§ 01Who We Are
Planet B 21, LLC is a Wyoming limited liability company. In this Privacy Policy, we refer to ourselves as "Planet B 21," "we," "our," or "us." We are the data controller for personal information we collect about you, including personal information collected through cashtoha.sh and hashsentinel.com (each a product brand of Planet B 21, LLC and not a separate company).
Our contact details are at the end of this Policy.
§ 02Scope of this Policy
This Policy applies to personal information we collect when you:
- Visit planetb21.com, cashtoha.sh, or hashsentinel.com.
- Create a Planet B 21, Cash to Hash, or HashSentinel account or engagement.
- Complete verification where required.
- Purchase digital compute products from us or communicate with our support team.
- Interact with us in any other context governed by our Terms of Service.
It does not apply to information collected by third-party services you may interact with separately, even if we link to them. Those services have their own privacy practices, which we do not control.
§ 03Information We Collect
We collect only the minimum information necessary to provide our products and comply with legal obligations:
3.1 Account information
Your name, email address, and password (stored in hashed form). We do not collect government-issued identification, proof of address, biometric data, or financial account details beyond what our payment processors handle.
3.2 Transaction information
The product type (Hashrate or AI Compute Credits), amount, price, and date of each purchase. For Hashrate: the Bitcoin mining pool stratum endpoint and worker credentials you provide (this is not a wallet we control, and we do not custody your mining rewards). For AI Compute Credits: token redemption metadata (we do not store your prompts, outputs, or inference data). Payment card or bank information is handled by Stripe, Inc.; we receive only limited details such as last four digits, card brand, and transaction identifier for reconciliation and dispute handling.
3.3 Compliance information
We screen your name against sanctions lists (including OFAC SDN, PEP lists, and adverse media) for every transaction. We retain the screening result and date only.
3.4 Communications
Records of your messages to our support team and any notices we send you.
3.5 Technical information
- Device information (operating system, browser type).
- Log information (IP address, access times, pages viewed, referring URLs).
- Cookies and similar technologies — see Section 10.
3.6 Information from third parties
We receive information from sanctions screening providers, from payment processors (Stripe, Inc.), and from upstream capacity providers (for Hashrate routing only) to the extent necessary to deliver the product. We do not receive personal information from Routstr regarding your AI usage.
What we do NOT collect: We do not collect government-issued identification documents, proof of address, biometric data, or full financial account details for standard purchases.
§ 04How We Use Your Information
We use your personal information for the following purposes:
- Providing the products: creating your account, processing purchases, delivering Hashrate to your specified pool, delivering AI Compute Credits as Cashu tokens, and communicating with you about your account and orders.
- Compliance: screening against sanctions and watchlists, meeting our legal obligations, and maintaining records as required by law.
- Fraud prevention and security: detecting, investigating, and preventing fraudulent transactions, account takeover, unauthorized access, and other abuse.
- Payment processing and dispute resolution: facilitating payments and representing our position in chargeback or payment disputes.
- Legal compliance: responding to lawful requests from authorities.
- Product improvement: analyzing usage patterns in aggregated or de-identified form.
- Marketing communications: sending you product news and updates, where permitted by law — you may opt out at any time.
We do not use your information for: selling to third parties; cross-context behavioral advertising; or building profiles for purposes beyond our own service delivery and security.
4.1 Legal bases (for individuals in the EEA, UK, and similar jurisdictions)
Where GDPR or similar legislation applies, we rely on the following legal bases:
- Performance of a contract (delivering services you purchase).
- Legal obligation (sanctions screening, record retention, tax and financial compliance).
- Legitimate interests (fraud prevention, dispute resolution, product improvement, direct marketing to our customers — balanced against your rights and interests).
- Consent (where required, for example, for non-essential cookies or marketing communications).
§ 05How We Share Information
We do not sell your personal information, and we do not share it with third parties for their own direct marketing. We share personal information only in the following circumstances:
5.1 Service providers (processors)
We share information with carefully selected service providers who process it on our behalf under written agreements:
- Payment processing — Stripe, Inc.
- AI credit redemption infrastructure — Routstr network (we share only token redemption requests, no personal information or inference data).
- Upstream capacity providers — for Hashrate delivery only (we share only your pool stratum endpoint and worker credentials, no personal information).
- Sanctions and PEP screening — third-party screening vendor.
