1.Who we are
StrategyAlgo.com is the data controller for the information described in this policy. You can reach us through the contact details on our contact page.
2.What we collect
We collect only what the Service needs to function:
- Account data — your name and email address, supplied by Google when you sign in, or entered by you if you register with email and password.
- TradingView username — required so we know where to grant access.
- Contact channel — a WhatsApp number or Telegram username, used for support and access notifications.
- Payment data — invoice records, transaction hashes, and the wallet address you send from. Blockchain data is public by nature; we read it, we do not create it.
- Affiliate data — your promo code, referred accounts, commission records, and the payout wallet address you provide.
- Support messages — anything you send us when asking for help.
- Technical data — IP address and browser information, used for security and fraud detection.
3.What we never collect
Some things are deliberately absent from our systems:
- No card numbers or bank details. We do not process card payments at all.
- No private keys, seed phrases, or exchange API keys. We never ask for them, and you should never send them to anyone claiming to be us.
- No identity documents. We do not run a KYC process.
- No behavioural advertising profiles. We do not sell data and we do not run ad networks.
4.Why we use it
Each piece of data has a purpose:
- To create and secure your account, and to authenticate you.
- To verify payments against the blockchain and activate the right subscription.
- To grant, track, and revoke access on TradingView.
- To calculate affiliate commissions and process payouts.
- To send transactional email: invoices, access confirmations, renewal reminders.
- To detect fraud and abuse, including affiliate fraud.
- To comply with legal obligations where they apply.
5.Legal basis
Where the GDPR or a similar law applies to you, we rely on performance of a contract for account, payment and access data; legitimate interests for fraud prevention and service security; and legal obligation for record keeping. We do not rely on consent for anything essential to the Service, so withdrawing consent will never break your access.
6.Who else sees your data
We use a small number of processors, each for one purpose:
- Supabase — database, authentication, and file storage.
- Vercel — website hosting.
- Google — sign-in, if you choose that method.
- Resend — sending transactional email.
- BscScan and TronGrid — reading public blockchain data to verify payments. We send them a transaction hash, nothing about you.
- Anthropic — translating catalogue content into other languages. Only published product text is sent, never personal data.
We do not sell your data, and we do not share it with advertisers. We disclose data to authorities only where legally required.
7.International transfers
Our providers operate globally, so your data may be processed outside your country. Where required, transfers rely on standard contractual clauses or an equivalent safeguard offered by the provider.
8.How long we keep it
- Account data — for as long as your account exists, then 90 days after deletion.
- Invoices, payments, and commission records — 7 years, for accounting and tax purposes. These cannot be deleted on request.
- Access history — for as long as your account exists, so that we can answer disputes about what was granted and when.
- Support messages — 24 months.
- Technical logs — 90 days.
9.Your rights
Depending on where you live, you may have the right to:
- Ask what data we hold about you and receive a copy.
- Correct anything inaccurate.
- Delete your account and the data that is not legally required to be kept.
- Object to processing based on legitimate interests.
- Export your data in a portable format.
Contact us to exercise any of these. We respond within 30 days. We may ask you to confirm your identity first, because we would rather be slow than hand your data to the wrong person.
10.Cookies
We use very few cookies, and none for advertising:
- Session cookie — keeps you signed in. Essential.
- NEXT_LOCALE — remembers your chosen language for one year.
Our analytics is cookieless and does not track individuals across sites, which is why you are not being shown a consent banner. Video thumbnails on our pages are static images; YouTube is only contacted after you press play.
11.Security
Access to your data is enforced at the database level, not only in the interface, so a flaw in the front end does not expose other member records. Administrative accounts require two-factor authentication. All traffic is encrypted in transit.
No system is perfect. If a breach affects you, we will tell you and the relevant authority within the timeframes the law requires.
12.Children
The Service is not for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, tell us and we will remove it.
13.Changes to this policy
When this policy changes materially we will email account holders and update the version and date on this page. Minor clarifications may be made without notice.
14.Contact
Privacy questions, access requests, and deletion requests can all be sent through our contact page.