Privacy clause

Page 1 | General Provisions and Privacy Commitments
Welcome to use the NFTOWER platform (hereinafter referred to as “the Platform”). We are aware of the importance of personal information to users, and we promise to provide a reliable service environment on the basis of respecting user privacy and ensuring data security.
This Privacy Policy (hereinafter referred to as “this policy”) applies to all products, services, and related features provided by this platform, including but not limited to NFT browsing, trading, creation, co-creation, and participation in on-chain activities. By accessing or using this platform, you indicate that you have read, understood, and agree to be bound by this policy.
We are committed to:
Minimize data collection: collect only the information necessary to implement the platform functions;
On-chain decentralization principle: respect users’ full control over their on-chain assets;
Do not abuse or sell data: do not sell or rent user information to third parties, and do not use it for commercial purposes without authorization;
User control: the user has the maximum control over his own off-chain information;
Open and transparent: Specify how and why data is collected and used.
This policy is designed to clarify how we collect, use, store, share and protect your information, and to describe your relevant rights when using the Platform services. If you do not agree with any part of this policy, please stop using the Platform services immediately.

Page 2 | What information do we collect
In order to provide safe, stable and personalized Web3 NFT services, the platform may collect the following types of information during user use. We adhere to the “minimum necessary” principle of information collection, and only obtain the data necessary to implement relevant functions.
1. Information voluntarily provided by users
Basic identity information: such as the data you actively input when setting your personal nickname, profile picture and language preference on the platform;
On-chain address information: such as wallet address and public key information, which is used to identify your on-chain identity and conduct contract interaction;
Work information: such as the description, label, metadata and so on attached to your original work published on the platform;
Record of participation: off-chain interaction data provided when you participate in co-creation activities, voting, and proposals.
2. Information automatically collected by the system
Devices and browsing information: including but not limited to device type, browser version, access time, IP region, operation log, etc.;
Usage behavior information: such as browsing path, click preference, interaction frequency, content preference, etc., aiming at optimizing user experience;
On-chain interaction information: including public on-chain records of your NFT casting, trading, transfer, etc.
Third, identify the information that will not be collected
In order to maximize your privacy, the platform will not actively collect or store the following information:
Real name, identification certificate and bank card number;
Mobile phone number, email address;
Sensitive credentials such as social account password or wallet private key, mnemonic word, etc.
Users shall abide by their privacy policies when using third-party wallets or services, and the Platform shall not be responsible for controlling the processing of external data.

Page 3 | Ways of collecting information
In the process of providing services to users, nftower will collect necessary information in various ways according to different interaction situations. We ensure that the privacy rights of users are respected and protected in each way.
1. Information voluntarily provided by users
You may voluntarily provide information to the Platform in the following operations:
Set up profile (such as nickname, language);
Upload or publish original NFT content;
Participate in activities, co-create and vote for the platform;
Fill out a questionnaire or submit feedback within the platform.
Such information is voluntarily filled in by users and can be modified or deleted in the account.
2. Data automatically recorded by the system
In order to ensure the security of service operation and interaction continuity, we will automatically record some technical information when you visit the platform, including but not limited to:
Access time and frequency, page click path, stay time;
The type of device, operating system, browser type and version used;
Network status and IP address segment (not used for precise location);
Preferences recorded in Cookies and local storage files.
We use this information to optimize the interface experience, adjust content recommendations, and enhance platform stability and security.
3. Information sources of blockchain and third-party services
The platform reads the relevant transaction behaviors and NFT asset status of users on the chain by invoking smart contract or blockchain browser interface;
If the user accesses a third-party wallet (such as MetaMask, WalletConnect), the platform will identify it according to the public data provided by the user (such as wallet address, public key);
For cross-chain and cross-platform behaviors authorized by users, we will complete data synchronization or intercommunication under the premise of respecting user authorization.
Please note that the openness of blockchain determines that some data (such as NFT transaction history) can be accessed and verified by any user, and the platform cannot control its visibility.

Page 4 | How we use this information
The fundamental purpose of nftower to collect user information is to provide more secure, efficient and personalized NFT services. We use the collected information strictly in accordance with the principle of “expressed purpose and reasonable use” within the following scope:
1. Used to optimize user experience
Content recommendation and personalized presentation: according to users’ browsing preferences and participation behaviors, recommend related works and “Tower” content modules;
Language and interface customization: automatically identify the user’s language setting and device type, and provide adaptive interface;
Account function management: support information update, work management, history behavior review and other basic functions;
2. Used for platform system operation and maintenance
Behavior log analysis: help us to find out the system running bottleneck and optimize the platform architecture;
Service stability monitoring: identify potential failures, crashes, or malicious access behaviors through behavioral data;
Usage frequency statistics: evaluate the popularity of the core modules of the platform and continuously improve the function experience;
3. Used for safety protection and risk control identification
Identity authentication and behavior analysis: identify abnormal account activities, prevent volume brushing, malicious manipulation, false transactions;
Abuse prevention and control mechanism: automatic identification of suspicious operations, repeated uploads, or aggressive content;
Restrict the permission of illegal accounts: take restrictive measures against users who seriously violate the platform rules based on their behavior records;
4. Not for the following purposes
Unauthorized advertising: We will not push third-party advertising to you based on your user behavior;
Do not share identifiable information with marketing agencies: The Platform will not sell, rent or provide any data that can be used to identify identity to marketing companies, advertisers and other third parties;
No off-chain social behavior: We do not track users’ browsing, social, or purchasing behavior outside the platform.

