Legal
Privacy Policy
This Privacy Policy describes how LVL LTD CO (“LVL”, “we”, “us”) handles information when you use the x402 agent skill marketplace at lvlltd.com and related machine APIs. We design the product for public verification and minimal personal data.
1. Who this applies to
Humans browsing the marketplace, connecting a wallet, or purchasing skills; and automated agents calling our JSON/HTTP APIs (catalog, shop, pay, proof, MCP, A2A).
2. What we collect
- Wallet addresses — when you connect a wallet or submit an on-chain payment proof for unlock.
- Transaction data — Base network tx hashes, amounts, skill ids, and timestamps needed to verify USDC payments and re-issue sealed packs.
- Purchase / unlock records — confirmed unlocks may appear on the public proof ledger at /api/proof (skill id, amount, explorer link). We intentionally do not invent volume.
- Technical logs — standard request logs (IP, user-agent, path, status) from our host (Cloudflare) for abuse prevention, reliability, and security.
- Optional seller content — if you list on the open market, the metadata and files you upload for that listing.
- Local browser storage — client-side preferences (for example wallet connection state or local purchase history helpers) stored in your browser, not as a central account profile.
We do not require a traditional email/password account for the core buy path. On-chain payments are public by design on Base; that is inherent to blockchain settlement, not a separate marketing database.
3. What we do not sell
We do not sell personal information to data brokers. We do not build advertising profiles from skill purchases. Public proof data is product transparency for agent commerce, not a resale list.
4. How we use information
- Verify USDC payments and unlock sealed skill packs (idempotent re-download).
- Operate catalog, shop, escrow, and machine discovery surfaces.
- Prevent fraud, double-spend abuse, and payment bypass attempts.
- Improve reliability (health, rate limits, incident response).
- Comply with law and enforce our Terms of Service.
5. On-chain and third parties
- Base / USDC — payments settle on a public blockchain. Anyone can inspect transactions via explorers such as BaseScan.
- Cloudflare — hosting, CDN, edge functions, and security tooling process requests to serve the site.
- Optional funding partners — if you buy USDC with a card via Coinbase, MetaMask, or similar, that provider’s privacy policy applies to the card flow. Skill unlocks on LVL remain on-chain USDC.
6. Cookies and analytics
We may use operational cookies or similar storage required for security and session continuity. We avoid third-party ad trackers on the core product surfaces. Funnel beacons, when present, are first-party product metrics only.
7. Retention
Unlock verification records are retained as long as needed to honor re-downloads and maintain the integrity of the proof ledger. Edge/security logs are retained according to host defaults and operational need, then deleted or aggregated.
8. Your choices
- Browse free outlines and samples without connecting a wallet.
- Use a fresh wallet if you prefer not to link purchases to a known address.
- Clear local browser storage at any time.
- Contact us via the channels on /about/ for access or deletion questions about off-chain records we control.
Note: we cannot delete data that is already committed to a public blockchain.
9. Children
The marketplace is not directed at children under 16. Do not use the service if you are under the age required by your jurisdiction to enter binding contracts and make crypto payments.
10. International users
The service is operated from the United States and may process data in regions where our infrastructure providers run. Crypto payments may be restricted in your location; you are responsible for compliance with local law.
11. Changes
We may update this policy. Material changes will be reflected by the effective date on this page. Continued use after updates constitutes acceptance of the revised policy.
12. Contact
Privacy questions: use the contact paths on https://lvlltd.com/about/. Security issues: Security and security.txt. Brand identity: /status/ · status.json.