Privacy Policy
1. Introduction
This Privacy Policy describes how the TRX Resource Platform ("Platform", "we", "us") collects, uses, stores, and shares personal data when you use our services, including the Sensei Wallet, Resource Marketplace, TRX Staking Pool, Telegram bots, MiniApp, web interface, admin panel, and Partner API.
We are committed to protecting your privacy while meeting our regulatory obligations, including anti-money laundering requirements that mandate certain data collection and retention.
2. Data We Collect
2.1 Data Collected Automatically
| Data Type | Source | Purpose |
|---|---|---|
| Telegram user ID | Telegram bot / MiniApp | Account identification, authentication |
| Telegram username and display name | Telegram API | User interface display, support |
| TRON wallet addresses | Account creation, activity | Transaction processing, compliance |
| Transaction history | On-chain activity | Service delivery, compliance |
| IP address | Web interface, API | Security, fraud detection |
| Browser user agent | Web interface | Security, compatibility |
| Timestamps | All interfaces | Audit trail, compliance |
| Referral relationships | Referral link usage | Referral program administration |
2.2 Data You Provide
| Data Type | When Collected | Purpose |
|---|---|---|
| Full legal name | KYC (Tier 2+) | Identity verification, sanctions screening |
| Date of birth | KYC (Tier 2+) | Identity verification |
| Country of residence | KYC (Tier 2+) | Jurisdictional compliance |
| Government-issued photo ID | KYC (Tier 2+) | Identity verification |
| Proof of address | KYC (Tier 3) | Enhanced due diligence |
| Source of funds declaration | KYC (Tier 3) | Enhanced due diligence |
| Corporate documents | KYC for businesses | Beneficial ownership verification |
2.3 Data from Third Parties
We may receive data from the TRON blockchain, TronGrid API, Telegram, and sanctions list providers.
2.4 Partner API Data
Partners provide API client identification, order requests, and webhook endpoint URLs. Partners are responsible for their own users' privacy.
3. How We Use Data
3.1 Service Delivery
Processing transactions, executing delegations, managing staking positions, providing wallet functionality, delivering notifications, and administering the referral program.
3.2 Security and Fraud Prevention
Authenticating users, detecting unauthorized access, identifying fraudulent patterns, enforcing rate limits, and maintaining audit logs.
3.3 Compliance
KYC verification, sanctions screening, transaction monitoring, filing SARs, responding to regulatory and law enforcement requests, and maintaining records.
3.4 Platform Operations
Monitoring service health, debugging, and reconciliation.
4. Data Sharing
We do not sell your personal data. We share data only with:
- Law enforcement and regulators -- when required by law
- Service providers -- AWS, and our sanctions-screening provider. Our identity-verification provider is selected but not yet connected, and receives nothing until it is; when it is, identity documents go to it directly and never through us -- see the KYC page
- On-chain -- TRON blockchain transactions are public by nature
We do not currently generate or share aggregated or anonymized data; if that changes, it will be added here alongside how it is produced.
5. Data Retention
We should be straightforward about the state of this: the periods below describe what we retain, but we do not currently run an automated retention job that deletes data when a period expires. The 72-hour figure for access logs is enforced by the log store itself. Everything else is retained until we delete it by hand. Building automated retention is outstanding work.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account identifiers | Account duration + 5 years | AML regulatory requirement |
| Transaction records | 5 years from transaction | AML regulatory requirement |
| KYC documents | 5 years from closure/last transaction | AML regulatory requirement |
| Compliance alerts | 5 years from review | AML regulatory requirement |
| Audit log entries | Retained indefinitely. We have no automated deletion for these, so in practice they are kept for the life of the database | Security and regulatory |
| IP addresses and access logs | 72 hours | These live in our operational log store, which is configured to discard anything older |
| Support conversations | Retained in Telegram for as long as the chat exists; we operate no separate ticketing system | Operational necessity |
6. User Rights
You have the right to request access to your personal data, its correction, its deletion, a restriction on how we process it, and a copy of it in a portable form.
On a verified deletion request we erase the personal attributes we hold about you -- your Telegram username, the KYC answers on your profile, your two-factor secret and recovery codes, your saved wallet selection, and any free-text notes on your transactions -- and we restrict processing of your account. Your account identifier and your transaction, deposit and withdrawal records are retained for the period anti-money-laundering law requires, together with your identity documents, because we are obliged to keep them. This means your records are de-identified, not anonymised, and we do not describe it as anonymisation. Deletion is carried out by an operator using a script that verifies the database schema before it changes anything and reports which records were altered and which were retained; we will pass that account to you. Entries in the audit log cannot be removed without breaking the hash chain that makes it tamper-evident.
We have not built an automated export, so a portability request is assembled by hand. We cannot yet commit to a turnaround time for either request.
Contact us through the Telegram support bot to exercise these rights.
7. Security Measures
We implement comprehensive security measures including:
- Isolated Docker containers with network segmentation
- Signer service on a restricted network segment with no outbound access
- Secrets stored in AWS Secrets Manager with IAM policies
- Encrypted database transport and S3 backups
- Hash-chained audit log, verified hourly (detects tampering; not write-once storage)
- Role-based access control (RBAC)
- 24/7 monitoring via Prometheus, Grafana, and Loki
8. Cookies and Tracking
None of the Telegram bot, MiniApp, or web interface set cookies. We do not use analytics or advertising cookies.
9. Children's Privacy
The Platform is not directed at individuals under 18. We do not knowingly collect data from minors.
10. International Data Transfers
The application, its database and its backups are hosted in the AWS ap-south-1 (Mumbai) region. In addition, we operate our own TRON and Monero blockchain nodes on dedicated servers at Hetzner in Germany; these process public on-chain data and are part of the running system. Appropriate safeguards are in place for any cross-jurisdictional transfers.
11. Changes to This Policy
Material changes will be communicated through the Telegram bot, web interface, and notification system.
12. Contact
For privacy-related questions, contact us through the Telegram support bot.