Privacy Policy
Last updated August 16, 2026
IMPORTANT: PERMANENT DATA STORAGE & JURISDICTIONAL RISK
DACR USES AN IMMUTABLE EVIDENCE LAYER, INCLUDING BLOCKCHAIN, DISTRIBUTED LEDGER TECHNOLOGY, AND APPEND-ONLY INFRASTRUCTURE. ONCE DATA IS WRITTEN TO THE PERMANENT EVIDENCE LAYER, DACR MAY BE TECHNICALLY UNABLE TO DELETE, MODIFY, OR ERASE IT. WHERE DELETION IS NOT TECHNICALLY FEASIBLE, DACR WILL TAKE REASONABLE STEPS WITHIN ITS CONTROL TO LIMIT THE VISIBILITY AND FURTHER USE OF YOUR DATA, BUT CANNOT GUARANTEE THE REMOVAL OF DATA FROM ALL SYSTEMS. THE SERVICES' ARCHITECTURE MAY CONFLICT WITH DATA PROTECTION LAWS IN CERTAIN JURISDICTIONS. IF YOUR LOCAL LAWS REQUIRE DELETION RIGHTS THAT THE SERVICES CANNOT HONOR, YOU SHOULD NOT USE THE SERVICES. BY USING THE SERVICES, YOU ACCEPT THIS RISK. SEE SECTIONS 7, 8, AND 14.
This Privacy Policy explains how Dacr Inc. and its affiliates ("Dacr") collect, use, disclose, retain, and protect information about you when you use our websites, mobile apps, APIs, and all other products and services (the "Services"). By using the Services, you agree to this Policy. We may update it from time to time with notice. Capitalized terms used but not defined in this Policy have the meanings set forth in the Terms of Service.
1.Information We Collect
1.1Information You Provide
Account and identity: Name, username, email, postal address, phone, date of birth, gender, government-issued ID, nationality, tax IDs, beneficial-owner information, and proof-of-authority documentation.
Financial: Payment information processed through third- party payment providers (such as Stripe), which may include credit/debit card details, bank account information, billing address, and digital wallet addresses. Dacr receives limited payment data from these providers, such as transaction tokens, last four digits of the card, card type, expiration date, and billing address, but generally does not receive or store full card numbers.
User Content: Files, text, images, audio, video, creative works, metadata, registration data, authorship information, and documentation.
Communications: Emails, chat messages, support requests, and feedback.
Transaction data: Purchase details, licenses, assignments, and transaction records.
Verification data: Government-issued photo ID, proof of address, tax documentation, and KYC/AML documentation. Where identity verification is enabled, this may include facial images, liveness data, and other biometric identifiers, which are collected and processed with your consent by Dacr's third-party verification providers for identity- verification, fraud-prevention, and compliance purposes. Biometric identifiers are used for verification purposes only and are never written to the Permanent Evidence Layer or any Immutable System.
1.2Information Collected Automatically
Log data: Browser type, app version, access times, pages viewed, IP address, referring URL.
Device data: Hardware model, OS, unique device identifiers, mobile network info.
Location: Precise or approximate location information, which may be derived from GPS, Wi-Fi, cellular network data, Bluetooth, IP address geolocation, or other available signals, depending on your device, settings, and how you access the Services.
Usage data: Search terms, features used, actions taken, interaction patterns, session duration.
Transaction metadata: IP address at purchase time, device fingerprint, geolocation, timestamps (retained for chargeback defense).
Cookies: See Section 4.
1.3Third-Party Sources
We may receive information about you from third-party sources, which may include identity verification and KYC providers (including those used by Dacr or by government authorities operating within Dacr's platform), payment processors, credit bureaus, fraud prevention services, publicly available sources, social media platforms, government databases, marketing partners, and other service providers.
