Effective August 6, 2026. MoonTools is primarily a browser-local preview with optional server-side holder verification and opt-in product email.
Ticket plans, receipts, drafts, display settings, and raffle preview changes are stored in local or session storage when available. They are not on-chain records. Settings provides a reset for preview state; site-data controls in your browser can remove all local preferences.
When holder verification is requested, the server receives a public Solana wallet address and queries configured Solana RPC and Helius DAS providers. Structured logs exclude the wallet address. A successful result may be cached for up to one hour; shared-cache keys are hashed. Signed-wallet profiles and HTTP-only sessions are stored in Upstash with separate Preview and Production namespaces.
After signing into a MoonTools wallet profile, you may separately provide and verify an email address for optional product alerts or the weekly newsletter. MoonTools stores the verified address and category choices in Upstash and uses Brevo to send the verification message, transactional alerts, and to add or remove newsletter list membership. These messages are not wallet-login emails; Para or thirdweb would handle any future embedded-wallet authentication email. All email categories default to off, and clearing the address in Settings disables them.
Vercel Analytics is disabled unless the deployment explicitly enables it and you opt in under Settings. When enabled, it may process page, referrer, device, and coarse network information under the deployment operator’s Vercel configuration.
Vercel hosts the application, Better Stack receives configured operational telemetry and alerts, Upstash stores shared identity and notification records, Alchemy and Helius perform bounded public-chain reads, and Brevo processes opted-in email delivery. Provider credentials remain server-side.
Browser-local data remains until reset or browser eviction. Email verification links expire after 30 minutes; wallet sessions expire after seven days. Verified notification preferences remain until the address is cleared or the operator processes a deletion request. Provider logs and delivery records follow their configured retention. The production operator, contact, final retention schedule, transfer terms, and rights-request procedure must be published before public production use.
MoonTools does not ask for a seed phrase or private key. The browser-local demo identity is not authentication; signed holder-wallet verification is authentication only for the read-only profile and preference features described here. Do not submit sensitive personal information in free-text preview fields.