SolidRPC (“we”, “us”) operates self-hosted blockchain RPC infrastructure at solidrpc.io. This page describes what data we collect, why we collect it, and how to reach us about it.
Who we are
The data controller is SolidRPC, Inc., a Delaware (United States) corporation operating solidrpc.io. For any privacy question or request, contact [email protected].
Data we collect
- Account data. Email address, optional name, password hash. Used to authenticate you and contact you about your account.
- API keys. Stored. You can revoke any key at any time from the dashboard.
- Usage data. Usage metadata (timestamp, chain, RPC method calls, response status, byte count). Aggregated for billing and analytics.
- Security data. When you create an account, sign in, or use the service to make RPC requests, we record your IP address in a hashed, pseudonymized form — not the plain address. We use it to keep the service secure and to detect fraud and abuse. We do not use it to track you across other websites.
- Billing data. Payments are processed by Stripe; we store the resulting Stripe customer ID and a redacted payment summary. We never see card numbers.
- SLA data. For an enrolled eligible paid plan, we store gateway-observed outcome counts, selected networks, exclusions, terms acceptance, settlement, text claims, and credit records. Automated SLA evidence does not contain RPC request or response bodies.
What we do not collect
- We do not log RPC request bodies or responses.
- We do not sell, rent, or share your data with advertisers.
- We do not use third-party tracking on the marketing site.
Legal basis
- Performance of a contract. Creating your account, authenticating requests, and delivering the service you signed up for.
- Legitimate interests. Securing our infrastructure, preventing fraud and abuse, and producing the usage analytics shown in your dashboard.
- Legal obligation. Retaining billing and tax records where the law requires it.
Data retention
- Hourly usage records are pruned after 7 days.
- Daily usage aggregates are kept while your account is active.
- Operational and audit logs are retained for 30 days.
- Hashed IP records from sign-ins and service usage are retained for 90 days, then deleted.
- Raw SLA evidence remains in hot storage for 90 days and in immutable archives for 24 months.
- SLA policy publications, acceptances, agreement and coverage revisions, settlements, claims and attachments, and service-credit records are retained for seven years.
- Billing records are retained as required by applicable tax law.
- Ordinary account data is kept while your account is active and is deleted or deactivated when you delete the account, except where contractual, billing, fraud-prevention, tax, or other legal-retention requirements require us to keep specific records for longer.
Sub-processors
- EU data center providers — infrastructure hosting.
- Cloudflare — CDN, DDoS protection, and edge rate limiting (processes request IP addresses).
- Third-party RPC and beacon providers — upstream infrastructure for some networks.
- Stripe — payment processing.
- Email delivery provider — transactional email (verification, password reset).
A current list of named sub-processors is available on request to [email protected].
International transfers
Your data is hosted in the EU and accessed by SolidRPC, Inc. in the United States; some sub-processors (such as Stripe) are also US-based. Where data leaves the EEA, we rely on Standard Contractual Clauses to protect it.
Cookies & local storage
We store your authentication token and a copy of your API key in your browser’s local storage so the dashboard works and you can copy your endpoint URL, plus your dark-mode preference. We do not use advertising or cross-site tracking cookies.
Your rights
You can access, correct, export, delete, restrict, or object to the processing of your account data, and request portability. You can do most of this yourself in the dashboard; otherwise email [email protected] and we’ll respond within 7 days. You also have the right to lodge a complaint with your local data protection supervisory authority.