Skip to content
Kestrel

Privacy policy

Version 1.0. This describes what [OPERATOR LEGAL NAME — set in admin settings] collects, why each item is needed, and what you can require us to do with it.

1. What is collected, and why

DataWhy it is needed
Email address and password hashTo create and secure your account. Passwords are stored hashed and are not readable by us.
Identity verification documentsRequired by financial regulation before deposits and withdrawals can be processed.
Broker account credentials (managed service only)To place and manage trades on the account you have connected. Encrypted at rest and never displayed back in full.
Cryptocurrency transaction identifiersTo match an incoming payment to your account and to verify a withdrawal request against your deposit history.
Trading and balance historyTo calculate your holding, the performance fee and the figures shown in your account area.
Consent recordsWhich version of the terms and risk disclosure you accepted, and when.

2. What is not collected

  • No advertising or cross-site tracking identifiers. The platform sets no third-party marketing cookies.
  • No IP address logging at the network edge. A request blocked by the platform’s bot protection is refused without a record being kept, because storing an address for that purpose would be personal data collected for no benefit.
  • No biometric data beyond what an identity check provider processes on our behalf.

3. Broker credentials — specific commitments

These are the most sensitive items held, so the handling is stated explicitly rather than in general terms:

  • They are encrypted at rest and are never returned to a browser in full.
  • They are used only to place and manage trades under the settings you set.
  • They cannot be used to withdraw from or transfer out of your account.
  • You can revoke them at any time from your account area, which deletes them and disconnects the service immediately.
  • A connection left unused is removed automatically. We give notice first, and using it again resets the clock. A trading password nobody is using cannot help you and is a standing risk if data is ever exposed, so we do not keep one indefinitely. Only the connection is removed — your account, balance and history are kept, and you can reconnect in seconds.

4. Who else processes your data

  • The authentication and database provider that hosts the platform.
  • The payment network used to send and receive cryptocurrency.
  • The broker holding the account, for the managed service.
  • The identity verification provider, at the point a check is performed.

Each processes data only to deliver the service described. Your data is not sold, and is not shared for advertising.

5. How long it is kept

  • Financial and transaction records: for the period required by applicable financial regulation, which is typically several years after an account closes and is not shortened on request.
  • Broker credentials: until you revoke them, or until the connection has gone unused long enough to be removed automatically — whichever comes first. The current period is shown in your account area.
  • Identity documents: for the retention period the applicable regulation requires, then deleted.
  • Account and consent records: for the life of the account, then per the above.

6. Your rights

  • Request a copy of the data held about you.
  • Correct anything inaccurate.
  • Request deletion, subject to the retention obligations above — records a regulator requires us to keep cannot be deleted on request, and we will say which those are rather than refusing without explanation.
  • Withdraw consent for anything not required to operate the service.
  • Complain to your local data protection authority.

Requests go to [CONTACT EMAIL — set in admin settings] and receive a substantive reply.

7. Security

Access to your data is restricted by row-level authorisation, so an account can read only its own records. Secrets are held server-side and are never included in anything sent to a browser. Traffic is encrypted in transit.

No system is impossible to breach. The largest realistic risk to your account is your own password being reused elsewhere and exposed in an unrelated breach, which is why a unique password and two-factor authentication matter more than anything else you can do here.

8. Changes

Material changes will be notified and the version number above will change.

9. Contact

[CONTACT EMAIL — set in admin settings]