EarnMark, LLC

Privacy Policy

Effective DateNovember 11, 2025
Last UpdatedNovember 11, 2025

This Privacy Policy ("Policy") explains how EarnMark, LLC ("EarnMark," "we," "our," or "us") collects, uses, stores, and protects personal information when you use our website, platform, and certificate issuance services (collectively, the "Services"). This Policy applies to:

  • Client organizations and their authorized users who access our Platform to request and manage certificate issuance ("Clients").
  • Recipients who access the EarnMark portal to view their issued certificates ("Recipients").
  • Visitors to our website.

By using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree, please discontinue use of our Services.

1
Who We Are

EarnMark, LLC is a technology company that provides blockchain-based digital certificate issuance and management services. We issue NFT Certificates on the Solana blockchain on behalf of Client organizations. Recipients are individuals — such as employees, trainees, or credentialed professionals — designated by a Client to receive a digital certificate.

EarnMark operates as both a data controller and a data processor depending on context:

  • Data Processor: When processing Recipient Data submitted by a Client, EarnMark acts as a data processor under the direction of the Client, who is the data controller responsible for the legal basis of that processing.
  • Data Controller: When collecting data directly from Recipients (such as email addresses for portal login) and from website visitors, EarnMark acts as the data controller.
2
Information We Collect

2.1 Information from Clients

When a Client organization signs up for and uses the EarnMark Platform, we collect:

  • Business contact information, including company name, address, and authorized user names and email addresses.
  • Billing and payment information (see Section 3 — Payments).
  • Platform usage data, account activity logs, and support communications.
  • Recipient Data submitted by the Client for Certificate issuance, including Recipient names, email addresses, job titles, and credential or completion information.

2.2 Information from Recipients

When a Recipient accesses the EarnMark portal, we collect:

  • Email address, used for one-time password (OTP) authentication and account identification.
  • Certificate and credential information provided by the issuing Client organization.
  • Portal login activity and access logs.
  • PIN usage activity in connection with the Certificate Verification Portal.

2.3 Automatically Collected Information

Like most web-based platforms, we automatically collect certain technical information when you interact with our website or Platform, including:

  • Browser type and version.
  • Device type and operating system.
  • IP address and approximate geographic location.
  • Pages visited, time spent, and interaction data.
  • Cookies and similar tracking technologies (see Section 10 — Cookies).

This automatically collected data is used for security monitoring, fraud prevention, and Platform performance improvement. It is not used to identify individual users except where necessary for security purposes.

2.4 What We Do NOT Collect

EarnMark does not collect or store full credit card numbers on its systems (see Section 3). EarnMark does not store personally identifiable Recipient information on any public blockchain. Our blockchain records contain only non-identifiable cryptographic identifiers and technical data.

3
Payments

Fees for EarnMark's services are processed via credit card through third-party payment processors. EarnMark does not store, transmit, or have access to full credit card numbers, CVV codes, or other sensitive payment card data on its own systems.

Payment processing is conducted by our third-party payment processor(s), who maintain their own security standards and privacy practices. When you submit payment information, that data is transmitted directly to and stored by our payment processor in accordance with Payment Card Industry Data Security Standards (PCI DSS). EarnMark retains only limited transactional information necessary for billing records, such as the last four digits of a card number, transaction amounts, and dates.

4
Blockchain Records & Personal Data

4.1 Our Privacy-by-Design Approach

EarnMark has deliberately designed its certificate issuance system so that no personally identifiable information is stored on any public blockchain. We believe recipients should benefit from the authenticity and permanence of blockchain-based credentials without compromising their personal privacy. This is a foundational design principle of our Platform.

4.2 What Is Stored On-Chain

When a Certificate is minted on the Solana blockchain, the following non-identifiable technical data is publicly recorded on the public ledger:

  • The Client's assigned Minting Wallet address (a cryptographic public key assigned to the Client by EarnMark).
  • The Client's Collection Address (the on-chain collection under which all of a Client's Certificates are recorded).
  • NFT token identifiers and transaction hashes for each minted Certificate.

None of the above on-chain data includes Recipient names, email addresses, job titles, or any other personally identifiable information. This data is visible to anyone using a public Solana blockchain explorer but cannot by itself be used to identify any individual Recipient.