2.How We Use Your Information
We use information to: (a) provide and improve the Services; (b) process payments and collect amounts owed; (c) facilitate government registrations; (d) send administrative communications; (e) market products; (f) monitor and analyze usage; (g) detect and prevent fraud; (h) verify identity for KYC/AML; (i) comply with laws; (j) defend chargeback disputes; (k) personalize experiences; (l) conduct R&D; (m) pursue collection of unpaid amounts; and (n) any other disclosed purpose.
3.How We Share Your Information
We share with: (a) affiliates; (b) service providers, payment processors, analytics, and identity verification; (c) government authorities in Partner Jurisdictions; (d) marketing and advertising partners (you may opt out through the cookie consent mechanism described in Section 4, the Global Privacy Control (GPC) signal, the opt-out tools described in Section 13, or by emailing legal@dacr.com); (e) in response to legal process; (f) to protect rights and safety; (g) in business transfers; (h) counterparties in Transactions; (i) the Permanent Evidence Layer (publicly accessible); (j) collection agencies and attorneys; (k) financial institutions for chargeback disputes; (l) law enforcement; and (m) with your consent. We may share aggregated or de-identified data.
If you enroll in the Membership Program and elect to use a benefit provided by a third-party partner, we may also share your information with that partner as necessary to provide, administer, verify eligibility for, and deliver the benefit. The partner's use of your information is governed by the partner's own privacy policy.
4. Cookies and Tracking Technologies
We and our third-party partners use cookies, tracking pixels (including the Meta Pixel, Google Analytics tags, TikTok Pixel, and Microsoft tracking technologies), web beacons, software development kits (SDKs), session recording tools, local storage, and similar technologies (collectively, "Tracking Technologies") to collect information about your interactions with the Services.
Types of Tracking Technologies:
(a) Essential Cookies are required for the operation of the Services, including authentication, security, session management, fraud prevention, and load balancing. These are strictly necessary for the Services to function and do not require your consent. They cannot be disabled without impairing core functionality.
(b) Performance/Analytics Cookies help us understand how the Services are used, measure performance, and identify errors. These cookies collect aggregate or anonymized usage data.
(c) Functionality Cookies enable enhanced features, personalization, and preferences such as language settings.
(d) Advertising/Targeting Cookies are used by Dacr and third-party advertising partners (including Meta, Google, Microsoft, TikTok, and others) to deliver relevant advertisements and measure advertising campaigns, including cross-context behavioral advertising on third-party platforms. These cookies may result in you seeing advertisements related to the Services on third-party platforms after interacting with the Services.
Tracking Technologies in categories (b), (c), and (d) above may result in data being transmitted to third-party providers' servers, including servers operated by Meta, Google, Microsoft, and other advertising and analytics providers. These third parties may use such data for their own advertising, analytics, and measurement purposes, subject to their own privacy policies.
Consent and Opt-Out. Where required by applicable law, Dacr will obtain your consent before placing non-essential Tracking Technologies (categories (b), (c), and (d) above) on your device. You may manage your Tracking Technology preferences through: (i) any cookie consent mechanism provided through the Services; (ii) your browser settings; (iii) the Global Privacy Control (GPC) signal; or (iv) industry opt-out tools such as those provided by the Digital Advertising Alliance or equivalent programs. Disabling non-essential Tracking Technologies may reduce the personalization and functionality of the Services but will not prevent you from accessing core features.
Consent to Essential Tracking. By accessing and using the Services, you acknowledge that Essential Cookies (category (a) above) are strictly necessary and will be placed without separate consent, as permitted by applicable law. Your use of the Services constitutes acknowledgment of Essential Cookies, not consent to non-essential tracking. Non-essential tracking is governed by the consent mechanisms described above.
CIPA Consent. For Users in California: to the extent that any Tracking Technologies described above involve the recording, interception, or transmission of electronic communications, your consent to such Tracking Technologies (whether provided through a cookie consent mechanism, by adjusting your browser settings to allow cookies, or by other affirmative means) constitutes all-party consent within the meaning of California Penal Code Sections 631 and 632. See also Section 27.9 of the Terms of Service.
