Skip to main content

1. About Us

At Turtle, we believe privacy is a fundamental human right. This privacy policy (“Privacy Policy”) explains how we process and protect your personal data when you use this Website or the services provided via the Platform provided via https://app.turtle.xyz (together, the “Services”). These Services are operated by Turtle DAO, orchestrated through the Turtle Association (the “Association”, “we”, “our”, or “us”), which is the controller for the data processing described below. 
What We CollectAccount details, device identification, usage metrics, coarse region mapping, and organizational compliance, financial, and due diligence data.
Core PurposeTo facilitate fundraising activities and comply with Anti-Money Laundering (AML)/Know Your Customer (KYC) regulations, securely operate the platform, resolve software bugs, and satisfy global legal obligations.
Your Rights & ControlsFrictionless access, deletion, data porting, correction, and processing restrictions.

2. Categories of Personal Data We Collect

To provide a seamless, secure user experience, we explicitly collect and organize personal data into the following categories:
  • Account Profile Information: Legal name, validated email address, telephone contact number, and encrypted password metrics.
  • Technical & System Attributes: Internet Protocol (IP) address, browser definitions, operating system details, device model identifiers, and detailed software crash telemetry.
  • Platform Usage Analytics: Specific feature interactions, engagement timestamps, system navigation behaviors, and performance benchmarks.
  • Geographic Location: Coarse, non-precise regional location extrapolated exclusively from IP addressing to enforce compliance parameters. We do not collect precise hardware GPS metrics.
  • Corporate & Due Diligence Information: Details related to organizational structure, fundraising, and compliance, which may include the names, contact details, financial interests, and identity verification records (such as government IDs) of founders, directors, Persons with Significant Control (PSCs), and investors associated with the organization.

3. Sources of Personal Data (How We Collect Your Information)

To maintain complete transparency in line with global regulations, Turtle gathers personal data through three primary mechanisms: A. Data You Direct to Us (Direct Collection): We collect personal information that you manually enter or supply during your interactions with our ecosystem. This includes:
  • Information provided when creating or verifying an account (e.g., name, email address, phone number).
  • Data submitted when contacting Turtle support, participating in surveys, or requesting technical assistance.
  • Corporate documentation, capitalization tables, and official identity verification credentials (such as government-issued identification) transmitted throughout institutional onboarding procedures, due diligence assessments, or capital-raising cycles. This encompasses personal metrics supplied regarding third-party individuals, including corporate directors, equity investors, or Persons with Significant Control (PSCs).
B. Data Captured Electronically and Automatically (Passive Collection): When you navigate or interact with Turtle platforms, our systems automatically log operational metrics. This includes:
  • Cookies and Tracking Technologies: Unique identifiers, session states, and tracking pixels deployed within your browser or device interface.
  • System and Infrastructure Logs: IP addresses, browser configurations, internet service provider (ISP) details, entry/exit pages, timestamps, and crash telemetry records.
C. Data Acquired from Third Parties (External Sourcing): Turtle may occasionally receive data about you from external commercial partners. This includes:
  • Identity & Fraud Prevention Services: Vendors utilized to verify user age, validate regional compliance, or detect malicious platform actors.
  • Analytics and Infrastructure Partners: Services providing aggregate market metrics, software performance debugging data, or localized advertising conversion statistics.
  • Corporate Registries: Openly accessible government databases and official repositories, such as Companies House, leveraged to authenticate corporate governance frameworks, legal entity architecture, and beneficial ownership status.

4. Cookies and Automated Tracking Technologies

Turtle utilizes cookies, pixels, and localized script-based identifiers to optimize performance, preserve user preferences, and secure our infrastructure. In alignment with global frameworks, including the EU ePrivacy Directive, we categorize our automated tracking deployment into two clear operational tiers:
  • A. Strictly Necessary & Functional Cookies (Mandatory): These tracking elements are mathematically required to operate the basic functions of Turtle. They handle secure session routing, identity authentication parameters during active logins, network load balancing, and anti-fraud server validation. The platform cannot function without these identifiers, and they do not track your behavior across external internet ecosystems.
  • B. Performance & Analytics Cookies (Optional): We utilize first-party analytics tools to assess how users collectively interact with our software interfaces. This data is fully aggregated and pseudonymized, tracking software crashes, page latency, and interface feature engagement metrics. We use this data solely to improve system speed and usability. Turtle does not deploy third-party tracking cookies or pixels for cross-context behavioral marketing or targeted advertising.

How to Manage and Control Cookies

Most web browsers are configured to accept cookies by default. You retain the right to modify your browser settings to reject, wipe, or block cookies entirely. However, because Strictly Necessary cookies are structurally tied to Turtle’s baseline operations, disabling them completely may result in platform failures, rendering account access inoperable. To audit or disable your cookie preferences, please consult the “Help,” “Tools,” or “Privacy” menus within your specific browser application (such as Apple Safari, Google Chrome, or Mozilla Firefox). Our Services contain links to websites or apps that are not operated by us. When you click on a third-party link, you will be directed to that third party’s website or app. We have no control over the content, privacy policies, or practices of any third-party websites or services. We maintain online presences on social networks to, among other things, communicate with customers and prospective customers and to provide information about our products and Services. If you have an account on the same network, it is possible that your information and media made available there may be seen by us, for example, when we access your profile. In addition, the social network may allow us to contact you. As soon as we transfer personal data into our own system, we are responsible for this independently. This is then done to carry out pre-contractual measures and to fulfil a contract. For the legal basis of the data processing carried out by the social networks under their own responsibility, please refer to their data protection declarations.

