Privacy Policy
How we collect, use and protect your personal data.
Last updated: [EFFECTIVE DATE]
1. Who we are
The controller of your personal data is [LEGAL ENTITY NAME], with registered address at [REGISTERED ADDRESS] ("VScalp", "we", "us"). For any privacy question you can contact us at [CONTACT EMAIL] or our Data Protection Officer at [DPO EMAIL].
2. Scope
This policy explains what personal data we collect when you visit our website, create an account and use the VScalp Service, why we collect it, how we use it and what rights you have. It applies to individuals in the EU/EEA and, where relevant, to users in other jurisdictions.
3. Personal data we collect
Account data
- Email address, password hash and authentication metadata.
- Subscription status, plan and billing history received from Stripe.
Usage data
- Pages viewed, features used, timestamps, referrer, session identifiers.
- Device, browser, operating system, language and approximate location derived from IP.
Exchange / API metadata
- Names and identifiers of the exchanges you connect and the API key label / masked prefix.
- Order and execution metadata generated when you use automation features (symbol, side, size, timestamps, status, exchange order IDs, PnL).
- API secrets are stored encrypted at rest and are used exclusively to sign requests on your behalf. We do not sell or share your API secrets.
Communications and support
- Messages, attachments, feedback and metadata when you contact us or use in-app support.
Diagnostics
- Error reports, performance traces and logs needed to keep the Service reliable and secure.
4. Legal bases
Under the GDPR we rely on the following legal bases:
- Contract — to create your account, provide the Service and process your subscription.
- Legitimate interest — to secure the Service, prevent fraud and abuse, improve features and communicate service updates.
- Consent — for non-essential cookies, analytics and marketing communications, where consent is required.
- Legal obligation — to comply with accounting, tax and other applicable laws.
5. Processors and subprocessors
We share personal data with vetted service providers acting on our instructions, including:
- Cloud hosting and database providers used to run the Service.
- Payment provider Stripe for billing and subscription management.
- Email and messaging providers for transactional and support communications.
- Analytics and error-monitoring providers for diagnostics.
A current list is available on request from [DPO EMAIL].
6. International transfers
Some processors are located outside the EU/EEA. When personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission Standard Contractual Clauses and additional technical measures.
7. Retention
We retain personal data only as long as needed for the purposes described above, to comply with legal obligations (for example, accounting), and to defend legal claims. When you delete your account, we delete or anonymize account and usage data within a reasonable period, subject to mandatory retention rules.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent at any time where processing is based on consent. You can exercise these rights by writing to [DPO EMAIL].
You also have the right to lodge a complaint with your local data protection authority.
9. Security
We use technical and organizational measures to protect personal data, including encryption in transit and at rest for sensitive fields such as API secrets, role-based access controls, audit logs and regular reviews. No system is 100% secure, and you are responsible for keeping your own credentials and API keys safe.
10. Children
The Service is not directed to persons under 18 and we do not knowingly collect personal data from minors.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced through the Service or by email.
12. Contact
Data controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
General privacy contact: [CONTACT EMAIL] · Data Protection Officer: [DPO EMAIL].