5.Advertising and Analytics
We may allow third parties (including Meta (Facebook/Instagram), Google (including Google Analytics, Google Ads, and YouTube), X (formerly Twitter), LinkedIn, Snap, TikTok, Microsoft, and others) to provide analytics services and serve advertisements on our behalf using Tracking Technologies. These third parties may collect information about your use of the Services and other websites, including IP address, device identifiers, pages viewed, and conversion events, for purposes of analytics, targeted advertising, retargeting, audience creation, and ad measurement.
You may see advertisements related to the Services on third-party platforms after interacting with the Services. This is a result of the Tracking Technologies described above, to which you have consented.
6.Social Sharing
Social sharing features enable sharing with your connections per your settings. Review relevant platforms' privacy policies.
7.Data Retention; Permanent Evidence Layer
7.1 We retain information as long as necessary for stated purposes, legal compliance, dispute resolution, enforcement, and legitimate interests.
7.2 PERMANENT EVIDENCE LAYER. Certain data is permanently written to Immutable Systems (append-only databases, blockchains, distributed ledgers, and Dacr's own append-only infrastructure). DUE TO THE IMMUTABLE NATURE OF THIS TECHNOLOGY, DACR MAY BE TECHNICALLY UNABLE TO DELETE, MODIFY, OR ERASE SUCH DATA. By using the Services, you accept that such data will in all likelihood remain permanent and irremovable. Where deletion is not technically feasible, Dacr will take reasonable steps within its control to limit the visibility and further use of your data (which may include deleting data from some systems, suppressing or restricting access to data in others, and ceasing active processing), but certain data may remain on the Permanent Evidence Layer, third-party systems, or infrastructure that Dacr cannot modify without compromising the integrity and intended function of the system.
7.3 Upon account deletion request, Dacr will take reasonable steps within its control to delete, suppress, or restrict access to your personal data across its systems, to the extent technically feasible without compromising the integrity and intended function of the Permanent Evidence Layer and the Services. Some data may be deleted entirely; other data may be suppressed or restricted; and certain data may remain permanently on systems that Dacr cannot modify. Data may also be retained as required by applicable law, as shared with government authorities, in backups deleted in ordinary rotation, or in aggregated or de-identified form that is no longer linked to you.
7.4 Transaction records are retained for a minimum of 7 years for chargeback defense, fraud prevention, tax compliance, and legal proceedings.
8.International Data Transfers
Controller. The data controller for the processing described in this Policy is Dacr Inc., a Florida corporation, with registered address at 20801 Biscayne Blvd, Suite 506, Aventura, Florida 33180, United States. Contact: legal@dacr.com.
International Transfers. Dacr processes data primarily in the United States. Your personal data may be transferred to, stored in, and processed in the United States and other countries that may have data- protection laws different from those of your country of residence. Where personal data originating from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland is processed by Dacr's service providers (including cloud infrastructure and payment processors), those providers maintain appropriate transfer safeguards, which may include Standard Contractual Clauses (SCCs) approved by the European Commission or UK International Data Transfer Agreement / Addendum, as applicable. You may request information about the applicable transfer safeguards by contacting legal@dacr.com.
Blockchain and distributed ledger networks are decentralized and replicate data across nodes worldwide. Dacr does not control node locations, and data written to the Permanent Evidence Layer may be stored and replicated in multiple jurisdictions simultaneously. Data may also be transferred to government authorities in Partner Jurisdictions as described in Section 16.
9.Data Security
We implement commercially reasonable technical and administrative security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, and access controls and authentication requirements. Dacr regularly evaluates and updates its security practices as its operations evolve. No method of transmission or storage is completely secure, and Dacr cannot guarantee absolute security.
However, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security and are not responsible for the actions of third parties, hackers, or other unauthorized persons. Blockchain and distributed ledger networks, by their nature, are publicly accessible and Dacr cannot control the security of data once it has been written to the Permanent Evidence Layer. You use the Services at your own risk and are responsible for maintaining the security of your account credentials.
