Last Updated & Effective Date: July 2026 | Document Ref: ALG-PRIV-001
Entity: Algor Terminal
Compliance Framework: Standard SaaS Data Privacy, UK GDPR & CCPA Aligned
This Privacy Policy outlines how Algor Terminal ("we", "our", or "us") collects, secures, processes, and protects end-user data within our algorithmic trading studio and SaaS application. By utilizing our platform, you consent to the data practices described herein.
2.1 Account & Identity Data: We collect basic profile information required for SaaS authentication, including email addresses, display names, and OAuth authentication tokens via our identity provider (Supabase Auth).
2.2 Brokerage Integration Data (OAuth 2.0 Exclusivity): When a user links a third-party brokerage account, authentication is conducted exclusively via OAuth 2.0 Authorization Code Flows or secure API keys. Algor Terminal never collects, intercepts, transmits, or stores raw brokerage account usernames, passwords, or Two-Factor Authentication (2FA) credentials.
2.3 Quantitative & Strategy Data: We store user-created algorithmic trading strategies, backtest parameters, custom webhook endpoints, and automated execution logs within our encrypted database to provide core software functionality.
3.1 Core Service Delivery: Collected information is utilized exclusively to:
3.2 No Proprietary Trading or Front-Running: Algor Terminal and its developers do not inspect, exploit, mirror, or front-run user-created trading strategies or order pipelines. All user strategies are treated as confidential intellectual property of the end-user.
4.1 No Data Sale or Commercial Licensing: We do NOT sell, rent, lease, or monetize user personal information, strategy logic, or trade execution histories to advertisers, data brokers, or hedge funds.
4.2 Authorized Brokerage Communication: Data is exchanged with integrated brokerage partners strictly through encrypted API requests authenticated by the user's OAuth token or API keys for the sole purpose of fetching account balances and routing execution orders as directed by the user.
4.3 Infrastructure Providers: We share encrypted data payloads with audited cloud infrastructure providers (Vercel for serverless hosting; Supabase/AWS for PostgreSQL database storage) solely for hosting and data retention purposes.
5.1 User Revocation: Users may disconnect their linked brokerage accounts at any time via the Algor Terminal Universal Broker Vault. Disconnecting an account immediately invalidates and purges the stored OAuth Access Token from our active production database.
5.2 Right to Erasure: Users reserve the right to request full deletion of their Algor Terminal SaaS account and all associated strategy histories by submitting a written request to privacy@algor.trade. Upon verification, all user profile and strategy data will be purged within 30 days.