1. Introduction and Scope
This Privacy Policy applies to the AlgoStack platform (www.algostack.com and all subdomains), agency partner dashboards, client-facing portals, mobile applications, APIs, and all related services.
We collect personal information from:
- Agency partners (businesses using our white-label platform)
- End clients (individuals trading through agency partners)
- Website visitors, job applicants, and vendors
Important Note for White-Label Partners
When you use AlgoStack's white-label platform under your own brand, you are the data controller for your clients' information. AlgoStack acts as a data processor. You are responsible for providing your own privacy policy to your clients and obtaining necessary consents.
AlgoStack is a service provided by AlgoFintech Inc., a Delaware corporation.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email, phone, business info, encrypted passwords, payment details, and tax IDs.
- Profile & Preferences: Settings, algorithm selections, risk parameters, and notification preferences.
- Trading Connections: Encrypted API keys, broker identifiers, and OAuth tokens. Note: We do NOT store broker passwords.
2.2 Information Collected Automatically
- Usage Data: Features used, time spent, click patterns, and navigation paths.
- Device Data: IP address, browser type, OS, device identifiers, and ISP.
- Trading Activity: Execution records, strategy status, performance metrics, and system logs.
2.3 Information from Third Parties
- Integrated Platforms: Account balances and trade confirmations from NinjaTrader, MT5, Schwab, etc.
- Payment Processors: Transaction status and billing validation.
- Data Enrichment: Business verification and fraud prevention data.
3. How We Use Your Information
Core Services
- Execute algorithmic trading strategies
- Connect to integrated broker platforms
- Monitor algorithm performance and system health
Operations & Security
- Process payments and calculate commissions
- Detect and prevent fraudulent activity
- Comply with legal and regulatory obligations
Legal Basis (GDPR): We process data based on Contractual Necessity, Legitimate Interests, Legal Obligation, and Consent.
5. Data Security
Encryption
- TLS 1.3 for Data in Transit
- AES-256 for Data at Rest
- End-to-End API Encryption
Access Control
- Multi-Factor Authentication (MFA)
- Role-Based Access (RBAC)
- Regular Security Audits
Compliance
- Annual SOC 2 Type II Audits
- Regular Penetration Testing
- 24/7 Threat Monitoring
6. Your Privacy Rights
GDPR (EEA, UK, Switzerland)
How to Exercise Your Rights
You can manage most settings in your account dashboard. For formal requests:
We verify identity before processing. Response times: 30 days (GDPR) or 45 days (CCPA).
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Active Accounts | Duration of account |
| Trading Activity | Active + 7 Years |
| Payment Records | 7 Years |
| Closed Accounts | Deleted within 90 days* |
*Backup copies are overwritten during normal cycles (30-90 days). Legal holds override standard retention.
9. International Data Transfers
AlgoStack operates globally. Your data may be processed in the US, EU, or APAC. For transfers from EEA/UK to countries without adequacy decisions, we rely on:
- Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreements (IDTA)
- Technical safeguards including encryption
10. Children's Privacy
Our services are not intended for individuals under 18. We do not knowingly collect data from children. If discovered, we delete such data immediately. Contact us if you believe a child has provided us with information.
11. Third-Party Services
We link to third-party services (brokers, payment processors). We are not responsible for their privacy practices. Review their policies before connecting your accounts.
12. California Privacy Rights (CCPA/CPRA)
Residents of California have specific rights:
- Right to Know: Categories collected/shared.
- Right to Delete: Request deletion.
- Right to Correct: Fix inaccuracies.
Sale of Data: We do NOT sell personal information as defined by CCPA.
Shine the Light: We do not share data for third-party direct marketing.
13. Changes to This Policy
We may update this policy. Material changes will be notified via email (30 days prior) or prominent website notice. Continued use implies acceptance.
14. Contact Us
Mailing Address
AlgoFintech Inc.
Attn: Privacy Team
[Street Address]
[City, State ZIP]
Regulatory Authorities:
EU Users: Contact your local Data Protection Authority.
UK Users: Information Commissioner's Office (ICO).
Automated Decision Making & DPIAs
We use automated systems for fraud detection and security. We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing. Contact us for details.