Abstract
Commerce is already recorded everywhere. Every purchase leaves evidence: a receipt, an email, a merchant record, a payment trace, a loyalty entry, a point-of-sale event.
But the buyer does not carry that history.
Purchase history sits inside the systems that captured it. A retailer sees what happened in its own store, a loyalty platform sees its enrolled buyers, a payment network sees its payment view, and a retail media platform sells audiences built from the data it controls.
Each system holds a partial view of demand inside its own wall. The buyer created the commerce, but cannot carry the proof. The brand wants verified demand, but must rent access from whoever controls the record.
Crinkl creates a portable record of purchase history without attaching identity.
A buyer submits purchase evidence. A verification service checks it under protocol rules. If the evidence qualifies, the service signs a spend token: an attestation that a real purchase occurred.
The token records the purchase, not the person.
Spend tokens let buyer history become provable without becoming exposed. A wallet can prove that it satisfies a condition — repeat buyer, lapsed buyer, category buyer, competitor buyer, local buyer, newly converted buyer — without revealing the purchase trail behind it.
The brand receives proof of the condition, not the buyer's identity.
This changes the role of the intermediary. A brand no longer needs to rent someone else's segment, panel, loyalty base, or transaction stream to reach a buyer state. The condition is proven by the buyers in it.
Once this record exists, markets can act on it. Buyers are paid for contributing verified commerce. Brands buy access to verified buyer states. Campaigns settle against proven outcomes. Crinkl's native economy uses a fixed $CRINKL reserve to bootstrap that record: users earn, unclaimed residual supply burns, and brand demand replaces subsidy over time.
Bitcoin adds hard cost to rewards. When rewards settle in bitcoin, fake commerce is no longer merely bad data. It becomes real money paid against fraud.
The result is an identity-free commerce network where purchase history becomes portable proof, validators constrain the record, users are paid to create it, and brands act on verified demand without renting identity from intermediaries.
Introduction
Commerce is already measured.
Every purchase leaves a trace: a paper receipt, a digital receipt, an email, a card transaction, a loyalty entry, a merchant record, a point-of-sale event. The problem is not that purchase history does not exist. The problem is that the buyer does not carry it.
Purchase history is fragmented across the systems that captured it. A retailer sees what happened inside its own store, a payment network sees payment activity, a loyalty platform sees its enrolled users, and a retail media network sells audiences built from the data it controls.
Each system can prove some version of commerce, but the proof does not travel with the buyer.
That structure gives intermediaries control over buyer history. The platform owns the audience. The brand buys a segment. The buyer appears only as an inferred target inside someone else's system.
This is the problem Crinkl solves.
The buyer creates the commerce, but cannot carry the proof. The brand wants verified demand, but receives rented access to an intermediary's partial view. The same purchase may matter to a merchant, a brand, a market, a campaign, or a wallet, but the evidence remains trapped where it was recorded.
Crinkl begins from a different premise: purchase history should become portable proof.
A buyer should be able to prove that commerce happened without exposing who they are. A brand should be able to act on verified demand without receiving a name, account, or surveillance profile. A market should be able to count commerce without publishing receipts. A reward should be able to settle against a real purchase without turning buyer history into public data.
The unit that makes this possible is the spend token.
A spend token is created when purchase evidence is verified under Crinkl protocol rules. It records the purchase, not the person. The buyer carries it under a blinded wallet. The raw evidence remains private. The public record receives the attestation alone.
This changes the structure of campaigns.
Today a brand reaches buyers by renting someone's view of them — a platform's segment, a panel's extrapolation, a loyalty base, a card network's transaction stream. Each version follows the same pattern: an intermediary's inference, drawn from its partial view, sold inside its wall.
Crinkl changes the route. The brand defines a condition — a repeat buyer, a lapsed buyer, a category buyer, a competitor buyer, a local buyer, a newly converted buyer — and buyers qualify themselves by proving that their spend tokens satisfy it. The network routes the campaign, reward, and settlement to the wallet that proved eligibility.
The audience is not rented. It is proven by the buyers in it.
The record must also be constrained. A system that admits fake or duplicate purchases inflates commerce. A system that exposes raw receipts recreates surveillance. Crinkl separates the party that reads evidence from the parties that admit the record.
