// legal
Privacy Policy
Last updated: 2026-07-12
This policy describes what ccscan.xyz (operated by Blueprint Infrastructure, LLC, "Blueprint") collects and why. The short version: the chain data we serve is public by nature; the personal data we hold is the minimum needed to run accounts, API keys, and billing. We don't sell it, and we don't track you across the web.
1. What we collect
- Account data — when you create an account: your email (if you provide one), display name, an optional profile image, your passkey public keys (never private keys), an optional two-factor secret, and — if you use social sign-in — the identifier from your chosen provider.
- Webhooks — if you configure them: the endpoint URL and the Canton party id you ask us to notify.
- API usage — per-key request counts, endpoint families, and coarse daily aggregates, used for your usage dashboard and rate/quota limiting. Rate limiting also processes client IP addresses transiently in memory; we don't keep request-level IP logs.
- Billing — paid plans are processed by Stripe; we store your Stripe customer and subscription identifiers, never card numbers.
- Server logs — standard, size-capped operational logs retained briefly for reliability and abuse prevention.
2. How we use it
- To operate your account, authenticate you, issue and meter API keys, enforce rate limits and quotas, and process subscriptions.
- To send transactional email — address verification, usage and quota alerts, and webhook-health notices — only to a confirmed address. We don't send marketing email.
- To keep the service secure and available (abuse prevention and capacity planning).
3. What we don't do
- No advertising, no sale of personal data, no third-party analytics or tracking pixels.
- No cookies beyond the strictly necessary ones: the session cookie when you sign in, and Cloudflare Turnstile's own cookie when bot protection is enabled on signup.
- No passwords — sign-in is by passkey or social provider. API keys are stored only as one-way SHA-256 hashes; the raw key is shown once and cannot be recovered by us.
4. Third parties
We rely on a small set of processors, each receiving only what its function requires:
- Stripe — payment processing and subscription billing.
- Amazon Web Services — hosting and, via Amazon SES, delivery of the transactional email above. Our infrastructure runs in the United States.
- Cloudflare Turnstile — bot protection on signup, when enabled.
- CoinGecko — market-price data shown on the site (fetched server-side; no personal data is sent).
- Your sign-in provider (e.g. Google, GitHub) — only if you choose social sign-in.
Chain data comes from the public Canton Network Scan API.
5. Public chain data
Party identifiers, transactions, balances, and names shown on ccscan are records of a public blockchain. They are not collected from you by us and cannot be deleted by us — they exist on the network itself, independent of ccscan.
6. Data security
All traffic is served over HTTPS. Sign-in uses passkeys (public-key cryptography) or your social provider — we never hold a password. API keys are hashed at rest, optional two-factor authentication is available, and card data is handled entirely by Stripe.
7. Your rights
You can view your data in the dashboard, export your usage history as CSV, correct your display name and profile image, and delete your account at any time. Deleting your account removes it and all associated data — API keys, sessions, passkeys, webhooks, and profile image — immediately; aggregate usage counters no longer linked to you may be retained for capacity planning. To make any other data request, contact us below. Where applicable law grants additional rights (such as the GDPR or CCPA), we honour them.
8. Retention
Account data is kept while your account is open and removed on deletion as described above. Operational logs are short-lived. Billing records are retained by Stripe, and by us only as needed to meet legal and accounting obligations.
9. Changes and contact
We may update this policy; material changes are reflected by the date above. Questions or data requests: Blueprint Infrastructure, LLC — legal@theblueprint.xyz · theblueprint.xyz.
See also: Terms of Service · Documentation · Service status