10.Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Dacr will: (a) notify the applicable supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, as required by applicable law (including GDPR Article 33); (b) where the breach is likely to result in a high risk to your rights and freedoms, notify affected individuals without undue delay as required by applicable law (including GDPR Article 34); (c) describe the nature of the breach, likely consequences, and measures taken or proposed; and (d) comply with any additional breach-notification requirements under U.S. state laws, the LGPD, or other applicable laws. Notification may be delayed where a law enforcement authority requests a delay or where notification would compromise an ongoing investigation.
11. Automated Decision-Making and Profiling
The Services may use automated processes, including artificial intelligence, machine learning, deep learning, and algorithmic systems, for the following purposes:
(a) Fraud Detection and Prevention: Automated analysis of transaction patterns, device information, IP addresses, and behavioral signals to identify and prevent fraudulent activity, unauthorized access, and payment fraud.
(b) Content Moderation: Automated screening of User Content for compliance with these Terms, including detection of prohibited content, spam, and policy violations.
(c) Copyright Fingerprinting and Matching: Automated analysis of User Content to generate digital fingerprints, identify potential similarities with other works, and surface Match Alerts.
(d) Risk Scoring and Identity Verification: Automated assessment of identity verification data, KYC/AML compliance, and account risk levels.
(e) Account Security: Automated monitoring for suspicious login activity, credential stuffing, and unauthorized access attempts.
(f) Personalization: Automated analysis of usage patterns and preferences to personalize your experience with the Services.
(g) Service Development and Improvement: Automated analysis that supports the development, improvement, and optimization of the Services, including the analysis, detection, fingerprinting, and matching systems described above and broader operational improvements.
These automated processes may result in decisions that affect your access to the Services, your account status, the processing of your registrations, or the visibility of your content. In most cases, automated decisions that have a significant effect on you are subject to human review upon request.
If you are located in a jurisdiction that provides rights with respect to automated decision-making (including under GDPR Article 22), you may have the right to: (a) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects; (b) obtain human intervention; (c) express your point of view; and (d) contest the decision. To exercise these rights, contact legal@dacr.com. Dacr will respond within the timeframes required by applicable law.
12.Your Rights and Choices
12.1Update account information via settings or support@dacr.com.
12.2Control location via device settings.
12.3Manage cookies via browser settings.
12.4 Opt out of promotional emails via unsubscribe links. Transactional, billing, and legal messages cannot be opted out of.
12.5 DELETION LIMITATIONS: Due to the immutable nature of the Permanent Evidence Layer and Dacr's infrastructure, Dacr may be technically unable to delete certain data. Where deletion is not feasible, Dacr will take reasonable steps within its control to limit the visibility and further use of your data. See Section 7.2.
13.U.S. State Privacy Rights
Residents of states with comprehensive privacy laws (including but not limited to California, Colorado, Connecticut, Virginia, and others) may have rights to: confirm processing, access, correction, deletion (subject to Section 7), opt-out of targeted advertising/sales/profiling, and limit sensitive data processing. As additional states enact privacy legislation, Dacr will extend applicable rights to residents of those states in accordance with mandatory law. To exercise your rights, contact legal@dacr.com. To appeal a decision regarding your rights, contact the same address.
California: Under CCPA/CPRA: (i) Dacr does not "sell" personal information as defined by the CCPA/CPRA; (ii) Dacr may "share" personal information (as defined by the CCPA/CPRA) with third-party advertising partners for cross-context behavioral advertising; (iii) you may opt out of such sharing by emailing legal@dacr.com with the subject "Do Not Share," by using any opt-out mechanism provided through the Services, or by enabling the Global Privacy Control (GPC) signal in your browser; (iv) Dacr honors GPC signals as a valid opt-out of sale/sharing to the extent required by the CCPA/CPRA and CPPA guidance; (v) Dacr will not discriminate against you for exercising your rights; and (vi) you may designate an authorized agent to exercise rights on your behalf.
