Privacy Policy

This Privacy Policy explains how your information is processed when using the Golden Hour Labs website.

Last updated: July 22, 2026

1. Responsible Entity and Contact

Michael Schubert Golden Hour Labs Email: contact@goldenhourlabs.tech

2. General Website Use

This website is designed with a focus on data minimization. We do not use intrusive tracking databases or analytics software to monitor your presence on this domain.

3. Vercel Hosting and Technical Logs

This website and its server-side functions are hosted by Vercel. Hosting and server-side execution can involve the processing of technical request data such as IP-related information, timestamps, diagnostics, and system configuration data to ensure network integrity and security.

4. Contact-Form Submissions

If you submit an inquiry through our contact form, we collect the information you provide (such as your name, email address, inquiry purpose, and message content) to review and respond to your request.

5. Resend Email Delivery

Contact details, inquiry content, and delivery metadata are processed through our email delivery provider, Resend, to transmit your inquiry securely by email.

6. Cloudflare Turnstile Spam Protection

We use Cloudflare Turnstile on the Contact form to help protect against automated submissions, spam and abuse. Turnstile may process technical request data and browser signals to verify that a submission is legitimate. The resulting verification token is validated server-side before your message is processed. Additionally, Vercel Web Application Firewall (WAF) rate limiting may be enforced on form submissions based on our deployment configuration.

7. Functional Cookies and localStorage

This website and related client applications may use browser localStorage (and, where applicable, sessionStorage) for client-side interface and application state. This can include language or interface preferences, clearance or access state for The Lab, non-sensitive UI state, and other app-specific client-side state required for functionality. Within X COLLECTOR, the browser may also store temporary or persistent client-side state such as wallet-related scan results, token metadata caches, preferences, and similar non-secret application data. We do not store private keys, seed phrases, or wallet secrets in localStorage. Data stored in your browser remains on your device and can typically be removed by clearing your browser storage. The public website uses localized path-based routing (e.g. /en, /de) and does not rely on language-preference cookies.

8. Recipients and Service Providers

Depending on which parts of our services you use, technical request data and, where applicable, inquiry data may be processed by the following service providers strictly as needed to operate the website and applications: Public website and Contact form: • Vercel for hosting and serverless infrastructure • Resend for delivering contact emails • Cloudflare Turnstile for bot protection on the Contact form X COLLECTOR and related Solana app flows (when you use those features): • Solana RPC infrastructure via Helius, accessed through our server-side RPC proxy • token metadata sources such as Jupiter • your connected wallet provider through Solana wallet-adapter interactions • external blockchain explorers such as Solscan when you choose to open account links We do not sell your personal data.

9. Retention Criteria

We retain your contact inquiries only for as long as necessary to process your request or as required by applicable law.

10. User Requests and Rights

Depending on your jurisdiction, you may have rights regarding your data, including the right to access, correct, or request deletion of the information you provided. Please direct any such requests to our contact email.