We respect your privacy. We don't sell your data, we don't send it to advertisers, and we store your broker credentials encrypted at rest. You can request deletion at any time.
1. Introduction
HFTSignal ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your information.
This policy applies to the Platform at app.hftsignal.com and any related services.
2. Data We Collect
2.1 Account Information
When you sign in via Google OAuth, we receive and store:
- Your email address — used for account identification and communication.
- Your Google profile name — used for display purposes within the Platform.
- Your Google account ID — used as a unique user identifier.
We do not receive or store your Google password.
2.2 Broker Credentials
To connect to your broker account, you voluntarily provide:
- API Key and API Secret — stored encrypted at rest using envelope encryption (AES-256).
- Access Tokens — obtained via broker OAuth flows, stored encrypted, and used only to route orders on your behalf.
Broker credentials are never logged, transmitted in plain text, or shared with third parties.
2.3 Strategy and Configuration Data
We store:
- Strategy code (YAML) that you create, copy, or configure on the Platform.
- Profile and run configurations, including parameter values you set.
- Run history, backtest results, trade logs, and execution metrics from your strategies.
2.4 Usage and Analytics Data
We collect anonymised or pseudonymised usage data to improve the Platform, including:
- Pages visited and features used — via Google Analytics 4 (Firebase Analytics).
- User ID — your internal HFTSignal database user ID (not your email or Google ID) is set as the Analytics User ID for session stitching.
- Hashed email — a one-way SHA-256 hash of your email is stored as a User Property for cross-platform analytics mapping. This is not reversible.
- Screen views, button clicks, and error events — to understand product usage and fix issues.
We do not send your raw email address, name, or broker credentials to any analytics service.
2.5 Audit and Security Logs
We maintain append-only audit logs of sensitive operations including:
- Secret access events (when credentials are resolved for trade execution).
- Account connection and disconnection events.
- Run launches and cancellations.
These logs are used for security monitoring and are not shared externally.
2.6 Technical Data
Standard server logs including IP addresses, browser type, operating system, and timestamps are collected for security, debugging, and operational purposes.
3. How We Use Your Data
| Data | Purpose |
|---|---|
| Email address | Account identification, communication, support |
| Broker credentials | Executing trades and fetching data on your behalf |
| Strategy / run data | Providing the Platform's core functionality |
| Analytics data | Product improvement, understanding feature usage |
| Audit logs | Security monitoring, compliance |
| Technical logs | Debugging, infrastructure operations |
We do not use your data to:
- Sell to third parties.
- Target you with advertising (beyond in-product communications about HFTSignal features).
- Build profiles for external marketing purposes.
- Make automated decisions that have legal or significant effects on you.
4. Legal Basis for Processing
We process your personal data on the following bases (under applicable Indian data protection law):
- Contractual necessity — to provide the Platform services you have signed up for.
- Legitimate interests — for security monitoring, fraud prevention, and product improvement.
- Consent — where you have provided explicit consent (e.g., analytics tracking).
5. Data Sharing
We do not sell your personal data. We share data only in the following limited cases:
5.1 Broker APIs
Your broker credentials and trade instructions are transmitted to your chosen broker's API systems (e.g., Zerodha Kite API) solely to execute the actions you have configured on the Platform.
5.2 Infrastructure Providers
We use cloud infrastructure providers (e.g., Google Cloud) to host the Platform. These providers process data on our behalf under appropriate data processing agreements.
5.3 Analytics
Google Analytics 4 (Firebase Analytics) receives pseudonymised usage event data. No raw personal data (name, email, broker credentials) is sent to Google Analytics.
5.4 Legal Requirements
We may disclose your data if required by law, court order, or a legitimate request from a regulatory authority (such as SEBI or law enforcement), or to protect our legal rights.
6. Data Retention
| Data Type | Retention |
|---|---|
| Account data | Retained while your account is active; deleted within 90 days of account closure on request |
| Broker credentials | Deleted immediately on broker account disconnection |
| Run and backtest history | Retained while your account is active |
| Analytics data | Governed by Google Analytics 4 data retention settings (default 14 months) |
| Audit and security logs | Retained for 2 years for security and compliance purposes |
7. Data Security
We implement the following to protect your data:
- Encryption at rest — broker credentials use envelope encryption (AES-256 key wrapping).
- Encryption in transit — all data transmitted between your browser, our servers, and broker APIs uses TLS 1.2 or higher.
- Access controls — internal access to production data is restricted to authorised personnel only.
- No plaintext logging — broker API keys, secrets, and access tokens are never written to logs.
Despite these measures, no system is completely secure. You use the Platform at your own risk with respect to data security.
8. Your Rights
Under applicable Indian data protection law (including the Digital Personal Data Protection Act, 2023 to the extent in force), you have the following rights:
To exercise any of these rights, reach us through:
- In-app (preferred): Use Help → Submit a Query inside the Platform.
- Email: shubh.agr1994@gmail.com
9. Cookies
The Platform uses the following cookies:
| Cookie | Purpose |
|---|---|
_forum_session | Authentication session management |
_ga, _ga_* | Usage analytics (pseudonymised) |
| Firebase Analytics | In-app event tracking |
You can disable analytics cookies through your browser settings. This will not affect your ability to use the core Platform.
10. Third-Party Links
The Platform may contain links to third-party services (e.g., broker login pages, documentation). We are not responsible for the privacy practices of those third parties. Please review their privacy policies separately.
11. Children
The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us at shubh.agr1994@gmail.com and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice. The "Last Updated" date at the top of this document reflects the most recent revision.
13. Contact and Grievance Officer
For any privacy concerns or to exercise your rights:
- In-app (preferred): Use Help → Submit a Query inside the Platform.
- Email: shubh.agr1994@gmail.com
Data Protection / Grievance Officer: Shubham Agrawal
Address: HFTSignal, Bengaluru, Karnataka, India
We will respond to all requests within 30 days.
© 2026 HFTSignal. All rights reserved.