4.3 What Is Stored Off-Chain

All personally identifiable Recipient information — including names, email addresses, job titles, and credential details — is stored exclusively in EarnMark's secure, encrypted off-chain systems. This information is accessible only through the EarnMark portal (via email and OTP authentication) or through the Verification Portal (requiring a Certificate ID and Recipient PIN).

4.4 Blockchain Immutability

Once a Certificate is minted on the Solana blockchain, the on-chain record is permanent and cannot be altered, removed, or deleted by EarnMark, the Client, the Recipient, or any other party. This immutability is an inherent and intentional characteristic of public blockchain technology that ensures the long-term authenticity of issued credentials.

Because no personally identifiable information is stored on-chain, this immutability does not prevent EarnMark from fulfilling data deletion requests for off-chain personal data, subject to the limitations described in Section 8.

4.5 Certificate Verification & PIN Control

Third parties who wish to verify a Certificate's authenticity must provide a valid Certificate ID and the Recipient's PIN number through EarnMark's Verification Portal. Recipient names and personal information are not displayed publicly — they are only accessible to a verifying party who possesses both the Certificate ID and the correct PIN. This means Recipients retain meaningful control over who can verify their credentials.

5
How We Use Your Information

EarnMark uses personal information for the following purposes:

  • To provide and operate our certificate issuance and management services.
  • To mint NFT Certificates on the Solana blockchain on behalf of Client organizations.
  • To provide Recipients with secure portal access to view and manage their certificates.
  • To operate the Certificate Verification Portal.
  • To process payments and manage Client billing accounts.
  • To respond to support requests and communicate with Clients and Recipients about their accounts and certificates.
  • To verify certificate ownership and authenticate portal access.
  • To detect, investigate, and prevent fraud, unauthorized access, and security incidents.
  • To improve our Platform and services using aggregated, de-identified analytics data.
  • To comply with applicable legal obligations and respond to lawful requests from authorities.

EarnMark does not use personal data for advertising, marketing profiling, or any purpose unrelated to the delivery of our services.

6
How We Share Your Information

EarnMark does not sell, rent, or trade personal information. We may share personal data only in the following limited and defined circumstances:

  • With the Issuing Client: Recipient Data is accessible to the Client organization that authorized the Certificate issuance, as that Client is the data controller for that Recipient's data. Clients access Recipient Data through the Platform in accordance with their signed Vendor Agreement with EarnMark.
  • With Payment Processors: Billing information is shared with our third-party payment processor(s) solely for the purpose of processing transactions. These processors are contractually bound to protect payment data in accordance with PCI DSS standards.
  • With Cloud Storage & Infrastructure Providers: We engage vetted cloud hosting and infrastructure providers who store and process data on our behalf under data protection agreements that prohibit unauthorized use or disclosure.
  • With Technical Service Providers: We may engage technology providers (including Solana RPC node providers) to support Platform operations. All such providers are subject to confidentiality and data protection obligations.
  • For Legal Compliance: We may disclose personal data as required by applicable law, regulation, court order, or lawful request from a government authority. Where permitted, we will notify affected parties prior to such disclosure.
  • For Safety & Security: We may disclose data if we reasonably believe disclosure is necessary to protect the rights, property, or safety of EarnMark, our Clients, Recipients, or the public.
  • In a Business Transfer: In connection with a merger, acquisition, reorganization, or sale of all or substantially all of EarnMark's assets, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections. We will notify affected parties of any such transfer.

A current list of our third-party sub-processors is available upon written request to information@earnmark.com.

7
Data Storage & Security

EarnMark takes the security of personal data seriously and maintains commercially reasonable technical and organizational measures to protect it, including:

  • Encryption of all personal data in transit (using TLS) and at rest.
  • Secure private key management for custodial blockchain wallet infrastructure.
  • Role-based access controls ensuring that only authorized EarnMark personnel can access personal data.
  • Audit logging of data access and administrative actions.
  • OTP-based authentication for Recipient portal access, eliminating static passwords.
  • Regular security assessments, vulnerability scanning, and penetration testing.
  • A documented incident response plan for security breaches.

In the event of a confirmed security breach affecting personal data, EarnMark will notify affected Clients within 72 hours of becoming aware of the incident, and will take prompt steps to investigate, contain, and remediate the breach.

While EarnMark implements industry-standard security practices, no system is completely immune to risk. We encourage Clients and Recipients to maintain strong email account security, as email access is used for platform authentication.