Verification is private. Admission is public.
A verification service reads purchase evidence inside a privacy boundary and signs qualified spend tokens. Proof validators admit those tokens to the record without seeing the receipts themselves.
Once admitted, spend tokens accumulate into a portable history of verified commerce. A buyer can later prove buyer state from that history without revealing the underlying purchases. A brand can act on the proof without receiving identity. A market can count demand without exposing the people behind it.
This is the base layer of Crinkl: verified purchase history without identity.
The economy builds on top of that layer. Buyers must be paid to contribute the evidence they hold. The protocol can fund the record's construction, but it cannot remain the record's only source of demand. A record funded forever by its own protocol is a subsidy. A record funded by demand becomes a market.
The protocol uses a fixed $CRINKL reserve to bridge that transition. Verified commerce spends the reserve down. Users earn from the record they help create. Unclaimed residual supply burns. Over time, brand demand replaces subsidy by buying access to the verified buyer states those users created.
Bitcoin adds hard cost to rewards. Because rewards can settle in bitcoin, rewarded commerce can carry a real payout cost. Fake commerce is no longer abstract bad data. It becomes fraud paid for in real money.
The result is a commerce network built from portable proof rather than rented identity. Spend tokens make purchase history usable outside the walls that captured it. Validators constrain the record. $CRINKL funds its construction. Bitcoin prices bad reward issuance. Brands create demand for the buyer states the record makes provable.
Together, these components turn verified commerce into an economy rather than a database.
Spend Tokens
A spend token is a signed attestation that a specific purchase occurred.
A buyer submits purchase evidence: a paper receipt, a digital receipt, an email receipt, a merchant-origin record. The verification service checks the evidence under protocol rules. The merchant must exist. The transaction must be real. The amounts must be consistent. The evidence must not have been admitted before.
If the evidence qualifies, the service signs a spend token. If the evidence fails, nothing enters the record.
The spend token carries the purchase fact and nothing else: where the purchase occurred, when it occurred, for how much, and what was bought, under a schema that buckets commerce into portable form.
It carries no name, no account, and no exposed wallet address.
The raw evidence does not enter the public record. Publishing receipts would recreate the surveillance this system exists to remove. What enters the record is the attestation alone.
Each spend token is unique.
A purchase can become a spend token once, or not at all. Evidence that qualifies twice would inflate the record the way a coin spent twice inflates a money supply. Every submission is checked against prior commitments before admission.
Spend tokens accumulate into Verified GMV.
Verified GMV is the gross merchandise value observed through qualified purchase evidence and recorded by admitted spend tokens. It is not modeled demand, estimated intent, or platform-reported attribution. It is commerce observed through evidence, attested by a verification service, and admitted under validator constraint.
A spend token proves commerce. It does not promise reward.
The token is not a coupon, a claim, or an incentive. It carries no economic obligation by itself. Rewards are applied afterward, by the program using the token. The same spend token can support different reward, campaign, proof, or settlement policies without changing the underlying purchase fact.
That separation is enforced by ordering.
In the protocol's native economy, one policy routes rewards for verified commerce from a fixed $CRINKL reserve. Other programs may apply different policies to the same underlying fact. The spend token remains the same. The purchase does not change because a reward was later attached to it.
Identity enters only when necessary to claim or route value, and only through a blinded commitment. The record can show that value was committed without exposing the person behind the purchase.
The spend token remains identity-free even after a reward is claimed.
From these tokens, buyer history becomes provable.
A wallet can prove it satisfies a condition — repeat buyer of a brand, lapsed buyer of a category, buyer within a market, new conversion after exposure — without revealing the history behind that condition. The brand receives proof of the condition, not the buyer's purchase trail.
The spend token is the base unit of Crinkl: a purchase made portable without becoming identity.
Verification and Admission
Verification cannot be fully public because purchase evidence must be read.
A receipt contains merchant names, items, amounts, timestamps, store locations, payment fragments, and other data that can become personal when combined. Broadcasting raw evidence to unknown parties for inspection would recreate the surveillance the system is designed to remove.
So evidence is read inside a privacy boundary.
A verification service receives purchase evidence, checks it under protocol rules, and emits a signed spend token if the evidence qualifies. Raw evidence terminates at the service. The public record is built from attestations, not receipts.
