This Privacy Policy explains how Meme Limited ("we", "us") collects, uses and shares personal data when you use meme.com and its games and related services (the "Services").
1. Who we are
Meme Limited is the controller of your personal data.
Meme Limited, Madison Building, Midtown, Queensway, Gibraltar GX11 1AA Email: legal [at] meme.com
2. What we collect
When you create or use an account
- Wallet addresses (EVM and Solana) you connect, and the signature you use to sign in. We never ask for your private keys or seed phrase.
- Email address, if you sign in with email or add one, and whether it is verified. We send one-time sign-in and verification codes to it.
- Profile: your username and profile image.
- Connected accounts: if you connect X (Twitter), your X account ID, handle and profile image, plus an access token that lets us read your profile and posts (used for sign-in and quests; we cannot post on your behalf). If you connect Discord, your Discord account ID and username, plus access that lets us add you to the meme.com Discord server when you choose to join it.
- Activity in the Services: Points (memescore), game activity such as votes, trades and races, quests, rewards, digital collectibles you mint, and the terms version you accepted and when.
- How you found us: the campaign, source or referring page that brought you to sign up.
When you contact us or send suggestions
- The content of your message or suggested article edit, and your contact details.
Automatically, when you use the Services
- Usage data through Google Analytics: pages viewed, clicks, approximate location (country/city derived from IP; Google does not store the IP address itself in Analytics), device and browser type, and referring site.
- Security and fraud-prevention data: when you sign in, claim rewards, complete quests or use games, we record your IP address, browser user agent and basic device characteristics (such as screen size, time zone, language and platform). We delete the raw IP address after 90 days and the raw browser/device details after 12 months. We also keep pseudonymous (one-way, peppered) hashes (of the device fingerprint, the browser, the device settings and the network prefix (never your full IP address)) for as long as this security record exists (see section 7). We use this data, raw or hashed, only to detect multiple accounts, bots and reward abuse.
- Server logs: technical logs of requests and errors, used to run and secure the Services.
From public sources
- Public blockchain data about wallets you connect, such as holdings or transactions relevant to a feature.
- Our wiki articles describe memes and sometimes the people who appear in or created them. That information comes from public sources cited in each article.
3. Why we use it and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account, sign-in, games, Points, quests and collectibles | Performance of our contract with you (these Terms) |
| Sending sign-in and verification codes and service messages | Performance of contract |
| Preventing fraud, multiple accounts, bots and reward abuse, and securing the Services | Our legitimate interest in fair games and a secure service |
| Understanding how the site is used and improving it (Google Analytics) | Our legitimate interest in measuring and improving the site; you can opt out (see section 6) |
| Understanding which campaigns and partners bring users | Our legitimate interest in running our marketing |
| Publishing articles about memes, including people connected to them | Our legitimate interest in, and the public's interest in, information about internet culture |
| Keeping records and complying with legal requests | Legal obligation |
We do not sell your personal data, and we do not use it for third-party advertising. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects, except that automated fraud checks may withhold a reward; you can ask us to review such a decision.
4. Who we share it with
We share personal data only with service providers that process it for us, under contract, and only as needed:
- Hosting, content delivery and storage: our web hosting and cloud providers.
- Analytics: Google Analytics.
- Email delivery: our email provider, to send codes and service messages.
- Blockchain data and infrastructure providers: to read public blockchain data and verify transactions for the wallets you connect.
- Sign-in and bot protection: X, Discord and our bot-protection provider, when you use them.
- AI and research tools: to help write and check wiki articles from public sources. We do not send your account data to them.
- Partners you choose to interact with: for example, if you arrive through a partner campaign, the partner may receive the fact that your wallet completed that campaign.
We may also disclose data if the law requires it, to protect our rights or users' safety, or as part of a merger, acquisition or sale of our business.
Information you make public, such as your username, profile image, Points and leaderboard position, is visible to other users.
5. International transfers
Some of our service providers are located outside Gibraltar, the EEA and the UK, including in the United States. Where required, we rely on adequacy decisions (including the EU-US Data Privacy Framework for certified providers) or standard contractual clauses to protect your data.
6. Cookies and analytics
We use cookies and similar storage that the site needs to work, for example to keep you signed in and remember your wallet connection. We also use Google Analytics cookies to measure how the site is used, by default.
See our Cookies page for the full list. You can turn Google Analytics off at any time with the Cookie settings link in the footer of any page. The change applies immediately, on this device. You can also opt out of Google Analytics on all websites with Google's opt-out browser add-on, and block or delete cookies in your browser settings. If you block cookies the site needs, some features may not work.
We do not use advertising or retargeting cookies.
7. How long we keep it
- Account data (wallets, email, profile, Points and game history): while your account is active. If you ask us by email to erase it, we handle the request manually within 30 days and keep only what the law requires.
- IP addresses in security and fraud-prevention data: deleted after 90 days. Other raw browser and device characteristics we record for security and fraud prevention are deleted after 12 months. We keep pseudonymous (one-way, peppered) hashes (of the device fingerprint, the browser, the device settings and the network prefix (never your full IP address) for as long as the security log row they belong to exists) that is, indefinitely, for fraud and abuse prevention, unless you ask us to erase them (see section 8).
- Server logs in our central logging system: deleted after 30 days.
- One-time email codes (sign-in and verification codes): anonymised 30 days after they expire.
- Messages and suggestions: as long as needed to handle them.
- Analytics data: Google Analytics keeps event-level data for 14 months.
- Public blockchain data is permanent by nature and outside our control.
8. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and receive a copy in a portable format;
- correct inaccurate data;
- ask us to erase your data and close your account;
- object to processing based on legitimate interests, including analytics and fraud prevention, or restrict processing;
- withdraw consent where we rely on it;
- complain to a data protection authority. In Gibraltar this is the Gibraltar Regulatory Authority; you can also contact the authority where you live or work.
To use these rights, email legal [at] meme.com from the email address on your account, or tell us the wallet address you sign in with; we may ask you to prove it is yours. We answer within 30 days.
9. Children
The Services are not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
10. Security
We use technical and organisational measures to protect personal data, such as encrypted connections, access controls and limited staff access. No system is completely secure. If a personal data breach is likely to put your rights at risk, we will notify you and the authorities as the law requires.
11. Changes
We will update this policy when our practices change and change the "Last updated" date above. We will tell logged-in users on the site about material changes.
12. Contact
Questions or requests about your personal data: legal [at] meme.com