Privacy Policy
Effective date: 30 July 2026 · Version 1.0 · Last updated: 30 July 2026
1. Scope and application
1.1. This Privacy Policy (“Policy”) describes the categories of personal data processed in connection with the website at validator.info and its subdomains (the “Service”), the purposes and legal bases of that processing, the recipients of such data, the applicable retention periods, and the rights available to data subjects.
1.2. This Policy applies to visitors to the Service. It does not apply to third-party websites accessible from the Service, including advertisers’ websites, which are governed by their own privacy notices.
1.3. This Policy forms part of, and is incorporated by reference into, the Terms of Service governing use of the Service.
1.4. Where this Policy refers to “personal data”, that term has the meaning given to it in Regulation (EU) 2016/679 (the “GDPR”) and, where applicable, the equivalent term under the law of any other jurisdiction whose data protection legislation applies.
2. Controller and contact details
2.1. The Service is operated by the team publishing under the name Validator Info (“Validator Info”, “we”, “us”, “our”), which acts as the controller in respect of the processing described in this Policy.
2.2. Enquiries concerning this Policy, and requests to exercise any right described in Section 11, may be addressed to us using the contact details published on the Service.
3. Categories of data processed
3.1. Technical data received automatically
3.1.1. Access to the Service causes the visitor’s browser to transmit technical information, which our servers and infrastructure providers process in order to deliver the requested resources. This information comprises:
- (a) the date and time of the request;
- (b) the resource requested and the HTTP status code returned;
- (c) the referring URL, where transmitted by the browser;
- (d) the browser type and version, operating system, device type, display characteristics and language settings;
- (e) an approximate geographic location, ordinarily at country level.
3.1.2. The processing described in this paragraph 3.1 is inherent to the operation of the hypertext transfer protocol and cannot be avoided while the Service is accessed.
3.2. Internet protocol addresses
3.2.1. The visitor’s IP address is necessarily received by our hosting, content delivery and security providers, as the routing of a response to the visitor’s device is not technically possible without it.
3.2.2. The IP address is used transiently for the purposes of routing responses, protecting the Service against attack and abuse, applying rate limits, and deriving an approximate country of origin.
3.2.3. We do not store IP addresses in our own application databases, and we do not use IP addresses to construct profiles of visitors or to identify visitors.
3.2.4. Our analytics provider does not store IP addresses. Google Analytics 4 processes the IP address transiently to derive an approximate location and thereafter discards it without logging or retaining it.
3.2.5. IP addresses may appear in the operational and security logs maintained by our infrastructure providers. Such logs are retained for the periods stated in Section 8 and are accessed only for the investigation of faults, attacks or abuse.
3.2.6. For the avoidance of doubt, we acknowledge that a dynamic IP address may constitute personal data within the meaning of the GDPR.
3.3. Cookies, analytics and similar technologies
3.3.1. We use third-party web analytics, currently Google Analytics, to measure aggregate usage of the Service, including pages viewed, sources of traffic, duration of visits, features used and errors encountered.
3.3.2. For this purpose, cookies and similar technologies, including local storage and pixels, may be placed on the visitor’s device. Such technologies may assign the browser a pseudonymous identifier for the purpose of distinguishing returning visits from new ones. Our analytics configuration limits the collection of directly identifying information, and analytics data is not used to identify any individual.
3.3.3. Cookies used on the Service fall into the following categories:
- Strictly necessary — Delivery of pages, security, load balancing, and retention of interface preferences such as display theme or selected network. Not used for tracking. Refusable: No — the Service cannot operate without these technologies.
- Analytics and performance — Aggregate measurement of traffic and feature usage by means of Google Analytics. Refusable: Yes — see Section 9.
3.3.4. We do not employ advertising cookies, retargeting pixels, cross-site advertising identifiers, ad-network tags or data brokers.
3.4. Information provided voluntarily
3.4.1. Where a visitor communicates with us by electronic mail or through a public social channel, we receive the information contained in that communication, including the sender’s address or handle, the content of the message and any attachments. Such information is processed solely for the purpose of responding to and administering the enquiry.
