Your privacy is important to us.

Last Updated: May 8, 2026

Citron Holdings LLC (“we”, “us”, or “our”) operates Mintive and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information in connection with your use of the Mintive website, application, and related services (the “Service”).

This Privacy Policy is designed to align with our Terms of Service and should be read together with them. In the event of any inconsistency, our Terms of Service govern.

By using the Service, you agree to this Privacy Policy.

1. Information We Collect

We collect only the information necessary to operate, secure, and improve the Service.

1A. Analytics Data

We collect limited, non-identifying analytics to understand usage and improve the Service, including:

  • Page views, clicks, and navigation behavior
  • Feature usage and interaction events
  • Device type, browser type, and user agent
  • Session identifiers and anonymous usage metrics
  • Performance and error events

We use PostHog as a third-party analytics processor. PostHog processes this data on our behalf in the European Union.

We do not intentionally use analytics systems to identify users via wallet addresses, blockchain signatures, or other direct identifiers.

Users who accept cookies may be assigned a persistent analytics identifier. Users who reject cookies are tracked using anonymous, session-based identifiers that reset periodically.

PostHog operates under its own infrastructure and retention policies. We configure and use it in accordance with applicable data protection laws, but we do not control its internal system-level retention behavior.

1B. Operational, Security, and Abuse Prevention Data (Security Logs)

We collect and store limited operational data necessary for security, fraud prevention, and system integrity.

This may include:

  • IP address
  • Wallet address
  • Blockchain signature or message proof
  • Timestamps of interactions
  • Request metadata (endpoints accessed, response status)
  • Error logs and system events
  • Device/session metadata

This data is stored in a separate secure security database, distinct from analytics systems.

We may use this data where reasonably necessary for:

  • Fraud and abuse prevention
  • Security monitoring and system protection
  • Verification of user actions (including acceptance of Terms)
  • Dispute resolution and legal defense
  • Compliance with applicable legal obligations

This data is not used for advertising, marketing, or behavioral profiling.

Some operational and system logs may be processed and temporarily stored by our hosting provider for up to 14 days. These logs may include technical metadata and limited interaction data necessary for system performance, security monitoring, and infrastructure maintenance. Such data is subject to the hosting provider's own infrastructure retention and security policies.

1C. Consent and Verification Records

When you interact with the Service and accept the Terms (including via wallet interaction or message signing), we may generate and store a cryptographic verification record as proof of consent and system integrity.

This may include:

  • Wallet address used for interaction
  • IP address at time of interaction
  • Cryptographic signature of an off-chain message (non-blockchain, non-transactional)
  • Timestamp of acceptance or interaction

These records are created solely for:

  • verifying acceptance of Terms
  • fraud and abuse prevention
  • dispute resolution and legal defense

These records are stored in secure operational systems and are not part of blockchain data or analytics systems.

1D. Future Data Collection

We may collect additional categories of data reasonably necessary to operate, secure, improve, or maintain the Service, provided such processing is consistent with the purposes described in this Privacy Policy.

2. Legal Bases for Processing

Where applicable under GDPR and similar laws, we process personal data under the following legal bases:

  • Contractual necessity: to provide the Service
  • Legitimate interests: security, fraud prevention, and service improvement
  • Legal obligations: compliance with applicable laws and regulatory requirements
  • Consent: where required for cookies or optional analytics features

3. How We Use Information

We use collected information for the following purposes:

  • Providing and operating the Service
  • Improving functionality, performance, and user experience
  • Detecting, preventing, and responding to fraud and abuse
  • Securing the Service and infrastructure
  • Verifying user actions and consent
  • Complying with legal and regulatory obligations
  • Responding to support or safety requests

We do not sell or rent personal data.

4. Data Retention

We retain data only as long as reasonably necessary for the purposes described in this Policy.

4A. Analytics Data

Retained according to PostHog configuration and applicable retention policies.

4B. Security and Operational Logs

Security and operational data is retained for as long as necessary for:

  • fraud prevention
  • security monitoring
  • dispute resolution
  • legal compliance
  • system integrity

This may include extended retention periods where legally required or necessary to protect the Company from claims.

4C. Third-Party Storage

Some data may be stored in third-party systems subject to their own retention and processing policies.

5. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Enable analytics functionality
  • Distinguish between anonymous and identifiable usage (with consent)
  • Improve Service performance and reliability

Users can accept or reject non-essential cookies at any time. Cookie preferences can be managed or withdrawn via our Privacy Settings page. Rejecting cookies may limit analytics functionality but does not affect core Service functionality.

6. Data Sharing

We do not sell personal data.

We may share limited data with third-party service providers strictly for operational purposes, including:

  • Analytics providers
  • Infrastructure and hosting providers
  • Security and monitoring systems

These providers act as processors and are contractually restricted from using data for unrelated purposes.

Some data may be processed and temporarily stored by infrastructure providers as part of service delivery and system logging. These providers operate under their own security and retention policies and act solely as data processors on our behalf.

7. Data Security

We implement reasonable technical and organizational measures to protect data, including:

  • Access controls and restricted permissions
  • Separation of analytics and security systems
  • Secure hosting infrastructure
  • Monitoring and abuse detection systems

However, no system is completely secure, and we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction (including GDPR where applicable), you may have rights to:

  • Access personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of personal data (subject to legal limitations)
  • Withdraw consent for cookie-based tracking
  • Object to certain types of processing

8A. Limitations on Deletion

Some operational, security, or verification data may not be fully deletable where retention is necessary for:

  • fraud prevention and abuse protection
  • legal compliance
  • dispute resolution and legal defense
  • system integrity
  • or where stored in third-party infrastructure outside our direct control

9. International Data Transfers

Your data may be processed in jurisdictions outside your country of residence, including the United States and European Union. We take appropriate safeguards where required under applicable law.

10. Minors

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted with a revised “Last Updated” date. Continued use of the Service constitutes acceptance of the updated Policy.

12. Contact

For questions regarding this Privacy Policy or data practices:

contact@mintive.xyz

Legal Version ID: dfc85b56b38b