Draft for legal review — not final
This working draft has not been approved by legal counsel, is not an effective agreement or notice, and must not be represented as final. Highlighted bracketed items require an owner decision or legal confirmation.
Core Currency Index
Draft Privacy Notice
Draft version: July 28, 2026 · Proposed effective date: [TO BE APPROVED]
1. Scope and controller
This proposed Privacy Notice would explain how the Core Currency Index Service collects, uses, discloses, and protects personal information. The proposed data controller or business is Prope Solem LLC, a Kansas limited liability company, at 509 Seitz Drive, Salina, Kansas 67401.
This draft covers participants, individual account holders, organization members and administrators, and platform administrators. Counsel should confirm whether separate notices or data-processing agreements are required for sponsoring organizations.
2. Information the Service collects
Account and identity information
Email address, account identifier, authentication records, display name when provided, account role, organization membership, and administrator authorization.
Assessment and result information
Assessment answers; item, section, and currency scores; profile and blend results; scoring and content version identifiers; preserved report snapshots; completion status; timestamps; timing and navigation events; and participant feedback.
Entitlement and organization information
Seat allocations, sponsor organization, cohort or program labels, entitlement status and expiration, gifting details, code status and masked code hints, and entitlement audit events. Plaintext access codes are shown only when issued and are not stored after issuance.
Invitation and sharing information
Inviter account, intended recipient email and optional name, invitation status and expiration, acceptance timestamp, applicable sharing-disclosure version, and the specific completed result linked to an accepted invitation. Complete invitation tokens are not stored.
Technical and security information
Browser and device information, IP address, request and diagnostic logs, security events, and abuse-prevention results. Cloudflare Turnstile may process technical signals to distinguish legitimate people from automated abuse.
Future transaction information
Payment processing is not currently enabled. The disabled checkout integration uses Stripe-hosted Checkout and stores provider-neutral order amounts, status, provider identifiers, terms acceptance, and hashed webhook audit records. Stripe processes billing, card, tax, and fraud-prevention information under its own terms. CCI does not directly store full payment-card numbers or complete webhook payloads. When commerce is enabled, Stripe Tax is intended to calculate applicable tax from transaction and billing-location information based on CCI’s active tax registrations.
Account credit records include available and reserved balances, purchase or administrator-grant provenance, invitation reservation and release events, gift-code status and masked hints, quantities, and privacy-minimized audit reasons. Plaintext gift codes are shown only when issued and are not stored after issuance. Credit records do not contain assessment answers or report content.
3. Sources of information
Information comes from the participant or account holder; a sponsoring organization or administrator; the user’s interaction with the Service; authentication, hosting, email, and security providers; and, after commerce launches, Stripe as payment processor.
4. Why the Service uses information
- authenticate accounts and deliver secure sign-in links;
- issue, purchase, reserve, release, and administer assessment credits and access;
- administer and score assessments under the applicable version;
- generate, preserve, and display owned historical results;
- create invitations, record sharing acceptance, and provide authorized read-only reports;
- operate organization seats and authorized dashboards;
- provide support and respond to feedback;
- protect the Service, users, content, and intellectual property;
- monitor reliability and improve the participant experience; and
- comply with law and enforce applicable agreements.
Applicable legal bases, where required, are [COUNSEL TO MAP CONTRACT, CONSENT, LEGITIMATE INTERESTS, AND LEGAL-OBLIGATION BASES BY JURISDICTION].
5. How information is disclosed
Service providers
The current Service uses Supabase for authentication and database services, Vercel for application hosting, Resend for transactional email, Cloudflare Turnstile for abuse prevention, and Stripe for hosted payment processing when commerce is enabled. These providers process information to perform services for CCI under their own agreements and privacy terms.
Sponsoring organizations
Current organization dashboards show organization membership and aggregate seat lifecycle counts, such as unissued, claimed, in progress, and completed totals. They do not identify which participant redeemed or completed a seat and do not display participant answers, currency profiles, blends, or complete reports. Any future participant-level operational disclosure or result sharing must be separately documented and, where applicable, use an explicit participant consent process.
People who invite participants
Before an invited participant accepts, the Service identifies the inviter and explains that the report produced through that invitation will be shared with the inviter. After completion, the inviter may view and download that one report in read-only form. The inviter does not receive raw answers, timing data, feedback, or unrelated past or future results. The participant can stop future report access from the invitation and sharing page in their account.
Other disclosures
Information may be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate fraud or abuse, or complete a merger, financing, acquisition, or transfer of assets with appropriate notice and safeguards.
Position for legal confirmation
CCI does not currently sell personal information or use it for cross-context behavioral advertising. Counsel should confirm the legally required definitions, opt-out language, and signals before this statement becomes final.
6. Retention
Historical assessment results and their versioned report snapshots are designed to remain available to the owning account. Other information should be retained only as long as needed for the purposes described above, support, security, legal compliance, and dispute resolution.
Required schedule: [COUNSEL AND OWNER TO APPROVE RETENTION PERIODS FOR ACCOUNTS, ANSWERS, RESULTS, SECURITY LOGS, EMAIL EVENTS, FEEDBACK, ENTITLEMENTS, ORGANIZATION RECORDS, AND FUTURE TRANSACTIONS].
7. Security
CCI uses administrative, technical, and organizational safeguards intended to protect information, including password-based authentication, verified email ownership, role and organization access controls, hashed access codes and invitation tokens, invitation-scoped report grants, server-side verification for protected operations, and versioned historical snapshots. No system is completely secure, and the final notice should avoid guaranteeing absolute security.
8. Individual choices and rights
Depending on location, a person may have rights to access, correct, delete, restrict, or obtain a copy of personal information; object to certain processing; withdraw consent; or appeal a privacy decision. Authentication may be required before a request is fulfilled, and lawful exceptions may apply.
Requests would be submitted to privacy@corecurrencyindex.com. CCI may verify the requester’s identity and authority before fulfilling a request. Counsel should confirm the authorized-agent, response-timing, denial, and appeal processes required in each applicable jurisdiction.
9. Organization-sponsored participants
The final notice and organization agreement should identify when CCI acts as an independent controller, a service provider or processor, or a joint controller. An organization is responsible for providing any notice and obtaining any authority it needs to sponsor participation or supply member information. CCI should separately explain any optional organization sharing of participant results before consent is requested. Personal invitation sharing is limited to the single report disclosed when the participant accepts.
10. Children and minors
The Service is not intended for children under [MINIMUM PARTICIPANT AGE]. Before allowing minors, the owner and counsel must approve age screening, parental authorization, school or organization requirements, and deletion procedures.
11. International and state-specific disclosures
[COUNSEL TO IDENTIFY TARGET JURISDICTIONS, CROSS-BORDER TRANSFER MECHANISMS, U.S. STATE PRIVACY ADDENDA, AND REQUIRED SENSITIVE-DATA OR PROFILING DISCLOSURES].
12. Changes to the final notice
The effective notice should identify its revision date. Material changes should be communicated through the Service, email, or another legally appropriate channel before they take effect when required. Prior versions should be retained for auditability.
13. Contact
Privacy questions and requests: privacy@corecurrencyindex.com, or Prope Solem LLC, 509 Seitz Drive, Salina, Kansas 67401. Data protection officer or representative, if required: [NAME AND CONTACT OR NOT APPLICABLE].
Legal-review checklist
- Approve the data inventory and processor list.
- Choose the retention and deletion schedule.
- Confirm organization roles and the implemented invitation-sharing consent.
- Complete jurisdiction, legal-basis, and rights analysis.
- Approve minor-use rules and future commerce disclosures.
- Complete vendor and data-processing agreement review.