But the service that reads evidence cannot be allowed to admit its own record alone.
That is the division of power.
Verification is private. Admission is public.
Any service may operate as a verifier, read evidence within its own privacy boundary, and sign spend tokens under its own key. The protocol does not appoint a single verifier. Services compete to admit qualified commerce.
Their output is judged by the same record rules.
A spend token is valid only if it is well-formed, unique, signed by a valid service key, and ratified by proof validators. A signed spend token is therefore a proposal. It enters the record only when validators admit it.
Validators check what can be checked without seeing raw evidence: the token schema, the service signature, the signing key, the commitment, the absence of collision with prior admissions, and the integrity of the service's output over time.
Validators operate on the public plane. They do not read receipts.
The audit is adversarial by design.
Validators test verification services with crafted submissions: deliberate duplicates, cross-wallet collisions, malformed receipts, inconsistent totals, edge-case merchants, and evidence designed to probe the boundary between qualified and unqualified commerce.
An honest service rejects them. A service that loosens its standards fails probes it cannot see coming.
A verifier's credibility is measured continuously. Duplicate rejection, uniqueness coverage, malformed evidence handling, admission patterns, and audit results become part of the public integrity surface.
The service earns belief one admitted purchase at a time.
The penalty for failure is disbelief.
Nothing needs to be seized. No central party needs to punish the verifier. Validators simply stop admitting its attestations. A service that loses ratification loses its product. Its spend tokens become worthless to buyers, brands, and campaigns because they no longer enter the record.
Whoever can see the receipt cannot unilaterally admit it. Whoever admits the token cannot fabricate the receipt. Whoever pays against the buyer state feels bad admission as real economic loss.
Crinkl's record is built at that boundary: private verification, public admission, economic disbelief.
Data Density Burn Reserve
The spend-token record has to be built before the market can price it.
Buyers hold the evidence. They have the receipts, emails, merchant records, and purchase traces that can become portable proof. But a buyer does not contribute evidence to a new record for free. The network has to pay for the first history before brands can buy against it.
The Data Density Burn Reserve exists for that purpose.
Crinkl has a fixed total supply of 100,000,000 $CRINKL. Of that supply, 70,000,000 $CRINKL forms the Data Density Burn Reserve, funding verified commerce during the construction of the record. This pool is not an open-ended emission schedule. It is not refilled by inflation. It is not replenished when depleted.
The pool is the subsidy, and it is designed to end.
Each admitted spend token adds verified commerce to the record. That commerce creates reward eligibility under the protocol's native policy. The reward does not live inside the spend token itself. The purchase is attested first, the attestation is admitted second, and only then may policy act on it.
The Data Density Burn Reserve is one such policy.
Verified GMV drives reserve depletion through the reward curve. As qualified commerce enters the record, the curve releases rewards from the reserve according to its tranche schedule. Early commerce draws the reserve down fastest because the record is least developed. Later commerce draws less because the record has become denser, more useful, and closer to brand demand.
The reserve does not pay for time. It pays for density.
A thin record cannot prove much. A dense record can prove repeat buyers, lapsed buyers, category buyers, competitor buyers, market-level demand, and conversion after exposure. The reserve buys the density needed for those buyer states to become useful.
Users elect how value settles.
If a user elects $CRINKL, the native reward emits from the reserve to the eligible wallet. If a user elects bitcoin, the reward settles in bitcoin instead. The $CRINKL that would have been emitted does not become a future claim on the reserve. It becomes residual supply.
Residual supply burns.
That burn is part of the transition. The reserve is not designed to maximize token distribution. It is designed to construct the record and remove unused subsidy as the system matures. Every unit of verified commerce either pays a user under the active policy or reduces future supply through residual burn.
This gives the reserve two jobs at once.
It pays buyers for contributing the evidence they hold. It reduces the subsidy as verified commerce accumulates.
The result is a finite bridge from contribution to demand. At the beginning, Crinkl pays buyers to surface purchase history. Over time, brands pay to reach the buyer states that history makes provable. The same record that required subsidy at launch becomes the record that attracts demand later.
The reserve ends when its job is done.
