Legal
Privacy policy
What we collect, why we collect it, how long it stays, and what you can ask us to do with it. Stated in the same register as the rest of the product.
Effective [EFFECTIVE DATE]
Who we are
[QORIN LEGAL ENTITY], registered at [REGISTERED ADDRESS], builds software that lets traders configure and run automated strategies against their own brokerage or exchange accounts. It is the controller of the personal data described here.
Qorin is a software provider. We are not a broker-dealer, futures commission merchant, custodian, or investment adviser. We never hold your funds or securities. Your trades execute at your broker or exchange, under your account, using authorisation you grant us.
This policy applies to [PRODUCT NAME] and [WEBSITE DOMAIN]. Questions and requests go to [PRIVACY CONTACT EMAIL].
What we collect
Account information. Your name, email address, and a hashed representation of your authentication credentials. We do not store your password in readable form — we cannot see it, and neither can anyone who gains access to our systems.
Trading configuration and activity. The strategies you build or select, your risk limits and sizing rules, and the orders, positions, and performance history that result from running them. This is the data the product exists to produce and show back to you.
Broker and exchange credentials. When you connect an account, we store the credentials or access tokens needed to place orders and read account data on your behalf. This is the most sensitive category of data we hold, and it has its own section below.
Technical data. Your IP address, browser and device information, and the pages and features you request. Used to operate the service, keep it secure, and diagnose faults.
We do not collect health, biometric, precise location, or government-ID data, and we do not want it. If a feature ever changed that, we would update this policy and tell you before it took effect.
Broker and exchange connections
This section covers the credentials and tokens you give us to connect a broker or exchange, because it is the part of our system where a mistake would hurt you most.
- What we store. Where your broker or exchange supports OAuth or similar token-based authorisation, we store the token they issue, not your broker password. Where a broker only supports API key and secret pairs, we store those. [CONFIRM OAUTH VS API-KEY PER INTEGRATION]
- How it is protected. Credentials are encrypted at rest using [ENCRYPTION STANDARD] and decrypted only in memory, at the moment of use, by the systems that place orders. [EMPLOYEE ACCESS CONTROLS AND BREAK-GLASS LOGGING]
- What scope we request. We request the narrowest permissions your broker or exchange allows for placing trades and reading account data. [CONFIRM WHETHER ANY SUPPORTED BROKER API EXPOSES WITHDRAWAL OR TRANSFER SCOPES, AND WHETHER QORIN EVER REQUESTS THEM — IF NOT, SAY SO PLAINLY: IT IS A MATERIAL FACT]
- Revocation. You can disconnect an account at any time, from Qorin or directly at the broker. We then stop placing new orders under that connection and delete the stored credential within [X DAYS]. Orders already pending at your broker are unaffected — cancel those with your broker.
- What we never do. We do not use your broker credentials for any purpose other than the trading functions you configured, and we do not sell or share the contents of your brokerage account.
How we use information
We use the information above to provide the account and trading functionality you signed up for, execute the strategies and limits you configure, show you your own positions and performance, detect fraud and unauthorised access, keep the systems secure and reliable, provide support, meet legal obligations that apply to us, and improve the product using aggregated or de-identified data wherever the purpose allows it.
We do not use your trading activity, positions, or performance to build advertising profiles.
How we share information
We do not sell personal data. We do not share your trading activity, positions, or performance with advertisers, data brokers, or other customers.
We share information only with:
- Service providers who host our infrastructure, process payments, or provide support tooling, under contracts limiting them to that service. [NAME KEY SUBPROCESSORS]
- Your broker or exchange, to the extent necessary to place the orders you configured. This is inherent to how the product works.
- Law enforcement or regulators, where required by valid legal process, or to protect the rights, property, or safety of Qorin, our customers, or the public.
- A buyer or successor, if Qorin is involved in a merger, acquisition, or asset sale. We will tell you if your information changes hands this way.
How long we keep it
We keep information as long as we need it to provide the service, meet legal obligations, resolve disputes, and investigate security incidents:
- Account information — for the life of your account, plus [RETENTION PERIOD] after closure.
- Trading configuration and activity — [RETENTION PERIOD] after closure, to support dispute resolution and security investigations.
- Broker and exchange credentials — deleted or revoked within [X DAYS] of disconnection or account closure. We do not keep a live credential once it is no longer in use.
- Technical and log data — [LOG RETENTION PERIOD].
We are not ourselves subject to broker recordkeeping rules, so these periods are our choice rather than an obligation we inherited. Where you have a right to request deletion sooner we will honour it, except where we have a legitimate need to retain specific records, such as an open fraud investigation or a legal hold.
Security
We maintain administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, access controls and multi-factor authentication for internal systems, and [MONITORING AND TESTING PRACTICES].
No system is perfectly secure. If we learn of an incident that puts your information at risk we will tell you promptly, consistent with applicable law.
Your rights
If you are a California resident, you have the right to know what personal information and sensitive personal information we have collected, to correct it, to delete it, to limit our use of sensitive personal information, and to know whether we sell or share it. We do not sell personal information. We honour Global Privacy Control signals as a valid opt-out. [IF ANY MARKETING OR ANALYTICS TOOL COULD CONSTITUTE SHARING UNDER CCPA, THIS SECTION AND A FOOTER LINK MUST BE REVISED]
If you are a resident of Colorado, Connecticut, Virginia, or [OTHER APPLICABLE STATES], you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of its sale, use for targeted advertising, or certain profiling. If we deny a request you may appeal at [APPEAL CONTACT].
If you are in the EU or UK, you have the right to access, correct, delete, and port your data, to restrict or object to certain processing, and to withdraw consent where we rely on it. You may lodge a complaint with your local data protection authority.
We process EU and UK data on these bases: performance of our contract with you, our legitimate interests in fraud prevention and service reliability, legal obligation, and consent for marketing and non-essential cookies. Transfers outside the EU or UK rely on [THE EU-US DATA PRIVACY FRAMEWORK / STANDARD CONTRACTUAL CLAUSES / UK ADDENDUM — CONFIRM MECHANISM].
Contact [PRIVACY CONTACT EMAIL] to exercise any right described here. We will verify your identity before acting on a request involving your account, and we will not discriminate against you for asking.
Children's privacy
Qorin is not directed to, and is not available to, anyone under [MINIMUM AGE]. We do not knowingly collect information from children.
Changes
If we make a material change to this policy we will notify account holders by email before it takes effect. The effective date above always reflects the current version.