Privacy Policy

Effective date: [DATE]

1. Who we are

CharterSpace.IO (“we”, “us”) operates charterspace.io and its subdomains (app., providers., api., admin., docs.charterspace.io), a marketplace for residual cargo capacity on commercial space launches. Data controller contact: [legal@charterspace.io] / [registered business address].

2. What we collect

Category Examples Source
Account data Name, email, password hash, role User-provided at registration
KYC/KYB data Organization legal name, registration number, country of incorporation, contact details, export-control questionnaire answers, uploaded registration/end-user documents User-provided via the quote request form
Transaction data Quote requests, bookings, payment method (tokenized — see §6), NFT wallet address (if crypto payment used) Platform-generated / user-provided
Technical data IP address (server-captured), device/browser info, log data Automatically collected
Communications Support/contact form submissions User-provided

3. How we use it

  • Provide the marketplace service: process RFQs, notify Providers, manage bookings.
  • Perform KYC/export-control screening required by law and Platform policy.
  • Send transactional emails (RFQ confirmation, booking updates, security notices).
  • Maintain the audit log required for compliance.
  • Detect and prevent fraud, abuse, and export-control violations.
  • Send marketing communications — only with opt-in consent, and only as permitted by applicable law.

4. Legal basis (EU/UK visitors)

Where the GDPR or UK GDPR applies, we rely on a different legal basis for each purpose in §3: performance of a contract for creating and running your account and processing quote requests; compliance with a legal obligation for export-control and KYC/KYB screening and the associated record-keeping; legitimate interests for fraud prevention, abuse detection and platform security; and consent for marketing communications, which you may withdraw at any time.

5. Sharing

We share data with: the Provider associated with an RFQ (contact + KYC details necessary to respond), payment processors (Stripe / crypto payment provider — tokenized payment data only, we never receive or store raw card numbers), email delivery provider, hosting provider (IONOS), and as required by law (e.g. export-control compliance reporting). We do not sell personal data.

6. Payment & Blockchain Data

Card payments are processed by a PCI-compliant third-party processor; CharterSpace.IO never stores raw card numbers. Cryptocurrency payments and any resulting NFT Certificate are recorded on a public blockchain — wallet addresses and transaction hashes are, by the nature of public blockchains, publicly visible and not something CharterSpace.IO can delete on request (see §8 limitation).

7. International Transfers

The Platform is hosted by IONOS on EU-based infrastructure, and personal data is processed there. Where data reaches a recipient outside the country or region it was collected in — for example a Provider, a payment processor, or an authority to which we are required to report — that transfer is made only under the safeguards applicable law requires for it. The specific safeguard relied on for each transfer route is being settled ahead of launch and will be set out in this section; until then, contact us at the address in §13 if you need to know the position for a particular transfer.

8. Retention

KYC/export-control records are retained for [X years] to satisfy regulatory and audit requirements. Account data is retained while the account is active plus [X years]. Blockchain records cannot be deleted or modified once written (see §6) — this limitation is disclosed to users at the point NFT Certificates are minted (see Terms & Conditions §11).

9. Your Rights

Subject to applicable law (GDPR, CCPA/state law, etc.), you may request access, correction, deletion, or portability of your personal data, and may object to or restrict certain processing. Contact [privacy@charterspace.io]. Note the blockchain limitation in §6 applies to deletion requests concerning on-chain data.

10. Security

We apply technical measures including MFA/Passkeys for provider/admin accounts, encrypted transport, rate limiting, audit logging, and access controls.

11. Children

The Platform is not directed to individuals under 18 and we do not knowingly collect their data.

12. Changes

We will post updates here and, for material changes, notify registered users via email.

13. Contact

[privacy@charterspace.io]