JuridischPrivacy Policy
Privacy Policy
Privacy Policy v1 · Effective 25 July 2026 · Last updated 25 July 2026
Deze pagina is in het Engels. De Engelse tekst is de bindende versie van dit document. Vragen? Mail info@aetherdesk.io.
This Privacy Policy explains how Aether Desk ("we", "us") collects, uses, and shares personal data when you use our website and application (the "Service"). It should be read with our Terms of Service.
Contact for privacy requests: info@aetherdesk.io.
1. Who we are
Aether Desk provides software for live-market practice and (when armed and supported) live automated futures trading workflows on exchanges you connect. Formal controller entity details may be updated when the operating company is designated; until then, privacy requests go to info@aetherdesk.io.
2. Data we collect
Account and profile
- Email address and authentication data (via our auth provider).
- Profile fields such as selected country / region, locale preference, onboarding step, plan tier, and referral codes when you use them.
Billing
- Subscription status, plan, interval, and payment references needed to deliver access.
- Stripe handles subscription checkout and billing (card and other methods Stripe supports); we do not store full card numbers on our servers. Crypto annual checkout may be handled by NOWPayments.
Exchange credentials and trading operations
- Exchange API credentials you submit (stored encrypted at rest for operation of the desk). You should use trade-only keys and disable withdrawals where possible.
- Operational data required to run paper and live desks: strategy selections, arm / disarm state, paper book state, fills and positions we record, kill / flatten events, and related audit or control events.
Technical and usage data
- Server logs, IP address, user agent, approximate request metadata, error reports, and security signals needed to operate, debug, and protect the Service.
- Cookies and similar technologies for authentication/session, locale preference, and essential site function (see Cookies below).
We do not sell personal data.
3. Why we process data (purposes and legal bases)
For users in the EEA/UK (where UK GDPR or GDPR concepts apply by analogy), we rely on:
- Contract: creating your account, providing the trial and paid Service, processing subscriptions, operating paper/live desks you configure.
- Legitimate interests: securing the Service, preventing abuse, improving reliability, understanding aggregate usage, and supporting customers, balanced against your rights.
- Legal obligation: where we must retain or disclose information under applicable law.
- Consent: where required for optional cookies or similar technologies (if introduced). Essential auth and security cookies do not rely on marketing consent.
4. Processors and subprocessors
We use service providers that process data on our behalf to run the product:
- Supabase: authentication, database, and related backend storage.
- Stripe: subscription checkout and billing (card and other methods Stripe supports).
- NOWPayments: crypto checkout for annual plans when offered.
- Vercel: hosting and delivery of the web application.
- Railway: hosting of backend / engine workers that operate desk logic.
Exchanges you connect (for example OKX, Binance, Bybit, Kraken, or others shown in product) receive API requests you authorize; those platforms process data under their own terms and privacy policies. We do not control exchange KYC or their retention.
5. Cookies
We use cookies and similar storage that are necessary to:
- Keep you signed in (session / auth cookies).
- Remember locale preference (for example NEXT_LOCALE).
- Remember a referral code when you arrive via an affiliate link (ad_ref, up to 30 days) so signup and checkout can attribute correctly.
- Remember first-touch campaign parameters when you arrive from ads or tracked links (ad_acq, up to 90 days: utm_source, utm_medium, utm_campaign, utm_content, utm_term, fbclid, and landing path) so we can attribute signup to the original campaign.
- Protect against common web abuse and ensure basic security.
We use the Meta (Facebook) Pixel to measure ad performance and conversions (for example page views, signup, and checkout). Meta may set cookies or use similar storage for this measurement. Where local law requires consent for advertising cookies, we will obtain it before enabling those cookies.
6. Retention
- Account and profile data: kept while your account is active and for a reasonable period afterward for security, dispute, and legal record needs.
- Billing records: retained as needed for accounting, chargebacks, and legal obligations.
- Exchange credentials: kept while needed to provide connect / live features you use; you may remove or rotate keys in product settings. We may delete or deactivate credentials when an account is closed or after prolonged inactivity, subject to backup cycles.
- Operational logs and desk history: retained for troubleshooting, abuse prevention, and product integrity for a limited period, then deleted or aggregated where practical.
7. Sharing
We share personal data only with:
- Processors listed above, under contractual obligations.
- Exchanges you choose to connect, via APIs you authorize.
- Authorities or advisors when required by law or to protect rights, safety, and security.
- A successor entity in a reorganization or sale, with notice where required.
8. International transfers
Our providers may process data in the EU, US, or other countries. Where GDPR applies, we rely on appropriate safeguards offered by those providers (such as Standard Contractual Clauses) where required for transfers outside the EEA.
9. Your rights (GDPR-oriented for EEA)
If you are in the EEA (and similarly where UK GDPR or local law grants comparable rights), you may have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase data in certain circumstances.
- Restrict or object to certain processing.
- Data portability for data you provided, where applicable.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local supervisory authority.
To exercise rights, email info@aetherdesk.io from the address on your account. We may need to verify your identity. Some data must be retained for legal or security reasons even after a deletion request.
10. Security
We use industry-standard measures appropriate to a small SaaS product, including encrypted storage of exchange credentials, HTTPS, and access controls. No method of transmission or storage is perfectly secure. You are responsible for strong passwords and for protecting devices used to access the Service.
11. Children
The Service is not directed to children. We do not knowingly collect personal data from anyone under 18 (or the higher age of digital consent in your country). If you believe a minor has provided data, contact us and we will take appropriate steps.
12. Changes
We may update this Privacy Policy. The "Last updated" date will change. Material changes may be communicated by email or in-product notice where appropriate.
13. Contact
Privacy: info@aetherdesk.io
Support: info@aetherdesk.io