Legal
Privacy policy
What we collect, why we collect it, and how it is protected.
What we collect
- Account data: name, email address, and your password stored as a one-way hash.
- Contact details you choose to add, such as mobile number and country.
- KYC documents: identity document and selfie, used solely for verification.
- Transaction data: deposits, withdrawals, allocations and your account ledger.
- Security data: two-factor authentication settings and session tokens.
How we use it
- To operate your account: balances, allocations, withdrawals and statements.
- To meet legal obligations, including identity verification and record-keeping.
- To secure the platform, prevent fraud and respond to support requests.
We do not sell your personal data, and we do not use it for third-party advertising.
Storage and protection
Passwords are hashed with bcrypt and never stored in plain text. Sessions use signed, httpOnly cookies. KYC documents are stored outside the public web root and are accessible only to authorised staff. Access to production systems is restricted and logged.
Retention
We retain account and transaction records for as long as required by applicable financial-services and anti-money-laundering regulations, after which they are deleted or irreversibly anonymised.
Your rights
You may request a copy of the personal data we hold about you, ask us to correct inaccurate data, or — subject to our legal retention obligations — request deletion. Contact support through your account to exercise these rights.