Page 5 | Information sharing and disclosure
NFTOWER respects users ‘control over their personal information. Except as expressly required by law or authorized by users, we will not disclose, sell, lease or disclose users’ information to any irrelevant third party in any form. Our control of information disclosure follows the principle of minimum necessity and is only conducted under the following legal, reasonable and necessary circumstances:
1. Situations of disclosure in accordance with the law
We may disclose user information in accordance with legal requirements in the following circumstances:
Receive a formal request from the court, regulatory authority or law enforcement agency;
To fulfill legal obligations, such as combating money laundering, anti-terrorism financing, intellectual property infringement;
To safeguard the legitimate rights and interests of the Platform itself or other users (such as dealing with disputes, malicious attacks, etc.).
Where legal conditions are met, we will try our best to notify users before disclosure.
Second, restricted sharing in cooperative services
In some co-creation, activity or function, such as:
When users actively participate in cross-platform NFT exhibitions, on-chain joint issuance and content cooperation;
The platform has functional integration relationship with smart contract service providers, audit institutions and storage node operators;
When the platform, content curator and DAO organization conduct joint planning and users authorize to join;
We will minimize the disclosure of necessary user information and ensure that the recipient has a legal data protection responsibility, subject to the scope, purpose and confidentiality obligations clearly defined in the Agreement.
3. Use of de-identified and anonymous data
To improve platform performance and research analysis, we may use aggregated, non-identifiable statistical data for the following purposes:
Research on user behavior trends;
Optimization of content ecology;
Technical performance improvement.
This data does not include on-chain private keys, personal identities, contact information, or content that can be traced back to a specific user.

Page 6 | Blockchain transparency and non-removal
As a blockchain-based NFT aggregation platform, nftower adheres to the core principles of Web3: —— Openness, Decentralization, and Non-Tamperability. These technical features introduce new dimensions to user information visibility and control. Before using the platform’s services, users should fully understand the following:
1. Permanence and irreversibility of on-chain data
The on-chain operations (such as NFT casting, trading, transfer, confirmation of rights, etc.) carried out by users on the platform will be irreversibly written into the blockchain system;
All operation records on the blockchain (such as transaction hashes, contract calls, NFT metadata) will be permanently retained and cannot be deleted or tampered with;
Even if the user chooses to log out of the account, their historical on-chain behavior will continue to exist on the blockchain.
2. Publicly accessible technical attributes
All on-chain interaction data is publicly available to the world by default, including but not limited to NFT ownership transfer records, timestamps, contract addresses, on-chain wallet addresses, etc.;
Anyone can access this kind of data through the blockchain browser, and the platform cannot restrict its dissemination or secondary reference;
Users should avoid embedding sensitive personal information into the name, description, metadata and other immutable fields of the chain during the creation process.
Third, the boundary of responsibility of the platform
As an interactive platform, NFTower does not own the assets of users on the chain, nor can it control or interfere with the operations of users on the chain;
The platform cannot provide technical path for deleting, hiding and revoking on-chain data;
Users are responsible for ensuring that their on-chain actions are legal and compliant, and fully assessing the permanent visible consequences.
4. User information and suggestions
Do not embed personal identification information (such as name, contact information, id photo, etc.) in the uploaded NFT image, video or description;
Please properly manage wallet addresses and on-chain identities to prevent them from being associated with real identities in public scenarios;
We recommend that users preview and double check before performing any on-chain operations.

Page 7 | Cookie and Local Storage Policies
In order to improve the functionality and user interaction experience of the website, nftower uses Cookies and local storage technology within reasonable limits. These technologies are not used to track personal identity or for any form of advertising.
What are Cookies and local storage?
A Cookie is a small text file that a website stores on a user’s device to remember preferences, login status, language Settings, etc.;
Local storage is an enhanced data storage mechanism provided by the browser, which supports larger capacity information storage and is used for page state retention and content caching;
These two mechanisms do not include your wallet private key, mnemonic phrase, public key signature, and other on-chain credentials.
Second, the purpose for which we use these technologies
Maintain user session status: for example, remember the location of the last page you visited to improve browsing coherence;
Storage preference Settings: such as the language version you choose, display mode, NFT content filter tags, etc.;
Support security verification: assist in identifying abnormal operation behaviors and preventing malicious access;
Reduce repeated loading: Cache some resources (such as images, UI components) to improve loading speed.
3. Type of Cookie description
Functional Cookies: Used to support basic service functions and cannot be disabled;
Cookie performance analysis: used to count the frequency of access, duration of stay and interaction mode, which helps us optimize the page structure;
User preference Cookie: Record the user’s visual and language choices to improve ease of use.
Fourth, the user’s choice
You can manage the use of Cookies in your browser, including clearing stored information or blocking new Cookie Settings;
Please note that completely disabling Cookies may affect the normal use of some platform functions;
Nftower does not force the collection of Cookies or covert tracking.