14. Jurisdictional Risk Acknowledgment
IMPORTANT. The Services use permanent, immutable architecture that may conflict with data protection laws in certain jurisdictions (GDPR, UK GDPR, LGPD, and others providing deletion, erasure, or rectification rights the Services cannot honor).
If your local laws require deletion rights that the Services cannot honor, you should not use the Services. Your use of the Services despite this warning constitutes your informed acknowledgment and acceptance of the permanence of the data architecture and the potential legal conflicts described above, and you proceed at your own risk.
Where Dacr provides Services in such jurisdictions, it may process data under: (a) performance of contract; (b) legal obligations; (c) legitimate interests; and (d) consent for optional processing where required. The permanent retention of data on the Permanent Evidence Layer is independently supported under GDPR Article 17(3) as necessary for: (i) the establishment, exercise, or defense of legal claims (Article 17(3)(e)): copyright registration records serve as primary evidentiary proof of ownership in legal proceedings, and this is Dacr's primary basis for retention; and (ii) to the extent applicable, compliance with a legal obligation under Union or Member State law (Article 17(3)(b)). These bases operate independently of consent. Dacr acknowledges that the applicability of these exceptions depends on a case-by-case assessment.
Where Dacr cannot honor deletion requests due to the Permanent Evidence Layer, it will: (a) inform you; (b) delete from controlled systems; and (c) restrict further processing within its control.
To the fullest extent permitted by applicable law, you release and hold harmless the Dacr Parties from any and all Claims, damages, or liabilities arising from or related to: (i) any conflict between the Services and the laws of your jurisdiction; (ii) any inability of Dacr to honor deletion, erasure, rectification, or portability requests due to the Permanent Evidence Layer; or (iii) any action taken against you in connection with your use of the Services in a jurisdiction whose laws conflict with the Services' architecture. See Section 27 of the Terms of Service for full details.
15.Brazil (LGPD)
If you are located in Brazil, the Lei Geral de Protecao de Dados (LGPD) provides you with certain rights, including: (a) confirmation of the existence of processing; (b) access to your personal data; (c) correction of incomplete, inaccurate, or outdated data; (d) anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non- compliance with the LGPD; (e) portability of your data to another service provider; (f) deletion of personal data processed with your consent, subject to the retention exceptions in Section 7 (including the Permanent Evidence Layer and LGPD Article 16); (g) information about public and private entities with which your data has been shared; (h) information about the possibility of denying consent and the consequences of denial; and (i) revocation of consent.
The limitations on deletion described in Section 7.2 (Permanent Evidence Layer) and Section 14 apply to the extent permitted by the LGPD, including the retention exceptions under LGPD Article 16 (legal/regulatory obligation, exclusive use by the controller with anonymization) and the processing basis under LGPD Article 7(VI) (regular exercise of rights in legal proceedings). To exercise your LGPD rights, contact legal@dacr.com.
16. Partner Jurisdiction Data Practices
In connection with Government Registration Services, we process and share your personal data (including your identity information, User Content, registration data, authorship information, and supporting documentation) with government authorities, intellectual property offices, copyright registries, and other governmental entities in Partner Jurisdictions as necessary to process your registrations and facilitate cross-border recognition.
The handling, retention, security, and protection of your data by government authorities in Partner Jurisdictions is governed by the applicable laws and policies of those jurisdictions, not by this Privacy Policy. Dacr does not control and is not responsible for the data- protection practices of any government authority. Government authorities may retain, publish, share, or process your data in accordance with their own laws and practices, which may differ from the standards described in this Policy.
Authorized personnel of governmental authorities in Partner Jurisdictions may also access, view, monitor, and export registration data and related user data through administrative interfaces provided as part of the Official Registry Services. Such access and any subsequent use, processing, storage, or disclosure of data by a governmental authority or its personnel is governed by the laws and policies of that jurisdiction, and Dacr is not responsible or liable for it.
