BadRock Capital processes personal data needed to operate accounts, terminal workflows, payments, support and security.
Privacy requests and legal notices: support@badrock.capital.
We may process account data such as email, display name, locale, password hash, authentication provider IDs, Telegram IDs, access roles, subscription status, referral data and support messages.
We may process product data such as strategy settings, optimizer inputs and outputs, presets, reports, notifications, workspace preferences, terminal settings, connected account metadata, balances, positions, orders, trades, logs and local runtime connection status.
We may process security and operational data such as IP-derived data, device/browser data, timestamps, error logs, audit logs, rate-limit events and abuse-prevention records. Where practical, IP addresses and user agents used for legal acceptance are stored as hashes rather than raw values.
If you use Google Sign-In, BadRock requests only basic OAuth scopes such as openid, email and profile. We receive the Google account ID, email address, email verification flag, profile name and, if returned, profile picture or locale.
If Apple or Telegram sign-in is enabled, BadRock processes the identifiers and profile fields that the provider returns for account creation, login and security. Provider consent screens do not replace acceptance of BadRock Terms, Privacy Notice and Risk Disclosure.
We process data to create and secure accounts, provide terminal and optimizer functionality, maintain subscriptions and prepaid access, process invoices, prevent abuse, provide support, maintain audit trails, improve reliability and comply with legal or tax duties.
For users in GDPR-like jurisdictions, the main legal bases are contract for account and service delivery, legitimate interests for security, fraud prevention and operational logs, legal obligation for records that must be retained, and consent only where an optional feature requires consent.
The launch version does not use marketing emails, advertising pixels, third-party behavioral analytics or session replay. We use internal technical logs for security, diagnostics, reliability and abuse prevention.
If non-essential analytics, advertising tracking, session replay or marketing emails are introduced later, BadRock must update this notice and request the required opt-in or preference choice before using those features where required by law.
Data may be processed by hosting, database, email, authentication, Telegram, Google, Apple, TryBit, infrastructure and support providers where needed to operate the service. These providers may be located in different countries.
International transfers may occur depending on infrastructure and provider locations. BadRock applies appropriate safeguards where required by applicable law.
Account and product data is kept while the account is active and for a reasonable period afterward. Billing, payment, tax, legal acceptance, security and audit records may be retained longer where needed for legal, accounting, dispute, anti-fraud or security reasons.
Users may request account deletion through support. Some records may be anonymized, aggregated or retained where deletion would conflict with legal duties, security investigations, payment records, dispute evidence or abuse prevention.
BadRock applies technical and organizational safeguards such as authentication, role checks, access controls, encryption or hashing where appropriate, logging and limited access to operational systems. No system can be guaranteed to be perfectly secure.
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to or export your personal data, and to complain to a regulator. Contact support@badrock.capital to exercise privacy rights.