Privacy Policy

Effective date: April 24, 2026

RealSun (“RealSun”, “we”, “us”, or “our”) operates the website at realsun.infoand related services (collectively, the “Service”), which enable users to invest in fractionalized solar-power NFTs, earn on-chain rewards, and transfer RSP points. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

1. Information We Collect

1.1 Information You Provide

  • Account data: email address, password hash, full name, and profile preferences you supply at sign-up or in account settings.
  • Wallet data: public blockchain addresses you link to your account for receiving RSC rewards or holding fragments.
  • Transaction data: NFT purchases, sales, marketplace listings, dividend payouts, and RSP transfers.
  • Support communications: messages, attachments, and contact details you send when you contact us.

1.2 Information Collected Automatically

  • Usage data: pages visited, features used, timestamps, and referring URLs.
  • Device data: IP address, browser type, operating system, device identifiers, and language preferences.
  • Cookies & similar technologies: authentication cookies, session tokens, and locale cookies. See Section 6 for details.

1.3 Information from Third Parties

We receive limited information from service providers that help us operate the Service, including Supabase (auth and database), Resend (transactional email delivery), and blockchain RPC providers (public on-chain activity tied to a wallet address you connect).

2. How We Use Information

  • To create and secure your account and authenticate sign-ins.
  • To record, process, and settle NFT purchases, sales, dividend distributions, and RSP transfers.
  • To send transactional emails (verification, password reset, payout confirmation) through our email-delivery provider.
  • To comply with applicable legal, tax, accounting, and anti-fraud obligations.
  • To monitor, troubleshoot, and improve the reliability and performance of the Service.
  • To communicate with you about product updates, security notices, or changes to these terms.

3. Legal Bases (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with similar rules, we process your personal data on the following bases: (a) performance of a contract to provide the Service; (b) compliance with legal obligations; (c) our legitimate interests in operating, securing, and improving the Service; and (d) your consent, where required (for example, for non-essential analytics or marketing).

4. How We Share Information

We do not sell your personal information. We share data only with:

  • Service providers acting on our behalf under confidentiality obligations (e.g., Supabase, Resend, hosting providers).
  • Blockchain networks. When you receive RSC or NFT transfers, the transaction is recorded on a public blockchain and cannot be erased or reversed by us.
  • Legal and safety disclosures when required by applicable law, regulation, legal process, or to protect the rights, property, or safety of RealSun, our users, or others.
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets, with notice to you where required by law.

5. Data Retention

We retain personal data for as long as your account is active and for a reasonable period thereafter to satisfy our legal, tax, accounting, and fraud-prevention obligations. Transaction records that are required for regulatory or audit purposes may be retained longer. On-chain data is, by design, permanent and outside our control.

6. Cookies

We use strictly necessary cookies to keep you signed in, remember your locale, and secure form submissions. We do not use third-party advertising cookies. You can control cookies through your browser, but disabling strictly necessary cookies may prevent the Service from functioning.

7. Security

We use industry-standard safeguards — including TLS in transit, encrypted data at rest, hashed passwords, role-based access controls, and Row Level Security policies on our database. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for safeguarding your login credentials and wallet private keys; we never have custody of your private keys.

8. Your Rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data; to receive a portable copy; and to withdraw consent where processing is based on consent. To exercise these rights, contact us at privacy@realsun.info. We will respond within the period required by applicable law. You may also lodge a complaint with a supervisory authority.

9. International Transfers

Our infrastructure and service providers may process data in countries other than your own. Where required, we rely on recognized transfer mechanisms (such as the EU Standard Contractual Clauses) to protect your data in transit and at rest.

10. Children

The Service is not directed to children under 14 (or under the age required in your jurisdiction to enter into a binding contract), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email. The “Effective date” at the top indicates when the latest version took effect. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

12. Contact

Questions, requests, or complaints about this policy can be sent to privacy@realsun.info.