Privacy

Lodestar Stamp is a dated public-record receipt on named businesses. Assistants and people read it before they book, call, or pay. We publish dated facts. We do not approve bookings. Payment never touches the record.

What we operate

The Trust API and MCP tools are read-only. Callers look up receipts; they do not write the record through those interfaces. Public receipts and docs are meant to be read.

What is on the record

Receipts show business identity facts drawn from public sources (for example: whether the business appears real, at that address, licensed, and — when the city publishes it — inspection). Each field carries a source and verified-on / expires-on dates when we have checked it. Fields we have not checked say so.

What we do not sell

Nothing on the receipt is for sale. We do not sell grades or placement on the record. Paying for an agent read buys that read, never the record. Payment never changes what the receipt says.

Payments

Card payments for Watching (and related paid products) are processed by Stripe. We do not store full card numbers on Lodestar systems. Stripe’s privacy terms apply to payment processing.

Agent-read payments (x402)

When an agent read is paid over x402, the payer's wallet address and the settlement transaction are visible on-chain to anyone, and they cannot be removed. To check a payment, and to settle it when it is charged, we send the signed payment to a payment facilitator, which submits a charged payment on-chain. For each payment we keep: the payer's wallet address; the transaction reference and network; the token, amount and receiving address; the read it paid for (the businesses and market, and how many reads); the price; the name the request declared in X-Lodestar-Consumer, the product name at the start of its User-Agent, or the name on the key or sign-in it used; a hash of the signed payment; whether it settled, failed or could not be confirmed, and why; and when it was made and settled. The billing record of a settled payment is kept for our books; the working records used to settle a payment expire after 30 days. For each OAuth login, API key or paying wallet we also keep a monthly count of its free reads, which expires after about two months; a wallet's count is kept even when its payment was not charged. We count payment requests, settlements, replays and failures by network, consumer name and number of reads, without the payer address. The per-minute limit on free reads checks the client's IP address in memory and does not store it. Separately, our API host's request logs may keep a paid request's IP address and headers, including the signed payment in its PAYMENT-SIGNATURE header, for up to 7 days. If a billing record cannot be written, its transaction reference, network and the hash of the signed payment are written to those logs instead. We use these records to reconcile payments, keep our books, prevent abuse and answer questions. We do not link a payer address to a person or business unless you give us that information. No card is involved.

Text messages (SMS)

If you give a phone number and check the separate text-message box, we collect that phone number, the consent record, and a message log. We use them only for the texts they agreed to. STOP is honored and ends all texts to that number. Phone numbers and SMS consent are not shared for others' marketing.

Email

If you watch a business or write us, we use watch@lodestarstamp.com (and related Lodestar Stamp mail) to send Watching notices and operational replies. We do not use that mailbox for unrelated marketing blasts.

Logs and operators

Like most web services, our hosts may keep standard request logs (time, path, IP, user agent and other request headers) to keep the service working and secure. Lodestar Stamp is operated by Banjo Ventures.

Product measurement

We use PostHog, hosted in the United States, to understand use of the site and receipts, checkout completion, and service reliability. We send selected events and operational counts. Browser journeys use an existing identifier stored in local storage; an identifier may accompany checkout so we can connect the journey with payment and delivery outcomes. Identifiers sent to PostHog are pseudonymous. We do not send email addresses, message contents, business names, or raw caller identifiers through this event integration. Links we send by email or text may include a short reference code so we can tell which business's outreach led to a visit; the code is pseudonymous and contains no name, email, or phone number.

Error reporting

When enabled, Sentry receives normalized service error categories, response status, environment, and software release identifiers. This integration does not send request bodies, customer email addresses, message contents, or raw error messages and stack traces.

Retention and choices

Our product-measurement integration honors browser Do Not Track and Global Privacy Control signals. Operational error reporting and essential hosting logs are separate. Analytics and error data are subject to the providers’ configured retention settings. Contact watch@lodestarstamp.com about access or deletion requests. We do not record browser sessions through these integrations.

Contact

Questions: watch@lodestarstamp.com — Lodestar Stamp · https://lodestarstamp.com

Effective

Effective date: 2026-09-29. First effective 2026-09-18; updated 2026-09-28 for agent-read payments. We will update this page when practices change.