Tonhub is a software service accessible via a mobile device application and a web browser interface for the TON Network (“Network”), provided by Whales Corp. (“we,” “us,” or “our”). Tonhub empowers users to securely self-custody digital assets; access a cryptocurrency browser; connect to decentralized applications and exchanges; view blockchain addresses and related information; broadcast transactions; and use additional partner-provided services and ongoing functional enhancements (collectively, the “App,” “Tonhub,” or “Tonhub Wallet”). This Privacy Policy (“Policy”) explains how we collect, handle, protect, and use your information when you interact with the App, developer software, or our website at https://tonhub.com (collectively, “Services”). Please also review our Terms of Service (“Terms”), which explain the legal conditions of your use.
- Key Definitions and Scope
- What Personal Data We Collect and How
We do not require account creation or personal data submission to use our primary wallet functions. However, when you communicate with us—for support, inquiries, or feedback—you may provide identifiers and contact details such as:
- Full name
- Email address
- Telephone number
When you use our Services, we automatically collect technical and usage information, including but not limited to:
- Public wallet addresses linked to your activity
- Device IP address
- Device and browser information (type, version)
- Operating system data
- Date, time, and duration of access
- Behavioral data necessary for service optimization and troubleshooting
2.3 Sensitivity and Children’s Data
We do not knowingly collect data from users under the age of 13 (Article 8 General Data Protection Regulation (GDPR)). If sensitive data (e.g., ethnicity, health) is submitted, we process it only under strict legal bases and with explicit consent. If you share personal data of others, you confirm you have their requisite consent.
- How We Use Your Data & Our Legal Bases
- Contractual Obligations (Art. 6(1)(b)): To provide you services, process transactions, and maintain operation.
- Legal Obligations (Art. 6(1)(c)): To comply with laws, regulations, and governmental requests.
- Legitimate Interests (Art. 6(1)(f)): For security, fraud prevention, service improvements, analytics, and communications not requiring consent.
- User Consent (Art. 6(1)(a)): For marketing campaigns, newsletters, and offers you opt-in for.
- Disclosure & Sharing of Your Data
- Data Processors (Art. 28 GDPR): Trusted partners including banks, technical providers, and support services, who meet strict data security criteria.
- Third-Party Controllers: Auditors, government agencies, courts, or debt recovery agencies where required by law or legal rights protection.
- Corporate Successors: Entities acquiring business assets with clear data protection commitments.
- Authorized Representatives: Individuals or entities you authorize in writing to interact on your behalf.
- With Your Consent: Other third parties relevant to marketing or service offers with your explicit approval.
- Your Privacy Rights and How to Exercise Them
- Access: Obtain confirmation and copies of your personal data (Art. 15 GDPR).
- Correction: Request correction of inaccurate or incomplete data (Art.16 GDPR).
- Erasure: Request deletion when data is no longer necessary or consent withdrawn (Art. 17 GDPR).
- Restriction: Temporarily limit data processing (Art. 18 GDPR).
- Portability: Receive and transfer your data in a structured format (Art. 20 GDPR).
- Object: Object to data processing for legitimate interests or marketing (Art. 21 GDPR).
- Withdraw Consent: Revoke given consent freely at any time (Art. 7 GDPR).
- Lodge Complaint: File with data protection authorities if you believe rights are violated (Art. 77 GDPR).
We respond within one calendar month (Art. 12 GDPR). In complex situations, this can extend by two more months with notice.
Requests that are repetitive, excessive, or manifestly unfounded may incur reasonable fees or be declined.
- Data Retention
- Data Security
Despite best efforts, absolute security cannot be guaranteed. Users share data at their own risk and should promptly report suspicious activity.
- Cross-Border Information Transfer
When we transfer your personal data to countries that the European Commission has not recognized as providing an adequate level of data protection, we rely on appropriate legal safeguards. These include, but are not limited to, Standard Contractual Clauses or other mechanisms approved by the European Commission to ensure that your personal data receives an adequate level of protection.
If you would like further information about the specific data transfer mechanism(s) we use or details about the countries involved, please contact us at privacy@tonhub.com.
- Cookies and Similar Tracking Technologies
We prohibit and penalize unauthorized automated scanning or crawling of our website.
Cookie Categories:
- Essential: Required for the website functionality; non-optional.
- Preferences: Remember your choices (language, region).
- Analytics: Collect anonymized interaction data for improvement.
- Marketing: Target ads based on behavior, limit exposure frequency.
- Complaint Handling and Resolution
- Via email at contact@tonhub.com
- Via the support/feedback form in the Tonhub application.
- Confirm receipt within 5 business days (Article 12(3) GDPR).
- Investigate and respond within 2 months or notify about extension.
- Retain complaint records securely for a minimum of 5 years.
- Provide detailed decisions with remedies or escalation paths.