Draft — pending legal review · text as of 5 August 2026
Privacy Policy
What Mason Lab stores about you, why, who else sees it, and how long we keep it. Written to match what the system actually records. Pending review by counsel before it takes effect on [EFFECTIVE_DATE].
Placeholders to be completed before publication
- [LEGAL_ENTITY] — the data controller: registered name of the company operating Mason Lab
- [JURISDICTION] — country of incorporation and governing law
- [REGISTERED_ADDRESS] — registered office
- [CONTACT_EMAIL_OR_TELEGRAM] — channel for privacy requests
- [EFFECTIVE_DATE] — date this policy takes effect
- [HOSTING_REGION] — country where the servers and backups are located
- [RETENTION_YEARS] — retention period for financial, order and compliance records (docs/AML_POLICY_AND_CONTROLS.md §7.6 proposes 5 years, to be confirmed for [JURISDICTION])
Not yet in effect
- Telegram as identity. Accounts are currently created with an email address and a password; the move to Telegram identifiers is in progress. Until it lands, an email address is still what an account is registered with.
- Payment data. No payment provider is connected, so no payer address, transaction hash, or screening result exists yet.
1. Who we are
The controller of your personal data is [LEGAL_ENTITY], [REGISTERED_ADDRESS], [JURISDICTION]. Privacy requests: [CONTACT_EMAIL_OR_TELEGRAM].
2. What we collect
- Account. Your Telegram account identifier (numeric — never the username as identity), a display name, and, if you choose to add one, an email address as an optional contact. An email address is not an authentication factor and cannot be used to sign in or to recover access.
- Sign-in security. Sessions, and with each session a salted hash of your IP address and of your browser user-agent — the raw IP address is not stored and the hashes are not shown to anyone. Where a password is set, it is stored only as an Argon2id hash. Failed sign-in counters and lock timers.
- Orders and money. Your orders, amounts, ledger entries, invoices, payouts, and the resulting balances. These records are the accounts of the Platform and cannot be edited or removed on request.
- Payments. For every incoming payment: the originating address, the transaction hash, the network, confirmations, the amount received, and the risk score returned by our screening provider. We keep the originating address because money leaves Mason Lab only to the address it came from (see the Refund Policy). A payout destination is stored encrypted, with only a short preview visible in the interface.
- Delivery. Whether and when you revealed a delivered item, and how many times. This is evidence of delivery in a dispute and is described in the Terms.
- Disputes and support. Messages in the order chat, evidence you upload, and the decision. Order chat is retained as dispute evidence and is visible to the other party and to the arbiter.
- Selling. Store name, description, contact details in a seller application, listings, and uploaded images.
- Anti-abuse. Signals such as unusual order velocity, links between accounts, and moderation actions, together with an append-only audit log of security-relevant actions.
We do not ask for government-ID documents to browse or buy. We may request identity or source-of-funds verification in the specific cases set out in the AML Policy.
3. What we cannot see
The contents of a delivered item — a key, a code, a credential, a file — are encrypted at rest and are decrypted only for the buyer of that order, after payment. Mason Lab stores ciphertext. We do not read the contents of deliveries, and in a dispute we cannot confirm what a given item actually was: only the parties can show that.
4. Why we use it
- To perform the contract with you — run your account, process orders, escrow, refunds, and payouts.
- To comply with legal obligations — anti-money-laundering controls, sanctions screening, accounting records, and responses to lawful requests.
- For our legitimate interests — securing accounts against takeover, detecting fraud, fake transactions, and abuse of refunds, deciding disputes on evidence, and keeping the marketplace usable.
5. Notifications
Notifications we send through our Telegram bot are part of the protection mechanism of every trade: warning before escrow is auto-released, delivery, dispute movement, sign-in from a new device, and every operation affecting money. They are mandatory and cannot be switched off while you hold an account. We do not send marketing through this channel.
6. Who else sees your data
We do not sell or rent personal data, and we run no advertising or cross-site tracking. Data is shared only where it is necessary to operate the Platform:
- Hosting and infrastructure providers ([HOSTING_REGION]), which process data on our instructions;
- Telegram, as the identity and notification channel — Telegram sees that our bot messages you and processes that message under its own privacy policy;
- Payment and payout providers, which see the payment data required to move funds;
- Our blockchain analytics provider, which receives the originating address of an incoming payment to return a risk score;
- The other party to your order — a seller sees your store-facing display name, order, and chat messages, and never your email address, your addresses, or your other orders;
- Competent authorities, where the law requires it. Where the law forbids us from telling you, we will not.
7. Cookies
We use two cookies, both strictly necessary: a session cookie that keeps you signed in, and a CSRF-protection cookie. Both are HttpOnly or otherwise scoped for security. There are no advertising, analytics, or cross-site tracking cookies, and therefore no consent banner to click through.
8. Retention and deletion
You may ask us to close your account and delete your personal data at any time via [CONTACT_EMAIL_OR_TELEGRAM]. When we do:
- profile data and contact details are deleted or anonymised, and sessions are revoked;
- order, ledger, payment, and dispute records are retained for [RETENTION_YEARS] — they are financial records and evidence, required for accounting, AML, and the protection of the other party to a trade;
- the audit log is append-only and survives account deletion, because a security record that can be erased by the person it describes is not a security record;
- a balance is returned only to the address it came from, under §9 of the Terms; an account with an unresolved dispute or an open investigation is closed only after it ends;
- the Telegram identifier of a terminated account is not released and cannot be used to open a new account.
Session records and security hashes are kept while the session is valid and for a short period afterwards for takeover detection. Compliance records hold payment and order facts — addresses, amounts, times, screening results, and whether and when an item was revealed — and never the contents of a delivered item.
9. Your rights
Subject to the law of [JURISDICTION] and to the retention rules above, you may request access to your data, correction of it, deletion, a copy in a portable format, or restriction of processing, and you may object to processing based on our legitimate interests. Write to [CONTACT_EMAIL_OR_TELEGRAM]. We answer within one month. If you believe we have handled your data wrongly, you may complain to the supervisory authority in [JURISDICTION].
10. Security, transfers, and children
Secrets are encrypted at rest, passwords are hashed with Argon2id, sessions are bound to CSRF tokens, and access to production data is limited to the operator of the Platform. No system is perfectly secure; we notify affected users of a breach that puts their data at risk, through the Telegram bot.
Data is stored in [HOSTING_REGION] and may be processed by service providers in other countries under appropriate safeguards. The Platform is not intended for anyone under 18, and we do not knowingly collect data from children.
11. Changes
We may update this policy. Material changes are announced through the Telegram bot before they take effect, and the date at the top of this page always shows the current version.