Privacy

Privacy Notice

This notice explains how Infinblock Inc processes personal information when you visit or use Dapping, create public proof, communicate, publish, connect accounts or wallets, and contact support.

Effective 11 August 2026Last updated 11 August 2026

1.Who is responsible for your information

Infinblock Inc, a Company Limited by Shares registered in Ras Al Khaimah Digital Assets Oasis, United Arab Emirates, is the controller of personal information covered by this notice. Its registered address is RAK Digital Assets Oasis, Post Box #30099, RAKBANK Headquarters, Government of Ras Al Khaimah, United Arab Emirates.

Privacy questions and rights requests can be sent to [email protected].

2.Scope

This notice applies to the Dapping website, account experience, profiles, company hubs, listings, messaging, discovery tools, support, and related public pages operated by Infinblock Inc.

Third-party websites, wallets, authentication services, application destinations, blockchain networks, and external services have their own privacy practices. Review their notices before using them.

3.Information we process

The information available to Dapping depends on how you use the platform and the choices you make.

Categories of personal information
CategoryExamplesTypical source
Account and identityInternal user ID, authenticated email, X identity, supported wallet address, login and connection stateYou and supported authentication providers
Profile and professional proofName, handle, image, headline, About text, skills, experience, projects, ecosystems, intentions, recommendations, endorsementsYou, other participants, companies, and connected public sources
Connected platform activityPublic GitHub repositories, merged pull requests and reviews from a GitHub account you linked; campaign participation, points and rank from a Zealy community or Galxe space an ecosystem has connectedPublic data from platforms you linked, and campaign platforms connected by ecosystem organisers
Company and publishingCompany details, roles, invitations, products, opportunities, events, team relationships, application destinationsYou, company administrators, publishers, and public sources
Wallet and on-chain contextPublic wallet addresses, selected primary wallet, visible NFTs, public network activity and contract informationYou, wallet providers, and public blockchains or data providers
Content and communicationsMessages, comments, reviews, reports, feedback, support requests, group settings, and invite activityYou and other participants
Device, usage, and consentBrowser and device context, pages and features used, consent choices, diagnostics, security events, sponsored-placement impressions and clicksYour browser, device, and use of the service

4.What is public

Information you publish to a profile, company hub, dApp page, listing, review, recommendation, endorsement, comment, or other public surface can be viewed, copied, indexed, quoted, and shared by other people, search engines, AI services, and third parties.

A public wallet address and public blockchain activity are already visible on the relevant network. Hiding or deleting them from Dapping does not remove them from the blockchain, explorers, caches, screenshots, archives, or copies controlled by others.

Use visibility controls before publishing and do not add sensitive personal information, confidential material, identity documents, seed phrases, private keys, passwords, or verification codes.

6.Matching, Karma, and relevance signals

Dapping can use profile, listing, relationship, category, ecosystem, location, skill, intent, freshness, activity, and proof context to calculate Karma, provide matches, organize discovery, and identify potentially relevant content.

These signals can be incomplete and do not decide whether a person is hired, funded, admitted, paid, verified by a third party, or legally eligible. Publishers and users make their own decisions. Dapping does not publish the formulas, weights, anti-gaming controls, or private review signals behind these systems.

7.Connected platforms and contribution evidence

If you connect a GitHub account to your Dapping profile, we read your public GitHub activity so your real contribution history can appear alongside the skills you list yourself. We read public data only. We never read private repositories, and we never store pull request titles, descriptions, code, commit messages, review comments, file paths, or your email address.

Contribution evidence is shown to companies and ecosystems on signed-in company surfaces, such as the Ecosystem Tracker and the company Talent portal. It is not shown on the public builders directory.

Separately, an ecosystem can connect its own Zealy community or Galxe space. Where a campaign participant can be matched to your Dapping account through an account you already linked or a wallet you already verified, that campaign participation is recorded as engagement evidence. Points, XP and rank are participation records only and never establish a skill.

By default, campaign participation contributes to your builder record across Dapping, so an ecosystem you have not worked with can still see that history. The ecosystem that connected the platform can switch this off, in which case the record stays within that ecosystem.

A company can also attest that you took part in a campaign it ran. You choose whether that attestation appears on your public profile, and you can dispute it. Keeping it off your public profile removes it from the public web, and companies signed in to Dapping can still see it on their own company surfaces. Attestations under an open dispute are shown only to the company that issued them.

To stop us reading your public GitHub activity, disconnect GitHub in your account settings. Existing contribution evidence is withdrawn and no longer displayed.