Page 8 | Data security and protection measures
Nftower is committed to ensuring that the data collected and stored on the platform is fully protected throughout its life cycle through advanced and reasonable technical and management means. We always regard user data security as our basic responsibility and core value.
1. Platform security mechanism
Transmission encryption: all off-chain data is encrypted through HTTPS to prevent data from being stolen or tampered with during communication;
Access control: the platform has a hierarchical permission system to ensure that user data is only open to authorized modules;
Hot and cold data isolation: frequently accessed data and long-term stored data are managed separately to improve security and reading efficiency;
Smart contract audit: Key chain contracts are audited internally or by a third party before deployment to avoid code level vulnerabilities.
Second, the independent management guarantee of user assets
NFTower does not store or host users’ private keys, mnemonics, or wallet accounts;
All on-chain interactions require users to actively initiate signatures through their own wallets, and the platform cannot control their assets on behalf of users;
Users should ensure the security of their devices when using wallets for signature interactions to avoid credential leakage.
3. Security incident response mechanism
The platform has an abnormal behavior monitoring system, which can identify risks such as malicious registration, brushing volume and attack behavior;
In case of data leakage or system security incidents, we will locate the source of the problem, limit the scope of influence and inform users in the first time;
For major risks, the emergency response process will be initiated and relevant modules will be suspended to ensure that users’ rights and interests are minimally affected.
4. Regular review and upgrade
Security policies will be updated regularly to address new technology risks or attack methods;
Major updates will be announced to users to explain the scope of impact and operational suggestions;
The platform welcomes users to submit security suggestions or vulnerability clues, and we promise to respond positively and continue to improve.

Page 9 | User rights and control
NFTower respects the right of every user to know, control and delete their own data. On the premise of not violating the principle of imtamability of blockchain, we give users the maximum management freedom of their off-chain data, while providing clear and transparent operation path.
1. Rights that users can exercise
Access: Users can log in to the platform at any time to view their account information, uploaded work information, co-creation activities and operation records;
Right to correct: off-chain data such as nickname, profile picture, profile, language setting and so on can be directly modified by users in the personal Settings page;
Restricted processing rights: If users do not want certain off-chain information to be used for content recommendation or algorithm optimization, they can set up to turn off the relevant services;
Data portability: upon application by the user, the platform can provide an export interface for its off-chain information for migration or backup;
Right to delete (off-chain): Users can delete the uploaded content that has not been uploaded to the chain or log out their accounts. The platform will remove their off-chain records within a reasonable period of time.
Second, the immutability of on-chain behavior
Based on the principle of openness and imtamability of blockchain, users’ records such as on-chain transactions, NFT casting and transfer cannot be modified or revoked by the platform;
Users shall be responsible for their on-chain actions, including smart contract interactions and asset transfers arising from their operations;
The user’s cancellation of the platform account does not affect the continued existence of his wallet address on the chain and the status of his asset holding.
Account cancellation and data clearing
Users can apply to cancel their accounts voluntarily, and the platform will complete the processing without outstanding matters (such as contract execution or pending reports);
After the cancellation is successful, the platform will clear its off-chain account information, preferences, browsing history and other information;
Cancellation does not affect the visibility and ownership of on-chain data.
4. Complaints of abnormality and misuse
If users find that their data is misused, incorrectly handled or displayed abnormally by the platform, they can submit feedback through the appeal channel in the platform Settings;
The platform will check and deal with the valid complaint within a reasonable time after receiving it, and reply to the result;
Nftower promises not to put artificial obstacles in the exercise of users’ rights and not to bypass their choice by technical means.

Page 10 | Clause change and effectiveness statement
In order to respond to technological evolution, business adjustment, legal and policy changes or user needs, nftower has the right to update and revise the contents of this Privacy Policy from time to time. We promise to continue to protect users’ right to know and choice during the process of changing the terms.
1. Clause update mechanism
Any material change to these Privacy Terms will be notified in advance by nftower through platform announcements, pop-ups or other visual means;
The changes will clearly list the revised parts and when they will take effect, ensuring that users have sufficient time to understand and decide whether to continue using the service;
If the user continues to use the platform after the new policy takes effect, it shall be deemed to have accepted the updated content;
If the user does not agree to the updated terms, he/she may choose to stop using the service and apply for account cancellation according to this policy.
2. Common reasons for revision include but are not limited to:
New services, functions or data processing scenarios on the platform;
Security adjustments related to the blockchain contract mechanism;
Compliance with new regulatory rules, compliance obligations or legal updates;
Optimize the structure of user experience and data control capabilities.
3. Interpretation and application of the provisions
These Privacy Terms are the official statement of nftower on user data processing, applicable to all users who register and use the platform services;
The title of the clause is only for the convenience of reading and does not affect the interpretation of the content;
The final interpretation of this policy is owned by nftower.
4. Effective time
These Privacy Terms shall come into force on the date of official release of the Platform and shall apply to all current and future registered users until a subsequent version replaces this Policy.