1. Who controls your data
H.O.H Trading Card House (“H.O.H”, “we”, “us”, or “our”) is the data controller for personal data processed through coreos.live/hoh, our marketplace, package-opening, auction, rewards, custody, delivery, account, and related services (the “Services”).
- Controller
- H.O.H Trading Card House
- Registration number
- To be confirmed before public launch
- Business address
- To be confirmed before public launch
- Telephone
- To be confirmed before public launch
- Privacy contact
- legal@coreos.live
This notice is intended to explain our processing under Malaysia’s Personal Data Protection Act 2010 (Act 709), as amended (“PDPA”), and other applicable privacy laws. It applies to visitors, account holders, buyers, sellers, bidders, referrers, and recipients of physical deliveries.
2. Personal data we collect
Depending on how you use H.O.H, we may collect:
- Account and identity data: display name, email address, password hash, internal user ID, authentication provider identifiers, profile image, referral code, and account role.
- Wallet and blockchain data: public wallet address, signed authentication messages, network and smart-contract identifiers, token IDs, and public transaction hashes. We do not ask for or store your wallet private key or seed phrase.
- Transaction and collection data: purchases, listings, offers, bids, package draws, published odds/configuration version, randomisation proof, sell-back decisions, rewards, points, commissions, ownership and custody status, and related timestamps.
- Payment data: payment provider, checkout/session and payment-intent identifiers, amount, currency, payment status, and fulfilment reference. Stripe processes full card or bank credentials; H.O.H does not receive full payment-card numbers.
- Delivery and intake data: recipient name, postal address, city, postcode, country, phone number, tracking reference, card certification details, and images or details supplied for custody or authentication.
- Technical and usage data: IP address and server/error logs, browser/device information made available in requests, session and security events, pages/actions involved in an error, and fraud-prevention signals.
- Preferences and communications: currency, theme, music and sound preferences, consent choices, and messages or evidence you send in a support, privacy, payment, delivery, or dispute request.
We do not intentionally collect sensitive personal data unless it is necessary to handle a legal claim, fraud report, or regulatory request and permitted by law.
3. Where data comes from
- Directly from you when you register, sign a wallet message, transact, request delivery, link a wallet, or contact us.
- From authentication providers you choose, such as Google, GitHub, X, Facebook, Apple, Resend, and wallet-connection providers, subject to which providers are enabled.
- From payment, delivery, custody, grading, fraud-prevention, and infrastructure providers involved in your request.
- From public blockchains and blockchain index/RPC services. Blockchain records are public by design.
- From another user where needed to complete a marketplace trade, referral, auction, ownership transfer, or delivery.
4. Why we process personal data
We process personal data where needed to provide the Services you request, comply with law, protect legitimate business and user interests, or where you have given consent. Purposes include:
- Creating and securing accounts; verifying email, password, OAuth, or wallet authentication; and linking one wallet to one account.
- Processing payments, purchases, transfers, listings, offers, auctions, draws, sell-backs, points, referrals, custody, and delivery.
- Publishing and preserving verifiable package odds, commitments, outcomes, NFT metadata, and transaction records.
- Preventing duplicate fulfilment, abuse, money laundering, fraud, account takeover, market manipulation, and violations of our Terms.
- Providing support, resolving disputes, processing refunds where due, enforcing agreements, and maintaining business/accounting records.
- Operating, debugging, measuring, protecting, and improving the Services.
- Sending service messages. We will use personal data for direct marketing only where permitted and with any consent required by law.
5. Required and optional data
You may browse public pages without an account. Account credentials are required for private account functions and transactions. A wallet address is optional for an email-first account but required for wallet authentication and on-chain features. Payment information is required for a paid checkout. Recipient and address data are required only when physical delivery is requested.
If you do not provide required data, we may be unable to create an account, process a transaction, verify ownership, prevent fraud, or deliver a card. Theme, currency, music, profile, and optional communication preferences may be withheld without preventing basic browsing.
7. Public and immutable blockchain data
Public networks are separate systems that H.O.H does not control. Once a transaction is broadcast, wallet addresses, token IDs, contract interactions, amounts, and transaction history may be permanently visible and copied by anyone. Even if we delete an account or off-chain record, we cannot erase or alter a blockchain record.
A wallet address may be personal data when it can be linked to an individual. Avoid publishing personal information in transaction data and use a wallet appropriate for public activity.
8. Cross-border processing
Some providers, networks, infrastructure, or support personnel may process data outside Malaysia. Where personal data is transferred abroad, we will use a transfer condition and safeguards required by section 129 of the PDPA, such as an adequacy assessment, contractual protections, consent where appropriate, or a transfer necessary to perform your requested contract. Public blockchain distribution cannot be limited to one country.
9. How long we retain data
We retain personal data only while reasonably needed for the purposes above and applicable legal requirements. In general:
- Account and collection records are kept while the account or custody relationship remains active and for a reasonable period afterwards.
- Payment, order, ownership, tax, fraud, and dispute records are kept for the period required by accounting, tax, limitation, anti-fraud, and other applicable laws.
- Delivery data is restricted after fulfilment and deleted or anonymised when no longer needed for delivery, claims, tax, or legal compliance.
- Security and error logs are kept for a shorter operational period unless needed to investigate an incident.
- Public blockchain data and copies held by independent network participants may remain indefinitely.
We may retain a minimal suppression, fraud, legal-hold, or transaction record after an erasure request where required or permitted by law.
11. Randomisation and automated processing
Package and pack outcomes are generated automatically from the disclosed pool and probabilities using the randomisation method identified on the relevant product or proof page. The outcome determines which card is allocated; it is not based on profiling your identity, spending, or personal characteristics.
Where applicable law gives you rights relating to automated decisions, you may contact us for information about the method, to report a technical error, or to request review. A request for review does not permit a re-roll of a valid random outcome.
12. Security and data breaches
We use proportionate technical and organisational safeguards, including password hashing, signed wallet authentication, access controls, server-side secrets, transaction locking/idempotency, database and transport protections, and operational monitoring. No internet or blockchain system is completely secure.
If a personal data breach creates the level of risk specified by law, we will notify Malaysia’s Personal Data Protection Commissioner and affected individuals within applicable periods. You are responsible for protecting your password, email account, wallet, private keys, seed phrase, and devices. H.O.H will never ask for your seed phrase.
13. Your privacy rights
Subject to the PDPA and any applicable exceptions, you may ask to:
- be informed whether and why we process your personal data;
- access a copy of personal data we hold about you;
- correct inaccurate, incomplete, misleading, or outdated data;
- withdraw consent, where processing depends on consent;
- prevent processing likely to cause unwarranted damage or distress;
- object to or stop direct marketing; and
- exercise data portability or automated-decision rights where those rights apply.
Email legal@coreos.live with your request. We may verify your identity and wallet/account control before acting. Some requests may be limited by transaction, custody, fraud-prevention, legal-retention, or public-blockchain requirements. You may also complain to Malaysia’s Personal Data Protection Commissioner.
14. Children
The transactional Services are intended only for people aged 18 or older and legally capable of entering a contract. We do not knowingly offer accounts or chance-based purchases to children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
15. Changes and contact
We may update this notice when the Services, providers, or law changes. We will post the revised date and provide prominent or direct notice where a change materially affects your choices.
Questions, complaints, access/correction requests, and withdrawal of consent should be sent to legal@coreos.live. Please do not include wallet private keys, seed phrases, full payment-card numbers, or unnecessary identity documents.
This English notice should be issued together with an accurate Bahasa Malaysia version where required by the PDPA.