3.5. Information submitted by validator operators
3.5.1. Where a validator operator submits information concerning its validator for publication on the Service, including a name, description, logotype, website address or contact address, that information is processed for the purpose of publication and is thereafter publicly visible.
3.5.2. Provisions concerning the correction and removal of such information are set out at paragraph 12.6.
3.6. Public blockchain data
3.6.1. The Service displays data obtained from public blockchains and from the public gossip and remote procedure call layers of the networks covered, including validator identities and vote accounts, stake amounts, delegation records, commission rates, block and slot production, votes, governance proposals, fees, tips, client versions, and infrastructure information derived from publicly advertised node endpoints.
3.6.2. Such data is published by the networks themselves and not by us. It is inherently public, permanent, and outside our control. We do not associate it with visitors to the Service, and we are not able to alter or delete records recorded on a blockchain.
3.6.3. Operators of nodes are advised that information broadcast to a public network, including gossip endpoints and the IP addresses associated with them, is observable by any participant of that network.
3.7. Categories of data not processed
3.7.1. The Service does not:
- (a) offer registration, accounts, profiles or authentication, and accordingly stores no credentials;
- (b) request or support the connection of wallets, the signing of transactions, or any interaction with private keys;
- (c) request private keys, seed phrases or recovery phrases under any circumstances. Any communication purporting to originate from us and requesting such information is fraudulent;
- (d) process payments or store payment card or bank account details;
- (e) operate any subscription, newsletter, alerting or notification service, whether by Telegram, electronic mail, short message service, push messaging or otherwise, and accordingly maintains no subscriber list;
- (f) process special categories of personal data within the meaning of Article 9 of the GDPR;
- (g) knowingly process the personal data of children, as provided in Section 13.
4. Purposes and legal bases
4.1. Where the GDPR or the equivalent United Kingdom legislation applies, processing is carried out on the following legal bases:
- Delivery of the Service and transmission of requested resources — Data: technical data (3.1), IP address (3.2). Legal basis: Article 6(1)(f) — legitimate interests in operating a website requested by the visitor; Article 6(1)(b) where performance of the Terms of Service is engaged.
- Security, prevention of abuse, rate limiting, and mitigation of attacks — Data: technical data (3.1), IP address (3.2). Legal basis: Article 6(1)(f) — legitimate interests in protecting the Service, its users and its infrastructure.
- Diagnosis of faults and improvement of performance — Data: technical data (3.1), analytics data (3.3). Legal basis: Article 6(1)(f) — legitimate interests in maintaining a functional service.
- Measurement of aggregate usage and assessment of content value — Data: analytics data (3.3). Legal basis: Article 6(1)(a) — consent, where required by the applicable law implementing Directive 2002/58/EC; otherwise Article 6(1)(f).
- Measurement of advertising impressions and clicks in aggregate, and reporting of aggregate campaign results to advertisers — Data: analytics data (3.3), technical data (3.1). Legal basis: Article 6(1)(a) — consent, where required for the analytics employed; otherwise Article 6(1)(f) — legitimate interests in funding the Service and evidencing delivery to advertisers.
- Response to enquiries — Data: correspondence (3.4). Legal basis: Article 6(1)(f); Article 6(1)(b) where relevant.
- Publication of validator operator information — Data: submitted information (3.5). Legal basis: Article 6(1)(a) — consent of the submitting operator; Article 6(1)(f) — legitimate interests in maintaining a public reference resource.
- Compliance with legal obligations and response to lawful requests — Data: any of the above. Legal basis: Article 6(1)(c).
- Establishment, exercise or defence of legal claims — Data: any of the above. Legal basis: Article 6(1)(f).
4.2. Where processing is founded on legitimate interests, we have assessed those interests against the rights and freedoms of data subjects, taking into account the limited and predominantly technical character of the data concerned, and have concluded that those interests are not overridden. A data subject may object to such processing in accordance with paragraph 11.1(e).