8
Your Privacy Rights & Data Deletion

Depending on your location, you may have the following rights with respect to your personal data:

Access
You may request a copy of the personal data EarnMark holds about you.
Correction
You may request correction of inaccurate or incomplete personal data. Note that corrections to Certificate credential content must be authorized by the issuing Client organization.
Deletion
You may request deletion of your off-chain personal data. EarnMark will honor deletion requests subject to applicable legal retention requirements. Important limitation: deletion requests cannot be applied to On-Chain Data recorded on the Solana blockchain, as such records are technically immutable and permanent. Because EarnMark's architecture stores no personally identifiable information on-chain, the practical impact of this limitation is minimal.
Portability
You may request your personal data in a structured, commonly used, machine-readable format.
Restrict Processing
In certain circumstances, you may request that we restrict the processing of your personal data.
Object
You may object to certain types of processing, including processing for purposes beyond those described in this Policy.

To exercise any of these rights, please submit a written request to information@earnmark.com. We will respond within thirty (30) days. We may request verification of your identity before processing your request.

9
Data Retention

EarnMark retains personal data only for as long as necessary to fulfill the purposes described in this Policy or as required by applicable law:

Data CategoryRetention Period
Client account & business dataDuration of active agreement plus a 24-month Wind-Down Period following termination, after which it is securely deleted.
Recipient DataSame period as the associated Client's data. Off-chain Recipient Data is securely and permanently deleted following the Wind-Down Period.
Payment transaction recordsAs required by applicable financial regulations and tax law.
Security & access logsUp to 12 months for security monitoring and incident investigation purposes.
On-Chain Data (Solana)Permanently — cannot be deleted as described in Section 4.4.

Upon termination of a Client's account, EarnMark will maintain Recipient access to existing Certificates through the portal for the applicable Wind-Down Period. Clients are responsible for notifying their Recipients of the termination and Wind-Down Period so that Recipients may preserve their Certificate information.

10
Cookies & Tracking Technologies

EarnMark uses cookies and similar tracking technologies to operate our website and Platform. Cookies are small text files stored on your device that help us recognize returning visitors, maintain session security, and understand how our Platform is used.

Cookie TypePurpose
Essential CookiesRequired for the Platform to function, including session management and authentication. These cannot be disabled without impairing Platform functionality.
Analytics CookiesUsed to collect aggregated, de-identified data about how visitors interact with our website, helping us improve our services.
Security CookiesUsed to detect and prevent fraudulent activity and unauthorized access.

You may control cookie settings through your browser settings. Please note that disabling non-essential cookies will not affect your ability to use the core Platform features.

11
Children's Privacy

EarnMark's Platform and Services are intended solely for use by adults who are 18 years of age or older. We do not knowingly collect personal data from individuals under the age of 18. Client organizations are contractually required to ensure that all Recipients are adults before submitting their information to the Platform.

If we become aware that we have inadvertently collected personal data from a minor, we will promptly delete such data from our systems. If you believe we may have collected data from a minor, please contact us immediately at information@earnmark.com.

12
California Privacy Rights (CCPA)

California residents have additional privacy rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). These rights include:

  • The right to know what personal information EarnMark collects, uses, discloses, and shares about you.
  • The right to delete personal information EarnMark has collected about you, subject to the blockchain immutability limitations described in Section 4.4 and applicable legal retention requirements.
  • The right to correct inaccurate personal information.
  • The right to opt out of the sale or sharing of personal information. EarnMark does not sell or share personal information for cross-context behavioral advertising.
  • The right to limit the use and disclosure of sensitive personal information.
  • The right to non-discrimination for exercising your CCPA/CPRA rights.

To submit a California privacy request, please contact us at information@earnmark.com with the subject line "California Privacy Request." We will respond within 45 days as required by law.

13
Changes to This Policy

EarnMark reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, services, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Policy.
  • Notify active Clients by email at the address associated with their account.
  • Post a notice on the EarnMark Platform and website.

Your continued use of our Services following notice of any changes constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.

14
Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

CompanyEarnMark, LLC
Mailing Address30 N Gould St, Suite R
Sheridan, Wyoming 82801
General Inquiriesinformation@earnmark.com
Privacy Requestsinformation@earnmark.com
Websitewww.earnmark.com

We are committed to resolving any privacy concerns promptly and transparently. If you are not satisfied with our response, you may have the right to lodge a complaint with your applicable data protection authority.