Privacy
Effective July 2026, Version 1.0. This notice is incorporated into the Conditions of Sale and the Terms of Service. It includes the parts of the record that cannot be deleted, and says why.
What we collect#
- Your account. The email address and handle you register with, and a hash of your password. Signing in by email through Privy gives us the email address, nothing more.
- Your wallets. The wallet addresses you connect or that Privy creates for you.
- Your activity. Your bids, invoices, consignments, payments, and payouts.
- Your shipping address, where you supply one. It is required before bidding on a consigned lot, for the related-party check described in Authenticity and enforcement, and it is compared as a one-way fingerprint rather than stored for comparison in the clear.
- The audit trail. The house keeps an append-only record of what the auction engine did and when, including actions on your account.
We do not collect more than the auction needs. There is no advertising, no tracking pixels, and no analytics service on the site.
Why we hold it#
To run the auction: taking bids, issuing invoices, settling sales, and paying consignors. Wallet addresses are used for compliance screening where screening is enabled, for bid collateral where the bid escrow is enabled, and for settlement. Contact details are used to run your account and to send the notices the Terms of Service describe. Nothing is sold to third parties, and bidder identities are never published; bid histories show anonymized handles.
Where it goes#
- Privy handles email sign-in, so it processes your email address under its own terms.
- Peer Pay provides the onramp and cash-out rails. An order you place with it is your relationship with it, under its terms.
- The chain. Deposits, locks, and settlements involving the escrow contracts pass through the configured RPC provider. Anything written to a blockchain is public, permanent, and outside anyone’s power to delete, including ours.
- Google Fonts. The site’s typefaces load from Google’s servers, which see your IP address when a page loads. This documentation site loads the same faces from the same place.
Where the bid escrow is enabled, a lock records the standing maximum plus the published auction house fee. Observers can therefore infer that maximum from the on-chain amount, permanently. This is a deliberate trade the house makes for solvency and states rather than hides; the reasoning is in What is revealed.
In your browser#
Minthouse itself writes one localStorage key, your theme choice, and a sign-in cookie that expires after 30 days. There are no third-party cookies. Connecting a wallet through WalletConnect stores that provider’s own session data in your browser as well.
This documentation site writes one localStorage key: the same theme choice, under the same name, and sets no cookies at all. It makes no requests to the auction API and runs no analytics.
Retention#
Account data is kept while the account stands. The ledger and the audit trail are append-only by design: the record of a sale is the record of the sale, and rows are not rewritten or deleted. On-chain data is permanent by nature.
Your rights#
Requests about your data, including access, correction, and deletion requests under laws such as the GDPR or the CCPA, go to notices@minthouse.io. The house answers what the applicable law requires of it.
The limits of deletion, stated exactly#
Deletion has three limits, and none of them is a policy choice the house could reverse on request:
- Invoices and the ledger. Kept as the record of transactions that occurred, for the periods the law requires of a business that sold goods.
- The audit trail and the event chain. Append-only and hash-linked: each event carries the hash of the one before it, so removing or editing one breaks every hash after it and destroys the integrity of the whole record. This is the property that makes the house's own conduct checkable, and it is not selectively reversible.
- Anything on chain. Deposits, locks, releases, expiries and settlements are public and permanent. No party (Minthouse, you, the RPC provider, or the chain's validators) can delete them.
Where a right to erasure applies and the record cannot be erased, the house will say which of the three categories the data falls into rather than deleting an account row and describing the request as fulfilled.
Contact#
Write to notices@minthouse.io, or by post to Minthouse Markets, Inc. New York.