Introduction
Orchid Edge ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our website and services.
Information We Collect
We collect information you provide directly to us, including:
- Contact Information: Name and email address when you join our waitlist or contact us
- Communication Data: Messages you send through our contact form
- Account Information: When you create an account, we collect username, email, password (encrypted), and profile settings
- Trading Data: Journal entries, trade logs, notes, screenshots, performance metrics, and custom tags you create within the app
- Broker Connection Data: If you choose to connect your trading account, we collect API credentials (encrypted and stored securely), trade execution data, and account balances. We never have access to withdraw funds from your accounts.
- Prop Firm Account Data: Account names, rule configurations, and performance tracking data for your prop trading accounts
- Usage Data: Information about how you interact with our website and app, including pages visited, features used, and error logs
- Device Information: Browser type, operating system, IP address, and device identifiers
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve Orchid Edge services
- Process and display your trading journal entries and analytics
- Connect to broker APIs to import your trade data (only with your explicit permission)
- Monitor prop firm rules and send you violation alerts
- Send you updates about Orchid Edge and our launch
- Respond to your inquiries and support requests
- Send occasional trading insights and educational content (if subscribed)
- Detect and prevent fraud, abuse, and security incidents
- Analyze usage patterns to improve our features and user experience
- Comply with legal obligations and enforce our Terms of Service
Data Security
We take the security of your financial and trading data seriously and implement industry-standard security measures:
- Encryption: All data transmission uses TLS/SSL encryption. Passwords and broker API credentials are encrypted at rest using industry-standard algorithms.
- Access Controls: Your trading data is only accessible to you. We implement strict access controls and authentication requirements.
- Secure Infrastructure: Our servers and databases are hosted with reputable cloud providers with SOC 2 compliance.
- No Sale of Data: We do not sell, trade, or rent your personal information or trading data to third parties. Your journal entries and trades are yours alone.
- Read-Only Broker Access: When you connect broker accounts, we only request read-only API permissions. We cannot execute trades or withdraw funds from your accounts.
While we implement strong security measures, no system is 100% secure. You are responsible for keeping your account credentials confidential.
Email Communications
By joining our waitlist or subscribing to our newsletter, you agree to receive email communications from us. Every email includes an unsubscribe link, and you can opt out at any time. We respect your inbox and will never spam you.
Cookies
We use essential cookies to ensure our website functions properly. These cookies do not track your browsing activity across other sites. You can control cookie settings through your browser preferences.
Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Unsubscribe from marketing communications
Third-Party Services
We use the following third-party services to operate Orchid Edge. These providers are bound by their own privacy policies and we only share the minimum information necessary:
- Hosting & Infrastructure: Vercel (hosting), Supabase/PostgreSQL (database), AWS S3 (file storage)
- Authentication: Supabase Auth for secure user authentication
- Email Services: Resend or similar service for transactional emails and notifications
- Analytics: We may use privacy-focused analytics tools to understand usage patterns. We do not use invasive tracking.
- Security: Google reCAPTCHA to prevent spam and abuse on our contact forms
- Payment Processing: Stripe for secure payment processing (coming soon)
- Market Data: Databento for historical market data used in Academy and replay features
We do not share your trading journal data, trade logs, or personal notes with any third-party service. This data remains strictly within our secure infrastructure.
Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Active Accounts: Your trading data and journal entries are retained for as long as your account is active
- Deleted Accounts: When you delete your account, we permanently delete your trading data, journal entries, and personal information within 30 days, except where we are required to retain data for legal or regulatory compliance
- Backups: Deleted data may persist in encrypted backups for up to 90 days before permanent deletion
- Waitlist Data: Email addresses collected before launch are retained until you opt out or request deletion
Children's Privacy
Orchid Edge is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. Trading futures and leveraged products requires you to be of legal age in your jurisdiction. If you believe we have inadvertently collected information from a child under 18, please contact us immediately and we will delete such information.
International Data Transfers
Orchid Edge is based in the United States, and your information is processed and stored on servers located in the United States. If you access our services from outside the U.S., your information will be transferred to, stored, and processed in the United States. By using Orchid Edge, you consent to the transfer of your information to the United States and processing in accordance with this Privacy Policy and U.S. law.
Your Privacy Rights
Depending on your location, you may have specific privacy rights:
California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell your data)
- Non-discrimination for exercising your privacy rights
European Residents (GDPR)
If you are in the European Economic Area, you have the right to:
- Access, correct, or delete your personal data
- Object to or restrict processing of your data
- Data portability (receive your data in a structured format)
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
To exercise any of these rights, please contact us using the information below.
Governing Law
This Privacy Policy and any disputes related to privacy are governed by the laws of the State of Delaware and the United States, without regard to conflict of law provisions. You agree to submit to the exclusive jurisdiction of the courts located in Delaware for resolution of any disputes.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any significant changes by posting the new policy on this page, updating the "Last updated" date, and (for material changes) sending you an email notification if you have an account with us. Your continued use of Orchid Edge after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this privacy policy, our data practices, or wish to exercise your privacy rights, please contact us:
- Email: Via our contact form
- Response Time: We will respond to privacy requests within 30 days