The Buy ButtonData notice / 2026-07-31

Operational transparency / effective July 31, 2026

Small surface.
Named data.

This page says what the public site receives, what remains in your browser, what becomes public onchain, and which outside services are involved. It is an operating notice—not a legal certification, audit, or promise that outside providers never change.

Site accountNone
Private keysNever requested
Public-chain identityAddress, not person

Scope and contact

The independent publisher operating The Buy Button is responsible for this website, its first-party APIs, and the project Telegram bot. Questions, access requests, corrections, or deletion requests can be sent to security@hoodbuybutton.com.

The Witness participant notice governs proposed historical contributions. The Quick Meme Drawer policy governs the browser extension. Those narrower notices control where they are more specific.

Ordinary visits

Vercel hosts the site and may process ordinary request and security information such as IP address, IP-derived location, requested path, time, browser or device configuration, and diagnostics under its own privacy notice.

Selected public pages use Vercel Web Analytics for page views and named interaction events, and Speed Insights for performance measurements. Vercel says Web Analytics data points are anonymous, are not associated with a person or IP address, and use no third-party cookies. Page-view data can include the path, filtered query parameters, referrer, coarse location, browser, operating system, device type, and timestamp. Read Vercel's Web Analytics privacy documentation and Speed Insights documentation.

Custom events describe the action—not a private identity. Examples include opening a tool, selecting a public token or time window, copying a meme, requesting a quote, or recording a ballot choice. They are not designed to contain an email address, wallet address, signature, private draft, witness text, or lore search phrase.

Actions you choose

  • Treasury ballot. The site receives the public wallet address, choice, message signature, observed BUY balance, and block number. The signature is a message signature, not a transaction or token approval. Individual records use private database storage with public access disabled; the site publishes aggregate results.
  • SOL route. A quote uses the source Solana address, destination EVM address, and amount. The route provider receives the data needed to quote and execute the route. Status checks use the transaction signature and quote identifier. The wallet signs; the site does not receive a seed phrase or private key.
  • Community directory. Intake receives the project name, ticker, contract, official links, and proof URL, then checks public contract metadata. Pending records use private database storage and publish only after manual review.
  • Email. If you email the project, the sender address, message, attachments, and normal email headers are processed by the relevant email providers. Do not send keys, identity documents, home addresses, or somebody else's sensitive information.

Browser-only data

Local and session storage hold interface state such as dismissed entrances, sound level, local button attempts, cached public Pulse data, and recent public-chain events. This makes the interface faster and does not create a project account. Clearing site data in the browser removes those local records.

Clipboard access happens only after an explicit copy action. Wallet access happens only after an explicit connect, add-token, quote, or ballot action.

Public-chain data

The site reads public blocks, transactions, token balances, liquidity positions, and wallet addresses. Those records already exist on public networks and can remain available independently of this site. A wallet address is a public pseudonymous identifier—not proof of a person, app user, intent, or social identity.

The site does not attempt to join public addresses to private identities. Any research note that discusses a possible relationship must label observation, inference, and unknowns separately.

Outside services

Depending on the page or action, the browser or server may contact Vercel, Robinhood Chain RPC, Blockscout, DexScreener, GeckoTerminal, Lighter, Hyperliquid, 0x, CoinGecko, jsDelivr, Telegram, and email providers. Those services receive ordinary network information and any request fields needed for the chosen action under their own terms.

Following an outbound link also creates a direct relationship between the visitor and the destination. An external listing, explorer record, or source match is not an endorsement or security review.

Retention and control

Public chain records and published archive material may remain available indefinitely outside the project's control. Private ballot records are retained as integrity evidence while their signal archive is maintained. Pending directory records are retained for review and correction; a fixed automated deletion schedule is not yet implemented. Vercel's analytics and performance reporting windows depend on the active service plan.

You can decline optional wallet and form actions, block analytics scripts, clear browser storage, or request access, correction, or deletion of an active private project record. The project can correct or remove data on systems it controls; it cannot erase independent blockchains, screenshots, caches, quotations, or third-party archives.

Material changes to this notice should change the effective date. Known unknowns are stated rather than converted into guarantees.