Policy

Privacy Policy

What information we collect through the Portal, the Agent, our websites and our certification and warranty services — how we use it, who we share it with, and the choices you have.

Document details
Document
Wright One Privacy Policy
Version
2.1
Effective
August 19, 2026
Supersedes
v2.0
Last updated
September 1, 2026
Related
Wright One Terms of Service v2.4 · Wright One Limited Warranty v2.5

1. Who we are and what this covers

Wright One, Inc. (“Wright One,” “we,” “us”) provides equipment certification, monitoring, warranty administration and related services to bitcoin mining operators, hosting facilities, resellers and individual owners of mining equipment.

This Privacy Policy explains what information we collect through the Wright One portal, the Wright One Agent, our websites and public certificate verification page, and our certification and warranty services (together, the “Services”) — how we use it, who we share it with, and the choices you have.

This is a notice document. It is not a contract, and it does not form part of our Terms of Service.

Most of our customers are businesses. Some are individuals operating equipment on their own account. Where the two are treated differently under privacy law, we say so.

2. The short version, and the honest part

Most of the data flowing through our systems describes machines, not people: chip temperatures, hashrate, fan speeds, error counts, power draw, uptime. Under U.S. privacy laws, information about equipment is generally not personal information.

But there are five places where that stops being the whole story, and we would rather name them than let you discover them:

  1. Sole proprietors and one-person operations. When the operator is an individual, data about that person’s machines can also say something about that person — their working patterns, their revenue, the health of their business. We treat data associated with an individual account accordingly.
  2. Named people. Who logged in, who acknowledged an alarm, who changed a setting, who filed a claim, who signed for a delivery. That is always personal information.
  3. Business contacts in California. California’s privacy law covers business-to-business contact information. If you are a California resident whose contact details we hold because you work for a customer, that information carries privacy rights even though our relationship with your employer is purely commercial.
  4. Device identifiers linked to an account. A serial number or MAC address is not personal information on its own. We hold the record that connects them to accounts, so in our hands the link exists.
  5. Site data describes places, and places have people. Facility layouts, rack maps and access patterns can reveal who works where and when.

This policy is written assuming all five are real.

2.1 A note if you operate mining equipment

If you operate mining devices — your own or someone else’s — you may be a data controller in your own right under some laws, with obligations of your own toward the people whose information passes through your systems. That is your assessment to make, not ours. We are happy to answer questions about what we do with the data you send us, but we cannot advise you on your own obligations.

3. Information we collect

3.1 Information you give us

  • Account and contact information — name, business email, phone number, job title, company name and address, and the name and role of the person who accepts our Terms.
  • User records — the individuals you authorize on your account, their roles and permissions.
  • Fleet and Site information — the equipment you operate, where it is installed, Site names and labels, facility layouts, rack and row maps, naming conventions, and inventory and asset records, and the facility operator you work with.
  • Transaction and billing information — orders, invoices, credit balance and ledger entries, purchase and payment records. Card and bank details are collected and stored by our payment processor, not by us. We receive a token and limited details such as the card brand and last four digits.
  • Claim, RMA and support information — what you tell us about a failure, photographs and documents you upload, shipping addresses, and the content of your support communications.
  • Certification submissions — equipment you send us for certification, and the ownership and provenance information you provide with it.

3.2 Information collected automatically from your equipment

We ingest telemetry from equipment enrolled in our services, through the Wright One Agent running on your network or through a direct integration. Specifically:

  • performance — hashrate and per-board output, accepted and rejected shares, uptime and downtime;
  • thermal — chip and board temperatures, temperature imbalance across boards, inlet and outlet readings where available;
  • cooling — fan RPM, fan duty cycle, fan fault and degradation indicators;
  • electrical — power draw, voltage and frequency settings, power limit and mode;
  • errors and faults — hardware error counts, chip failure indicators, fault and failure records, restart and crash events;
  • identity and configuration — serial numbers, MAC addresses, IP addresses, model and generation, firmware name and version, and pool configuration settings on the device;
  • connectivity — Agent status and configuration, connection and reconnection events, telemetry gaps;
  • control — throttle, curtailment and demand-response events, and any configuration change made through the portal.

