1. Introduction
Tactyx (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, applications, and services (collectively, the “Service”).
By using the Service, you consent to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
When you create an account or use the Service, you may provide us with:
- Account Information: Email address, name, password (securely hashed)
- Profile Information: Timezone, theme preferences, notification settings
- Strategy Data: Trading strategies you create, backtest configurations, bot settings
- Communications: Messages you send to us, support requests, feedback
- Payment Information: Billing details processed through our payment providers
2.2 Information Collected Automatically
When you access the Service, we automatically collect:
- Device Information: Browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, backtest results, trading activity
- Log Data: IP address, access times, referring URLs, error logs
- Location Data: Approximate location based on IP address
- Performance Data: Page load times, errors, crash reports
2.3 Information from Third Parties
If you connect external services, we may receive:
- OAuth Providers: Basic profile information from Google, GitHub when you sign in
- Broker Integrations: Account information, trade data, balances from connected brokers
- Market Data: Price data, historical information from data providers
2.4 Legal Acceptance Records
When you accept our legal documents, we record:
- Timestamp of acceptance
- IP address at time of acceptance
- Version of documents accepted
3. How We Use Your Information
We use collected information for the following purposes:
3.1 Service Delivery
- Provide, operate, and maintain the Service
- Process your strategy configurations and run backtests
- Execute paper trading and live trading through broker integrations
- Authenticate your identity and manage your account
- Process payments and subscriptions
3.2 Communication
- Send important service notifications (security alerts, updates)
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
- Notify you of changes to our Terms or Privacy Policy
3.3 Improvement and Analytics
- Analyze usage patterns to improve the Service
- Develop new features and functionality
- Conduct research and analysis (using aggregated, anonymized data)
- Monitor and improve Service performance
3.4 Security and Compliance
- Detect, prevent, and address fraud, abuse, or illegal activity
- Enforce our Terms of Service
- Comply with legal obligations and regulatory requirements
- Protect the rights, safety, and property of our users
4. Third-Party Services We Use
We use the following categories of third-party services to operate the Service:
Infrastructure & Hosting
Cloud hosting providers for data storage and application hosting. These providers may process data in various geographic locations.
Authentication
OAuth providers for secure sign-in. When you use OAuth, we receive basic profile information according to the permissions you grant.
Payment Processing
Payment processors handle all financial transactions. We do not store your full credit card numbers on our servers.
Analytics
Analytics services help us understand how the Service is used. Data is typically aggregated and anonymized.
Broker Integrations
When you connect brokers (e.g., Binance, Coinbase, Kraken), we interact with their APIs on your behalf. Review each broker's privacy policy for their data practices.
5. Data Sharing and Disclosure
We do NOT sell your personal information. We may share your data only in the following circumstances:
- Service Providers: Third parties that help us operate the Service (hosting, analytics, email, payment processing). These providers are contractually obligated to protect your data.
- Broker Integrations: When you connect a broker account, necessary data is shared to execute your trading requests. Only data required for the integration is transmitted.
- Legal Requirements: When required by law, court order, subpoena, or government request. We will attempt to notify you when legally permitted.
- Safety and Security: When necessary to protect the rights, safety, or property of Tactyx, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets. Users will be notified of any such transfer.
- With Your Consent: In any other circumstances where you have given explicit consent.
6. Data Security
We implement comprehensive security measures to protect your information:
Technical Safeguards
- TLS/SSL encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Secure password hashing using Argon2
- Encrypted storage of API keys and broker credentials
- Regular security audits and penetration testing
- Web application firewall (WAF) protection
Organizational Safeguards
- Role-based access controls for employees
- Security awareness training for team members
- Incident response procedures
- Regular data backup and disaster recovery testing
Important: While we implement industry-standard security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
7. Data Retention
We retain your data according to the following guidelines:
- Active Accounts: Data is retained for as long as your account is active
- Account Deletion: Personal data is deleted within 30 days of account deletion
- Anonymized Data: Aggregated, anonymized usage data may be retained indefinitely for analytics
- Legal Requirements: Some data may be retained longer as required by law (e.g., tax records, legal disputes)
- Backup Systems: Data may persist in backups for up to 90 days after deletion
8. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
General Rights
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a portable format
- Restriction: Request restriction of processing
- Objection: Object to certain types of processing
- Withdraw Consent: Withdraw consent where processing is based on consent
For European Union Residents (GDPR)
If you are in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to lodge a complaint with a supervisory authority
- Right to object to profiling and automated decision-making
- Right to receive information about data transfers outside the EEA
Our legal bases for processing include: consent, contract performance, legitimate interests, and legal obligations.
For California Residents (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed and to whom
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
- Right to correct inaccurate personal information
- Right to limit use of sensitive personal information
To Exercise Your Rights: Contact us at trytaktyx@gmail.com. We will respond within the timeframe required by applicable law (typically 30-45 days). We may need to verify your identity before processing your request.
9. Cookies and Tracking Technologies
We use cookies and similar technologies for the following purposes:
Essential Cookies
Required for the Service to function properly:
- Session management and authentication
- Security features (CSRF protection)
- Load balancing and performance
Functional Cookies
Enhance your experience:
- Remember your preferences (theme, timezone)
- Store your language preferences
Analytics Cookies
Help us understand how the Service is used:
- Track page views and feature usage
- Measure performance and errors
- Understand user journeys
Managing Cookies: You can control cookies through your browser settings. Note that disabling certain cookies may affect Service functionality. Most browsers allow you to block or delete cookies, but this may prevent you from using certain features.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer data internationally, we implement appropriate safeguards such as:
- Standard contractual clauses approved by relevant authorities
- Data processing agreements with service providers
- Compliance with applicable data transfer frameworks
11. Data Breach Notification
In the event of a data breach that affects your personal information:
- We will notify affected users within 72 hours of becoming aware of a qualifying breach
- We will notify relevant supervisory authorities as required by law
- We will provide information about the nature of the breach and steps you can take
- We will take immediate steps to contain and remediate the breach
12. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at trytaktyx@gmail.com.
If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.
13. Do Not Track Signals
Some browsers include a “Do Not Track” (DNT) feature that signals to websites that you do not want your online activity tracked. Currently, there is no uniform standard for responding to DNT signals, and we do not currently respond to DNT signals. However, you can manage your privacy preferences through your account settings and browser controls.
14. Third-Party Links
The Service may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
- Material Changes: We will notify you by email and/or prominent notice on the Service at least 30 days before changes take effect
- Non-Material Changes: May be made without prior notice
- The “Last updated” date at the top indicates when this policy was last revised
Your continued use of the Service after changes are posted constitutes acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Inquiries: trytaktyx@gmail.com
Data Protection Officer: trytaktyx@gmail.com
General Support: trytaktyx@gmail.com
We will respond to your inquiry within a reasonable timeframe, typically within 30 days.