4.3. No processing described in this Policy involves automated decision-making producing legal effects concerning the data subject or similarly significantly affecting the data subject within the meaning of Article 22 of the GDPR, and no profiling is carried out for advertising purposes.
5. Advertising
5.1. The Service is funded in part by banner advertising.
5.2. Advertising space is sold and served directly by us. Advertisements are not supplied by an advertising exchange, advertising network, demand-side platform or programmatic auction, and no third-party advertising code is executed on the Service.
5.3. Advertisements are not personalised. The selection of an advertisement is not determined by the identity of the visitor, the visitor’s browsing history, device profile or inferred interests, or any data collected concerning the visitor. No advertising profiles are constructed, and no behavioural targeting or retargeting is performed. An advertisement may be selected by reference to the page or network section being viewed, such selection being contextual and not personal.
5.4. The display of an advertisement does not cause the visitor’s browser to contact the advertiser, advertising assets being hosted on our own infrastructure.
5.5. Activation of an advertisement causes the visitor’s browser to make a request directly to the advertiser’s website. As with the following of any hyperlink, that request discloses to the destination website the visitor’s IP address, browser and device information and, unless suppressed by the browser or by the referrer policy applied to the link, the address of the originating page. Such disclosure is an inherent property of hyperlink navigation and does not constitute a transfer of data by us. Upon arrival at the destination, the visitor is subject to the privacy notice of that website and not to this Policy.
5.6. Outbound advertising links carry campaign tracking parameters, being UTM parameters of the form utm_source, utm_medium and utm_campaign. Such parameters identify the campaign, the placement and the referring site. They are identical for every visitor activating a given advertisement, do not identify any individual, and do not permit the destination website to associate a visitor’s activity on the Service with that visitor’s activity elsewhere. No personal data, persistent identifier or session identifier is placed into such parameters.
5.7. Advertising impressions and clicks are measured in aggregate by means of the first-party analytics described at paragraph 3.3. Advertisers receive aggregate totals only, and receive no data concerning any individual visitor.
5.8. Advertising does not influence the metrics, scores, rankings, sort order, comparisons, reports or commentary published on the Service. Provisions concerning advertising and editorial independence are set out at Section 6.5 of the Terms of Service.
6. Disclosure to third parties
6.1. Personal data is not sold, rented or traded. Disclosure occurs only in the circumstances set out in this Section.
6.2. Processors. Personal data is disclosed to third parties operating elements of our infrastructure on our behalf, under contract, and solely for purposes specified by us. These comprise:
- (a) providers of hosting and cloud infrastructure, for the delivery of the Service and the operation of our data pipelines;
- (b) providers of content delivery and denial-of-service protection, for the delivery of assets and the filtering of malicious traffic;
- (c) our analytics provider, Google LLC and Google Ireland Limited, in respect of Google Analytics;
- (d) our electronic mail provider, in respect of correspondence addressed to us;
- (e) providers of error monitoring and logging tools, where employed, for the diagnosis of faults.
6.3. Legal and protective disclosure. Personal data may be disclosed where we consider in good faith that disclosure is necessary to comply with applicable law, regulation or legal process, to respond to an enforceable governmental request, to enforce the Terms of Service, to detect, prevent or address fraud or security or technical issues, or to protect the rights, property or safety of any person.
6.4. Business transfer. In the event that the Service or its operating business is the subject of a merger, acquisition, reorganisation or sale of assets, personal data may be transferred as part of that transaction. Reasonable steps will be taken to ensure that the recipient continues to process such data in accordance with this Policy, and any material change will be notified in accordance with Section 14.
6.5. Aggregated and anonymised data. Statistics, metrics, reports and charts which are aggregated or anonymised, and which cannot reasonably be used to identify any individual, may be published or otherwise disclosed without restriction.
6.6. Advertisers. Personal data is not disclosed to advertisers or sponsors. Reporting on campaign performance is limited to aggregate counts, including total impressions and total clicks over a defined period. The consequences of activating an advertisement are addressed at paragraph 5.5.