6. Lawful Bases for Data Processing (GDPR/UK GDPR Compliance)

For users operating within the European Economic Area (EEA) and the United Kingdom, all processing activities are paired with an explicit legal basis defined under Article 6 of the GDPR:

7. Statutory California Consumer Disclosures (CCPA/CPRA)

In accordance with the California Consumer Privacy Act as amended by the CPRA, this section provides a retroactive 12-month lookback of personal information collected and disclosed for standard business operations:   Sensitive Personal Information: We collect government-issued identifiers (such as passports and driver’s licenses) which are classified as Sensitive Personal Information under the CPRA. We use this data strictly for legally permitted purposes (such as KYC/AML identity verification) and do not use it to infer characteristics about consumers Selling or Sharing Prohibitions: Turtle does not sell your personal information. Furthermore, Turtle does not “share” personal identifiers for cross-context behavioral or targeted advertising models as defined by California statutes.

8. Global Data Subject Rights & Control Protocols

We extend core data autonomy protections universally to all users, matching international privacy standards:
  • Right of Verification & Access: The right to demand confirmation of processing and obtain a complete copy of raw data files held by us.
  • Right of Correction: The right to modify out-of-date, incomplete, or broken account parameters.
  • Right of Total Erasure (Deletion): The right to request the permanent deletion of files, except where financial reporting or statutory hold regulations require data retention.
  • Right of Portable Export: The right to download your file system in a clean, machine-readable format for transition elsewhere.
  • Right to Object & Restrict: The right to halt data use for targeted updates or pause handling due to personal disputes.
  • Statutory Right to Non-Discrimination: We strictly guarantee that exercising any choice under this policy will never result in service degradation, billing increases, or feature limits.

8.1 Verification Procedures and Operational Timelines

To protect your privacy and maintain platform security, Turtle enforces strict operational protocols when processing data subject requests:
  • Submission Mechanics: You may initiate a formal rights request by contacting us at: info@turtle.xyz
  • Identity Verification Protocol: Upon receiving a request to access, correct, or delete personal data, Turtle must verify your identity before taking action. We will ask you to provide at least two to three pieces of personal identifiers that match information already maintained in our secure production environments (e.g., confirming the account email and recent account transaction dates). We will never disclose or delete data if we cannot establish identity to a reasonable or high degree of certainty.
  • Authorized Agents (California Residents): You may designate an authorized agent to submit requests on your behalf. To do so, you must provide the agent with signed, written permission, or a valid Power of Attorney. The agent must verify their own identity directly with us, and we reserve the right to confirm the agent’s authority directly with the account owner.
  • Response Timelines: Turtle acknowledges all received requests within ten (10) business days. For residents of the EEA and UK, we provide substantive responses within thirty (30) days. For California residents, we resolve requests within forty-five (45) days. If a request is highly complex, we reserve the right to extend these timelines as permitted by local law, providing you with an explicit justification for the delay.

9. Data Minimization, Retention, & Destruction

Personal data is stored exclusively for the baseline timeframe necessary to complete the functional operations outlined in Section 6, unless explicit statutory directives (such as corporate accounting and Anti-Money Laundering (AML) laws) mandate an extended preservation window. Upon the conclusion of a designated retention timeline, files are permanently wiped from production nodes or fully scrubbed via advanced anonymization methodologies to block any future re-identification risks.

10. Data Security and Safeguarding Measures

Turtle is committed to protecting your personal data from unauthorized access, alteration, disclosure, or destruction. We utilize a multi-layered defense strategy comprising technical, administrative, and physical safeguards:
  • Technical Safeguards: We deploy industry-standard encryption protocols. Data is encrypted while in transit across public networks using Transport Layer Security (TLS/HTTPS) and encrypted at rest on our secure cloud architecture using advanced encryption standards (such as AES-256). We routinely perform system vulnerability scanning and automated patch management to mitigate emerging software threats.
  • Organizational Safeguards: We enforce strict “least-privilege” access controls. Internal access to your personal information is restricted exclusively to authorized Turtle employees, contractors, and agents who require that data to execute designated operational functions (Section 6). These individuals are bound by strict, legally enforceable confidentiality obligations.
  • Your Responsibility for Security: Security is a shared responsibility. We strongly urge you to take every precaution to protect your personal data when navigating the internet. This includes using a unique, complex password for your Turtle account, keeping your authentication credentials strictly confidential, and ensuring your devices utilize updated software and security protections.
Please note: While we continuously review and reinforce our protective perimeters, no method of digital transmission or electronic storage is 100% impenetrable. Consequently, Turtle cannot guarantee absolute security, and users interact with the platform acknowledging these baseline risks.

11. Cross-Border Data Transfers

To ensure reliable global access, platform operations utilize international cloud infrastructure networks. For data originating within jurisdictions like the EU or UK that is subsequently routed to regions lacking native adequacy status, Turtle deploys European Commission-approved Standard Contractual Clauses (SCCs) to mandate an unbroken perimeter of data defense.

12. Protection of Minors (Children’s Privacy)

Platform access is restricted to individuals who have reached 18 years of age. Turtle does not knowingly gather, verify, or archive personal metrics relating to minors under 18. If a parent or guardian establishes that a minor has bypassed security checks to supply data, please contact our team immediately for prompt, systemic removal of the data footprint.

13. Privacy Governance & Contact Information

We maintain an internal Data Protection Officer (DPO) to manage our global alignment framework. For explicit rights enforcement actions, standard inquiries, or operational complaints, contact us directly: info@turtle.xyz