On pool configuration. We can see the pool and worker configuration on devices you enroll. We use it to interpret telemetry, attribute faults, and adjudicate claims. We do not use it to interfere with your pool relationships, and we do not disclose it to any pool or competitor.

Telemetry describes equipment and, unavoidably, the Site where that equipment runs.

3.3 Diagnostic uploads

For support and warranty claims, we may request and trigger an upload of diagnostic logs from the Agent or from your equipment. These uploads can contain more detail than routine telemetry — full device logs, configuration dumps, and crash traces.

We use them only for the support case or claim they relate to and for the purposes in Section 4, restrict access to personnel who need it, and delete them within 30 days unless they relate to an open claim, dispute or legal hold.

3.4 Information collected from our applications and website

Log and device information (IP address, browser and device type, operating system, timestamps), authentication and audit records, portal and API usage, and cookie or similar-technology data. Section 12 covers cookies.

Anti-abuse signals. To detect trial abuse, duplicate accounts and circumvention of usage limits, we may correlate account data, email domain, the IP addresses of Agents and the MAC addresses of managed devices, and similar identifying information.

3.5 Information from other sources

  • Resellers and dealers who sell our equipment or enroll customers on our behalf.
  • Repair and logistics partners handling RMA shipments and repairs.
  • Facility operators, where they provide Site-level information directly.
  • Payment processors, for transaction status and fraud signals.
  • Public and commercial sources, for business verification and sanctions and denied-party screening.

3.6 Information we do not collect

We do not knowingly collect information from children, and the Services are not directed to them. We do not collect biometric identifiers, government-issued identification documents, precise geolocation of individuals, cryptocurrency wallet addresses or private keys, or information about anyone’s personal finances, health or background. If that ever changes, we will update this Policy before we begin collecting it.

4. How we use information

We use the information above for the following purposes. This is a complete list, not an illustrative one.

  1. Operating the Services — providing the portal, the Agent, monitoring, alerting, reporting and analytics; authenticating users; maintaining and securing our systems.
  2. Certification and verification — testing and inspecting equipment, issuing certificates and scores, and operating the public verification page.
  3. Warranty administration — intake, triage, fault attribution, adjudication, RMA routing, repair coordination, and computing covered-day accrual.
  4. Establishing, exercising and defending legal claims — retaining and using records to support or contest a warranty claim, a billing dispute, or any other dispute, and to substantiate statements we make.
  5. Training, validating and improving models — including our predictive failure model, failure-mode classifiers, fault-attribution logic, thermal models and risk scoring. This uses data across our customer base, not only your own.
  6. Risk assessment and pricing — computing risk scores and equipment, fleet and Site grades; actuarial reserving; pricing coverage and services.
  7. Testing and experimentation — running controlled comparisons, staged rollouts and cohort experiments to measure whether a feature works.
  8. Product development — building and improving current and future products.
  9. Aggregated insight and publication — producing benchmarks, statistics and research in aggregated or de-identified form that does not identify any customer, Site or individual.
  10. Billing and finance — invoicing, payment processing, collections, tax, accounting and audit.
  11. Enforcing our terms — detecting misreported telemetry, falsified serials or configuration, trial abuse, duplicate accounts, and circumvention of usage or entitlement limits.
  12. Communications — service and security notices, transactional messages, and, where permitted, marketing you can opt out of.
  13. Legal and safety — complying with law, responding to legal process, sanctions and denied-party screening, and preventing fraud, abuse and harm.

If we want to use information we have already collected for a materially different purpose than those listed, we will ask for your consent first. See Section 17.

4.1 Why we collect what we collect

Two of these deserve plain explanation, because they are the reason the telemetry list in Section 3.2 is as detailed as it is.

Warranty depends on evidence. To decide whether a hashboard failed because of a defect or because it ran at 95 °C for a week, we need the temperature, fan and power history for that machine. Without it, we are adjudicating on guesswork — which is worse for you than for us, because the record is usually what proves a failure was covered.

Risk scoring depends on scale. A failure model built only on your fleet would be useless. It works because it learns from failures across every fleet we monitor. That is why the license in our Terms of Service covers cross-customer use, and why we say so plainly here rather than hiding it behind “to improve our services.”

5. How we share information

We do not sell personal information. Section 9 addresses the broader definitions of “sale” and “sharing” under state law.

