GCA Privacy Notice
This notice explains how the public GCA website handles email registration, contact suppression, controlled HTTPS account intake, read-only wallet verification, account status, reviewed service requests, and member/credit ledgers.
What The Public Site Collects
Email registration submits email, optional display name, source, language, interest tags, contact-consent acknowledgement, and no-secrets acknowledgement to the GCA Cloudflare Workers + D1 email API.
Email unsubscribe submits email, reason, source, contact-suppression acknowledgement, and no-secrets acknowledgement to the GCA Cloudflare Workers + D1 contact-suppression API.
The membership page publishes program rules and routes account actions to the controlled HTTPS Member Access service. It does not collect or store account data itself.
The live Member Access page submits controlled account intake, read-only wallet verification, eligible credit/member ledger records, and device-key service requests to Cloudflare Workers + D1. Service follow-up text is stored for authorized operator review but is never returned in public account history.
When Data Leaves The Browser
Email registration and email unsubscribe requests leave the browser when the user submits those forms on gcagochina.com; the production API base is https://gca-registration-api.gcagochina.workers.dev.
Controlled account, wallet, status, service request, follow-up, cancellation, and delivery-receipt data leaves the browser only when the user submits the corresponding live Member Access action.
Wallet Verification
Wallet verification is live as a read-only ERC-20 balanceOf check against the GCA contract on Base Mainnet. GCA does not need private keys, seed phrases, exchange API secrets, withdrawal permission, or custody to verify a public wallet balance.
Live Controlled Account Storage
The controlled HTTPS account UI stores account fields, wallet verification results, holding-period evidence, credit/member ledgers, service requests, public review prompts, private follow-up responses, delivery records, operational logs, and support notes needed to run the reviewed account path. Device status keys remain in the browser; D1 stores only their SHA-256 hashes.
How Data May Be Used
User Requests
Users can request correction or deletion by emailing support@gcagochina.com. Users can also use unsubscribe.html to request that an email be excluded from future GCA contact exports. Some records may be retained when needed for abuse prevention, security review, operational integrity, or legal compliance. GCA does not sell registration or contact data.
Privacy References
Use these readable privacy, terms, member, ledger, registration, unsubscribe, and support pages for public privacy and participation context.
Public Safety Boundary
No private key, seed phrase, exchange API secret, withdrawal permission, or custody request is part of the GCA member flow. Live service requests remain manually reviewed, do not create trading permission, and cannot override wallet balance checks or risk controls.