8.When information is disclosed

We disclose information only as reasonably needed for the purposes described in this notice.

Material providers include Dynamic for authentication, Cloudinary for media handling, PostHog for consent-based product analytics, and Sentry for consent-based browser error telemetry. Provider availability and roles may change as the service evolves.

  • To the public when you choose to publish information or use a public feature.
  • To other participants when necessary for messages, invitations, company roles, recommendations, endorsements, reports, or collaborative features.
  • To service providers supporting authentication, cloud hosting, media delivery, communications, product analytics, error monitoring, support, security, and data operations.
  • To professional advisers, auditors, insurers, or transaction counterparties under appropriate duties.
  • To authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish or defend legal claims.
  • As part of a merger, financing, acquisition, restructuring, or sale, subject to appropriate confidentiality and notice requirements.

9.International processing

Dapping is operated from the United Arab Emirates and uses providers and infrastructure that can process information in other countries. Those countries may have different privacy laws.

Where required, we use contractual, organizational, or other recognized safeguards for international transfers and provide additional information on request where legally available.

10.How long information is kept

We keep personal information only for as long as reasonably needed for the purpose collected, account operation, security, dispute resolution, legal obligations, and enforcement. The period depends on the information and context.

Retention approach
InformationGeneral approach
Account and private product dataUsually retained while the account is active, then deleted or de-identified subject to legal, safety, backup, and dispute needs
Public contentRetained until removed by an authorized user or Dapping, subject to copies, indexing, moderation records, and legal needs
Messages, reports, and supportRetained while needed to provide the feature, protect users, resolve the request, enforce policies, or meet legal duties
Security and operational recordsRetained for limited periods appropriate to detecting abuse, investigating incidents, and demonstrating service integrity
Optional analytics and browser errorsRetained according to consent choices, product configuration, and the applicable provider settings
Public blockchain dataControlled by the relevant network and generally cannot be altered or deleted by Dapping

11.How information is protected

We use technical and organizational safeguards designed for the sensitivity and context of the information, including authentication, role-based access, validation, monitoring, rate controls, and review processes.

No system can guarantee absolute security. Protect your authentication methods and wallets, and contact support promptly if you believe your account or information has been compromised.

12.Your privacy rights

Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information; object to certain processing; withdraw consent; opt out of certain uses; or complain to a data-protection authority.

Send a request to [email protected] from an address connected to your account where possible. Describe the right you want to exercise and the account or information involved. We may need to verify your identity and authority without collecting more information than reasonably necessary.

Rights can be limited by law, the rights of others, security needs, legal claims, and technical realities such as public blockchain records. We will explain an applicable limitation when required.

Dapping does not sell personal information and does not share it for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act, and does not use or disclose sensitive personal information for purposes that would require a right to limit. Browsers that send a recognized opt-out preference signal such as Global Privacy Control are treated as rejecting optional analytics and browser error telemetry when no explicit consent choice exists. You will not be treated differently for exercising a privacy right.

  • UAE residents may exercise rights available under the UAE Personal Data Protection Law.
  • EU and UK residents may exercise GDPR or UK GDPR rights and complain to their local supervisory authority.
  • India residents may exercise rights available under the Digital Personal Data Protection Act and applicable rules.
  • California and other US residents may exercise rights provided by applicable state law and may use an authorized agent where permitted.

13.Your choices

Some processing is necessary to provide a requested account or feature. If you do not provide or allow required information, that feature may not work.

  • Edit eligible profile, company, listing, connection, wallet, NFT, notification, and visibility settings.
  • Accept, reject, or customize optional browser analytics and error telemetry.
  • Disconnect supported accounts or wallets where the product allows.
  • Block or report participants and suspicious activity.
  • Delete your account or a company hub where you have the required authority.
  • Unsubscribe from optional emails using the available control.

14.Children

Dapping is intended only for people aged 18 or older. We do not knowingly allow children to create accounts. If you believe a person under 18 has provided personal information, contact support with enough information to locate the account without sending unnecessary sensitive data.

15.Changes to this notice

We may update this notice when the product, providers, law, or data practices change. The page will show the effective and last-updated dates. We will provide additional notice when a change materially affects how personal information is used or the law requires it.

16.Contact and complaints

Infinblock Inc

RAK Digital Assets Oasis, Post Box #30099, RAKBANK Headquarters, Government of Ras Al Khaimah, United Arab Emirates

[email protected]

You may also complain to the privacy or data-protection authority that applies in your location.