1. Information We Collect
We collect the following types of information:
Account Information: When you register, we collect your email address, display name, and password (hashed). If you use OAuth (Google), we receive your name, email, and profile picture from the provider.
Trading Data: Portfolio configurations, trading bot settings, watchlists, order history, and backtest results you create within the platform.
Usage Data: Pages visited, features used, session duration, device type, browser type, IP address, and interaction patterns.
Payment Information: If you subscribe to a paid plan, payment processing is handled by Stripe. We store your Stripe customer ID and subscription status but do not store credit card numbers or banking details.
Cookies: We use essential cookies for authentication and optional analytics cookies with your consent.
2. How We Use Your Information
We use your information to:
• Provide, maintain, and improve the Service
• Process your transactions and manage your subscription
• Send transactional notifications (trade alerts, bot activity, account updates)
• Analyze usage patterns to improve features and user experience
• Ensure the security of your account and the platform
• Comply with legal obligations
• Provide customer support
We do NOT use your trading data to trade against you or share it with third-party brokers.
3. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
Service Providers: Third parties that help us operate the Service (cloud hosting via AWS, payment processing via Stripe, email delivery).
Leaderboard: If you opt into the leaderboard, your display name and anonymized performance metrics are publicly visible.
Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
4. Data Security
We implement industry-standard security measures to protect your information:
• Passwords are hashed using bcrypt
• Data is encrypted in transit (TLS/HTTPS)
• Access tokens use short-lived JWTs
• Infrastructure is hosted on AWS with IAM access controls
• Database access is restricted to service-level permissions
No method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
5. Cookies and Tracking
We use the following types of cookies:
Essential Cookies: Required for authentication and core functionality. These cannot be disabled.
Analytics Cookies: Help us understand how you use the Service. These are optional and you can decline them via the cookie consent banner.
We do not use advertising cookies or share cookie data with advertisers.
6. Third-Party Services
The Service integrates with third-party services:
• Alpaca (brokerage API for paper/live trading)
• Stripe (payment processing)
• Google (OAuth authentication)
• AWS (cloud infrastructure)
Each third-party service has its own privacy policy. We encourage you to review their policies.
7. Data Retention
We retain your account data for as long as your account is active. After account deletion:
• Account information is deleted within 30 days
• Trading and analytics data is anonymized or deleted within 90 days
• Backups may retain data for up to 180 days before automatic expiration
• We may retain certain data as required by law
8. Your Rights
Depending on your jurisdiction, you may have the right to:
• Access the personal data we hold about you
• Correct inaccurate personal data
• Delete your personal data ("right to be forgotten")
• Export your data in a portable format
• Opt out of non-essential data processing
• Withdraw consent for analytics cookies
To exercise any of these rights, contact us at the email address below.
9. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected data from a user under 18, we will delete that information promptly.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States where our servers are located. By using the Service, you consent to the transfer of your data to these countries.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
The Y Chapter
Email: privacy@aldero.com