{"service":"Orcpin","last_updated":"2026-06-23","overview":"Orcpin is a read-only API that returns block-anchored snapshots of public Base on-chain data. It has no user accounts, no sign-up, and no login. This policy explains the limited data Orcpin processes and stores, and what it deliberately does not.","what_we_process":["The address(es) supplied in your request, used solely to read public on-chain state from the Base blockchain (and protocols on it, e.g. Aave v3) and return a snapshot.","For the endpoint-reliability service, the public x402 endpoint URL(s) you ask Orcpin to check. Only the endpoint location — scheme, host, and path — is used and retained; any query string, fragment, or embedded credentials are stripped before the endpoint is probed or stored. Orcpin uses this to measure that third-party endpoint's service delivery (reachability, response validity, latency). It is the address of public API infrastructure, not personal data, and is not linked to who requested the check.","Standard technical request metadata needed to operate the service: HTTP method, endpoint path, response status, latency, host, and a truncated user-agent string.","For paid endpoints, an x402 USDC micropayment, which is verified and settled on-chain via a payment facilitator. Orcpin does not receive or store card details, bank details, or off-chain identity."],"what_we_do_not_store":["Orcpin does not store the wallet address(es) you query. For the snapshot data endpoints the request query string is stripped before any usage metric is written, so the queried address is never recorded. (The endpoint-reliability service is the one deliberate exception: the public endpoint location (scheme, host, and path) you ask it to check is the subject of the measurement and is retained as an infrastructure reliability fact — see “What We Do Store” — even there, the query string is stripped first so request parameters are not stored, and Orcpin still never records who requested the check.)","Orcpin does not store request bodies, response data, IP addresses, accounts, passwords, or any off-chain personal information.","Orcpin does not build profiles of individuals and does not retain a per-caller history."],"what_we_store":["Aggregate, non-personal traffic counters: counts of requests by endpoint, outcome, coarse visitor class (agent / human / crawler / unknown), response status, and day. For settled payments this also includes a coarse own-wallet / external-customer split, the access channel (MCP wrapper vs direct API), and the total USDC amount paid per endpoint per day, so Orcpin can see which of its endpoints earn revenue. The payment amount is public on-chain information and is recorded as a per-endpoint running total only — never against a payer. These are numbers only and identify no one.","Reliability measurements about public third-party endpoints: for the endpoint-reliability service, Orcpin retains coarse service-delivery facts (e.g. reachability rate, valid-response rate, latency buckets, last status, first/last seen, and which HTTP method the endpoint answers on) keyed to the public endpoint location (scheme, host, and path only — query strings are stripped and never stored). This describes the operation of public API infrastructure, not any person, and is never linked to who requested a check.","A short rolling operational log of the most recent requests (currently the latest 50), each containing only a timestamp, HTTP method, endpoint path without the query string, response status, outcome, and the coarse visitor class. It contains no addresses, IP addresses, or user-agent strings.","Standard server logs retained by our hosting provider (Vercel) for a limited period for security and reliability. These contain operational request metadata (method, endpoint path without query string, status, latency, host, truncated user-agent) and no queried addresses, IP addresses, request bodies, or response data."],"cookies":["The API sets no cookies.","The marketing site sets no tracking or advertising cookies and uses no third-party analytics.","Orcpin uses no advertising, analytics, or cross-site tracking technologies. Any first-party browser storage is strictly necessary to operate the service and is never used to track or profile visitors."],"legal_basis":"Where data-protection laws such as the GDPR apply, Orcpin relies on legitimate interests: operating a read-only interface over already-public blockchain data, kept to the minimum needed, and never used to identify the people behind addresses. Processing of the address you supply is also necessary to perform the request you initiate.","no_identification":["Orcpin does not deanonymize wallets, link addresses to real-world identities, score or rate individuals, or combine on-chain data with off-chain personal data.","Derived metrics are transparent arithmetic on public on-chain values (see /methodology); they are factual computations, not profiles or judgments about any person."],"third_parties":["Hosting and standard server logging are provided by Vercel.","Public chain data is read through a third-party RPC provider.","x402 payments are verified and settled through a payment facilitator (Coinbase CDP on Base mainnet).","These providers process technical and transaction data only to deliver the service, under their own terms and privacy practices. Orcpin does not sell or share data for advertising."],"data_subject_rights":"Because Orcpin stores no personal data tied to an identity and retains no per-caller history, there is generally no personal record to access, correct, or delete. If you believe Orcpin has processed your personal data and wish to exercise a right under applicable law, contact us and we will respond as required.","retention":"Aggregate, non-personal counters may be retained indefinitely as service statistics. Endpoint-reliability measurements roll off automatically if an endpoint stops being probed (currently after about 60 days). The rolling operational log is limited to the most recent requests and overwrites itself. Hosting-provider server logs are retained only for the provider's standard period.","children":"Orcpin is a developer/agent API and is not directed to children, and it does not knowingly process children's personal data.","changes":"This policy may be updated at any time; continued use after an update constitutes acceptance. Material changes will be reflected in the date below.","contact":"Questions about this policy or a privacy request: massasoitadvisory.com."}