7. International transfers
7.1. Our infrastructure and analytics providers may process personal data in countries other than that of the data subject, including countries outside the European Economic Area and in particular the United States.
7.2. Where personal data is transferred outside the European Economic Area or the United Kingdom, such transfer is effected on the basis of an appropriate transfer mechanism, which may comprise an adequacy decision of the European Commission or the equivalent United Kingdom determination, the Standard Contractual Clauses adopted by the European Commission together with the United Kingdom International Data Transfer Addendum where applicable, and such supplementary technical and organisational measures as are appropriate.
7.3. Further information concerning the mechanism applicable to a particular transfer may be requested using the contact details at paragraph 2.2.
8. Retention
8.1. Personal data is retained for the periods set out below:
- Operational and security logs (hosting, content delivery and security providers), which may contain IP addresses — The retention periods determined by those providers, ordinarily from several days to several weeks. Logs relating to a security incident may be retained for the duration of the investigation and resolution of that incident. IP addresses are not copied from such logs into our own storage.
- Request data held in our own systems (resources requested, timestamps and status codes, excluding IP addresses) — Ordinarily not exceeding 12 months, following which such data is deleted or aggregated.
- Analytics data — The retention period configured within Google Analytics, ordinarily between 2 and 14 months for user-level and event-level data. IP addresses are not retained by Google Analytics 4. Aggregated reports may be retained indefinitely.
- Cookies placed on the visitor’s device — Session cookies expire upon closure of the browser. Persistent analytics cookies ordinarily expire within 24 months.
- Correspondence — For such period as is necessary to address the enquiry and for a reasonable period thereafter, ordinarily not exceeding 24 months, unless a longer period is required for legal reasons.
- Validator operator information published on the Service — For such period as the information remains relevant to the public record, subject to paragraph 12.6.
- Public blockchain data — Indefinitely. Such data constitutes a permanent public record which we are not able to delete.
8.2. Personal data may be retained beyond the periods stated where necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
9. Withdrawal of consent and control of cookies
9.1. Analytics collection may be controlled by the following means:
- (a) where a consent banner is presented, by declining non-essential cookies, such election being recorded and revocable at any time by clearing site data or by reopening the cookie settings;
- (b) by configuring the browser to block or delete cookies, generally or in respect of the Service. Blocking strictly necessary technologies may impair the operation of the Service;
- (c) by installing the browser add-on published by Google at https://tools.google.com/dlpage/gaoptout, which prevents collection by Google Analytics on any website;
- (d) by using private browsing modes or content-blocking extensions, which ordinarily prevent analytics from loading.
9.2. Global Privacy Control signals are honoured where the applicable law so requires. No common industry standard exists for the interpretation of Do Not Track browser headers, and such headers are not currently acted upon.
9.3. The withdrawal of consent to analytics does not restrict access to any part of the Service.
10. Security
10.1. We apply technical and organisational measures appropriate to the nature and scope of the data processed, including encryption in transit by means of Transport Layer Security, restriction of administrative access on a need-to-know basis, maintenance of infrastructure and dependencies at current patch levels, and minimisation of the data collected.
10.2. No method of transmission over the internet and no method of electronic storage is entirely secure, and absolute security cannot be guaranteed. Sensitive information should not be transmitted to us by electronic mail.
11. Rights of data subjects
11.1. Subject to the conditions and exceptions provided by the applicable law, a data subject may exercise the following rights:
- (a) access — to obtain confirmation as to whether personal data concerning the data subject is processed and, where that is the case, access to such data;
- (b) rectification — to obtain the correction of inaccurate personal data and the completion of incomplete personal data;
- (c) erasure — to obtain the deletion of personal data where one of the grounds provided by the applicable law is satisfied;
- (d) restriction — to obtain the restriction of processing in the circumstances provided by the applicable law;
- (e) objection — to object, on grounds relating to the data subject’s particular situation, to processing founded on legitimate interests;
- (f) portability — to receive personal data provided by the data subject in a structured, commonly used and machine-readable format;
- (g) withdrawal of consent — where processing is founded on consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal;
- (h) complaint — to lodge a complaint with the competent supervisory authority.
