Privacy Notice

What we publish, what we protect

Last updated: 18 July 2026. This page is maintained by the ImpactMiles team to answer the most common privacy questions about the public TrustMark Explorer and the personal data we hold.

Why we publish a public ledger

ImpactMiles issues a tamper-evident TrustMark for every donation, sponsorship, participation record and IMI report. The public TrustMark Explorer and the per-credential Verify pages exist for one reason: so that donors, regulators, journalists and the general public can independently confirm that the activity we report has actually happened, and that the numbers we quote on the site are backed by real, sealed records.

The Explorer is a trust and transparency surface. It is not used for advertising, profiling, ranking individuals, or any secondary purpose.

What the Explorer shows

Only organisational and technical metadata is ever published:

  • The registered name of the organisation holding the credential (charity or corporate body, both already public on their statutory registers).
  • The TrustMark family (Identity, Receipt, Proof, Report) and the technical credential type.
  • The SAID / TMID, which is an opaque cryptographic hash and is not linkable to a natural person.
  • The recorded amount in HKD, where the record is a donation, sponsorship or fee settlement. This is the same figure already visible on the sealed receipt issued to the payer and recipient.
  • The timestamp, the anchor status on the trust anchor service (TAS), and any revocation flag.

What the Explorer never shows

The following are treated as personal data and are excluded from every public surface:

  • Donor names, email addresses, phone numbers, billing addresses or payment instrument details.
  • Participant names, staff numbers, employer-employee linkage, department, salary or role.
  • Wallet AIDs, device identifiers or any handle that could re-identify an individual.
  • Payloads from activity proofs, including GPS traces, heart rate, other biometric or health signals, and photographs.
  • Free-text fields that a user has written about themselves or others.
  • Any field a participant or donor has chosen to keep private in their wallet settings.

Individual TrustMarks that relate to a natural person (for example a participant proof) are recorded on the ledger, but the Explorer only exposes the fact that a proof exists in aggregate. The subject remains pseudonymous and the underlying payload is not retrievable from the public API.

Lawful basis

Under the Hong Kong Personal Data (Privacy) Ordinance, the EU / UK GDPR and the PRC Personal Information Protection Law, we rely on the following bases for the limited data we do publish:

  • Legitimate interest in demonstrating that ImpactMiles is a truthful, non-fraudulent platform, balanced against the interests of data subjects by publishing only organisational names already in the public domain.
  • Contract and legal obligation for the sealed receipts we issue to donors and charities, which are shared with the payer and recipient but not with the wider public.
  • Consent for any additional profile information a corporate, charity or participant chooses to display on their own profile page.

Data we hold internally

We collect the minimum information needed to operate the marketplace: an email address for authentication, an organisation profile for onboarding, KYB / AML documents where a body corporate is being verified, and the activity or donation records the user creates. Access is protected by row-level security so that a given user only ever sees their own records or those they have been explicitly granted access to.

Payment method details are handled by the payment gateway configured for the transaction. ImpactMiles stores only the non-sensitive receipt fields returned by the gateway.

Retention and deletion

Ledger-related TrustMark records are kept for as long as they are needed to prove the integrity of the ImpactMiles trail, satisfy audit expectations, and support donor, charity, sponsor and regulatory enquiries. This includes the SAID / TMID, credential family, timestamp, organisation holder, public amount, TAS anchor status, revocation status, and the minimal receipt metadata shown on the Explorer.

  • Public ledger metadata is retained for seven years from the date the related donation, sponsorship, activity, report or identity credential is issued, unless a longer period is required by law, tax rules, audit obligations or an active dispute.
  • Underlying private payloads that may contain personal data are not published and are kept only for the period required to operate the relevant account, verify a claim, resolve a dispute or meet legal obligations.
  • KYB, AML and charity verification documents are reviewed periodically and deleted when they are no longer needed for verification, re-verification, legal retention or fraud prevention.
  • Payment method data is not stored by ImpactMiles. We keep only non-sensitive gateway references and receipt status fields needed for reconciliation.
  • Revoked or corrected TrustMarks are not silently rewritten. The public view is updated to show that the record has been revoked, corrected or withdrawn, while personal data is removed or suppressed from public display.

When a retention period expires, records are purged, anonymised, or reduced to non-identifying audit metadata. If a record is part of an active complaint, legal hold, security review, fraud investigation or accounting process, deletion may be paused until that matter is closed.