A permanent subsidy would make Crinkl another rewards program. A finite reserve makes it a construction phase. The network pays to build the first portable record of verified commerce, burns what is not claimed, and hands the market to the brands that need proven demand.
The reserve buys the first record. Brand demand must buy the next one.
Brand Demand
The reserve pays for the first record. Brand demand gives the record its market.
A spend-token record becomes useful when it can prove buyer states that brands already pay intermediaries to approximate: repeat buyers, lapsed buyers, category buyers, competitor buyers, local buyers, newly converted buyers, and conversion after exposure. Today those states are usually rented as segments, panels, audiences, or transaction views. In Crinkl, they are proven by the buyers who satisfy them.
A brand does not need to receive the buyer's history. It defines the condition it wants to reach.
The condition may be simple: a buyer who has purchased the brand before. It may be competitive: a buyer who has purchased inside the category but not from the brand. It may be temporal: a buyer who was active, then lapsed. It may be geographic: a buyer in a market where the brand wants to grow. It may be outcome-based: a buyer who received an offer and later produced verified conversion.
The spend-token record makes those conditions provable.
A campaign begins with a rule. The brand defines the buyer state, the market, the time window, the reward policy, and the settlement terms. The network checks eligible wallets against the admitted spend-token record. A wallet either proves the condition or it does not.
The brand receives proof of eligibility, not the buyer's identity.
This changes what a campaign buys. The brand is not buying a list. It is not buying modeled intent. It is not buying access to an intermediary's partial view. It is buying action against a proven condition.
Campaign value is escrowed before routing.
A brand-funded campaign commits the reward budget and settlement terms before users act on it. Campaigns are funded through $CRINKL. A brand may fund directly in the token, or pay a standard invoice in dollars — the network converts the payment, purchasing $CRINKL on the open market on the brand's behalf. Either path produces the same market event: campaign budget becomes demand for the float, and the sellers are the users who earned it. The escrowed $CRINKL is locked for the campaign's life, and settled campaign value burns.
Eligible wallets can then receive offers, boosts, rewards, or settlement according to the campaign policy. The record supplies the condition. The campaign supplies the value. The wallet supplies the proof.
No party needs the full buyer history to coordinate the action.
A buyer may prove eligibility without exposing the purchases behind it. A brand may reward a condition without receiving identity. The network may route value without publishing receipts. The same spend token can support multiple campaigns because the underlying fact does not change when a new policy acts on it.
Settlement closes the loop.
If the campaign pays for exposure, the eligible wallet receives the campaign value under the policy. If the campaign pays for conversion, the later purchase must be verified by a new admitted spend token. That token proves the outcome without exposing the buyer's full history. The campaign settles against verified commerce, not reported attribution.
This is where brand demand replaces subsidy.
The reserve pays buyers to construct the first density. Brand campaigns pay buyers because that density has become useful. As more spend tokens enter the record, more buyer states become provable. As more buyer states become provable, more campaigns can be routed. As more campaigns settle, the record becomes easier to price.
The market learns what the record is worth.
A thin record can only support broad rewards. A dense record can support precise buyer states, competitive conquest, reactivation, local growth, verified conversion, and outcome settlement. The economic value of the record rises with its density because every new admitted purchase can make future conditions more useful.
Brand demand is therefore not separate from the record. It is the market expression of the record.
The buyer creates the evidence. The spend token makes it portable. Validators admit it to the record. The reserve pays to build early density. Brands pay when that density can prove demand better than rented inference.
Crinkl does not sell the buyer. It sells access to conditions the buyer can prove.
The audience is not rented. It is proven by the buyers in it. The campaign is not settled against a platform's claim. It is settled against verified commerce. The record does not become valuable because Crinkl says it is valuable. It becomes valuable when brands pay to act on the buyer states it makes provable.
The Economics of Trust
Commerce begins outside the protocol.
A purchase happens in the world: at a store, in an app, through a merchant, inside a payment flow. The protocol does not create that event. It receives evidence of it after the fact.
That makes Crinkl different from a native digital money system. Bitcoin can order transactions created inside its own network. Crinkl must admit claims about commerce that occurred outside of it. Consensus alone cannot prove that a receipt is real, that a merchant exists, or that a buyer actually made the purchase.
The first source of truth is the buyer's evidence.
