1. Information We Collect
Account information
- Email address and display name (provided at registration).
- Hashed password (we never store plaintext passwords).
- Subscription tier and billing history.
- Telegram chat ID (if you link Telegram).
Usage data
- Backtest and hyperopt run metadata (timeframes, pairs, results).
- VPS instance metadata (tier, region, status, uptime).
- Audit logs of account actions (login, VPS creation, deletions).
Data we do NOT collect
- Exchange API keys — stored exclusively on your VPS, never on our servers.
- Strategy source code — resides on your VPS only.
- Trading PnL, balances, or portfolio data.
2. How We Use Your Information
- To provision and manage your VPS infrastructure.
- To process payments and maintain billing records.
- To send transactional emails (payment confirmations, trial notifications, service alerts).
- To provide customer support.
- To monitor service health and prevent abuse.
3. Data Storage & Security
- All data is stored in EU data centers (Hetzner, Germany).
- Databases are encrypted at rest and connections use TLS in transit.
- Exchange credentials on your VPS are encrypted with per-customer Fernet keys (AES-128-CBC + HMAC-SHA256).
- Passwords are hashed with Argon2id.
- Access to production infrastructure is restricted to authorized personnel with 2FA.
4. Data Retention
- Active accounts: data is retained for the duration of your subscription.
- After cancellation: your VPS and all data on it are permanently deleted within 7 days (or immediately upon request).
- Billing records: retained for 24 months after account closure to comply with tax and accounting obligations, then anonymized or deleted.
- Audit logs: retained for 12 months, then purged.
5. Your Rights Under GDPR
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access — request a copy of all personal data we hold about you via the data export feature in your account settings.
- Right to rectification — update your personal information from your account settings.
- Right to erasure — delete your account and all associated data from your account settings.
- Right to data portability — export your data in a machine-readable JSON format.
- Right to object — contact us to object to specific data processing activities.
- Right to lodge a complaint — you may file a complaint with your local data protection authority.
To exercise any of these rights, contact privacy@freqedge.io.
7. Third-Party Services
We share limited data with the following processors, all of which maintain their own GDPR-compliant privacy policies:
- Stripe — payment processing (email, billing details).
- Plausible Analytics — cookieless product analytics (pageviews and named funnel events; no personal identifiers stored in the browser). Prefer a self-hosted EU instance when configured.
- Hetzner Cloud — VPS infrastructure (server metadata).
- Resend — transactional email delivery (email address).
We do not sell, rent, or share your personal data with any other third parties.
8. International Data Transfers
All personal data is stored and processed within the European Economic Area (EEA). Our payment processor (Stripe) may process payment data in the United States under Standard Contractual Clauses approved by the European Commission.
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
10. Contact / Data Protection Officer
For privacy-related inquiries or to exercise your data rights:
- Email: privacy@freqedge.io
- General: legal@freqedge.io