Legal
Privacy policy
How NestHunt collects, uses, shares and protects personal data, what stays off-chain, and the rights you can exercise over your information.
Last updated 1 September 2026
1. Scope
This policy covers personal data processed when you use the NestHunt platform, whether as a home seeker, a partner firm or a visitor to this website. It sits alongside the terms of service and any privacy notice given at the point a specific product is provided.
NestHunt is the controller of the personal data described here. Partners you engage through the platform are separate controllers of the data you share with them directly, and their own notices apply to that use.
2. Data we collect
We collect only what is needed to verify who you are, operate the platform and meet our legal obligations.
- Account data: name, email address, phone number, country of residence and account preferences
- Verification data: government identification, proof of address, proof of funds, and for partners the licence and registration details we check
- Wallet data: public wallet addresses you connect and the membership tier held against them
- Transaction data: payments, conversions, savings contributions, escrow milestones and settlement records
- Usage data: searches, saved listings, dismissals, alerts and interactions used to rank recommendations
- Technical data: device type, browser, approximate location from IP address, and security event logs
- Communications: messages you send to our desks or to partners through the platform
3. What is recorded on-chain
Identity documents and personal details are never written to a public network. What appears on-chain is the transaction itself: contract addresses, wallet addresses, amounts, milestone states and timestamps. Verification status is recorded as an attestation confirming that a check passed, without exposing the underlying documents.
Public network records are permanent and cannot be edited or deleted by NestHunt or by anyone else. Wallet addresses are pseudonymous rather than anonymous, which means activity associated with an address may be linkable. Consider this before choosing which wallet to connect.
4. Why we process it
Each category of data has a defined purpose and a lawful basis for processing.
- To perform our contract with you: operating your account, memberships, payments and settlement
- To meet legal obligations: identity verification, anti-money-laundering checks, sanctions screening, tax and record keeping
- For our legitimate interests: preventing fraud and abuse, securing the platform, improving models and measuring service quality
- With your consent: marketing communications, optional analytics, and sharing your details with a partner as a lead
6. Lead generation and partner introductions
Partner lead generation runs on consent. Your details are shared with a partner only where you have asked to be introduced or have opted in to introductions for a market. The lead includes the information needed to help you, such as budget band, market and stage, and no more.
You can withdraw consent at any time from your account. Withdrawal stops future sharing immediately. It cannot recall data a partner has already lawfully received, and their own retention obligations then apply.
7. How long we keep it
Account and usage data is retained while your account is open and for a reasonable period afterwards to resolve queries and disputes. Verification and transaction records are retained for the period required by anti-money-laundering and tax law in the relevant jurisdiction, which is typically five to seven years after the relationship ends.
Marketing preferences are retained until you change them. On-chain records cannot be deleted, as set out in section 3.
8. Security
Personal data is encrypted in transit and at rest. Access is limited to staff who need it for their role and is logged. Verification documents are held in restricted storage separate from operational systems.
We test our systems and our contracts independently, run a vulnerability disclosure channel, and notify affected members and the relevant supervisory authority where a breach requires it. No system is without risk, and your own key management is a critical part of keeping your funds safe.
9. International transfers
NestHunt operates across multiple regions, so personal data may be processed outside your country. Where data leaves a jurisdiction that restricts transfers, we rely on an approved transfer mechanism such as standard contractual clauses or an adequacy decision, together with technical safeguards appropriate to the data.
10. Your rights
Depending on where you live, you may exercise the following rights. We respond within one month, and we will tell you if a legal obligation prevents us from acting on a request.
- Access a copy of the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete data where we no longer have a lawful basis to keep it
- Restrict or object to processing carried out under legitimate interests
- Receive your data in a portable format
- Withdraw consent at any time, without affecting processing already carried out
- Complain to your local data protection authority
12. Contacting us
Privacy questions and rights requests can be raised through the contact page or sent to the membership desk, which routes them to the data protection team. Suspected security issues should go to the security disclosures channel so they are seen the same day.
Exercise a data right or report a concern
Access, correction, deletion and portability requests go to the membership desk, which routes them to the data protection team. Suspected security issues go to the security channel and are seen the same day.