11.2. Residents of the State of California are further entitled to know the categories of personal information collected, used, disclosed or sold; to obtain the deletion of personal information; to obtain the correction of inaccurate personal information; to opt out of the sale or sharing of personal information; and not to be subjected to discriminatory treatment for the exercise of these rights. We do not sell or share personal information within the meaning of the California Consumer Privacy Act as amended by the California Privacy Rights Act. In particular, personal information is not disclosed to third parties for the purposes of cross-context behavioural advertising, the advertising carried on the Service being contextual and served directly by us as described in Section 5. We do not knowingly sell the personal information of any person under the age of 16.
11.3. Requests to exercise any right may be addressed to the contact details at paragraph 2.2. A response will be provided within the period prescribed by the applicable law, being ordinarily one month under the GDPR and 45 days under the California Consumer Privacy Act. We may request such information as is necessary to verify the identity of the requesting party or to locate the records concerned.
11.4. As the Service does not operate accounts, the data processed is predominantly pseudonymous technical data which is not associated with an identified or identifiable natural person. Where we are not in a position to identify the data subject within that data, and the data subject is unable to supply additional information enabling identification, Articles 11 and 12(2) of the GDPR may relieve us of the obligation to act upon a request. Where this applies to a particular request, the requesting party will be so informed.
12. Supplementary provisions
12.1. External links. The Service contains links to external websites, including block explorers, validator websites, documentation and social platforms. We are not responsible for the privacy practices of such websites, and their privacy notices should be consulted before information is supplied to them.
12.2. Embedded content. Pages of the Service may incorporate content served by third parties, including typefaces, charting libraries and images. The loading of such content transmits the visitor’s IP address and browser information to the relevant provider.
12.3. Social channels. We maintain public profiles on third-party platforms. Interactions occurring on those platforms are governed by the privacy notices of the respective platform operators and not by this Policy. We operate no subscription, alerting or notification service on Telegram or on any other channel, and any account offering paid access, alerts or delegation services purportedly on our behalf is not operated by us.
12.4. Application programming interface. Should a public application programming interface be published, requests made to it will be logged in the manner described at paragraph 3.1, and any supplementary terms will be published together with the relevant documentation.
12.5. Cross-site tracking. We do not participate in cross-site advertising networks and do not construct profiles of visitor activity on other websites.
12.6. Correction and removal of validator operator information. A validator operator who considers that information published concerning that operator is inaccurate, outdated or otherwise ought not to be displayed may address a request to the contact details at paragraph 2.2. Such requests will be reviewed and genuine errors corrected. We are not able to alter or delete records recorded on a public blockchain, and we may decline to remove information which is publicly available on-chain and which is relevant to the public interest in transparent network analytics. Reasons will be given where a request is declined.
13. Children
13.1. The Service is not directed at children and is not intended for use by any person under the age of 16, or such higher minimum age as the law applicable to that person may prescribe.
13.2. We do not knowingly process the personal data of children. Any person considering that a child has supplied personal data to us should contact us at the details given at paragraph 2.2, and such data will be deleted.
14. Amendments
14.1. This Policy may be amended to reflect changes in our practices, in the technologies employed, or in applicable legal requirements. The amended version will be published on this page and the version number and date at the head of this Policy updated accordingly.
14.2. Where amendments are material, reasonable efforts will be made to draw attention to them on the Service.
14.3. Continued use of the Service following the date on which an amendment takes effect constitutes acceptance of the amended Policy.
15. Complaints
15.1. Any concern regarding the processing described in this Policy should in the first instance be addressed to us at the details given at paragraph 2.2.
15.2. Data subjects situated in the European Economic Area or the United Kingdom who are not satisfied with our response are entitled to lodge a complaint with the supervisory authority competent in their place of residence, place of work or place of the alleged infringement.