- Cloud hosting and email infrastructure.
- Aggregate product analytics.
5.2 Legal and safety disclosures
We may disclose information when we believe in good faith that disclosure is necessary to comply with a legal obligation, respond to a valid legal process (including a subpoena, court order, or government request), enforce our Terms of Service, protect the rights, property, or safety of Planet B 21, our users, or others, or investigate and prevent fraud or abuse.
5.3 Business transfers
If Planet B 21 is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will notify you and require the successor to honor this Policy or provide equivalent protection.
5.4 With your consent
We may share personal information with third parties for purposes not described above when you direct us to do so or give separate consent.
§ 06International Data Transfers
Planet B 21 is based in the United States and operates infrastructure primarily in the United States. If you access the services from outside the United States, your information will be transferred to, stored, and processed in the United States. Where personal information is transferred from the EEA, UK, or Switzerland to the United States or other jurisdictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
§ 07How Long We Retain Information
We retain personal information for as long as needed to provide the products and meet the purposes described in this Policy. Specifically:
- Account and contact information: duration of the account plus 5 years after closure.
- Transaction records: 5 years after the transaction.
- Sanctions and fraud screening records: 5 years after account closure.
- Support communications: 3 years from last interaction.
- Technical logs: up to 24 months.
- Marketing preferences and unsubscribe records: indefinitely, to honor opt-outs.
We do not retain government-issued identification documents, biometric data, or proof of address because we do not collect these for standard purchases.
We may retain information longer when required to comply with a legal obligation, respond to lawful requests, resolve disputes, or enforce our agreements.
§ 08Security
We use commercially reasonable technical, organizational, and administrative measures to protect personal information, including:
- Encryption of data in transit using TLS and encryption of sensitive data at rest.
- Role-based access controls, with least-privilege access to verification and payment records.
- Multi-factor authentication for employee access to production systems.
- Logging, monitoring, and periodic review of access to sensitive data.
- Vendor security reviews for service providers who process personal information.
No method of transmission or storage is entirely secure. We cannot guarantee absolute security, but we work diligently to protect your information.
§ 09Your Rights and Choices
9.1 All users
- Access and update most of your account information from within the product dashboard.
- Contact us to request access to, correction of, or deletion of your personal information.
- Opt out of marketing emails by using the unsubscribe link or contacting us.
9.2 Users in the EEA, UK, and similar jurisdictions
If the GDPR or UK GDPR applies to you, you have the right to:
- Access your personal information.
- Request correction of inaccurate or incomplete information.
- Request deletion of your information (subject to legal retention obligations).
- Restrict or object to certain processing.
- Data portability where applicable.
- Withdraw consent where we rely on consent.
- Lodge a complaint with your local data protection authority.
9.3 California residents
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights regarding your personal information, including the right to know what we collect and how we use it, the right to delete, the right to correct, the right to opt out of sale or sharing for cross-context behavioral advertising (we do not engage in either), and the right to non-discrimination for exercising any of these rights. To exercise these rights, contact us using the details in Section 13.
9.4 Identity verification for requests
We may ask you to verify your identity before acting on a request concerning your personal information. This is to protect your information from unauthorized access.
9.5 Limits on deletion
Note that certain records — notably transaction records and sanctions screening records — must be retained for five (5) years or longer to meet our compliance obligations. Requests to delete information subject to a retention obligation will be honored after the retention period ends.
Because we do not collect government-issued identification or biometric data for standard purchases, there are no verification document retention obligations beyond basic account and transaction records.
§ 10Cookies and Similar Technologies
We and our service providers use cookies, local storage, and similar technologies to operate the services, remember your preferences, understand how the services are used, and detect fraud. You can control cookies through your browser settings; disabling essential cookies may prevent the services from working correctly. Where required by law, we will obtain your consent before placing non-essential cookies.
§ 11Children's Privacy
The services are not directed to individuals under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided personal information to us, please contact us and we will delete it.
§ 12Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this Policy indicates when it was most recently revised. Material changes will be communicated by email or in-product notice. We encourage you to review this Policy periodically.
§ 13Contact Us
If you have questions about this Policy or our privacy practices, or if you want to exercise any of your rights, contact us at:
Planet B 21, LLC
Wyoming, United States
General support: hello@planetb21.com
— END OF PRIVACY POLICY —