Privacy Policy
Effective date: February 11, 2026
Last updated: February 11, 2026
FerroQuant ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at ferroquant.com and related services.
1. Information We Collect
1.1 Information You Provide
- Account data: Name, email address, and authentication credentials (managed by our native authentication system)
- Payment data: Billing information processed securely by Stripe. We do not store full card numbers
- Exchange credentials: API keys for connected exchanges, encrypted with AES-256-GCM at rest
- Communication: Messages sent through our support system
1.2 Information Collected Automatically
- Operational audit data: Authentication/session lifecycle and authenticated state-changing account, settings, security, trading, backtest and administrative actions, including request method, route and outcome. Request bodies and sensitive values are not copied into this audit trail
- Optional usage analytics: With your consent, pages and product panels viewed, privacy-safe feature interactions, safe setting choices and changes, session duration, and technical errors
- Device data: Browser type, operating system, screen resolution
- Log data: IP address, access times, referring URLs
- Cookies: Session cookies for authentication and preferences
1.3 Information We Do NOT Collect
- We do not read, access, or store your exchange account balances or positions beyond what you explicitly request through our platform
- We do not sell, rent, or share your personal information with third-party advertisers
1.4 Optional Product Analytics and Session Replay
If you choose “Allow analytics”, FerroQuant records privacy-safe product telemetry and may create a masked visual replay of the session to help diagnose usability problems and understand product workflows. This includes panel usage, safe setting changes, navigation, layout interactions, and technical errors. Passwords, authentication tokens, API keys, broker credentials, payment data, private keys, and sensitive input values are excluded or masked before replay data leaves the browser.
This optional processing uses our self-hosted Umami service. It starts only after consent and can be withdrawn at any time from Privacy preferences in the account menu. Withdrawing consent stops analytics and reloads the current page to terminate any active replay recorder.
Separate from optional analytics, FerroQuant keeps essential server-side operational and security audit records needed to authenticate users, protect accounts, investigate failures and preserve the integrity of state-changing actions. Declining or withdrawing analytics does not disable these records. The mandatory audit trail records action metadata and outcome, not request bodies, passwords, authentication tokens, API keys, broker credentials, payment data or private keys.
2. How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and operate the Service | Contract performance |
| Process payments and manage subscriptions | Contract performance |
| Send transactional emails (welcome, payment receipts, alerts) | Contract performance |
| Maintain essential account, security and operational audit records | Contract performance and legitimate interests in security, fraud prevention and service integrity |
| Optional product analytics and privacy-masked session replay used to improve the Service | Consent |
| Prevent fraud and abuse | Legitimate interest |
| Send marketing communications (only with consent) | Consent |
| Comply with legal obligations | Legal obligation |
3. Data Sharing
We share data only with:
- Stripe: Payment processing
- Google: OAuth authentication (optional sign-in with Google)
- Listmonk: Transactional and marketing emails (self-hosted)
- Umami: Product analytics, heatmaps, and privacy-masked session replay hosted by FerroQuant on our own infrastructure and used only after analytics consent
- Cloudflare: CDN, DDoS protection, and DNS
We do not sell your data to third parties.
4. Data Security
- All data in transit is encrypted with TLS 1.3
- Exchange API keys are encrypted at rest with AES-256-GCM
- Database connections use SSL
- Sessions are secured with HttpOnly, Secure, SameSite cookies
- HMAC-SHA256 verification on all webhooks (Stripe, etc.)
- Content Security Policy (CSP) with per-request nonces
5. Data Retention
- Account data: Retained while your account is active, deleted within 30 days of account closure
- Optional usage analytics: Aggregated and anonymized after 90 days
- Operational audit records: Retained for up to 1 year for account security, service integrity, troubleshooting and dispute investigation
- Payment records: Retained as required by tax and financial regulations (typically 7 years)
- Exchange credentials: Deleted immediately upon disconnection
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Change or withdraw analytics/session-replay consent through Privacy preferences, and opt out of marketing communications at any time
To exercise these rights, email [email protected] or visit our Data Deletion page.
7. Cookies
We use essential cookies for the Service. Optional product analytics and replay are enabled only after you consent. That consent preference is stored in your browser; our self-hosted Umami integration does not require third-party advertising or tracking cookies.
- Session cookie: Maintains your login session (HttpOnly, Secure)
- CSRF token: Protects against cross-site request forgery
- Preferences: Remembers your theme and layout settings
We do not use third-party advertising cookies or sell analytics data. Optional analytics and replay are processed on FerroQuant-controlled self-hosted infrastructure.
8. International Data Transfers
Your data may be processed in countries outside your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where applicable.
9. Children's Privacy
FerroQuant is not intended for anyone under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email. The "Last updated" date at the top indicates the most recent revision.
11. Contact
Last updated: February 11, 2026