Buyers hold the receipts, emails, merchant records, and purchase traces that can become spend tokens. A verification service reads that evidence inside a privacy boundary and signs a claim if the evidence qualifies. Proof validators then admit or reject that claim under public rules.
A spend token is therefore an accountable claim that commerce occurred.
It is not raw evidence. It is not a published receipt. It is not a reward. It is a signed attestation that a verification service produced under protocol rules, and that validators admitted to the record.
Trust begins with that separation.
No party holds the whole system alone.
The verification service can read evidence, but cannot unilaterally admit its own record. Validators can admit attestations, but cannot read receipts. Brands can pay against buyer states, but do not receive buyer identity. Buyers can prove eligibility, but do not expose the full history behind the proof.
This division does not make offchain commerce trustless. It makes trust constrained.
Validators check what can be checked without seeing raw evidence: the token schema, the verification service's signature, the service's public key, the commitment, the absence of collision with prior admissions, and the integrity of the service's output over time. They do not prove that every purchase happened. They constrain which claims can enter the record.
Bitcoin adds another constraint.
Bitcoin does not prove that commerce occurred. It proves that rewards carried real payout cost. When rewards settle in bitcoin, bad admission is no longer merely bad data. It becomes money paid against fraud.
That cost matters because fake commerce is easiest when lies are free.
A verification service that admits bad commerce damages its own output. A campaign that pays against bad buyer states sees bad results. A record polluted by duplicates becomes less useful to brands. A verifier that repeatedly fails audits or produces contaminated buyer states loses the thing it sells: belief.
Trust is not assumed. It is priced, constrained, and withdrawn.
Audit makes disbelief possible. Validators can test verification services with malformed evidence, deliberate duplicates, cross-wallet collisions, inconsistent totals, and edge cases designed to probe the boundary between qualified and unqualified commerce. A service that loosens its standards fails where an honest service rejects.
Markets add the second test.
A record can grow through subsidy, but it becomes credible when outside demand pays against it. Brand campaigns test whether admitted buyer states are useful. If a buyer state produces poor outcomes, the campaign learns. If a verification service admits weak commerce, its record becomes less valuable. If a market pays repeatedly against a record, the record earns price.
The economics of trust are therefore not separate from the record. They are how the record is disciplined.
Crinkl cannot make offchain commerce trustless. It can make false commerce costly, constrained, measurable, and disbelievable. The system does not ask the market to trust every receipt. It asks the market to trust a process in which evidence originates with buyers, attestations are signed by verification services, admission is constrained by validators, rewards carry real cost, and brand demand tests the record over time.
A trusted record is not declared.
It is earned one admitted purchase, one rejected duplicate, one paid reward, one settled campaign, and one survived audit at a time.
Risks
Crinkl's record depends on evidence that begins outside the protocol. That creates risks the system must name directly.
The first risk is fake commerce. A malicious user may submit altered receipts, duplicated receipts, stale receipts, fabricated merchant records, or evidence copied from another buyer. A malicious verification service may admit weak evidence, ignore duplicates, loosen standards, or create valid-looking attestations from invalid inputs. Validators can constrain admission, but they cannot see raw evidence without destroying the privacy boundary.
The defense is not one mechanism. It is layered resistance. Evidence is checked before attestation. Commitments are checked before admission. Duplicate attempts are rejected. Validator probes test service behavior. Rewards settle only after policy acts. Bitcoin-priced rewards make bad admission expensive. Brand outcomes reveal whether the record is useful. A bad verifier can lose admission, reputation, and future demand.
The second risk is duplicate inflation. If the same purchase can enter the record more than once, Verified GMV inflates. Inflated GMV weakens the record because it makes demand appear denser than it is. Crinkl treats uniqueness as a record constraint. A purchase can become a spend token once, or not at all.
The third risk is surveillance creep. The system exists because raw purchase history should not become another identity graph. If receipts, item histories, wallets, claims, campaigns, and rewards are linked carelessly, the record can recreate the system it was designed to replace. The privacy boundary is therefore not cosmetic. Raw evidence terminates at the verification service. Validators admit attestations without reading receipts. Brands receive proof of conditions, not buyer histories.
