Placeholder. Not legal text and not legal advice. The headings below are the ones a GDPR-facing privacy policy needs; the text under them is a description of what to write, not the writing. Replace this document entirely before publishing the Google OAuth consent screen, before accepting a payment, and before any real person creates an account.
The controller's legal name, registered address, and a contact address for privacy questions. If a Data Protection Officer is appointed, their contact details.
Enumerated by category and by source, distinguishing what a person gives us from what is observed. For this product that includes: the email address and profile fields supplied at sign-up or by an identity provider; a device identifier and public key generated at enrolment; subscription and billing state held by the payment provider; and records of which data ranges were requested, for quota accounting.
Each category paired with a purpose and an Article 6 basis — performance of a contract, legitimate interests, consent, or legal obligation. Where legitimate interests are relied on, the balancing test and its conclusion.
Named processors and what each one receives: the identity provider, the payment provider, the cloud and object-storage providers, and the market-data vendors. For each, whether the transfer leaves the EEA and the mechanism that permits it.
A retention period per category, or the criteria used to decide one. Account records, audit records and billing records will not share a period; billing records in particular are usually held for a statutory minimum that outlives the account.
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where consent is the basis. How to exercise each, how long a response takes, and the right to complain to a supervisory authority — named, with its contact details.
Whether any is carried out, and if so its logic, significance and consequences. Note that trading decisions made by a customer's own strategies on their own machine are not our automated processing of their personal data, and the document should say so rather than leave it ambiguous.
A truthful summary of the measures in place — encryption in transit and at rest, access control, and the fact that content encryption keys are held per account. Do not describe controls that are not implemented.
What is stored in a browser, by whom, for what, and whether consent is required. If no analytics or advertising technology is used, say so plainly; it is the shortest and best version of this section.
How changes are notified and from when they take effect. Prior versions remain available.