You acknowledge and consent to the transfer and disclosure of your personal data to government authorities in Partner Jurisdictions as a necessary part of Government Registration Services. If you do not wish for your data to be shared with government authorities, you should not use Government Registration Services.
To exercise data-protection rights regarding data held by a government authority in a Partner Jurisdiction, you should contact that authority directly. Dacr may assist in facilitating such requests where commercially reasonable, but has no obligation or ability to compel a government authority to comply with your request.
A list of current Partner Jurisdictions is available in Schedule A of the Terms of Service at www.dacr.com/legal/terms.
17.Children's Privacy
Not directed to children under 13. We do not knowingly collect from children. If discovered, we will delete from controlled systems. Permanent Evidence Layer data may not be deletable. Contact: legal@dacr.com.
18.Third-Party Links
This Policy does not apply to third-party websites. Review their policies.
19. Data Protection Officer; EU/UK Representative
Data Protection Officer. Dacr assesses whether the nature and scope of its processing activities require the appointment of a Data Protection Officer (DPO) under GDPR Article 37 or equivalent provisions of other applicable laws. Dacr has not appointed a DPO at this time based on its current assessment. Dacr will appoint a DPO if and when its processing activities meet the thresholds set forth in Article 37.
EU/EEA and UK Representative. Dacr Inc. is incorporated in the United States and does not have an establishment in the European Economic Area (EEA) or the United Kingdom. Dacr acknowledges that, to the extent it offers goods or services to individuals in the EEA or UK or monitors their behavior within the EEA or UK (GDPR Article 3(2)), GDPR Article 27 may require the designation of a representative in the EEA and/or UK. Dacr is in the process of evaluating and appointing an EU/EEA representative and, where applicable, a UK representative, and will update this Privacy Policy with the representative's name and contact details upon appointment. In the interim, all data protection inquiries, requests, complaints, and communications from individuals located in the EEA or UK (including requests to exercise rights under GDPR Articles 15-22) should be directed to:
Dacr Inc. - Data Protection Inquiries
Email: legal@dacr.com (subject line: "Data Protection Inquiry - EEA/UK")
Mail: Dacr Inc., Attn: Data Protection, 20801 Biscayne Blvd, Suite 506, Aventura, Florida 33180, United States
Dacr will respond to all EEA/UK data protection inquiries within the timeframes required by applicable law, including the one-month period specified in GDPR Article 12(3). If you are located in the EEA and believe that Dacr's processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority in your Member State of habitual residence, place of work, or place of the alleged infringement. If you are located in the UK, you may lodge a complaint with the UK Information Commissioner's Office (ICO).
20.Changes
We may revise this Policy. Material changes communicated via effective date update and additional notice. Continued use constitutes acceptance.
21.Contact
Dacr Inc. | 20801 Biscayne Blvd, Suite 506, Aventura, Florida 33180
Email: legal@dacr.com | Support: support@dacr.com
Copyright 2026 Dacr Inc. All rights reserved.
Content
- 1.Information We Collect
- 2.How We Use Your Information
- 3.How We Share Your Information
- 4.Cookies and Tracking Technologies
- 5.Advertising and Analytics
- 6.Social Sharing
- 7.Data Retention; Permanent Evidence Layer
- 8.International Data Transfers
- 9.Data Security
- 10.Data Breach Notification
- 11.Automated Decision-Making and Profiling
- 12.Your Rights and Choices
- 13.U.S. State Privacy Rights
- 14.Jurisdictional Risk Acknowledgment
- 15.Brazil (LGPD)
- 16.Partner Jurisdiction Data Practices
- 17.Children's Privacy
- 18.Third-Party Links
- 19.Data Protection Officer; EU/UK Representative
- 20.Changes
- 21.Contact