The fourth risk is verifier power. The verification service reads evidence, and that position carries trust. If one service dominates the record, it can become a new intermediary rather than a bridge out of the old ones. The protocol's answer is role separation: the service reads evidence, validators admit attestations, brands test outcomes, and users carry the resulting proof. Over time, verification can become more open, more competitive, and more economically constrained, but the first principle is already fixed: the party that reads receipts cannot admit the record alone.
The fifth risk is subsidy dependence. If buyers scan only because the reserve pays them, and brands never replace the reserve, Crinkl becomes another rewards program. The Data Density Burn Reserve is designed to avoid that outcome. It does not refill. It does not exist to distribute tokens forever. It buys early density so brand demand can price the buyer states the record makes provable.
The sixth risk is brand indifference. Brands may keep renting audiences from incumbents if Crinkl's record is too thin, too noisy, too hard to buy, or too early to measure. This is why density matters. A few isolated purchases do not create a market. A dense record can prove repeat behavior, lapse, category participation, competitor spend, local demand, and conversion after exposure. Brand demand arrives only when the record proves something worth buying.
The seventh risk is overclaiming. Crinkl should not claim that validators prove every purchase. They do not. It should not claim that bitcoin proves GMV. It does not. It should not claim that spend tokens are rewards. They are not. The system is strongest when each role is named precisely: users originate evidence, verification services attest it, validators admit claims, policies route rewards, bitcoin prices payouts, and brands validate demand.
The final risk is that the record becomes valuable before it becomes sufficiently trusted. That is the hardest phase of any new proof network. If the record has no value, no one attacks it. If it has value, attacks begin. Crinkl's task is to make each stage of value harder to corrupt than the last: early rewards capped by policy, duplicate resistance enforced at admission, verifier behavior measured over time, brand demand earned through outcomes, and disbelief available when a service fails.
Risk does not disappear because the record is cryptographic.
Risk moves to the boundary between commerce and proof. Crinkl's design is to make that boundary visible, constrained, and economically accountable.
Conclusion
Commerce is already recorded.
It is recorded by retailers, payment networks, loyalty programs, merchant systems, inboxes, and retail media platforms. But those records do not belong to the buyer in any useful form. They sit inside the systems that captured them, and brands rent access to the partial views those systems sell.
Crinkl creates a different record.
A buyer submits purchase evidence. A verification service checks it under protocol rules. If the evidence qualifies, the service signs a spend token. Validators admit the attestation to the record. The buyer carries verified purchase history without exposing identity.
The spend token records the purchase, not the person.
That single separation changes the market. A brand no longer needs to rent an intermediary's inference to reach a buyer state. It can define the condition it wants — repeat buyer, lapsed buyer, category buyer, competitor buyer, local buyer, newly converted buyer — and eligible wallets can prove the condition without revealing the history behind it.
The audience is not rented.
It is proven by the buyers in it.
The first record has to be built before that market can price it. The Data Density Burn Reserve funds that construction. Crinkl has a fixed total supply of 100,000,000 $CRINKL, with 70,000,000 $CRINKL reserved to pay for verified commerce during the construction phase. The reserve does not refill. It depletes as Verified GMV grows. Users elect their reward — $CRINKL from the reserve or bitcoin — and residual $CRINKL burns.
The pool is the subsidy, and it is designed to end.
As the record becomes denser, brand demand replaces subsidy. Brands pay to act on buyer states the record makes provable. Campaigns settle against conditions and outcomes, not rented identity. The same spend-token record that begins as a paid construction effort becomes a market for verified demand.
The verification services mature with it.
A service begins by verifying spend. But every campaign that settles against its record teaches it something no single brand can see: which buyer states convert, what rewards clear, how markets respond, where competitive conquest works. The service that verifies the most commerce learns the most about commerce.
Verification matures into intelligence. The proof layer becomes a learning system for the market it serves — trained on aggregate outcomes, never on people — selling brands what works without exposing who it worked on. Crinkl does not seek arbitrary pricing power over rewards. Rewards clear where users participate; brand spend clears where verified buyers convert. The market between them prices the transaction, and the services that built the record earn their place by teaching it.
This is the transition Crinkl exists to make.
Crinkl does not make commerce valuable. Commerce is already valuable.
Crinkl makes it portable, provable, private, and payable.