Privacy Policy

Last Updated: 2026-08-09

This Privacy Policy explains what data Vector Trading processes, why it is processed, and how we handle it.

Platform Controller

For platform account, consent, access-grant, lifecycle, security, and audit processing, the controller is ITECH FZE, incorporated in Hamriyah Free Zone - Sharjah, United Arab Emirates, under trade licence . Its registered address is P1-ELOB Office No. E-41F-09, Hamriyah Free Zone - Sharjah, United Arab Emirates. Privacy requests may be sent to [email protected].

1. Data We Process

Depending on how you use the platform, we may process:

  • account identifiers and profile data received from authentication providers, including Telegram-linked account data;
  • uploaded profile and bundle avatar images, processed avatar assets, and related moderation metadata;
  • session data, such as session identifiers, login timestamps, IP addresses, and user agent data;
  • device, locale, and operational usage data;
  • exchange connection data, including exchange identifiers and encrypted or otherwise protected exchange API credentials you provide;
  • trading configuration, subscription, bot, order, position, webhook, notification, and profitability data;
  • bundle access grants, checkout state, and external billing reference identifiers used to prevent duplicate access grants and evidence access decisions;
  • support, abuse-prevention, and security records;
  • legal acceptance and audit-log data generated when you confirm legal documents or perform regulated-risk actions.

2. Purposes of Processing

We process data to:

  • authenticate users and secure accounts;
  • connect and operate supported exchange integrations;
  • provide strategy, subscription, bot, signal, notification, and autotrading features;
  • maintain logs, investigate incidents, prevent abuse, and enforce platform rules;
  • comply with legal obligations and respond to lawful requests;
  • support users and improve platform reliability.

3.1. Where applicable, processing may be based on performance of our contract with you, legitimate interests in operating and securing the platform, compliance with legal obligations, and your affirmative actions in enabling particular features.

3.2. You are responsible for ensuring you are authorized to provide third-party credentials, trading settings, and other data you submit to the platform.

4. Cookies and Sessions

4.1. The platform uses cookies or similar storage mechanisms required for authentication, session continuity, security, and core application behavior.

4.2. We may also store language and operational preferences necessary for the user experience.

5. Roles, Sharing, and External Services

5.1. Platform processors and service providers. Fly.io hosting, MongoDB Atlas database services, Cloudflare R2/object-delivery services, Sentry error monitoring, Google Vision SafeSearch image moderation, and comparable logging or security infrastructure process data for Vector Trading under the platform's instructions. They may receive account identifiers, technical request data, operational logs, encrypted records, or uploaded images only as needed for their role.

5.2. Independent third-party services. Telegram, supported exchanges including Bybit, OKX/MyOKX, and BingX, and TON wallet, RPC, or IPFS providers process data under their own terms when you direct the platform to use those services. Exchanges receive API-authenticated trading instructions and account requests; Telegram receives authentication or notification content; wallet infrastructure receives public wallet or network requests.

5.3. Market-data services. CoinMarketCap and exchange-rate or exchange market-data APIs receive asset, pair, and technical request metadata needed to obtain prices and mappings. They do not receive exchange API secrets through the ordinary market-data path.

5.4. Bundle providers. A provider is independently responsible for personal data and records it processes for external billing, cancellation, refund decisions, and direct customer communication. Vector Trading remains the controller for platform access grants, consent evidence, lifecycle state, and platform audit records. A grant's external is visible in a personal export only to the bundle owner; it is omitted from a recipient's export.

5.5. Authorities and protection. We may disclose data to authorities, courts, regulators, or enforcement bodies when required by law or reasonably necessary to protect rights, security, or users.

We do not sell personal data as part of ordinary platform operations.

6. International Transfers

Your data may be processed in countries other than your own, including wherever our service providers operate. By using the platform, you understand that cross-border processing may occur, subject to applicable legal requirements.

7. Retention

The following matrix states the ordinary maximum or lifecycle rule. A longer period applies only where required by law, a binding request, an unresolved dispute, fraud prevention, or establishment or defence of legal claims. When final deletion is not yet complete, the account remains restricted and retryable lifecycle evidence is retained so the platform does not falsely report deletion.

Data categoryOrdinary retention or deletion rule
Authentication sessions and refresh stateUntil logout/revocation or expiry; session validity is capped at 30 days.
One-time deletion/restoration challengesShort configured security TTL and removal or invalidation after use.
Personal-data export request and generated fileThe generated export is ordinarily removed under the configured cleanup window, 24 hours by default after completion or failure.
Checkout initiation stateOrdinarily expires after 15 minutes; resulting access and billing evidence follows the evidence periods below.
Account API keysActive until revoked; minimal revoked-key identification evidence is kept for 30 days. Secret key material is never included in the personal export.
Profile fields, exchange credentials, avatars, and private avatar objectsKept while the account or object is active and removed during confirmed finalization, subject to retry and mandatory evidence holds.
Personal bundle ratingsUp to 365 days and removed during confirmed account finalization.
Trading orders, positions, executions, profitability, and related historyUp to 7 years from the relevant trading event for account history, dispute resolution, and financial or security evidence.
Access grants, checkout/payment references, refund or cancellation evidence, legal acceptances, and audit/security recordsUp to 7 years from the end of access, account termination, or the relevant event. External providers separately retain their own billing records under their policies.
Minimal account tombstone and lifecycle evidencePseudonymized and restricted for up to 7 years after finalization to prevent replay, prove deletion state, and connect retained evidence; then deleted or irreversibly anonymized unless a mandatory hold applies.

Stopping autotrading or requesting deletion does not remove open orders or positions from an exchange. Operational personal fields are purged only after the platform has completed the safe handoff and all blocking paid grants are resolved.

8. Security

We use administrative, technical, and organizational measures designed to protect data against unauthorized access, alteration, disclosure, or destruction. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

9. Your Rights

Subject to applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal from optional processing where such withdrawal is legally available.

Requests may be sent to the contact address below. We may need to verify your identity before acting on a request.

During the cooling period, logging in may restore the account, but it does not automatically restore autotrading, subscriptions, bots, or former bundle links. If a cleanup dependency is temporarily unavailable, the platform retains a restricted retry state instead of claiming completion.

10. Third-Party Services

The platform may link to or integrate with third-party services. Their privacy practices are governed by their own policies, not this Privacy Policy.

11. Changes

We may update this Privacy Policy from time to time. The current version and update date will be published in the legal documentation presented on the platform.

12. Contact

Questions, privacy requests, and legal notices may be sent to [email protected].