@rsvp.io if you think that has happened.

15When This Policy Changes

In short Every version is numbered, dated and announced when it matters.

The cover shows the version and effective date of what you are reading. For significant changes we also let you know directly, through a notice in the Services or by email. If you keep using the Services once a new version applies, that version governs.

16Getting in Touch

In short One address, one named person on your case, and a route upwards if you are not satisfied.
Contact
Details
Privacy email
privacy@rsvp.io
Responsible organisation
RSVP Token Foundation
Official websites
rsvp.io · rsvp.finance · rsvp.network

Each message is acknowledged, given to a named person and answered in full within the time that applies to that kind of request. If the answer doesn't satisfy you, ask for a review and the Foundation's governing body will consider it. You remain free to take a concern to any authority able to hear it.

Annex

AGlobal Privacy Commitments

In short Our standard, stage by stage, with the evidence you can ask to see.
Stage
We commit to
Which means
Evidence you can ask for
Before we collect
Explain first
What we want, why, and who will see it, in plain words
The numbered, dated version of this policy
Before we collect
Ask for the minimum
Every item earns its place through a stated purpose
A list of what we hold about you, and why
While we hold it
Stay on purpose
New uses are checked for fit before they start
An explanation of any use you didn't expect
While we hold it
Keep it accurate
Corrections reach every system
Confirmation that a correction was made
While we hold it
Protect in proportion
Safeguards match sensitivity and potential harm
A description of the measures on your data
While we hold it
Never sell
No selling, renting, trading, or handing over for others' marketing
A direct answer to any concern you raise
When its job is done
Let go
Deletion or permanent anonymisation once the purpose ends
How long each category is kept
Whenever you ask
Show our work
Evidence for every commitment, reviewed on a regular cycle
An explanation of a decision about you
Whenever you ask
Treat you equally
No fee, poorer service or penalty for using a right
A review if you believe you were treated differently

To ask for any of this, write to privacy@rsvp.io.

This policy sits alongside the RSVP Terms of Use, the RSVP Token Whitepaper v1.0 and any product terms that apply to you. It describes our practices and is not legal, tax or investment advice.

← Back to RSVP Token