Template · pending legal review
Privacy Policy
Last updated: 9 October 2026
This policy explains what personal data Quantora collects, why we collect it, and the choices you have. It is written with India's Digital Personal Data Protection Act, 2023 in mind, and with the GDPR for users in the EU/UK.
Data we collect
- Account data: name, email, phone number (if you use phone sign-in) and profile data from social login providers you choose.
- Billing data: plan, status and payment references. Card details are handled by our payment processor (Stripe) and never touch our servers. Crypto payments are handled by NOWPayments.
- Exchange API keys: encrypted with AES-256-GCM at rest. We only ever display the last 4 characters.
- Trading data: bots, settings, orders, fills and logs created through the Service.
- Technical data: IP address, device and browser information, and security and audit logs.
- Marketing data: your email if you join our list, and your email preferences.
How we use it
- To provide the Service: authentication, running your bots, sending alerts.
- To bill you and prevent fraud.
- To secure the Service, including audit trails and abuse detection.
- To send product and marketing emails. You can unsubscribe at any time using the link in every email or in Settings.
- To comply with legal obligations.
Sharing
We do not sell personal data. We share data only with processors that help us run the Service (hosting, email/SMS delivery, payments, analytics) under contract, with exchanges or brokers you connect (orders only), or when the law requires it.
Retention
We keep account data while your account is active. After deletion we keep only what the law requires, such as tax and billing records. Exchange keys are deleted the moment you remove them.
Your rights
You can access, correct, export or delete your data, withdraw consent, and nominate a person to exercise your rights. Email support@quantora.trade. Our grievance officer, [NAME], will respond within the time the law requires.
Security
We use encryption in transit (TLS) and at rest for sensitive fields, least-privilege access and audit logging. No system is perfectly secure, and we will notify affected users and authorities of a breach as the law requires.
Children
The Service is not intended for anyone under 18.