Public verification

How to match a ledger row to its on-chain anchor

Five steps. No account required. No wallet identifier ever leaves the page.

  1. Step 1

    Copy the SAID or TMID

    Every public ledger row shows a Self-Addressing IDentifier (SAID) or a TrustMark ID (TMID). Copy it from the Explorer row you want to check. It is an opaque hash, not linked to any wallet or person.

  2. Step 2

    Open the Verify or Lookup page

    Paste the identifier into /verify or /lookup. The page fetches the sealed TrustMark from the trust anchor service (TAS) using only the hash, so no wallet identifier is exchanged.

  3. Step 3

    Compare the safe public fields

    Check that the credential family, holder organisation, issue time and amount on the Verify page match the Explorer row. If any field differs, the record has been rewritten or the identifier is wrong.

  4. Step 4

    Confirm the anchor status

    Look for the 'Anchored on TAS' state and its anchor timestamp. Anchored means the hash has been sealed into the immutable trail. Anyone can independently re-derive the SAID from the credential body and prove it has not been altered.

  5. Step 5

    Note what you should never see

    You should never see a donor name, participant name, email, phone number, wallet AID, GPS trace, biometric reading or free-text personal note. If you do, report it via the takedown form on the Privacy Notice.

Try it with a real identifier

No demo TMID is hard-coded here so you never chase a dead link. Open the Explorer, copy any live SAID or TMID from the ledger, and paste it into Lookup or Verify.

How the public can verify the ledger without personal data

Every public row includes a SAID or TMID. A member of the public can copy that identifier into the Verify or Lookup page to confirm that the published summary corresponds to an underlying TrustMark issued by ImpactMiles and anchored by TAS.

  • The Verify page confirms the TrustMark family, holder organisation, issue time, anchor status and whether the credential has been revoked.
  • The Explorer shows only the same safe public fields, so the public can compare the summary row with the verification result.
  • The cryptographic identifier proves that the displayed record corresponds to the sealed TrustMark without exposing donor names, participant names, wallet AIDs, health data, biometrics or private proof payloads.
  • If a TrustMark is later corrected or withdrawn, the verification result shows the changed status rather than hiding the fact that a correction happened.

Takedown and rectification requests

Anyone can ask us to review a public ledger entry if they believe it contains personal data, inaccurate information, unlawful content, confidential material, or anything that could identify a natural person. We will assess the request, preserve the audit trail where legally required, and remove, suppress, correct or revoke the public display where appropriate.

  • Email privacy@impactmiles.co with the SAID / TMID, the Explorer or Verify link, the reason for the request, and any evidence that helps us assess it.
  • We acknowledge receipt within five working days and aim to complete the initial review within 30 calendar days.
  • Urgent safety, doxxing, child protection, health data or financial harm concerns are prioritised for immediate suppression while the review is ongoing.
  • If the public display is wrong but the underlying TrustMark should remain part of the audit trail, we correct the public fields and mark the affected credential as corrected.
  • If the TrustMark itself should no longer be relied on, we revoke it and publish the revocation status without exposing the disputed personal data.

We may ask for enough information to verify that the requester is affected by the record or is authorised to act for the affected person or organisation. We do not require unnecessary identity documents for ordinary public takedown complaints.

Submit a takedown or rectification request

Use this form to formally log a request. It goes to the ImpactMiles privacy team and is never shown publicly. You will get a reference code you can quote in follow-up emails to privacy@impactmiles.co.

e.g. data subject, guardian, legal counsel, journalist

Used only to correspond about this request

Paste the identifier from the Explorer or Verify page

Explorer or Verify link, if applicable

Please do not include any additional personal data beyond what is strictly necessary.

Your rights

You can request access to, correction of, or deletion of the personal data we hold about you at any time. Where a credential has already been anchored to the public trail, we cannot rewrite history, but we can revoke the credential so that any subsequent verification clearly shows the record as withdrawn, and we can remove any personal profile fields you no longer wish to display.

To exercise any of these rights, contact privacy@impactmiles.co.

Changes to this notice

We will publish a new version of this notice, with a fresh "last updated" date, whenever we change the scope of what appears on the Explorer or the categories of personal data we process. Material changes will be flagged to signed-in users inside their portal.