We share information with:

  • Service providers and subprocessors who work on our behalf under contract — cloud hosting and infrastructure, database and analytics tooling, payment processing, email, SMS and push notification delivery, customer support, logging and monitoring, and business software. We maintain a current list of these subprocessors and will provide it on request — write to us at the address in Section 18.
  • Repair and logistics partners — for RMA handling, parts, repair and shipping.
  • Resellers and dealers — regarding equipment and customers they originated, limited to what they need.
  • Facility operators — where you ask us to, or where operating the service at their Site requires it.
  • Buyers and the public, through certificate verification — a WrightProof certificate and its verification page disclose equipment condition and provenance. They do not publish your contact information without your agreement.
  • Professional advisers — lawyers, accountants, auditors and insurers, under duties of confidentiality.
  • Legal and safety recipients — where required by law or legal process, to enforce our agreements, or to protect the rights, safety or property of Wright One, our customers or others.
  • In a corporate transaction — a merger, acquisition, financing or sale of assets, subject to this Policy or notice of a change.

We do not sell or license risk scores, equipment grades or Site grades to lenders, insurers or other third parties. If we ever offer such a service, we will update this Policy and describe it before the practice begins.

5.1 Where a partner or intermediary brought you to us

You may use our Services through a hosting provider, a fleet manager, a reseller or another intermediary. Where that is the case, we may provide that party with the data needed to perform the role you have given them, and we may treat their request as evidence of your authorization.

If your relationship with that party ends, tell us. We do not monitor your relationships with third parties, and we will keep providing access until you tell us to stop. We are not responsible for how a third party uses information we provided while it was authorized.

6. Aggregated and de-identified information

We produce statistics, benchmarks, models and model weights from the data we hold — for example, failure rates by model and generation, thermal performance distributions, fan lifespan curves, and efficiency benchmarks. Where we publish or disclose this material, it is aggregated across multiple customers and does not identify you, your Site or any individual.

We do not attempt to re-identify de-identified information, and we do not authorize others to. We may keep and use this material, and the models trained on it, indefinitely — including after our relationship with you ends.

7. Automated processing

We use automated systems to score equipment condition, predict failures, attribute faults, generate alerts, compute covered-day accrual, and — where enabled — select operating profiles for equipment. Where these outputs affect a decision that matters to you, such as whether coverage is offered, how a claim is attributed, or how many covered days you have accrued:

  • the output reflects our methodology applied to observed data, and is our opinion, not a statement of fact;
  • we will explain, in terms of the procedure and principles actually applied, how the result was reached and what inputs were used;
  • a person will review the decision on request; and
  • you may contest the result and provide additional information, through the process described in the portal.

We do not use automated processing to assess anyone’s creditworthiness, and our scores are not credit scores.

8. Your commercially sensitive information

Some of what we hold is not personal information but is commercially sensitive to you: Site layouts, fleet composition, curtailment behavior, uptime, and your unpublished pricing. Our Terms of Service treat these as your confidential information, and we protect them accordingly. This Policy does not reduce those obligations.

9. “Sale,” “sharing” and targeted advertising

Several state privacy laws define “sale” and “sharing” broadly, and can reach disclosures made for value that are not cash sales, including disclosures of derived insights rather than raw data.

We do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not use personal information for targeted advertising. We do not run advertising pixels or cross-site tracking technologies on our portal, website or verification page.

If this ever changes, we will update this Policy and provide the required opt-out mechanism before the practice starts.

10. How long we keep information

We operate two different retention periods, and we disclose both because they are genuinely different.

What you can see. Telemetry history visible to you in the portal is retained according to your service tier — 24 hours of live telemetry and 7 days of history are available at no charge, with longer windows in paid tiers as published in the portal. On termination or downgrade, read-only access and export remain available for 30 days.

What we keep internally. We retain records for longer than they are visible to you, because we need them to administer coverage, answer questions about a machine’s history, and resolve disputes:

Record

Retained for

Telemetry for covered equipment

The coverage period plus 2 years

Certification, provenance and verification records

7 years from issuance

Claim, RMA and fault-attribution records

2 years from claim closure

Diagnostic log uploads

30 days, unless tied to an open claim or dispute

Credit ledger, invoices and payment records

7 years, as required by tax, accounting and unclaimed-property rules

Account, User and contact records

The life of the account plus 2 years

Authentication and audit logs

12 months

Support communications

2 years

Backups

Overwritten on a 35-day cycle

The reasons for the longer internal periods are: administering warranty coverage; establishing, exercising and defending legal claims; and complying with tax, accounting, unclaimed-property and other legal obligations.

