Privacy Policy

Effective Date: 21 July 2026
This Privacy Policy explains how Novelty Today, Inc. ('Hinkal', 'we', 'us') collects, uses, and protects your information when you interact with our website, our apps at pay.hinkal.io and prime.hinkal.io, the Hinkal Wallet browser extension, and our SDK and API (together, our 'Platform').
Your trust is our most important asset. This policy is our commitment to you. By using our Platform, you agree to the terms of this policy and our Terms of Service.
Our Privacy Commitment (The TL;DR)
Hinkal is a private-by-design protocol. We do not run KYC and we never ask who you are. We are non-custodial, so we never hold your keys or your funds. We cannot see your shielded balances or your shielded transaction history. We never sell your data.
Like most business websites, it uses analytics and marketing tools. Everything we collect is listed below, and the ones that are not strictly necessary run only if you accept them.
What We Collect (and Why)
We are minimalist in our data collection. We only collect what is necessary to operate our Platform and remain compliant.
Type of Information
What We Collect
Why We Collect It
Usage data
IP address, approximate location, device, browser, pages visited, and how you move through a page - through Google Analytics and Microsoft Clarity
To understand how the Platform is used and to fix faults
Business identification
For some visitors, the company associated with your visit and, in the United States, professional contact details matched to it - through RB2B
To understand which businesses are interested in Hinkal, so our team can follow up
Email address (optional)
Your email, and any name or company you choose to give us, only if you submit a form or book a call
To answer you, send product updates, and schedule demos. Unsubscribe any time
Public wallet address
The address you connect to the app
To display your balances, build your transactions, and run the sanctions check below
Cookies and Consent
We use cookies that are strictly necessary to run the Platform. These are always on and cannot be turned off.

Everything else loads only after you choose. Select 'Accept all' in our cookie banner and both analytics and marketing load. Select 'Decline all' and neither does. Open 'Cookie preferences' in the banner to decide the two separately, then save with 'Confirm choices'.

Analytics covers Google Analytics and Microsoft Clarity. Marketing covers RB2B, the visitor identification described below. Until you make a choice, neither category is loaded on the page.

You can change your choice at any time by clicking 'Cookie Settings' in our footer. It reopens the same panel with your current settings, and turning a category off takes effect immediately. You can also block or delete cookies in your browser settings.
Visitor Identification
We use RB2B to tell us which businesses visit our site. It matches a visit against third-party data sources and, for visitors in the United States, can return professional contact details for the person behind the visit. It runs only if you accept marketing cookies.

It reaches our team as a notification in Slack, and nowhere else. We do not add it to any mailing list, and you will not receive marketing email because of it.

We use this to decide who to talk to about Hinkal. If you would rather we did not hold this, email us at the address below and we will delete it.
Sanctions Screening
Before funds enter the Hinkal smart contract, the depositing public wallet address is screened against sanctions and high-risk lists through Chainalysis. This keeps flagged funds out of the pool.
The check runs on addresses, never on people - we hold no identity data to check. It happens before shielding. Once funds are inside, neither we nor Chainalysis can see them.
What We Will Never Collect
Hinkal is architecturally private. Our technology makes it impossible for us to ever collect, log, or share:

• Your shielded balances.
• Your shielded transaction history - senders, receivers, or amounts.
• The link between your public address and your shielded activity.
• Your private keys or recovery phrase.
• Your name, ID documents, or any identity data. We do not run KYC
• Your banking or credit card information. We never ask for it.
Blockchain Data
Deposits and withdrawals are recorded on public blockchains. That record is permanent and outside anyone's control, including ours. We cannot delete or alter on-chain data.
How We Share Information
We do not sell your data. We share only what each provider needs to do its job.
• Google - analytics, and the calendar we use to book demos.
• Microsoft - Clarity, for analytics and session replay.
• RB2B - visitor identification, as described above.
• Slack - where visitor identification and enquiries reach our team internally.
• Brevo - our email platform, for product updates and replies to you. Your submission reaches it through a relay we run on Cloudflare.
• Webflow, Cloudflare and Amazon Web Services - hosting our site, apps and infrastructure, and serving fonts and scripts.
• Chainalysis - the sanctions check described above.
• Law enforcement - only where compelled by a valid and binding legal order, such as a subpoena. We do not share user data voluntarily.
Why We Are Allowed to Process It (Legal Bases)
For visitors in the EEA and the UK: strictly necessary cookies and the operation of the Platform rest on our legitimate interest in running a secure service. Sanctions screening rests on our legal obligation. Analytics, visitor identification and marketing email rest on your consent, which you can withdraw at any time.
How Long We Keep It
• Google Analytics - 14 months from your last visit.
• Microsoft Clarity - session recordings for 30 days. Heatmaps, click data, and any session our team saves or labels, for 9 months.
• Your contact details - until you unsubscribe or ask us to delete them. If you unsubscribe, we keep your email address on a suppression list so that we do not contact you again.
• Visitor identification data - 12 months.
• On-chain data - permanent, for the reason given above.
Where It Goes
We and our providers are based in the United States and the European Union, so your information may be transferred outside your country. Where that involves data leaving the EEA or the UK, transfers are made under the European Commission's standard contractual clauses.
Security
We use encryption in transit, access controls, and least-privilege access to the small amount of personal data we hold. No system is perfectly secure, but the architecture limits the damage: the sensitive data simply is not in our hands.
Your Data Rights (GDPR, CCPA)
You can ask us to access, correct, delete, or export any information we hold about you, object to how we use it, and withdraw your consent at any time. Email us at the address below. We will not treat you differently for asking.
We do not sell personal information for money. If you are in California, you may still have the right to opt out of 'sharing' for cross-context behavioural advertising: choosing 'Decline all' in our cookie banner, or turning Marketing off under 'Cookie Settings', is that opt-out.
If you are in the EEA or the UK, you can also complain to your local data protection authority.
On-chain data is the one thing we cannot delete, for the reason given above.
Children
The Platform is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us information, email us and we will delete it.
Changes to This Policy
We may update this policy from time to time. We will post the new version on this page and update the Effective Date at the top.
Contact Us
Questions about this policy, or any request under it: support@novelty.today, Novelty Today, Inc., Delaware, United States.