We may retain information longer where a legal hold, an open dispute or an unresolved claim requires it, and we retain aggregated and de-identified information indefinitely.

11. Your rights and choices

Depending on where you live, you may have the right to: know and access the personal information we hold about you; correct inaccuracies; delete it; obtain a portable copy; opt out of sale, sharing, targeted advertising and certain profiling; and not be discriminated against for exercising a right.

How to exercise them. Use either method:

  • email contact@wrightfan.com with “Privacy Request” in the subject line, or
  • use the privacy request tool in your portal account settings.

Verification. We verify your request against information we already hold. We may ask for additional information where we cannot otherwise confirm your identity. An authorized agent may submit a request on your behalf with proof of authority.

Timing. We respond within 45 days, extendable once by another 45 days where reasonably necessary. We will tell you if we need the extension and why.

Appeal. If we deny a request, we will explain why and how to appeal. To appeal, reply to our decision or write to contact@wrightfan.com with “Appeal” in the subject line. We will respond within 60 days. If we deny the appeal, we will give you a way to contact your state attorney general.

11.1 What we cannot delete, and why

Some records cannot be deleted on request without destroying the integrity of a warranty program that other people also rely on. Where an exception applies, we will tell you which one and what we kept.

We retain

Because

Certification and provenance records tied to a serial number

A certificate is relied on by subsequent buyers. Deleting it would make the verification page wrong

Telemetry for the coverage period of a covered machine

It is the evidence on which a warranty claim is decided — including a claim by a later owner

Claim, RMA and attribution records

Legal claims can be brought after a claim is closed, and the record is the defense

Ledger, invoice and payment records

Tax, accounting and unclaimed-property law require it

Records subject to a legal hold or open dispute

We are required to preserve them

Aggregated and de-identified data, and models trained on it

It no longer identifies you and cannot be disentangled

Deleting your account closes your access and removes your contact and User records on the schedule in Section 10. It does not delete the categories above.

Universal opt-out signals. We recognize opt-out preference signals, including Global Privacy Control, where required by law.

Marketing. You can opt out of marketing email using the unsubscribe link or by contacting us. Service, security, billing and warranty messages are not marketing and continue while your account is active.

12. Cookies and similar technologies

We use cookies and similar technologies that are:

  • strictly necessary — authentication, session management, security, and load balancing; and
  • analytics — understanding how the portal and our website are used, so we can improve them.

We do not use advertising, retargeting or cross-site tracking technologies.

You can control cookies through your browser settings. Disabling strictly necessary cookies will prevent parts of the portal from working.

13. Security

We maintain administrative, technical and physical safeguards designed to protect information in our custody, including access controls, encryption in transit, logging and audit trails, and restricting access to personnel who need it for their work.

Security is partly in your hands. The Agent runs on your network with credentials to your equipment, and portal accounts can affect physical machines. Keep credentials confidential, review your User list and API keys regularly, remove access promptly when personnel change, and tell us immediately if you suspect compromise.

No system is perfectly secure, and this section describes our practices rather than warranting a result. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.

14. Where the Services are offered

The Services are offered in the United States, and information is processed and stored in the United States. We do not currently offer the Services to customers in the European Economic Area, the United Kingdom or Switzerland, and this Policy is not written to satisfy the GDPR or UK GDPR.

15. Facility operators

If you operate a hosting facility where equipment enrolled in our services is installed, this section is for you.

What we receive. Telemetry from equipment operated at your Site, which necessarily reflects Site conditions — power quality and interruptions, ambient conditions, network reliability, curtailment behavior, and equipment failure and fault rates. We may also hold layout and configuration information about your facility. We receive it from our customer, who represents to us that it has the right to provide it.

What we do with it. We use it for the purposes in Section 4, including computing risk and Site-level assessments.

Your access, and your ability to contest. You may request the Site-level data we hold about your facility and the inputs behind any assessment concerning it, and you may contest that assessment by providing information or context we did not have. Contact contact@wrightfan.com. Where we obtain your consent directly to receive and use Site data, the terms of that consent govern.

Publication. We do not publish Site-level assessments. If we begin to, we will give the facility the underlying inputs and a defined window to respond before publication, and will publish the response alongside the assessment.

16. State-specific disclosures

16.1 All states with comprehensive privacy laws

If you are a resident of a state with a comprehensive consumer privacy law — including California, Texas, Colorado, Connecticut, Virginia, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island — the rights in Section 11 are available to you, together with the appeal process described there.

We do not sell personal data, we do not process it for targeted advertising, and we do not use it for profiling in furtherance of decisions that produce legal or similarly significant effects concerning an individual.

Categories of personal information we collect, and who we disclose each to:

Category

Examples

Disclosed to

Identifiers and contact information

Name, business email, phone, job title, employer, account and User IDs

Service providers, resellers, repair and logistics partners, professional advisers

Commercial information

Orders, invoices, credit balance, ledger entries, certification and claim records

Service providers, payment processors, repair partners, professional advisers

Internet and device activity

IP address, browser and device type, portal and API usage, authentication logs

Service providers

Equipment and operational data

Serial numbers, MAC addresses, device IPs, telemetry, firmware and pool configuration, Site labels and layouts, fault records

Service providers, repair partners, facility operators where relevant

Inferences

Risk scores, condition scores, failure predictions, fault attributions, covered-day accrual

Not disclosed outside Wright One and its service providers

Communications

Support tickets, emails, claim narratives, uploaded documents and diagnostic logs

Service providers, repair partners

We do not collect sensitive personal information as that term is defined under state privacy law.

16.2 California

California’s privacy law covers business-to-business contact information. If you are a California resident whose contact details we hold because you work for one of our customers, resellers or partners, you have the rights in Section 11 with respect to that information.

We have not sold or shared California residents’ personal information, and have not disclosed sensitive personal information for purposes requiring an opt-out, in the preceding 12 months. We disclose the categories above to service providers for the business purposes in Section 4. Retention periods are in Section 10.

You may designate an authorized agent to make a request on your behalf. We will not discriminate against you for exercising any right.

16.3 Texas

We do not sell sensitive personal data, and we do not sell biometric personal data. Texas residents may exercise the rights in Section 11 and may appeal a denied request as described there; if an appeal is denied, you may contact the Texas Attorney General at texasattorneygeneral.gov/consumer-protection/file-consumer-complaint.

16.4 Nevada

We do not sell personal information as defined by Nevada law. Nevada residents may submit a verified opt-out request to contact@wrightfan.com.

17. Changes to this Policy

We may update this Policy. We will post the updated version with a new version number and date, and keep prior versions available.

If we want to use personal information we have already collected for a materially new purpose, we will ask for your consent first. We will not broaden our data practices by amending this Policy and treating your continued use as agreement.

For other significant changes, we will provide notice through the portal or by email at least 30 days before they take effect.

18. Contact us

Privacy questions, requests and appeals: contact@wrightfan.com — put “Privacy Request” or “Appeal” in the subject line In the portal: account settings → privacy requests Subprocessor list: available on request at the address below Mail: Wright One, Inc., 11021 Avery Station Loop, Austin, TX 78717

Change Log
VersionDateChangeBy
2.1August 19, 2026Subprocessor list provided on request rather than at a published URL; privacy requests routed to email and the in-portal tool rather than a public form. Removes two pages that would otherwise have to exist at launch.Justin McAfee
2.0August 19, 2026Added: granular telemetry enumeration including MAC addresses, pool configuration and Site layouts (§3.2); diagnostic uploads with quantified retention (§3.3); anti-abuse fingerprinting disclosure (§3.4); operator-may-be-a-controller notice (§2.1); why we collect what we collect (§4.1); enforcement purpose (§4.11); partner and intermediary sharing with revocation burden (§5.1); commercially sensitive information (§8); limits on erasure with reasons (§11.1); shared-responsibility security note (§13); expanded facility operator section (§15).Justin McAfee
1.0First issue. US-only scope; no sale/sharing; coverage + 2 years telemetry retention.Justin McAfee

If any of these documents raises a question about your account, your coverage or your data, our team will answer it directly.

Contact Support